Built for Norwegian healthcare — from the ground up.
Health data is among the most sensitive information there is. NorgeVox is designed to meet the requirements of the Norwegian healthcare sector — with a framework of technical and organisational measures that protect the office and its patients.
-
Data stored in Norway and the EU
We process and store call data on servers in Norway and the EEA, and we are committed to keeping personal data within the EEA. This is a deliberate infrastructure choice: Norwegian healthcare providers face strict requirements on the geographic location of sensitive information, and NorgeVox is built to meet those requirements. Where we use a subprocessor for a specific function, we disclose it and ensure the processing has a lawful basis.
-
GDPR and the data processing agreement
NorgeVox acts as a data processor on behalf of the GP office, which is the data controller. Every office signs a written data processing agreement (DPA) before the system goes live — in line with the requirements of GDPR Article 28. The agreement sets out the purpose, legal basis, deletion obligations, and the office's right to instruct. If you have questions about the agreement, please get in touch.
-
Norm for informasjonssikkerhet
The system is designed in accordance with Norway's Norm for informasjonssikkerhet og personvern i helse- og omsorgssektoren — the sector standard for IT security in Norwegian healthcare. This covers access control, event logging, a governed update schedule, and procedures for incident management.
-
Identity with BankID and HelseID
Where regulations require secure patient identification, NorgeVox supports integration with BankID and HelseID. This provides a level of identity assurance that satisfies healthcare requirements, and reduces the risk of information reaching the wrong person.
-
Encryption in transit and at rest
All communication between the patient's phone, the NorgeVox infrastructure, and the journal system is encrypted in transit. Stored data is encrypted at rest with industry-standard key rotation. It is therefore not possible to read call data without valid authorisation — even if the storage medium is compromised.
-
Built-in safety guardrail — never medical advice
NorgeVox is programmed to detect signs of acute illness, clinical questions, or emergencies. The assistant stops immediately, instructs the patient to call 113 or the emergency GP (legevakt), and notifies the office. Medical advice is never given — this is an absolute limit that cannot be overridden by configuration or instruction.
-
Subprocessors and third-party services
NorgeVox uses a limited set of approved subprocessors for infrastructure and integrations, including a journal-system integration provider. All subprocessors are bound by data processing agreements and meet the requirements for transfers within the EEA. An up-to-date list of subprocessors is available on request.
Technical and organisational measures are documented internally and can be shared with qualifying offices on request.
Ready to take the pressure off your phones?
Book a no-obligation demo and we'll show how NorgeVox fits into your day — in under 30 minutes.
Book a demo