Quzek

Compliance & trust

Privacy & compliance you can build a practice on

Your clients trust you with their most sensitive information. Quzek is designed to help you honour that — with the privacy, security and consent tools you need to meet your obligations across the regions you work in.

Practices on Quzek operate under many different privacy laws depending on where they and their clients are. Rather than treat privacy as an afterthought, we build the underlying safeguards — consent, strong authentication, audit trails, encryption and strict data isolation — into the platform so you can meet your responsibilities wherever you practise.

The safeguards built into Quzek

A note on honesty. Quzek gives you the tools and safeguards to meet your obligations — it does not, on its own, make your practice compliant, and we do not claim certifications we do not hold. Where a regime needs a signed agreement (such as a Data Processing Agreement or a Business Associate Agreement) we can provide one on request. Compliance is a shared responsibility between the platform and how your practice uses it.

Read more about how we protect your data on our Security page, what we collect in our Privacy Policy, and how we process data on your behalf in our Data Processing Agreement.

Compliance questions, answered

Is Quzek HIPAA compliant?
Quzek is built to support HIPAA with access controls, audit logging, encryption and automatic logoff, and we can provide a Business Associate Agreement (BAA) on request. HIPAA compliance is a shared responsibility — the platform provides the safeguards, and your practice is responsible for how it uses them.
Is Quzek GDPR compliant?
Quzek provides the tools you need to meet GDPR — lawful-basis consent records, data export and deletion, encryption and access control — and we offer a Data Processing Agreement. You remain the data controller for your clients' information.
Do you have ISO 27001 certification?
We follow enterprise-grade security practices such as encryption, data isolation and role-based access. We are transparent about which formal certifications we do and do not currently hold — see our Security page or contact us for details for a due-diligence review.
Can I get a signed BAA or DPA?
Yes. Contact us and we will arrange a Business Associate Agreement (for HIPAA) or a Data Processing Agreement (for GDPR and similar regimes).
Where is my data stored, and who can see it?
Each practice runs in its own isolated database. Within your practice, role-based permissions control who can see what, and uploaded files are kept on private storage — never on public URLs.

Practise with confidence

Start a free 14-day trial and see the privacy and security tools built into every plan.

Start your free trial