Skip to content

Compliance & privacy

Client data. Handled with intent.

Ermetia designs every platform deployment around how your data is collected, routed, stored, and protected — not around badge lists on a landing page.

Data handling

Cloud where needed. Private where it matters.

Only what the platform must run in cloud stays there. The rest is classified and routed automatically to Ermetia-owned private servers — encrypted, controlled, and never left on generic paths by default.

  • Cloud for edge, orchestration, and shared services — not your full operational record
  • Sensitive workloads moved to private infrastructure without manual handoffs
  • TLS on every connection. Security built in, not added at go-live

Infrastructure

Cloudflare Deal — May 2026

Since May 2026, Ermetia partners with Cloudflare. Every deployment — live today, in release, or on the roadmap — runs behind the same edge: DDoS protection, encrypted routing, and a unified security layer you do not have to configure yourself.

  • Edge protection on all Ermetia-managed services
  • One standard from production through what we ship next
Cloudflare

Regional frameworks

Compliance reference.

Select a framework to see how Ermetia applies it in client deployments and links to official guidance and consumer rights resources.

Ermetia documents lawful basis, supports data processing agreements, and implements access, rectification, erasure, restriction, and portability workflows for platforms serving EU and UK clients.

As a Swiss-headquartered software house, Ermetia aligns client deployments with the revised FADP (nDSG): transparency, purpose limitation, data security, and documented cross-border transfer mechanisms.

For US enterprise accounts, Ermetia supports CCPA/CPRA readiness: disclosure of categories processed, consumer access and deletion requests, and opt-out of sale/sharing where applicable in platform design.

Ermetia applies PIPEDA-aligned practices for Canadian clients: consent where required, limited collection, safeguards, openness, and individual access — documented in deployment architecture and support runbooks.

Deployments for Australian organizations follow APP obligations: transparent handling, secure storage, access and correction rights, and procedures aligned with the Notifiable Data Breaches scheme.

For Japan-market deployments, Ermetia addresses APPI requirements on purpose specification, security control measures, and cross-border transfer rules — integrated into platform architecture and client documentation.

Clinical & Pharma modules are designed with HIPAA-ready controls: access logging, encryption, minimum necessary access patterns, and audit trails. Business associate agreements and environment isolation are scoped per engagement.

Ermetia engineering follows SOC 2 aligned practices across security, availability, and confidentiality — change control, monitoring, incident response, and vendor review — even where formal attestation is scoped to specific client environments.

Questions about data handling or compliance?