Data Management & Compliance

Trusted, secure, and compliant by design

At Amiko, we prioritize data security, regulatory compliance, and patient privacy. The Respiro platform is built to meet the highest industry standards, ensuring safety, integrity, and compliance in inhalation medicine. Our robust cloud infrastructure and ISO-certified quality systems provide a secure foundation for healthcare providers, pharma companies, and patients worldwide.

Certifications & Regulations 

CE Mark

Selected Respiro components are CE-marked medical devices under the EU Medical Device Regulation. Technical documentation available on request.

EU MDR

Design, manufacturing, and post-market surveillance for CE‑marked devices follow EU Medical Device Regulation requirements.

ISO 13485

Amiko operates a certified Quality Management System for medical devices covering design, production, and servicing.

HIPAA

US deployments are designed to support HIPAA requirements. Business Associate Agreements and administrative/technical safeguards are available.

GDPR

We act as a data processor and provide GDPR‑aligned processing, data‑residency options, and Data Processing Agreements.

Core quality, privacy, and security controls

The Respiro platform is designed for regulated healthcare environments and is built on an integrated set of quality, privacy, and security controls applied across the full product lifecycle.

Quality & lifecycle management

Certified Quality Management System governing product design, manufacturing, and post-market activities.

Certified quality systems and lifecycle processes ensuring product safety, traceability, and regulatory compliance.
Lifecycle processes driven by risk management, verification, validation, and documented traceability.

Structured change control, supplier oversight, and continuous process optimization to maintain product quality.

Privacy & Data Protection

Privacy-by-design principles supporting lawful, transparent, and secure handling of personal and health data.
Deployments aligned with international privacy regulations to ensure lawful and secure data processing.
System architecture supports operation with minimal personal data, reducing exposure and safeguarding user privacy.

Data Processing Agreements (DPAs) and Business Associate Agreements (BAAs) available to define responsibilities and ensure compliance.

Established procedures for user consent, access, correction, retention, and deletion of personal data.

Security & operational controls

Medical-grade security controls protecting data, systems, and operations.

Comprehensive encryption applied across data storage, transmission, and backup systems.
Role-based permissions, least-privilege principles, and secure authentication mechanisms.
Continuous monitoring with audit trails, alerting, and documented incident response workflows.
Integrated security controls across the SDLC, vulnerability management, and periodic security assessments