Aqua Voice is GDPR and HIPAA compliant
By Pablo Peniche
3 min read
Aqua Voice is now GDPR and HIPAA compliant. Together with our SOC 2 Type II report and ISO 27001 certification, this gives security, privacy, and procurement teams a documented account of how we protect personal data and health information, making it easier to get Aqua Voice approved across your company, wherever in the world you operate.
GDPR: privacy people can understand
The General Data Protection Regulation (GDPR) sets the rules for how organizations handle the personal data of people in the European Union and the European Economic Area. It also gives individuals rights over that data: to know what is collected, to access it, to correct it, and to have it deleted.
For Aqua Voice, this means treating privacy as part of how we build and operate the product, not a document we produce once a year.
From collection to deletion
Our GDPR program covers the full life of personal data at Aqua Voice: a data inventory that maps what we collect and where it lives, privacy risk assessments, agreements with the vendors that process data on our behalf, and documented procedures for handling requests about personal data.
Our Privacy Policy explains what information we collect, how we use it, and how long we keep it. To request access to, correction of, or deletion of your personal information, contact support@withaqua.com.
HIPAA: protecting health information
The Health Insurance Portability and Accountability Act (HIPAA) sets the requirements for safeguarding protected health information in the United States. For a service provider like Aqua Voice, acting as a business associate to healthcare organizations, that means protecting electronic health information with administrative, physical, and technical safeguards, and defining each side's responsibilities in a Business Associate Agreement (BAA).
What this means for healthcare teams
Our HIPAA program builds on the controls we already validated for SOC 2 Type II and ISO 27001: access controls, encryption in transit and at rest, security training for everyone at Aqua Voice, regular risk assessments, and incident response procedures.
Before using Aqua Voice with protected health information, contact our team at support@withaqua.com. We'll confirm which products and plans are covered, walk through any required settings, and discuss BAA terms.
Compliance partners
Vanta
We use Vanta to automate evidence collection and track our controls, keeping the documentation behind our compliance program organized as Aqua Voice grows. Because we built our SOC 2 Type II and ISO 27001 programs on Vanta, much of the groundwork for GDPR and HIPAA was already in place.
Workstreet
Workstreet guides our compliance work and helps us put policies and procedures into practice. We're grateful to both teams for their support as we build a product customers can trust.
An ongoing commitment
Privacy and security take ongoing work. Data protection law evolves, our product evolves, and the ways people use it evolve too. We'll keep reviewing our processes and safeguards as all three change.
Trust Center
Our Trust Center brings our security controls, subprocessors, and compliance resources together in one place. Your team can review this information and request access to supporting documentation, including our SOC 2 Type II report and ISO 27001 certificate.
For questions about data handling, your team's privacy review, or HIPAA requirements, contact support@withaqua.com.