Data Protection
Last updated 11 July 2026
This page explains how Bloomsline meets its data-protection obligations under the GDPR and the French health-data (HDS) framework.
Controller and processor roles
For practitioner account data, Bloomsline is the controller. For the patient data a practitioner enters, the practitioner is the controller and Bloomsline is the processor, acting on the practitioner’s instructions under a data-processing agreement.
Health data & HDS
Patient records are special-category health data. They are hosted on HDS-certified infrastructure in the EU, as required by French law for hosting health data.
Data Protection Officer
Our point of contact for data protection is privacy@bloomsline.care. [Confirm whether a formal DPO is appointed and, if so, their details.]
Patient rights
Patients can exercise their GDPR rights. Because the practitioner is the controller of clinical data, requests are handled with the practitioner; Bloomsline provides the tools to fulfil them.
Subprocessors
We maintain a list of subprocessors (hosting, email, analytics, AI features), each under a data-processing agreement with an appropriate data-protection posture. The current list is available on request.
Breach procedure
We have a procedure to detect, assess, and report personal-data breaches, including notifying the relevant authority and affected parties within the timeframes the GDPR requires.