FlowLeads is an AI virtual receptionist service for allied health clinics. This document summarises our security posture, data practices, and compliance frameworks for procurement and due diligence purposes. A full Data Processing Agreement and Privacy Policy are available at flowleads.co.nz/policy-hub.
| Layer | Description | Data Location | Certifications |
|---|---|---|---|
| Application Hosting | Serverless web application infrastructure — no persistent servers exposed to the internet | Global edge | SOC 2 Type II |
| Database & Storage | All clinic and patient call data — encrypted at rest and in transit | Australia (Sydney) | SOC 2 Type II |
| Authentication | User login, session management, and MFA — FlowLeads never stores passwords | USA | SOC 2 Type II |
| Telephony & SMS | Phone number provisioning and patient SMS delivery | USA | SOC 2 Type II, ISO 27001 |
| Payment Processing | All billing — FlowLeads never sees or stores card numbers | USA | PCI DSS Level 1, SOC 2 Type II |
| Voice & AI Processing | Aria's call handling — isolated per-call sessions, no persistent audio retention | USA | SOC 2 Type II |
Full sub-processor details available upon request under NDA.
FlowLeads operates as a data processor — clinics are the data controller and retain full ownership of patient information. Processing occurs solely on the clinic's instruction for the purpose of delivering the FlowLeads service. A countersigned Data Processing Agreement is available on request.