For occupational health

Security for sensitive data

As an occupational health service, you handle sensitive patient data for your customers. We take that responsibility seriously.

GDPR
SSL/TLS

How we protect your and your customers' data

Health declarations, medical notes, and personal data — everything is handled with the highest security.

GDPR-compliant for healthcare

We follow GDPR and the specific requirements for health and medical data. Your patients' information is processed according to applicable regulations.

Data in Sweden

All patient data and health declarations are stored with certified cloud providers within the EU. No uncertainty about where sensitive information ends up.

Strong encryption

All data is protected with strong encryption — both health declarations at rest and information sent between you, your customers, and us.

Access control

Each customer company only sees their own data. Your staff gets role-based access so the right person sees the right information.

Backup

Regular backups of all patient data ensure nothing is lost if something unexpected happens.

Continuous monitoring

We monitor the system around the clock and act quickly on deviations. Logging of all access for traceability.

Secure separation between your customers

Each customer company has its own isolated environment in Portway. Data can never leak between customers — you can safely manage multiple companies in the same system.

Strict data isolation per customer company
Separate permissions and user groups
Customer-specific portals with own branding
Complete logging of all access
Your customer companies
Företag AB
45 employees
Isolated data
Tech Nordic
120 employees
Isolated data
Konsult & Co
28 employees
Isolated data
No data shared between customers

Need more details?

If your IT department or data protection officer needs more information for security review, contact us and we'll send relevant documentation.

Contact us
Complete security documentation
Data Processing Agreement (DPA)
Technical architecture description
Incident handling procedures