GDPR & Irish Data Protection Programme
Our documented privacy programme is designed around the Irish Data Protection Act 2018 and GDPR. The product includes workflows that help controllers respond to access, rectification, erasure, portability and objection requests. Compliance still depends on each clinic selecting a lawful basis, configuring the service appropriately, training staff, and completing its own accountability duties.
Where records live: AWS Dublin (eu-west-1)
Supabase — the managed Postgres and object-storage service above — runs its EU project on AWS infrastructure in Dublin (eu-west-1), so a patient record created in Brigid is written and stored on AWS Dublin from the first save. Some communications, monitoring and mapping paths use US processors (for example email delivery and map display); the Sub-Processor Register names each route, and several of them — including telehealth recording, SMS to patients and WhatsApp — are switched off, and several that are on still have their transfer instrument not yet captured.
International Transfers (EU–US Data Privacy Framework)
Primary patient records are hosted in AWS Dublin (eu-west-1). Each communications, monitoring, voice, AI and telehealth route has its own location and transfer analysis. Google Generative AI on Vertex AI (Frankfurt, europe-west3) is used for drafting notes and letters the clinician reviews and signs, and for administrative routes with a declared administrative intended purpose; it is not approved for clinical decision-making.
Security controls and evidence
Provider-managed encryption at rest and transport protection are part of the intended control set. Production configuration, cipher and access evidence must be verified before launch; this page does not turn an unevidenced setting into a guarantee.
Irish healthcare context
The product is designed for Irish private-practice workflows. Relevant HSE, professional confidentiality and record-keeping guidance is considered during the control review, but no HSE, Medical Council, CORU, Dental Council, NMBI, PSI, PCRS or HealthLink approval or certification is claimed.
EU AI Act readiness
The intended purpose is clinic administration, including drafting notes and letters that the clinician reads and signs. AI that diagnoses, triages or recommends, and patient-facing Generative AI, are disabled. The system inventory, role analysis and risk classification are maintained as release records; each administrative route was declared by the accountable director (25 August to 28 September 2026), and EU AI Act Article 50 transparency has applied since 2 August 2026.
EU AI Act Article 50: what patients and clinics are told
Article 50 transparency duties have applied since 2 August 2026. Staff and patients are told when they are dealing with an AI system, and AI-generated output on the surfaces in production today is labelled before anyone acts on it — the same disclosure obligation, stated on its own here rather than folded into the wider AI Act readiness summary above.
EU Medical Devices Regulation (MDR)
DJG Media Limited (trading as Brigid), CRO No. 762838 does not claim a CE mark for the current product. The launch intended purpose is clinic administration. Brigid can draft a note or letter from what was said in the consultation, for the clinician to review and sign; Generative AI that interprets, diagnoses, triages or recommends, and patient-facing Generative AI, are disabled. A documented software-qualification and intended-purpose assessment, approved by an accountable person and reviewed by qualified counsel where needed, remains a launch gate; this page does not make the legal classification conclusion.
Certifications & Audits
We claim only what is evidenced today. A GDPR accountability programme is in progress and remains subject to final launch evidence and legal sign-off; GDPR is not itself a product certification. The Aikido feed is currently disabled and the latest retained snapshot still contains unresolved findings, so no continuous-scanning claim is made. We do not currently hold SOC 2, ISO 27001, or HIPAA certifications.
