
Self-declared regulatory positioning · Positionnement réglementaire auto-déclaré
Last updated: 5 August 2026 · compliance-1.0
EN. ChronoPill provides reference information about medicines from official sources. It is not a medical device and does not provide clinical decision support, diagnosis, prescription advice, or treatment recommendations. Always consult a qualified healthcare professional. This positioning is self-determined and documented, on the following basis:
FR. ChronoPill fournit une information de référence sur les médicaments, issue de sources officielles. Ce n'est pas un dispositif médical et n'assure aucune aide à la décision clinique, diagnostic, ni recommandation de traitement. Consultez toujours un professionnel de santé.
EN. ChronoPill is built privacy-first: your medication data, schedules and health metrics (HealthKit height/weight) are stored locally on your device and are never transmitted to our servers. Our reference/clinical database layer contains no personal or identifiable patient data (no PHI). We use no advertising or third-party tracking SDKs. We self-declare compliance with the applicable data-protection law of each market where the app is offered:
| Market | Applicable data-protection framework |
|---|---|
| 🇪🇺 EU / 🇫🇷 France | GDPR / RGPD (health data = special category, Art. 9); FR: hosting on HDS-certified infrastructure; EHDS / EU Data Act |
| 🇺🇸 USA | HIPAA (by design outside scope: no PHI stored server-side; safeguards aligned where applicable), HITECH, CCPA/CPRA |
| 🇬🇧 United Kingdom | UK GDPR + Data Protection Act 2018 |
| 🇦🇩 Japan | APPI (health data = sensitive; consent-based) |
| 🇨🇦 Canada | PIPEDA + provincial (PHIPA Ontario, Law 25 Québec) |
| 🇲🇦 Morocco | Loi 09-08 + CNDP |
FR. Données de santé stockées localement sur l'appareil, jamais transmises à nos serveurs ; la couche de référence ne contient aucune donnée personnelle. Conformité auto-déclarée au cadre de protection des données applicable dans chaque marché.
EN. ChronoPill's backend runs on Amazon Web Services (AWS), whose infrastructure is independently certified (ISO/IEC 27001, 27017, 27018, SOC 2; HDS-certified regions available; Business Associate Agreement available for HIPAA). ChronoPill targets ISO/IEC 27001 and 27701 and SOC 2 Type II for its B2B / hospital offering; these are pursued through independent third-party audit and are not claimed as obtained unless a valid certificate is held.
EN. Clinical coding in each market uses that country's official terminologies: ICD-10 (national editions), MedDRA (MedDRA/J in Japan), SNOMED CT (UK & US editions), dm+d (UK), YJ code (Japan), UNII/RxNorm (US), BDPM (France), AMMPS/EAN-13 (Morocco), ATC. Every data value carries per-field provenance; inferred or cross-country values are explicitly flagged, never presented as official source data.
Markets: European Union (incl. France), United States, United Kingdom, Canada, Japan, Morocco.
Authoritative languages of this notice: English, Français. Localized versions (العربية / 日本語 and other market languages) are provided for convenience only and will be reviewed by qualified counsel; in case of discrepancy the English or French version prevails.
This notice is a good-faith self-declaration of ChronoPill's regulatory positioning and does not constitute legal advice. Questions: contact us via the app or website.