How does amaise meet data protection requirements (GDPR, nDSG, US)?
amaise meets the data protection requirements of the relevant jurisdictions. Since the core principles — purpose limitation, data minimization, transparency, security, and data subject rights — largely align internationally, all customers benefit from the same high standards.
EU — GDPR:
Data processing agreement (DPA) compliant with Art. 28 GDPR
Notification obligation within 72 hours (Art. 33/34)
Data residency in the EU (AWS Frankfurt) or Switzerland
Details: see GDPR compliance
Switzerland — nDSG (effective since September 1, 2023):
Data residency in Switzerland (AWS Zurich, Azure OpenAI Switzerland North)
Tenant-specific encryption (dedicated KMS key per tenant)
Documented data deletion (8-step process at contract termination)
Compliance with Art. 321 StGB (professional secrecy: medical confidentiality, attorney-client privilege)
Notification to the FDPIC according to nDSG Art. 24
Processing record according to nDSG Art. 12
USA:
Data residency in the USA (AWS Ohio)
Compliance with applicable state privacy laws (e.g., CCPA/CPRA)
Security controls aligned with HIPAA requirements for healthcare customers
Industry-specific compliance available on request
EPO / International organizations:
amaise supports the requirements of international organizations and can address specific compliance needs on a customer basis.
For specific compliance inquiries, please contact us at [email protected].