This Data Processing Agreement ("DPA") forms part of your agreement with FlowLeads Limited and sets out the terms on which we process personal data on your behalf. A signed copy is available on request — email support@flowleads.co.nz.
"Controller" means the clinic or business that determines the purposes and means of processing personal data (you, the client).
"Processor" means the entity that processes personal data on behalf of the Controller (FlowLeads Limited).
"Personal data" means any information relating to an identified or identifiable natural person.
"Processing" means any operation performed on personal data, including collection, storage, retrieval, use, disclosure, and deletion.
"Data subject" means the individual whose personal data is being processed (in the context of FlowLeads, this is typically a patient or caller).
"Privacy Act" means the New Zealand Privacy Act 2020 and, where applicable, the Health Information Privacy Code 2020.
The parties acknowledge that:
FlowLeads processes the following categories of personal data on behalf of the Controller:
FlowLeads does not process: medical records, clinical notes, diagnoses, treatment histories, or sensitive health information beyond what a caller voluntarily states during a booking call.
FlowLeads will process personal data for the duration of the subscription agreement. Upon termination of the agreement, all personal data will be retained for 30 days to allow the Controller to request an export, after which it will be permanently and securely deleted.
FlowLeads will process personal data only on documented instructions from the Controller, which are established through:
If FlowLeads is required by law to process data in a manner that conflicts with the Controller's instructions, FlowLeads will notify the Controller before processing, unless prohibited by law.
FlowLeads implements and maintains the following technical and organisational measures to protect personal data:
The Controller authorises FlowLeads to engage sub-processors as listed at flowleads.co.nz/sub-processors. FlowLeads will:
FlowLeads will assist the Controller in responding to data subject requests (access, correction, deletion) by providing the Controller with the relevant data held in the platform within 10 working days of a written request.
Data subjects (patients) should direct requests to the Controller (the clinic), not to FlowLeads directly.
In the event of a personal data breach that affects data processed on behalf of the Controller, FlowLeads will:
Personal data is primarily stored in AWS ap-southeast-2 (Sydney, Australia). Some processing occurs in the United States via sub-processors (including voice AI services). FlowLeads takes reasonable steps to ensure adequate protections are in place for cross-border transfers, consistent with the requirements of the NZ Privacy Act 2020.
The Controller may request, no more than once per calendar year and with 30 days' written notice, a written summary of FlowLeads' security practices and compliance documentation. FlowLeads will cooperate in good faith with any such request.
Upon written request from the Controller, or upon termination of the subscription, FlowLeads will:
This DPA is governed by the laws of New Zealand. The parties submit to the non-exclusive jurisdiction of the New Zealand courts.
If your procurement process requires a countersigned Data Processing Agreement, we're happy to provide one. Get in touch and we'll have it back to you promptly.
Request a signed DPA →