Trust Center

Your clinic handles sensitive data.
So do we.

When a candidate messages your clinic about a hair transplant, they share personal information. Their name, their phone number, their health concerns. That data is your responsibility. And by extension, it becomes ours.

Maximum security on your patient data

Your patients share sensitive information: their name, their phone number, their health concerns. That data lives in EVED's patient CRM so your team can serve and follow up on every patient, and it is protected at every step with maximum security.

Every conversation and every record is end-to-end encrypted, and encrypted at rest with AES-256 on servers hosted inside the European Union. Access is limited to authorized personnel, and every interaction is logged in a tamper-proof audit trail.

You remain the data controller for your patients; EVED acts as your data processor under a Data Processing Agreement. We apply data minimization and retention limits: we keep only what is needed to serve your patients, and delete it on termination.

Your patients' data works for them, and stays under your control.

Infrastructure and data sovereignty

EU data residency

All patient data is stored within the European Union, with EU-level safeguards on any transfer.

Encrypted end to end

Every conversation and record is end-to-end encrypted, and encrypted at rest with AES-256.

Under strict control

Any processing on your behalf is bound by a Data Processing Agreement. Your patients' data is never sold or shared.

What this means for your clinic

As a clinic operator, you are the data controller for your patients. EVED acts as your data processor. This relationship is governed by a Data Processing Agreement (DPA) concluded at the time of subscription.

Deploying EVED does not create new compliance exposure for your clinic. The platform is designed so that the data processing it performs on your behalf meets the requirements of the regulations applicable to your market.

Applicable regulations by market

馃嚜馃嚭
European Union & UKGDPR / UK GDPR

Data minimization, purpose limitation, storage limitation, and anonymization by design are built into the platform at the infrastructure level.

馃嚬馃嚪
TurkeyKVKK

EVED's anonymization-by-design approach and EU-based infrastructure are consistent with KVKK requirements for cross-border data transfers and processor obligations.

馃嚫馃嚘
Gulf (Saudi Arabia, UAE)PDPL / DIFC / ADGM

EU-based infrastructure and anonymization architecture satisfy GCC requirements. Clinics retain full control as data controllers.

馃嚝馃嚪
FranceCNIL-regulated GDPR

As a French entity regulated by the CNIL, EVED's compliance posture is aligned with the strictest interpretation of GDPR in force in France.

馃嚤馃嚙
Lebanon & MENALaw 81 / Emerging frameworks

EVED's private infrastructure and anonymization-by-design approach are consistent with emerging data protection obligations across MENA.

What EVED does not do

Sell, share, or monetize patient data in any form
Use patient conversations to train AI models for third parties
Transfer patient data to external analytics platforms
Keep your patients' data after termination, or beyond what's needed to serve them

Your rights as a clinic operator

Request information about the data EVED processes on your behalf
Request correction or deletion of any identifiable data about your clinic or staff
Terminate the DPA and subscription at any time
Receive confirmation that your data has been deleted following termination

Security architecture

End-to-end encryption for all communications
Encryption at rest for all stored data (AES-256)
EU-hosted infrastructure, strictly access-controlled
Strict internal access controls, authorized personnel only
Regular security audits and vulnerability assessments

No transmission method is completely immune to risk. In the event of a security incident affecting your data, EVED will notify you and the relevant supervisory authority within the timeframes required by applicable law.

The team

Real people, accountable for your data.

EVED is built and run by a named, reachable team. When you trust us with patient data, you know exactly who stands behind it.

Data protection inquiries

For any DPA request, compliance question, or security review:

EVED SAS 路 1 Rue de Stockholm, 75008 Paris, France

contact@eved.ai