
Trust & compliance
Compliant where you operate.
HIPAA in the United States, GDPR in the UK and Europe, DPDP in India. One platform, three frameworks, no gaps between them.
Get a demo
30 minutes, on your own call flows.
Frameworks
What each one means, concretely.
The regulation, and the artefact your legal team can actually act on.
United States
HIPAA
2care is HIPAA-ready and will sign a Business Associate Agreement before any protected health information is exchanged.
- BAA available on request, signed before go-live
- PHI encrypted in transit (TLS 1.2+) and at rest (AES-256)
- Role-based access control, least privilege by default
- Full audit log of every access, call and write-back
- Breach notification procedures in line with the Breach Notification Rule
UK & Europe
GDPR
2care acts as a processor on your behalf, under a Data Processing Agreement, with personal data held in the EU and UK.
- DPA available, covering Article 28 processor obligations
- Data hosted in the EU/UK - no transfer outside without SCCs in place
- Right to access, rectification, erasure and portability supported
- Sub-processor register maintained and available on request
- Records of processing activity kept under Article 30
India
DPDP Act
2care processes personal data of Indian patients under the Digital Personal Data Protection Act, with data held in India.
- Data residency in India for Indian deployments
- Notice and consent captured at the point of collection
- Purpose limitation - data used only for the care workflow it was given for
- Data principal rights: access, correction, erasure and grievance redressal
- Grievance officer contactable at privacy@2care.ai
Controls
How the data is actually handled.
Encryption everywhere
TLS 1.2+ in transit, AES-256 at rest. Call audio and transcripts are encrypted with the same controls as the record itself.
Least-privilege access
Role-based access control with scoped credentials per integration. No shared logins, no standing admin access.
Complete audit trail
Every call, transcript, escalation and write-back is logged with a timestamp and an actor. Exportable on request.
Regional hosting
US workloads in the US, EU and UK workloads in the EU/UK, Indian workloads in India. No silent cross-border movement.
Retention you control
You set how long call audio and transcripts are kept. Deletion is honoured across backups within the stated window.
Clinical escalation by design
The agent is bounded. Anything clinical routes to a human - a safety control, not a limitation.
In progress
SOC 2 Type II is underway.
It is not finished, so we do not claim it. This page will say so the day it is - and until then your security team is welcome to review the controls already in place.
Security review pack
Architecture overview, sub-processor list, data-flow diagram, retention policy and penetration test summary - available under NDA for procurement and security review.
Request the packQuestions
What security teams ask us.
Yes. A Business Associate Agreement is available on request and is signed before any protected health information is exchanged.
Not yet. We will say so plainly here the day it is complete rather than before - and we are happy to walk your security team through the controls already in place in the meantime.
In the region you operate in: the US for US practices, the EU or UK for European practices, and India for Indian deployments. Data is not moved between regions without Standard Contractual Clauses in place.
Call audio and transcripts are retained for the period you configure. You can shorten it, and deletion is applied across backups within the stated window.
No. Your patients' data is not used to train shared models.
security@2care.ai for security and vulnerability reports, privacy@2care.ai for data protection and grievance matters.
Bring your security team to the demo.
We would rather answer the hard questions early than late.
- 18 specialties covered
- ·Live in weeks, not months
- ·HIPAA, GDPR and DPDP


