Privacy Policy
Last updated: September 2026
PathwayCare takes the protection of your personal data very seriously. This privacy policy explains which personal data we collect, what we use it for, and which rights you have.
This policy applies to the website pathwaycare.app and to the PathwayCare platform, which enables physicians and healthcare professionals to digitalise clinical patient pathways. It is addressed to website visitors, people requesting a demo, physicians and medical practices (customers), and patients who are cared for through the platform.
This is a translation of the German Datenschutzerklärung. Should the two versions differ, the German version prevails.
1. Controller
The controller within the meaning of the Swiss Federal Act on Data Protection (nDSG, SR 235.1) and the European General Data Protection Regulation (GDPR) is:
Note for patients: In the context of your medical care, the treating physicians and practices — not PathwayCare — are the controllers of your patient data. In that relationship PathwayCare acts as a processor under Art. 9 nDSG.
2. Applicable law
The processing of your personal data is based on the following legal framework:
- ·nDSG (Federal Act on Data Protection, SR 235.1) — the primary law for all data subjects domiciled in Switzerland and for all processing with effect in Switzerland.
- ·GDPR (EU 2016/679) — applies additionally where PathwayCare processes personal data of individuals in the European Economic Area (EEA) or offers services to them.
- ·KVG / KVV — the Federal Health Insurance Act and its ordinance, where insurance-relevant health data is processed through the platform.
- ·OR / ZGB — the Swiss Code of Obligations and Civil Code as the basis for contractual relationships and liability.
- ·Cantonal health legislation — depending on the canton of the treating physician, cantonal data-protection and health laws may apply in addition.
3. Categories of data collected
3.1 Website visitors and demo requests
When you visit our website and fill in the demo form, we collect:
- – Name, email address, medical specialty
- – IP address, browser type, operating system (server logs)
- – Date and time of the visit, pages viewed
3.2 Customers (physicians and medical practices)
In the course of using the PathwayCare platform we collect:
- – Contact details, medical register number, GLN
- – Practice name, address, specialty
- – Login data (passkey / two-factor authentication)
- – Usage logs, system events
- – Billing and contract data
3.3 Patients
Patient data is entered into the platform by the treating physician or practice, or — where a practice offers it — by patients themselves when they register through the practice's registration link or QR code. In both cases the practice is the controller and PathwayCare processes the data as a processor. It includes:
- – Name, contact details
- – Diagnoses, treatment plans, clinical pathway content
- – Medical history, medication lists, laboratory values
- – Form entries and responses within the patient app
- – Uploaded documents and photos, and voice messages recorded in the patient app together with their automatic transcription (see section 5)
- – Device information and login records of the patient app
3.4 Self-registration through a practice's link
Where a practice has enabled it, patients can register themselves through the practice's registration link or QR code. For this they enter their first name, last name and mobile number and confirm the number with a code sent by SMS. The account is created only once the number has been confirmed; until then nothing is stored but a pseudonymised value of the number (not the number itself), used solely to limit abuse of the registration and deleted automatically, as a rule within 48 hours.
A care pathway is opened only after the patient has given the consent requested in the patient app; without consent, no pathway and no health data are created. The practice can switch self-registration off at any time. Self-registration is available for Swiss, Liechtenstein and European mobile numbers; patients with other numbers are invited by the practice.
4. Sensitive personal data (health data)
Health data is sensitive personal data under Art. 5 lit. c nDSG and special-category data under Art. 9 GDPR. PathwayCare processes such data exclusively on behalf of treating physicians and practices and applies specific technical and organisational safeguards:
- ·Encryption at rest and in transit (AES-256 / TLS 1.2 or higher), plus field-level encryption of patient answers in the database
- ·Role-based access control — only explicitly authorised members of the treating practice have access to patient data
- ·Pseudonymisation of patient data in analysis processes
- ·Audit logs of every change to patient data and of every treatment report generated — with no health data in the log itself
- ·No access by PathwayCare staff to patient data without explicit instruction from the responsible physician, except for technical troubleshooting
- ·A data processing agreement under Art. 9 nDSG is concluded with every practice
5. AI-assisted analysis, translation and transcription of health data
Where the treating physician has provided for it in a care pathway, the questionnaire answers that patients submit through the platform — including uploaded photos and documents — are analysed automatically by an AI language model (Anthropic Claude, operated through Amazon Bedrock). The result is a summary for decision support that is shown only to the treating physician. If the patient uses the platform in a language other than the pathway's source language, free-text answers are also translated into the source language by the same AI language model so that the treating physician can read them; the translation is labelled as a machine translation and is always shown next to the original answer.
Where a care pathway includes a question that is answered by voice message, the patient records it in the patient app (three minutes at most). When the answers are submitted, the recording is converted to text automatically by a speech-recognition service (Amazon Transcribe). This transcription is shown to the treating physician together with the recording, is included in the treatment report and in the data export, and is treated like a written answer — including translation into the source language and AI-assisted analysis as described above. The recording itself always remains available; a failed transcription is marked as such.
- ·Data minimisation: Only the clinical questionnaire content or the voice recording is transmitted. By design, name, date of birth, contact details and other identifying information are sent neither to the AI model nor to the speech-recognition service.
- ·Place of processing and processor relationship: The AI analysis and the translation take place transiently in an AWS region within the EU, the transcription of voice recordings in the AWS region Zurich (Switzerland) — in each case under the existing data processing agreement with AWS (Art. 9 nDSG / Art. 28 GDPR). The transfer to the EEA is covered by the adequacy of its level of data protection.
- ·No storage, no training: AWS neither stores nor logs the content sent to the AI model, does not use it to train AI models, and does not pass it on to the model provider. For the speech-recognition service, PathwayCare has opted out organisation-wide of the use of content to improve AWS AI services (AWS AI services opt-out policy); the recording is processed only for the duration of the transcription, and the service's intermediate file is deleted immediately after it has been read. The only results stored permanently are the summary, the translation and the transcription themselves — field-encrypted in our database in Switzerland, with the same retention period as the rest of the medical record (10 years).
- ·No automated individual decision: The AI analysis is decision support only within the meaning of Art. 21 nDSG and Art. 22 GDPR. Every medical assessment and decision is made exclusively by the treating physician, who can always see the original answers.
- ·Consent and withdrawal: AI-assisted analysis, translation and transcription take place only after explicit consent in the patient app. In addition, a voice message is recorded only when the patient starts the recording; any voice question may be left unanswered where the care pathway marks it as optional. Consent can be withdrawn at any time with effect for the future; withdrawal may limit use of the platform.
6. Purposes and legal bases of processing
| Purpose | Legal basis (nDSG) | Legal basis (GDPR) |
|---|---|---|
| Handling demo requests | Steps prior to a contract | Art. 6(1)(b) |
| Providing and operating the platform | Performance of a contract | Art. 6(1)(b) |
| Delivering digital patient pathways | Performance of a contract / overriding interest | Art. 6(1)(b) / Art. 9(2)(h) |
| Security and abuse prevention | Overriding interest | Art. 6(1)(f) |
| Legal obligations (accounting, reporting duties) | Legal obligation | Art. 6(1)(c) |
| Product improvement (anonymised / aggregated) | Overriding interest | Art. 6(1)(f) |
| AI-assisted analysis of health data (decision support, see section 5) | Explicit consent | Art. 9(2)(a) |
| Automatic transcription of voice messages and translation of answers (see section 5) | Explicit consent | Art. 9(2)(a) |
| Self-registration through a practice's link: creating the account, and opening the care pathway (see section 3.4) | At the patient's request / explicit consent | Art. 6(1)(b) / Art. 9(2)(a) |
7. Data storage and hosting
The platform's data — database, uploaded documents and voice recordings — is stored in Switzerland (AWS region Zurich). Data is processed outside Switzerland only in the following cases, each described in this policy:
- – AI-assisted analysis and translation, transiently in an AWS region within the EU (section 5)
- – sending SMS messages through Twilio, USA (section 9)
- – this website's demo form through Formspree, USA (section 9)
Transfers to the EEA are based on the adequacy of its level of data protection. Transfers to the USA are made to recipients certified under the Swiss-U.S. or EU-U.S. Data Privacy Framework, or on the basis of standard contractual clauses (SCC).
8. Retention periods
- Demo requests12 months after the last contact, unless a contractual relationship arises
- Customer data (physicians)For the duration of the contract plus 10 years (commercial and tax retention duties under Art. 958f OR)
- Patient dataAccording to the instructions of the responsible physician and the cantonal retention duties for medical records (as a rule 10 years after the last treatment contact)
- Server logs90 days, then deleted automatically
- Platform audit logsAs part of the treatment documentation, for the same period as the patient data they relate to
9. Disclosure to third parties
PathwayCare does not sell personal data. Data is disclosed only in the following cases:
- ·Processors: technical service providers (hosting, SMS delivery, monitoring) that act solely on our instructions and are contractually bound to comply with the nDSG
- ·Authorities: where we are legally obliged to do so (e.g. criminal prosecution or an official order)
- ·Business succession: in the event of a merger, acquisition or sale of parts of the business, with the data subjects informed in advance
The platform's SMS messages (login and registration codes, invitations, reminders and notifications) are sent through the service provider Twilio (USA). The recipient's mobile phone number and the message text are transmitted for this purpose. The text contains the code or a link to the platform, the name of the practice and, where set, its welcome text — but no questionnaire answers and no medical findings. Twilio is certified under the EU-U.S. and the Swiss-U.S. Data Privacy Framework.
Demo form entries are transmitted through Formspree (USA). Formspree has joined the EU-U.S. Data Privacy Framework. The data is processed solely to forward it to us and is not stored permanently by Formspree.
10. Data security
We use state-of-the-art technical and organisational measures to protect your data against unauthorised access, loss or misuse:
Encryption
TLS 1.2 or higher in transit, AES-256 at rest
Authentication
Passkey / WebAuthn, two-factor
Access control
Role-based, least-privilege principle
Monitoring
24/7 security monitoring and alerting
Penetration tests
Regular external security reviews
Incident plan
Documented incident response procedure
In the event of a data security breach that is likely to result in a risk to the persons concerned, we notify the Federal Data Protection and Information Commissioner (FDPIC / EDÖB) within 72 hours under Art. 24 nDSG, and the persons concerned without undue delay.
11. Cookies, local storage and tracking
The PathwayCare website itself sets no cookies. We use neither tracking or advertising cookies nor third-party analytics services (e.g. Google Analytics); fonts are loaded from our own server, not from a third party. The platform (patient app and physician portal) stores only what is technically necessary on your device:
| Item | Purpose | Storage period |
|---|---|---|
| refresh_token Cookie (HttpOnly) | Keeps you signed in to the platform; not readable by scripts in the browser | Up to 60 days; ends when you sign out |
| pathwaycare_lang Local storage | The language chosen in the patient app | Until you clear your browser data |
| Answer drafts Local storage | Answers in the patient app that have not been submitted yet, so that they are not lost if the connection drops. They stay on your device. | At the latest until you sign out |
| Display settings Local storage | View settings of the physician portal (e.g. collapsed sidebar) | Until you clear your browser data |
| Care pathway test run Local storage | Test answers a physician enters during the anonymous test run of a care pathway (no patient data). They stay on the device and are not stored on the server. | Until the test run is restarted, otherwise until you clear your browser data |
12. Your rights
You have the following rights towards PathwayCare as controller. Patients should address requests concerning platform data directly to the treating physician or practice.
Access (Art. 25 nDSG / Art. 15 GDPR)
You have the right to know whether and which personal data we process about you, and to receive a copy of it.
Rectification (Art. 32 nDSG / Art. 16 GDPR)
You may request the correction of inaccurate or incomplete personal data.
Erasure (Art. 32 nDSG / Art. 17 GDPR)
You may request the deletion of your data, unless statutory retention duties prevent it.
Restriction of processing (Art. 18 GDPR)
Under certain conditions you may request that processing be restricted.
Data portability (Art. 20 GDPR)
You have the right to receive the data you have provided to us in a structured, machine-readable format.
Objection (Art. 32 nDSG / Art. 21 GDPR)
You may object to the processing of your data where it is based on overriding interests.
Withdrawal of consent
Consent you have given can be withdrawn at any time, without giving reasons, with effect for the future. Patients withdraw directly in the patient app (Profile → Withdraw consent); treatment records already created remain stored as required by statutory retention duties.
Complaint to the FDPIC
You have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC / EDÖB, www.edoeb.admin.ch).
Please send requests to datenschutz@pathwaycare.app. We answer within 30 days.
13. Minors
The PathwayCare website and the demo form are addressed exclusively to healthcare professionals. Where data of minor patients is processed through the platform, this lies within the responsibility of the treating physician, who must ensure the consent of the legal guardians.
14. Changes to this privacy policy
We reserve the right to adapt this privacy policy when the legal situation, our services or our data processing change. The current version is available on this page. Registered customers are informed by email of material changes.
Privacy requests
For any question about data protection, to exercise your rights or to report a data breach, contact:
datenschutz@pathwaycare.app