Signal Studio is in public beta. Usable, but still moving. Join the beta

GDPR and HIPAA

Where we stand under each, and where we do not. Written to be checkable rather than reassuring.

Written by engineers, not counsel

This describes what the system does and how we understand our obligations. It has not been reviewed by a lawyer and is not legal advice to you. Your institution must make its own assessment; we will answer any question that helps it do so.

GDPR

Who is what

RoleWhoFor what
ControllerNeuraCryptAccount and website data
ProcessorCloudflareHosting, database, file storage
ProcessorClerkAuthentication and sessions
Not involvedAnyoneYour recordings. They never reach us, so no role arises

That last row is the important one. When you analyse patient recordings in Signal Studio, we are not a processor of that data, because we never receive it. Your institution remains its sole controller, and no agreement with us is needed for it.

Lawful basis, per item

DataBasisArticle
Account, email, sessionContract: you cannot have an account without one6(1)(b)
What you publish or postContract, and your own act of publishing6(1)(b)
Install and vote recordsLegitimate interest: ranking, and the "installed it" marker on reviews6(1)(f)
Notification emailsConsent, per switch, off unless you turn it on6(1)(a)
Moderation logLegitimate interest: accountability of moderation6(1)(f)
Update checkLegitimate interest: telling you a fix exists. No identifier is sent6(1)(f)

No special category data under Article 9 is processed by us. Recordings would be, which is why the software has no path to send them.

Your rights, and how to use them

RightArticleHow
Access15Export as JSON, immediately
Rectification16Edit your profile, or ask us
Erasure17Delete the account
Portability20The same export: structured, machine-readable JSON
Object21Ask. In practice this means deleting the account, since we hold nothing else
Complain77To your national supervisory authority

Access and erasure are buttons rather than a form to fill in, because a right you have to request politely is a right in name only.

Transfers outside the EU

Account data is stored in the United States by Cloudflare and Clerk. Both operate under the standard contractual clauses and participate in the EU-US Data Privacy Framework. Our infrastructure region is documented on the data location page.

If your institution cannot accept that transfer, use the software without an account. Everything except publishing and posting works, and then nothing personal reaches us at all.

Breach notification

A breach affecting personal data would be reported to the relevant supervisory authority within 72 hours and to affected people without undue delay, and would appear on the status page with a written account of what happened.

HIPAA

NeuraCrypt is not a HIPAA business associate and does not sign business associate agreements. Do not treat any statement here as a claim of HIPAA compliance.

The honest position, because a vague answer here would be worse than none:

Why no BAA is needed for the software

A business associate agreement is required when a vendor creates, receives, maintains or transmits protected health information on a covered entity's behalf. Signal Studio does none of those. Recordings are opened from your disk, processed locally, and written back to your disk. We never receive them, so the relationship a BAA would govern does not exist.

Installing it is closer to installing MATLAB or Python than to using a cloud service. Your institution's assessment should reflect that, and we will say so in writing if that helps.

Where you must be careful

What we can provide

A written statement that the software transmits no data, a description of every network call it makes, a completed security questionnaire, and access to the network-handling source for review. Ask at privacy@eeg.studio.

What we cannot provide is a BAA or a certification. Anyone offering you either for locally-run analysis software is selling reassurance rather than protection.