For medical device manufacturers operating in the EU and UK

GDPR compliance across every Qevatrix application

QualityOS, RegulatoryOS, DeviceOS, ClinicalOS, StudyOS, EvidenceOS and TrademarkOS process personal data on your instructions as controller. The safeguards are built into the product, not bolted on as policy documents.

01

Processor under a signed DPA

Qevatrix acts as processor for customer data. The Article 28 data processing agreement — including the EU Standard Contractual Clauses and the UK International Data Transfer Addendum — forms part of every subscription.

02

EU data residency by default

Workspaces for EU and UK customers are hosted in EU regions. Where a subprocessor operates outside the EEA, transfers run on SCCs backed by a transfer impact assessment.

03

Minimised and pseudonymised

Clinical uploads are classified column by column and direct identifiers are removed on import. Subjects are handled by code, and cross-product transfers carry coded data only.

04

Rights requests on a clock

Access, rectification, erasure, restriction, portability and objection requests are recorded with a one-month response clock, upcoming and overdue notifications and a documented outcome.

05

Erasure that respects device law

Erasure is executed as irreversible pseudonymisation. Regulated quality and vigilance records are retained under Article 17(3), with the reason recorded in the retention register.

06

Breach notification within 24 hours

Qevatrix notifies affected workspace owners within 24 hours of becoming aware, so the controller can meet its own 72-hour supervisory authority duty under Article 33.

EU GDPR 2016/679 and UK GDPR

Control register

Each article, how the platform meets it, and where you retain responsibility as controller. The same register is available inside every console.

Processing principles

Lawfulness, fairness and transparency

GDPR Art. 5(1)(a)

Personal data must be processed lawfully, fairly and in a transparent manner in relation to the data subject.

Every processing purpose in the platform is documented in the records of processing below, and Qevatrix acts only on documented instructions from the customer as controller.

Your responsibility: Publish your own privacy notice covering the clinical, quality and regulatory processing you run in Qevatrix.

Purpose limitation

GDPR Art. 5(1)(b)

Data must be collected for specified, explicit and legitimate purposes only.

Records are bound to a workspace and a product module; cross-product transfers (for example ClinicalOS to EvidenceOS) are explicit, audited events carrying coded data for a stated purpose.

Data minimisation

GDPR Art. 5(1)(c)

Data must be adequate, relevant and limited to what is necessary.

Direct identifiers are detected and removed on import by default, subjects are handled by code, and exports carry only the fields required for the stated purpose.

Accuracy

GDPR Art. 5(1)(d)

Data must be accurate and, where necessary, kept up to date.

Records are versioned with controlled state transitions; corrections create a new revision rather than overwriting history, and the audit trail names the person who made the change.

Storage limitation

GDPR Art. 5(1)(e)

Data must be kept in identifiable form no longer than necessary for the purposes of processing.

Retention schedules and legal holds are configured per record class in the retention module; expired records are flagged for disposition with an approval step.

Your responsibility: Set retention periods that reflect your regulatory obligations (for example device lifetime plus the statutory record period).

Integrity and confidentiality

GDPR Art. 5(1)(f)

Data must be processed with appropriate security, including protection against unauthorised access.

Row-level security scopes every row to one workspace, transport is TLS 1.2+, data at rest is encrypted, and privileged operations run through audited server functions.

Accountability

GDPR Art. 5(2)

The controller must be able to demonstrate compliance with the principles.

Append-only audit trails, e-signature records, security scan history and validation packs provide documentary evidence on demand.

Lawful bases

Lawful basis for account and quality data

GDPR Art. 6(1)(b)/(c)/(f)

Processing needs a lawful basis: contract, legal obligation, legitimate interests, consent or a public interest task.

Account, billing and audit data are processed to perform the subscription contract (Art. 6(1)(b)) and to meet Qevatrix's own legal obligations (Art. 6(1)(c)). Security logging relies on legitimate interests (Art. 6(1)(f)).

Your responsibility: Record the lawful basis for your own use of the platform in your ROPA.

Special category health data

GDPR Art. 9(2)(i)/(j)

Health data may only be processed under an Article 9 condition, such as public health, scientific research or explicit consent.

Clinical data is de-identified at import wherever the study design allows. Where identifiable data is necessary, the customer as controller relies on explicit consent (Art. 9(2)(a)), scientific research (Art. 9(2)(j)) or the medical devices public-health condition (Art. 9(2)(i)).

Your responsibility: Hold and evidence the Article 9 condition — usually participant consent and ethics approval — before uploading identifiable clinical data.

Consent records

GDPR Art. 7

Where consent is the basis, it must be freely given, specific, informed and demonstrable, and withdrawable.

Consent versions, dates and withdrawal events are recorded against the subject record in ClinicalOS and carried on transfers to StudyOS and EvidenceOS.

Your responsibility: Upload the approved consent form version used at each site.

Data subject rights

Right of access

GDPR Art. 15

Data subjects may obtain confirmation of processing and a copy of their personal data.

A subject search across the workspace returns every record referencing a subject code, exportable as a structured pack with the processing purposes and recipients.

Your responsibility: Verify the requester's identity before releasing any pack.

Right to rectification

GDPR Art. 16

Inaccurate personal data must be corrected without undue delay.

Corrections are made as a new record revision; the previous value stays in the audit trail so regulated traceability is preserved.

Right to erasure

GDPR Art. 17

Data must be erased on request, unless processing is necessary for a legal obligation, public health, or archiving in the public interest.

Erasure is executed as irreversible pseudonymisation of the identifying fields; regulated quality and vigilance records are retained under the Art. 17(3)(b)/(c) exemptions and the retention register records why.

Your responsibility: Decide and document whether the medical device retention exemption applies before actioning an erasure request.

Right to restriction

GDPR Art. 18

Processing must be restricted while accuracy or a legitimate-interest objection is verified.

A legal hold flag freezes the record from further processing and export while keeping it readable to authorised reviewers.

Right to data portability

GDPR Art. 20

Data provided by the subject must be portable in a structured, commonly used, machine-readable format.

Subject packs and register exports are produced as CSV and XLSX alongside indexed PDF.

Right to object

GDPR Art. 21

Subjects may object to processing based on legitimate interests or for direct marketing.

Marketing subscriptions carry a one-click unsubscribe and are stored separately from clinical and quality records; objections are logged with the outcome.

One-month response clock

GDPR Art. 12(3)

Requests must be answered without undue delay and within one month, extendable by two further months for complex requests.

Rights requests recorded in the console start a one-month clock with upcoming and overdue notifications to the request owner, mirroring the CAPA and vigilance clocks.

Processor obligations

Documented instructions only

GDPR Art. 28(3)(a)

The processor may process personal data only on documented instructions from the controller.

The Data Processing Agreement forms part of the subscription terms and defines the instruction set; Qevatrix support staff access customer data only on a logged, time-boxed request.

Confidentiality of personnel

GDPR Art. 28(3)(b)

Persons authorised to process the data must be under a duty of confidentiality.

All Qevatrix personnel are bound by written confidentiality obligations that survive termination.

Subprocessors

GDPR Art. 28(2)/(4)

Subprocessors require general or specific written authorisation and must be bound by equivalent obligations.

The subprocessor register lists hosting, email and AI providers with their role, location and transfer mechanism. Customers are notified before a new subprocessor is added and may object.

Assistance with rights, DPIAs and breaches

GDPR Art. 28(3)(e)/(f)

The processor must assist the controller with data subject requests, impact assessments and breach notification.

Subject packs, the records of processing and the security register are self-service. Qevatrix supplies a DPIA input pack and supports breach assessment within 24 hours of becoming aware.

Deletion or return at end of service

GDPR Art. 28(3)(g)

Data must be deleted or returned at the controller's choice when the service ends.

On termination the workspace is exported in full on request and irreversibly deleted after a 30-day grace period, backups rolling off within a further 30 days.

Records of processing activities

GDPR Art. 30(2)

Processors must keep a record of all categories of processing carried out for each controller.

The ROPA register below is maintained per product and is exportable for supervisory authority requests.

Your responsibility: Maintain your controller-side ROPA under Art. 30(1).

Security of processing

Pseudonymisation and encryption

GDPR Art. 32(1)(a)

Appropriate technical measures including pseudonymisation and encryption of personal data.

Subjects are handled by code, identifiers are stripped at import, data at rest is encrypted and all traffic uses TLS 1.2+.

Confidentiality, integrity, availability and resilience

GDPR Art. 32(1)(b)

Ongoing confidentiality, integrity, availability and resilience of processing systems.

Row-level security on every table, append-only audit trails with SHA-256 integrity hashes on exports, managed Postgres with point-in-time recovery and daily backups.

Regular testing and evaluation

GDPR Art. 32(1)(d)

A process for regularly testing, assessing and evaluating the effectiveness of the measures.

Automated security scans run on a nightly schedule with findings triaged in an append-only register; software validation (IQ/OQ/PQ) is re-executed on material change.

Access control and authentication

GDPR Art. 32(4)

Persons acting under the processor's authority must not process data except on instruction.

Role-based access (owner, admin, member), per-site scoping in EvidenceOS, MFA and SSO options, idle logoff on consoles handling health data, and re-authentication for signatures.

Your responsibility: Remove leavers on their last working day and review workspace roles at least annually.

International transfers

Transfers outside the EEA

GDPR Art. 44–46

Transfers to third countries need an adequacy decision or appropriate safeguards such as Standard Contractual Clauses.

EU and UK customer data is hosted in EU regions by default. Where a subprocessor processes outside the EEA, the 2021 EU Standard Contractual Clauses and the UK International Data Transfer Addendum apply, backed by a transfer impact assessment.

Your responsibility: Choose the EU hosting region at onboarding if your data must remain in the EEA.

EU and UK representatives

GDPR Art. 27

Controllers or processors outside the Union must designate a representative in the Union where Article 3(2) applies.

Qevatrix designates an EU representative and a UK representative; contact details are supplied in the DPA and on request.

Personal data breaches

Notification to the controller without undue delay

GDPR Art. 33(2)

The processor must notify the controller without undue delay after becoming aware of a breach.

Qevatrix notifies the affected workspace owners within 24 hours of becoming aware, with the categories of data, approximate numbers, likely consequences and mitigation taken.

72-hour supervisory authority clock

GDPR Art. 33(1)

The controller must notify the competent supervisory authority within 72 hours unless the breach is unlikely to result in a risk.

Breach records in the console start a 72-hour clock with a documented risk assessment and notification decision, mirroring the HIPAA four-factor assessment for dual-regulated customers.

Your responsibility: Make and record the notification decision — it belongs to you as controller.

Communication to data subjects

GDPR Art. 34

High-risk breaches must be communicated to the affected data subjects without undue delay.

The breach record captures the subject-communication decision, the wording used and the date sent, so the file is complete for the supervisory authority.

Article 30(2)

Records of processing

The categories of processing Qevatrix carries out on behalf of customers, by application.

ActivityApplicationsData subjectsData categoriesPurposeRetention
Workspace accounts and access controlAll applicationsCustomer employees and contractorsName, work email, role, authentication events, IP addressProvide the service, authenticate users and evidence 21 CFR Part 11 access controlLife of the subscription plus 6 years of audit trail
Quality and regulatory recordsQualityOS, RegulatoryOS, DeviceOSEmployees, suppliers, complainantsAuthor and approver identity, e-signature meaning, complaint contact detailsOperate the quality management system and regulatory submissionsDevice lifetime plus the statutory retention period set by the customer
Clinical data intake and de-identificationClinicalOSStudy participants and patientsHealth data (special category), subject code, outcome scores, dates generalised on importCapture and de-identify investigational and registry data under the study protocolPer protocol, minimum 10 years for EU MDR clinical evidence
Sponsor oversight and monitoringStudyOSStudy participants, site staffCoded subject records, site personnel names and roles, monitoring findingsSponsor oversight of investigational sites under ISO 14155 and GCPPer protocol and trial master file requirements
Registry and evidence analysisEvidenceOSPatients in post-market registriesCoded, de-identified clinical outcomes and implant dataPost-market clinical follow-up and real-world evidence generationPer registry charter
Sales enquiries and newsletterPublic websiteProspective customersName, work email, company, message contentRespond to enquiries and send product updates on the basis of consent24 months after last interaction, or until unsubscribe
Billing and subscription managementAll applicationsCustomer billing contactsBilling name, address, VAT identifier, invoice history (card data never touches Qevatrix)Take payment and meet tax and accounting obligations10 years (statutory accounting retention)

Article 28(2)

Subprocessors

Customers are notified before a new subprocessor is engaged and may object.

Managed cloud hosting and database

Application hosting, database, object storage and backups

EU (default) — region selected at onboarding

Within the EEA; SCCs where support is provided from outside the EEA

Payment processing

Subscription billing and invoicing

EU / United States

EU Standard Contractual Clauses and UK Addendum

Transactional email

Account, subscription and notification email delivery

EU / United States

EU Standard Contractual Clauses and UK Addendum

AI model providers (Qevatrix Intelligence)

Drafting and cross-referencing text submitted by the user

EU / United States

EU Standard Contractual Clauses; zero-retention processing and no training on customer data

Request the DPA and the GDPR pack

The pack includes the data processing agreement with SCCs and the UK Addendum, the subprocessor list, the records of processing, the transfer impact assessment and the breach notification procedure.