Security and privacy

Health data, treated as it should be

In healthcare, trust is not a detail: it is the foundation. XIAgenda is built to comply with data protection laws — real compliance, not marketing.

Encrypted always

All communication travels encrypted (TLS) and data is stored encrypted at rest.

One isolated database per practice

Each practice has its own database, separate from others. Your patients are yours.

Two-step verification

Administrators log in with a second factor, to protect access to information.

Minimum necessary data

The agent asks for data only when needed and with a clear reason. Sensitive data like ID or insurance plan are optional and configurable.

The agent does not give medical advice

XIAgenda manages appointments, not medicine. Before a clinical consultation, an emergency signal or a delicate situation, refers to a person in the practice with context, and notifies the patient. It is a deliberate safety boundary: an agent trying to handle a medical emergency is a risk, not a savings.

What it remembers (and what it does not)

The agent remembers a structured profile that helps serve better: name, insurance plan, preferences and appointment history. Does not store diagnoses, raw transcriptions as "memory", or free inferences about the person.

Your rights as a patient

If you are a patient of a practice using XIAgenda, you can access your data, request rectification or deletion, and object to automated processing. Requests are managed through the practice. More details in our privacy policy.

Peace of mind for you and your patients

Try XIAgenda for free and see it working.

Try for free