Your patient data is stored in Geneva, Switzerland
Viali runs on Exoscale, a Swiss cloud provider. The application server and the database server are in the Geneva 2 zone (CH-GVA-2). This page names the provider, the location and the certifications, so that your IT team and your data protection officer have the answer in writing.
Where the data is
The four facts every clinic asks for in a procurement process.
Hosting provider
Exoscale — Akenes SA, Boulevard de Grancy 19A, 1006 Lausanne, Switzerland.
Server location
Geneva 2 zone (CH-GVA-2), an Equinix data centre in Geneva.
Data residency
The application server and the database are in Switzerland only. Patient data does not leave the country.
Transport and backup
Every connection uses TLS. Backups run daily and automatically, also in Switzerland.
Certifications of the infrastructure provider
Exoscale holds these certifications for its data centres and its operations. They are not a certification of the Viali software. Exoscale publishes the current status at exoscale.com/compliance.
Information security management system
Security controls for cloud services
Protection of personal data in the cloud
Audited effectiveness of controls over a period
French certification for the hosting of health data
German BSI criteria catalogue for cloud operations
Cloud Security Alliance registry
Security standard for payment data
What Viali does itself
- Each clinic works in its own tenant. No clinic can reach the data of another clinic.
- Role-based access control: the role governs which parts of the application a person uses.
- Access to the hosting environment is protected by two-factor authentication.
- The database server is not reachable from the internet. Only the application server can reach it.
- Audit logs record access to patient data.
- A Data Processing Agreement under GDPR Art. 28 and the Swiss FADP is available.
- Viali sells no patient data and discloses none for advertising purposes.
- We disclose technical infrastructure details in writing only, and only to a named clinic.
Access and logging
Who can reach a clinic's patient data, and what of that is traceable. The clinic is the controller; Viali processes the data on its behalf.
What is in place
- Access is only ever through a personal login. There are no shared accounts.
- Only staff of the treating clinic have access. No other clinic can reach the data.
- The role governs which parts of the application a person uses. The clinic assigns the roles and limits the circle to those involved in the treatment.
- Changes to the medical record are logged with the person and the time.
- Inactive sessions end automatically.
What does not exist today
- Individual read accesses are not logged today. Access logging is in preparation.
- There is no technical lock on individual patient records. Permissions act at the level of the clinic and the role, not of the single record.
The second point is a deliberate decision. Locking individual records would shut out, in an emergency, exactly the person who needs access. Clinical practice answers this with accountability rather than prevention — which is why access logging comes first.
Who else touches the data
| Provider | Purpose | Location |
|---|---|---|
| Exoscale (Akenes SA) | Operation of the platform, database and backups | Geneva, Switzerland |
| Resend | Delivery of the emails from the forms on viali.app. No patient data. | USA |
You receive the complete, current list of sub-processors together with the Data Processing Agreement.
Security questionnaires and detailed questions
We answer infrastructure questions in writing. Send your name, your function and your clinic from your business address to hello@viali.app. You receive the Data Processing Agreement, the list of sub-processors and a completed security questionnaire. We disclose no technical details by telephone.