Security & Compliance

Designed for clinical trust from the start

From data residency to access control, every decision in how Oncoly handles information is made with the realities of Swedish healthcare in mind.

How we approach security

Every layer of Oncoly is built with patient data sensitivity as a first principle.

Built with healthcare data sensitivity in mind

Healthcare data handling is central to architecture decisions, not an afterthought.

GDPR-aligned approach

Data minimization, consent management, and user rights built into every feature.

Role-based access control

Granular permissions ensure users only see data they are authorized to access.

Audit trail capability

Every data access is logged for compliance and accountability.

Permission-based data sharing

Patients control exactly what data is shared, with whom, and for how long.

Data minimization and consent handling

Only necessary data is collected, with explicit consent at every step.

No integration required for initial pilot

Oncoly works alongside existing workflows without connecting to EHR systems.

How data flows through Oncoly

A simplified view of how patient data moves from device to clinician, and the safeguards at each step.

Patient deviceMobile app
Encrypted in transit
OncolyHosted in Sweden
Permission gate
Clinician accessWeb dashboard
Encrypted storage
Role-based permission gate
GDPR consent layer
Data residency: Sweden

Questions about compliance? Talk to us.

We are happy to walk through our approach to data handling, security architecture, or GDPR alignment in more detail.