Ethics & Privacy

GPDR compliance logo

GDPR 
compliant

The General Data Protection Regulation (GDPR) is a regulation in the European Union that came into effect on May 25, 2018. It aims to protect the personal data and privacy of EU citizens. The regulation imposes strict rules on data handling, processing, and storage, giving individuals greater control over their personal data and ensuring transparency and security from organizations handling such data.

Swiss data protection law logo

HIPAA
compliant

The Health Insurance Portability and Accountability Act (HIPAA), enacted in 1996, protects the privacy and security of individuals’ medical information. It establishes national standards for handling, using, and disclosing protected health information (PHI) by healthcare providers and insurers. HIPAA mandates strict security measures to prevent unauthorized access and misuse.

ISO27001 compliance logo

Certified
servers

ISO 27001 is an international standard for Information Security Management Systems (ISMS). It provides a framework for organizations to manage and protect their information assets, ensuring the confidentiality, integrity, and availability of data. Compliance with ISO 27001 helps organizations to systematically manage sensitive information and implement robust security controls to mitigate risks.

We take your data privacy seriously.

Data Processing
We prioritize the security and protection of your personal information.

Data is stored securely on European servers designed to meet GDPR and HDS requirements, within infrastructure certified to ISO/IEC 27001 standards. Upon request, we can also deploy to in-region servers and support compliance with applicable local regulatory requirements, such as HIPAA or PIPEDA.

Data is encrypted in transit and at rest using industry-standard safeguards, including TLS and AES-256 where applicable. We apply strict access controls, audit logging, and data minimization practices to protect sensitive information at every stage.

Where possible, data is pseudonymized or de-identified to reduce the use of identifiable information

Customers retain full control over their data, including the ability to access or permanently delete it at any time.

Learn from Microsoft how Virtuosis AI handles data.
Data processing
Fairness
Virtuosis AI is built with diversity at its core.

Grounded in strong scientific literature and developed in collaboration with physicians and speech scientists, our models are trained on highly diverse datasets to support fair and equitable outcomes across sex, age, ethnicity, language, and accent.
Fairness at work
Transparency
Virtuosis AI always requires individual consent.

We believe AI should be transparent and explainable, and we can provide clear explanations of your results.
Data Transparency
Privacy
Your personal insights are visible only to you.

Only with your explicit consent may your doctor and authorized healthcare team access your information to provide better care.

We never share your personal data with your employer or insurance provider.
Data privacy