Data Protection

Last updated 11 July 2026

Draft — pending legal and DPO review. This wording is not final and should not be relied upon until reviewed.

This page explains how Bloomsline meets its data-protection obligations under the GDPR and the French health-data (HDS) framework.

Controller and processor roles

For practitioner account data, Bloomsline is the controller. For the patient data a practitioner enters, the practitioner is the controller and Bloomsline is the processor, acting on the practitioner’s instructions under a data-processing agreement.

Health data & HDS

Patient records are special-category health data. They are hosted on HDS-certified infrastructure in the EU, as required by French law for hosting health data.

Data Protection Officer

Our point of contact for data protection is privacy@bloomsline.care. [Confirm whether a formal DPO is appointed and, if so, their details.]

Patient rights

Patients can exercise their GDPR rights. Because the practitioner is the controller of clinical data, requests are handled with the practitioner; Bloomsline provides the tools to fulfil them.

Subprocessors

We maintain a list of subprocessors (hosting, email, analytics, AI features), each under a data-processing agreement with an appropriate data-protection posture. The current list is available on request.

Breach procedure

We have a procedure to detect, assess, and report personal-data breaches, including notifying the relevant authority and affected parties within the timeframes the GDPR requires.