European infrastructure. Uncompromising by design.
Every clinic that works with Cellythra is trusting us with their patients’ most sensitive information. We treat that as non-negotiable: EU-hosted, encrypted end to end, and never touched by advertising, data brokers or AI training pipelines.
What we do not do
Non-negotiable commitments.
- We do not sell patient data.
- We do not share patient data with third parties for advertising or marketing.
- We do not use patient data to train general-purpose AI models.
- We do not rely on third-party trackers or analytics that profile patients.
- We do not host patient data outside of Europe.
What we do
Security principles.
Encryption
Patient data is encrypted at rest and in transit, with keys managed within European infrastructure.
European residency
All patient data is hosted and processed within the European Union, under GDPR and EHDS-aligned controls.
Role-based access
Clinicians access only the patients they are responsible for, with full audit logging.
Data Processing Agreement
A formal B2B DPA governs every clinic relationship, with clear sub-processor disclosure.
Legal framework.
Cellythra acts as a data processor on behalf of licensed healthcare providers acting as data controllers. All processing is performed under a signed Data Processing Agreement (DPA), aligned with Regulation (EU) 2016/679 (GDPR) and prepared for the European Health Data Space (EHDS).
For privacy enquiries: privacy@cellythra.com
This privacy overview is a draft for review with qualified EU counsel before publication. The English version is the legally binding one.