SECURITY, PRIVACY & COMPLIANCE

Regional data hosting and compliance-ready deployments for healthcare and enterprise

LogMeal can deploy customer services on Google Cloud infrastructure in the European Union or the United States according to the agreed data-residency, privacy and regulatory requirements. Healthcare deployments can be configured for GDPR- and HIPAA-regulated workflows, including PHI processing under the appropriate contractual framework.

DATA RESIDENCY

Choose EU or US Google Cloud hosting according to customer requirements

LogMeal operates Google Cloud infrastructure in both European Union and United States regions. The hosting region for a customer deployment is selected according to the contracted service, customer location, data-residency requirements and applicable regulatory framework.

EU-based deployments are available for customers that require European data residency and GDPR-oriented processing. US-based deployments are available for customers whose service, healthcare or enterprise requirements call for data processing in the United States.

The applicable region and data-flow architecture should be agreed during onboarding and reflected in the relevant commercial agreement, Data Processing Agreement, Business Associate Agreement or other contractual documentation where required.

European Union

Google Cloud hosting in EU regions for European data-residency requirements and GDPR-regulated customer workflows.

United States

Google Cloud hosting in US regions for US customer deployments, including healthcare environments where HIPAA requirements and PHI processing are in scope.

GDPR

GDPR-oriented processing and European data protection safeguards

For services subject to the General Data Protection Regulation, LogMeal supports GDPR-compliant processing through customer-specific data flows, contractual data-processing terms and appropriate technical and organisational measures.

Where LogMeal processes personal data on behalf of a customer, the parties can document controller and processor responsibilities through the applicable Data Processing Agreement. The agreement should define the processing purpose, categories of data, retention, security obligations and subprocessors relevant to the service.

Where a GDPR-regulated transfer of personal data outside the EEA requires additional safeguards, Standard Contractual Clauses or another valid transfer mechanism can be used as applicable.

EU regional hosting can reduce unnecessary cross-border data movement, but hosting location alone does not determine GDPR compliance. The complete processing purpose, lawful basis, contracts, access model, retention and data flows must also be considered.

HIPAA & PHI

HIPAA-compliant healthcare deployments under a Business Associate Agreement

For US healthcare customers where LogMeal creates, receives, maintains or transmits Protected Health Information (PHI) on behalf of a HIPAA Covered Entity or another Business Associate, LogMeal can operate as a Business Associate under an applicable Business Associate Agreement (BAA).

The BAA defines the permitted and required uses and disclosures of PHI, the responsibilities of the parties and the safeguards applicable to the HIPAA-scoped service.

PHI should only be sent to LogMeal when the customer deployment has been explicitly approved for HIPAA use, the required BAA is in effect and the agreed technical architecture and data flows are configured for that scope.

LogMeal uses Google Cloud infrastructure for these deployments. Google Cloud supports HIPAA compliance within the scope of its BAA and covered services; HIPAA compliance remains a shared responsibility between the cloud provider, LogMeal and the customer.

Covered Entity

A HIPAA Covered Entity is generally a healthcare provider, health plan or healthcare clearinghouse that meets the HIPAA definition and is subject to the HIPAA Rules.

A Business Associate is an organisation that performs functions or provides services involving PHI on behalf of a Covered Entity, or acts as a subcontractor that creates, receives, maintains or transmits PHI on behalf of another Business Associate.

Protected Health Information (PHI) is individually identifiable health information protected under HIPAA when it is created, received, maintained or transmitted by a Covered Entity or Business Associate in the applicable context.

HHS explains that Covered Entities and Business Associates must use written Business Associate contracts where the Business Associate handles PHI.

HHS Business Associate Agreement guidance describes the required contractual protection of PHI.

Google Cloud states that its HIPAA BAA covers its infrastructure and listed covered services, while customers remain responsible for building and operating a HIPAA-compliant solution.

Contracts

Compliance requirements are reflected in the customer agreement

Data Processing Agreement (DPA)

Used where required to document GDPR controller/processor responsibilities, processing instructions, security obligations, subprocessors and data-transfer terms.

Business Associate Agreement (BAA)

Used for HIPAA-scoped services where LogMeal acts as a Business Associate or subcontractor Business Associate and PHI is processed.

Standard Contractual Clauses (SCCs)

Used where applicable as a GDPR safeguard for international transfers of personal data outside the EEA.

Customer-specific security and deployment terms

Used to document the agreed hosting region, data categories, access model, retention, integrations and other deployment-specific controls.

technology resources
ACCESS CONTROL

Role-based API access and customer-specific permissions

LogMeal uses bearer-token authentication and separates company administration, end-user activity and authorised manager or professional access through different user roles.

APICompany

Company-level administration and user-management access.

APIUser

User-specific access for meal submission, recognition and personal nutrition workflows.

APIUserManager

Authorised access to multiple users where supported by plan, permissions and customer configuration.

ENTERPRISE & HEALTHCARE ONBOARDING

Define compliance scope before production deployment

Confirm whether personal data, health data or PHI will be processed.

Confirm whether the customer is acting as a HIPAA Covered Entity, Business Associate or neither.

Select the agreed Google Cloud hosting region: EU or US.

Define controller/processor roles and execute a DPA where required.

Execute a BAA before PHI is processed where HIPAA applies.

Confirm the LogMeal services and Google Cloud services included in the HIPAA-scoped architecture.

Map data flows, integrations, access roles, retention and deletion requirements.

Assess international transfers and apply SCCs or another valid mechanism where required.

Document customer-specific security, procurement and compliance requirements before go-live.

Security, privacy and compliance questions

Where can LogMeal customer data be hosted?

LogMeal can provide Google Cloud hosting in EU or US regions. The applicable region is selected according to the customer contract, data-residency requirements and service architecture.

Yes. LogMeal supports GDPR-compliant deployments through appropriate regional hosting, privacy and security controls, Data Processing Agreements and international-transfer safeguards such as SCCs where applicable.

Yes, when the healthcare deployment is explicitly scoped for HIPAA, the required BAA is in effect and the technical architecture is configured for the agreed PHI processing.

For applicable US healthcare deployments where LogMeal acts as a Business Associate or subcontractor Business Associate, the parties can execute a BAA governing PHI processing.

HIPAA does not have a general HHS-recognized certification. The appropriate wording is that LogMeal supports HIPAA-compliant deployments when the required contractual and technical controls, including a BAA, are in place.

Yes, depending on the customer, data subjects and data flows. The requirements should be assessed together and reflected in the selected region, contracts and technical architecture.

Bearer-token authentication and role-based access separate company administration, end-user activity and authorised manager access.

Need to validate LogMeal for GDPR, HIPAA or regional data-residency requirements?

Share your deployment region, data categories, PHI requirements, security review and contractual needs with our team.

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.