HealthTech HQ Sync 44+ stakeholder roles 55+ products 48+ revenue streams 17 markets 18+ scheme paths 85+ OSS components Launch ready on subdomain, folder, or white-label
Platform Pulse 18 role journeys 253+ modules 48+ revenue paths 55+ products 17 markets 12+ deployment profiles regional & global languages 40+ compliance frameworks Launch deployment map

GDPR Compliance

Our commitment to protecting personal data under the EU General Data Protection Regulation.

IdeaDunes Healthcare is committed to GDPR compliance for all EU/EEA data subjects. We act as a Data Processor on behalf of our healthcare customers (Data Controllers).

Our GDPR Commitments

Data Subject Rights

Full support for access, rectification, erasure, portability, and objection rights.

Data Processing Agreement

Standard DPA available for all customers. Custom DPAs for enterprise.

Privacy by Design

Data minimization, purpose limitation, and privacy built into every feature.

EU Data Residency

Option to store data in EU-region data centers for EU customers.

Data Subject Rights

Under GDPR, data subjects (patients and users) have the following rights, which IdeaDunes fully supports:

Lawful Basis for Processing

Technical & Organizational Measures

International Data Transfers

For EU/EEA data subjects, we offer EU data residency. When data must be transferred outside the EU (e.g., to our India headquarters for support), we rely on Standard Contractual Clauses (SCCs) as approved by the European Commission.

Data Protection Officer

DPO Contact

Email: dpo@ideadunes.com

IdeaDunes, No. 9, Hindustan Court, Lane No. 6, Kalyani Nagar, Pune, Maharashtra 411006, India

Sub-Processors

We use the following sub-processors, all of which have been assessed for GDPR adequacy:

Sub-ProcessorPurposeLocationSafeguards
Amazon Web Services (AWS)Cloud infrastructure & hostingEU (Frankfurt), India (Mumbai)SCCs, SOC 2
Microsoft AzureCloud infrastructure (optional)EU (Netherlands), India (Pune)SCCs, SOC 2
Razorpay / StripePayment processingIndia / USAPCI DSS, SCCs
Twilio / SendGridSMS & email communicationsUSADPA, SCCs
SentryError monitoring (no PII)USADPA, anonymized

We notify customers 30 days before adding a new sub-processor. You may object if the new sub-processor does not meet your data protection requirements.

Data Processing Agreement (DPA)

Standard DPA Available

Our standard Data Processing Agreement covers GDPR Article 28 requirements, including processing instructions, confidentiality, security measures, sub-processor management, and breach notification.

Request DPA Security Practices

Related Policies

Get Started Today

Transform Your Healthcare Practice with IdeaDunes

Join hundreds of hospitals and clinics using IdeaDunes to streamline operations, improve patient care, and grow revenue. Start your free trial — no credit card required.

Start Free 30-Day Trial Schedule Live Demo

No credit card required • Free onboarding • Cancel anytime

Role Quick Start

Every major live page now routes back to the right stakeholder journey

Executives, hospital teams, partners, government buyers, and patient-facing users can jump directly to their correct next step from anywhere in the web experience.

Stakeholder Center Command Centers Deployment Map Sign In Free Trial Contact
Leadership Hospital Admin Clinical Staff Revenue & Claims IT & Assurance Partner Government Patient / Family
18 role journeys 253+ modules 48+ revenue paths 12+ deployment profiles