Skip to main content

Launch controls, stated plainly

Clinical decisions stay human.Staff stay in control.

How Brigid supports GDPR accountability and Irish health-data security, including the evidence that remains required before production launch.

Built in IrelandEU data hostingGDPR accountability programme
Last updated: 29 September 2026

GDPR & Irish Data Protection Programme

Our documented privacy programme is designed around the Irish Data Protection Act 2018 and GDPR. The product includes workflows that help controllers respond to access, rectification, erasure, portability and objection requests. Compliance still depends on each clinic selecting a lawful basis, configuring the service appropriately, training staff, and completing its own accountability duties.

Patient preference records support workflow choices but do not themselves establish a clinic lawful basis
Article 28 Data Processing Agreement published for execution with each clinic customer
Working Article 30 Records of Processing Activities (ROPA); accountable approval remains a launch gate
Incident-response process supports the controller’s Article 33 assessment and 72-hour deadline

Where records live: AWS Dublin (eu-west-1)

Supabase — the managed Postgres and object-storage service above — runs its EU project on AWS infrastructure in Dublin (eu-west-1), so a patient record created in Brigid is written and stored on AWS Dublin from the first save. Some communications, monitoring and mapping paths use US processors (for example email delivery and map display); the Sub-Processor Register names each route, and several of them — including telehealth recording, SMS to patients and WhatsApp — are switched off, and several that are on still have their transfer instrument not yet captured.

Primary database and object storage: AWS Dublin (eu-west-1), via Supabase
Backup, point-in-time recovery and restore evidence are tracked as release gates, not asserted here
Routes that use a non-EU processor are named in the Sub-Processor Register with their own transfer evidence
Availability commitments apply only where stated in an executed order form or service level agreement
Security controls are mapped against relevant HSE guidance; no HSE or other regional hosting certification is claimed

International Transfers (EU–US Data Privacy Framework)

Primary patient records are hosted in AWS Dublin (eu-west-1). Each communications, monitoring, voice, AI and telehealth route has its own location and transfer analysis. Google Generative AI on Vertex AI (Frankfurt, europe-west3) is used for drafting notes and letters the clinician reviews and signs, and for administrative routes with a declared administrative intended purpose; it is not approved for clinical decision-making.

Google Vertex AI (Frankfurt, europe-west3; Gemini 3.5 Flash) serves note and letter drafting and the declared administrative routes — pre-consultation chart summary, document-filing scan, mailbox triage, emailed-document filing, onboarding assistant and the staff assistant; production purpose, route and log evidence are release records
“Live with Brigid” is disabled by default; its only release candidate is EU Vertex administrative-only, with clinical tools and media attachments blocked
The former Google AI Studio / US-audio Live route is disabled and is not an opt-in fallback
Google Cloud Speech-to-Text provides the EEA transcription route without ElevenLabs or US medical-model fallback; original consultation audio is deleted within 24 hours after the clinician accepts the note, and within seven days at the most
Controller-enabled vendor routes remain disabled until the applicable agreement, region, retention and access evidence is complete

Security controls and evidence

Provider-managed encryption at rest and transport protection are part of the intended control set. Production configuration, cipher and access evidence must be verified before launch; this page does not turn an unevidenced setting into a guarantee.

Provider encryption and transport settings are checked against production evidence
Defined platform-security and clinical-access events are logged under the approved logging and retention schedule
Multi-factor authentication is available on every account; privileged access was last reviewed on 31 August 2026
RLS is required on in-scope patient-data tables; current database security-lint findings must be closed or formally accepted before launch

Irish healthcare context

The product is designed for Irish private-practice workflows. Relevant HSE, professional confidentiality and record-keeping guidance is considered during the control review, but no HSE, Medical Council, CORU, Dental Council, NMBI, PSI, PCRS or HealthLink approval or certification is claimed.

Professional and HSE guidance is mapped in the working accountability pack and remains subject to review
No regulator is represented as having accepted the audit-log format
HealthLink, PCRS and other external routes remain launch-gated until contract and configuration evidence is complete
Privacy, confidentiality and record-retention controls must follow applicable law, professional guidance and each controller’s documented schedule

EU AI Act readiness

The intended purpose is clinic administration, including drafting notes and letters that the clinician reads and signs. AI that diagnoses, triages or recommends, and patient-facing Generative AI, are disabled. The system inventory, role analysis and risk classification are maintained as release records; each administrative route was declared by the accountable director (25 August to 28 September 2026), and EU AI Act Article 50 transparency has applied since 2 August 2026.

Patient-facing Generative AI is disabled: the MyBrigid app has no AI chat or AI-written reply
AI runs only on routes with a declared administrative intended purpose — note and letter drafting, pre-consultation chart summary, document-filing scan, mailbox triage, emailed-document filing, onboarding assistant and the staff assistant — and remains subject to approved staff instructions and competence measures
No AI output may diagnose, triage, prescribe or recommend care, and a draft is not part of the clinical record until a clinician signs it
A patient preference or terms acknowledgement cannot override the server-side purpose boundary

EU AI Act Article 50: what patients and clinics are told

Article 50 transparency duties have applied since 2 August 2026. Staff and patients are told when they are dealing with an AI system, and AI-generated output on the surfaces in production today is labelled before anyone acts on it — the same disclosure obligation, stated on its own here rather than folded into the wider AI Act readiness summary above.

The in-product assistant identifies itself as AI before a staff member interacts with it (Article 50(1))
AI-generated output on the surfaces in production today is labelled before staff act on it (Article 50(2)); a small number of remaining surfaces are tracked as open actions ahead of their own deadlines
AI-generated images carry a machine-readable watermark; machine-readable marking of exported documents is being completed within the transition period ending 2 December 2026
Patient-facing Generative AI and AI that diagnoses, triages or recommends remain disabled, so no patient is put in the position of relying on an undisclosed AI system
Brigid can draft a note or letter from the consultation, marked as AI-drafted, for the clinician to review and sign

EU Medical Devices Regulation (MDR)

DJG Media Limited (trading as Brigid), CRO No. 762838 does not claim a CE mark for the current product. The launch intended purpose is clinic administration. Brigid can draft a note or letter from what was said in the consultation, for the clinician to review and sign; Generative AI that interprets, diagnoses, triages or recommends, and patient-facing Generative AI, are disabled. A documented software-qualification and intended-purpose assessment, approved by an accountable person and reviewed by qualified counsel where needed, remains a launch gate; this page does not make the legal classification conclusion.

Brigid does not diagnose, treat, triage, prescribe, code, or recommend care
Clinicians author and release clinical notes, letters, referrals and prescriptions
No CE mark is held or claimed for the launch product
See the working Software qualification statement; accountable approval remains required

Certifications & Audits

We claim only what is evidenced today. A GDPR accountability programme is in progress and remains subject to final launch evidence and legal sign-off; GDPR is not itself a product certification. The Aikido feed is currently disabled and the latest retained snapshot still contains unresolved findings, so no continuous-scanning claim is made. We do not currently hold SOC 2, ISO 27001, or HIPAA certifications.

GDPR — documented accountability programme; final evidence and legal sign-off remain explicit launch gates
Aikido feed currently disabled; the retained findings and endpoint-coverage gap must be closed and fresh evidence captured
No EU MDR CE mark is held or claimed; formal software qualification remains a release record
No SOC 2, ISO 27001, or HIPAA certifications held or claimed