Trust & Security
How RehabPilot protects clinic and patient data — based on our live contracts and architecture, not aspirational badges.
1. Roles and privacy-first design
RehabPilot is clinic software: the treating physiotherapy practice creates patient records and exercise plans. The clinic is the controller for patient health data. Rosenheinrich Software Solutions (RehabPilot) acts as processor under a data-processing agreement (Art. 28 GDPR).
We process clinic and patient data only to provide the contracted service. Optional app analytics and Crashlytics are off by default until a user opts in. Crash reports use a numeric user id and role — not email. Marketing-site Google Ads / GTM tags load only after Cookie CMP consent (Consent Mode v2 defaults denied).
Product scope: RehabPilot supports care workflows; it does not replace clinical judgement. See the Terms of Service.
2. Where data lives
- Application and databases — Rosenheinrich-operated dedicated servers at Hetzner Online GmbH, data centre Nuremberg, Germany.
- Exercise and media files — Cloudflare R2 bucket
rehabpilot-mediain Western Europe (WEUR), served over TLS via the custom domainmedia.rosenheinrich.com. - Transactional email — Amazon SES in the EU sending region we configure in production.
Made in Germany · EU hosting. Details and transfer safeguards are in the Data Processing Agreement.
3. Security controls
- Encryption and transport
TLS/HTTPS for public endpoints. Media uploads use SigV4-presigned PUT URLs; after authorization, delivery is HTTPS via
media.rosenheinrich.com. R2 media uses AES-256 at rest. - Access control and tenancy
Least-privilege admin access, hashed passwords, HTTP-only session cookies where applicable, and logical separation by
practice_id. The clinic controls staff and patient access in the product. - Payments
Clinic subscriptions bill through Stripe. We do not store bank or card numbers. Stripe handles payment details under PCI-DSS; we receive billing metadata only.
- Sub-processors
Authorised sub-processors are listed in the DPA (version dated 2026-09-19). The DPA is the source of truth; material changes bump the DPA version.
- Deletion and retention
On clinic request or account deletion: production data within 30 days, backups within a further 90 days (except legal retention). In-app messages auto-delete after 30 days.
Encryption detail
- In transit
TLS/HTTPS for public endpoints. Media uploads use SigV4-presigned PUT URLs. After authorization, media is delivered over HTTPS via
media.rosenheinrich.com(Cloudflare R2 custom domain). - At rest
Cloudflare R2 stores media with AES-256 encryption at rest.
We do not claim application-level column encryption of the database, nor “end-to-end encryption” of therapy content. Hosting and access controls are described in the DPA Annex B (technical and organisational measures).
Access detail
- Least-privilege admin access; passwords stored as secure hashes; session tokens in HTTP-only cookies where applicable.
- Logical separation of practice data by
practice_id. - The clinic controls which patients and staff have access in the product.
- Application and server logging for security and operations, with retention limits documented in the Privacy Policy (license audit log up to 90 days).
Sub-processor list
| Provider | Role |
|---|---|
| Hetzner Online GmbH (Nuremberg) | Application hosting and databases |
| Cloudflare, Inc. | R2 object storage (rehabpilot-media, WEUR) and CDN for media.rosenheinrich.com |
| Amazon Web Services EMEA SARL (Amazon SES) | Transactional email |
| Google LLC | FCM push; optional Firebase Analytics; Google Sign-In when used |
| Apple Inc. | Sign in with Apple when used |
| Stripe, Inc. | Clinic subscription billing |
8. Documents
- Data Processing Agreement (DPA) · German: AVV
- UK GDPR Addendum
- Swiss nDSG Addendum
- Business Associate Agreement (BAA) — contractual terms for US clinics that process HIPAA-covered PHI (not a “HIPAA certified” badge)
- Privacy Policy · Datenschutz
- Terms of Service · AGB
9. Independent audits and hosting attestations
RehabPilot does not currently hold an ISO/IEC 27001 certificate of its own. We do not display ISO or C5 badges for RehabPilot.
Our application host, Hetzner Online GmbH, publishes its own information-security certifications for hosting and data centres (including ISO/IEC 27001 and a BSI C5 Type 2 attestation). Those attestations cover Hetzner’s infrastructure — not RehabPilot as a SaaS product:
10. Report a vulnerability
If you believe you have found a security issue in RehabPilot (apps, API, or this website), email [email protected] with enough detail for us to reproduce it. Please act in good faith and avoid privacy-invasive testing.
Out of scope: social engineering of our team, physical intrusion, and denial-of-service or brute-force testing against production.
We will acknowledge reports and keep you informed while we investigate. We will not pursue legal action against good-faith, responsible disclosure within this scope.
