Skip to content

Data protection

Abi Global Health applies privacy by design, data protection by design, and data-ethics principles throughout product development and service delivery.

Abi is a service business rather than a data business. Users exchange the minimum information needed to access the configured service and receive health guidance. User data is processed in accordance with GDPR requirements and applicable partner agreements.

Communication with messaging channels is pseudonymized. Healthcare professionals receive only the information relevant to the consultation rather than a user’s full identity. Data is encrypted in transit and at rest.

Abi is HIPAA compliant and maintains certification to ISO/IEC 27001 for information security management, ISO/IEC 27701 for privacy information management, and ISO/IEC 42001 for artificial intelligence management. The applicable assurance scope is confirmed for each client service and launch.

Abi uses regional AWS and Google Cloud infrastructure to support the localization requirements agreed for each client launch. The applicable storage and processing locations, subprocessors, retention periods, and international-transfer arrangements are determined for the relevant service and documented in the applicable client agreements.