Regulatory Compliance
Mindmore develops a CE-marked digital platform for cognitive assessment. We work systematically with quality, information security and data protection in accordance with applicable regulations and standards.

MDR
MDR: Medical Device Regulation
Mindmore's platform is CE-marked as a Class IIa medical device under the EU Medical Device Regulation (MDR 2017/745). Conformity has been assessed by a notified body, and Mindmore is under the supervision of the Swedish Medical Products Agency (Läkemedelsverket).
We comply with the MDR by:
-
Maintaining technical documentation in line with regulatory requirements
-
Carrying out risk management and clinical evaluation of the product's safety and performance
-
Monitoring the product after it is placed on the market (PMS) and improving it continuously based on user data and regulatory requirements


Quality and information security
ISO 13485: Quality management for medical devices
Mindmore has a quality management system certified to ISO 13485. It ensures that our product is developed, produced and monitored in line with regulatory requirements, and covers, among other things:
-
Document control: structured and traceable documentation of product development and production
-
Risk management: systematic processes to identify and manage risks throughout the product lifecycle
-
Product development and validation: requirements for testing and validation before new versions are released
ISO 27001: Information security
Our information security management system (ISMS) is designed according to ISO 27001 and protects sensitive data through:
-
Risk management: identification, assessment and treatment of security risks
-
Encryption and data protection: secure storage and transfer of data
-
Access control and authentication: role-based access control and multi-factor authentication
-
Logging and monitoring: traceability through continuous monitoring of system activity
Privacy and GDPR
At Mindmore, we continuously work to improve our processes and strengthen security in the handling of personal data. We do not store more information than we need, whether you visit our website or use our digital platform.
All Mindmore employees and consultants have signed confidentiality agreements and agreements requiring compliance with the GDPR when handling data.
We always sign a data processing agreement with our customers covering the handling of test takers' data, and test data is handled in accordance with the Swedish Patient Data Act (patientdatalagen). If you are a user or test taker and want full information about your rights, please see Chapter 3 of the General Data Protection Regulation.

Security and data storage in Mindmore's digital platform
All data is stored and processed within the EU/EEA and is handled only by sub-processors whose owners are based in the EU/EEA. We do this to comply with the GDPR and to follow the practice established by the Schrems II ruling. Read more about the ruling and why it matters here.
Test results are linked to a pseudonym instead of a name or personal identity number. The pseudonym is generated automatically when a test session is created and is recorded by the healthcare provider in the patient record. Only the healthcare provider can link the pseudonym to a person; Mindmore cannot link test data to an individual.
Audio recordings from certain subtests are stored to enable manual scoring. Since a voice can in theory be recognised, audio recordings are not considered fully pseudonymised and are therefore given additional protection.
Which information about the test taker is stored, for example an email address for invitations, age and sex, is governed by the data processing agreement with each customer.
Mindmore provides a multi-tenant solution. This means that each organisation's data is separated through access control and can only be accessed by authenticated users with the right organisational affiliation and authorisation. All data traffic to and from the system is encrypted, and a centralised permission structure makes it easy to decide which user can do what. Mindmore also offers multi-factor authentication at login.