Built with privacy
at the foundation.
Ruana is designed for healthcare practitioners who need a platform they can trust with sensitive patient data. All of our legal documents are published here in full.
Everything in plain sight
Click any document to read it in full. All documents are in plain language and updated as of February 25, 2026.
Terms of Service
The agreement governing your use of Ruana. Covers subscriptions, data ownership, billing, termination, liability, and dispute resolution including EU statutory rights carve-outs.
All UsersPrivacy Policy
How we collect, use, and protect personal data. Includes GDPR legal bases, CCPA rights for California residents, cross-border transfer disclosures, and our full subprocessor list.
EU / GDPRData Processing Agreement
Our GDPR Article 28 compliant DPA. Includes processor obligations, Standard Contractual Clauses (2021/914) for international transfers, subprocessor list, and 72-hour breach notification commitment.
US / HIPAABusiness Associate Agreement
Required for US-based Covered Entities under HIPAA. Defines Ruana’s obligations as a Business Associate, PHI safeguards, breach reporting timelines, and subcontractor obligations.
All UsersSecurity Overview
A detailed breakdown of our technical and organizational security measures — AWS infrastructure, AES-256 encryption, access controls, audit logging, incident response, and backup procedures.
Frameworks we operate under
Ruana is built for practitioners who operate under strict regulatory environments.