GDPR (DSGVO)  ·  EU AI Act  ·  MDR - Medical imaging infrastructure

Your dataset is
a compliance asset.

The only data infrastructure platform that makes compliant medical image collection the default - built for MedTech companies training AI.

Compliance built in
GDPR (DSGVO) compliant
EU data residency
AI Act Art. 10 provenance
MDR Annex IV ready
The problem

Most medical AI datasets are already non-compliant.

Three converging regulations are creating an existential risk for companies that haven't acted yet.

01
Medical Records still have patient names in them

Raw Data exports can carry patient identity across their metadata tags. Storing or sharing these without pseudonymization is a GDPR (DSGVO) Art. 9 violation - right now, today.

GDPR (DSGVO) Art. 9 · Active violation
02
Consent is a PDF. Not a structured data record.

A signed form cannot answer "did patient X consent to AI training vs. research vs. third-party sharing?" without manual review. AI Act Art. 10 demands structured, queryable provenance.

EU AI Act Art. 10
03
Your MDR submission dataset has no ground truth documentation trail.

Notified bodies require annotator qualifications, IRR metrics, and versioned dataset snapshots. Without it, your conformity assessment fails - regardless of model performance.

MDR Annex IV · Benannte Stelle
How it works

From patient consent
to compliant dataset.

Three steps. One platform. No compliance rebuild later.

01 / Collect
Consent at point of care

Patient signs granular consent on a tablet kiosk - separately for storage, research, AI training, and third-party sharing. Structured, version-locked, and cascade-able on withdrawal.

02 / Protect
Pseudonymize at ingestion

Meta data identity tags stripped automatically. Three isolated databases - medical data, identity data, and a cryptographic linker - make re-identification structurally hard.

03 / Export
Compliance-ready datasets

R&D engineers download datasets with AI Act Art. 10 provenance reports and MDR Annex IV documentation built in. Every download logged. Every invalidation notified.

Platform features

Everything compliance.
Nothing unnecessary.

Built for the specific intersection of GDPR (DSGVO), EU AI Act, and MDR - not adapted from a generic SaaS tool.

Split-identity architecture

Three physically isolated databases. A breach of any single database reveals nothing. The split-identity pattern is the GDPR (DSGVO) pseudonymization requirement in infrastructure form.

GDPR (DSGVO) Art. 25 Privacy by Design · Art. 32 TOM
Full audit trail

Every upload, download, consent change, and access event logged with actor, timestamp, and reason. Exportable audit reports for supervisory authorities and notified bodies on demand.

GDPR (DSGVO) Art. 30 · Art. 33 breach reporting
MDR Annex IV export

One-click technical documentation export for notified body submissions. Ground truth metadata, annotator qualifications, IRR metrics, and versioned dataset snapshots included.

MDR (EU) 2017/745 Annex II + IV · MDCG 2025-6
Consent withdrawal cascade

A patient withdraws consent → studies automatically removed from all active datasets → all engineers who downloaded are notified within 24h. Deletion logged and confirmed.

GDPR (DSGVO) Art. 7(3) · Art. 17 Right to erasure
Ground truth storage

Ingest annotations from any tool via API. Pseudonymized annotator profiles, IRR metrics, and versioned snapshots stored alongside your images.

AI Act Art. 10 data quality · DICOM SR · NIfTI

Compliance debt only
gets more expensive.

Every study collected without proper compliance documentation today is a problem tomorrow. Start building your compliant dataset now.

GDPR (DSGVO)-konform · EU data residency · Made in Germany