Do you have ISO 27001 certification?
We don't hold ISO 27001 directly as a startup — but the infrastructure we're built on does. Vercel, Neon, Clerk, Twilio, and Stripe all hold independent SOC 2 Type II certification (and in Twilio's case, ISO 27001). These are the same platforms used by companies that do hold ISO 27001. As we scale, formal certification is on our roadmap.
Where is patient data stored?
Call transcripts, booking details, and caller information are stored in Neon PostgreSQL, hosted on AWS ap-southeast-2 in Sydney, Australia. Data does not leave ANZ jurisdiction for storage purposes.
What happens to data if we stop using FlowLeads?
We retain your data for 30 days after subscription termination to allow you to request an export. After that, all patient call data is permanently and securely deleted. Written confirmation of deletion is available on request.
Can FlowLeads staff access our call recordings or patient data?
Access to client data is strictly limited to essential operations (support and troubleshooting) and only with documented need. We do not access, review, or use your call data for any purpose other than delivering the service.
What happens if there's a data breach?
We carry cyber liability insurance and have a defined incident response process. In the event of any breach affecting your data, we notify you within 72 hours with details of what happened, what data was affected, and what steps we've taken. We assist with any notification obligations to the Office of the Privacy Commissioner.
Is Aria HIPAA compliant?
HIPAA applies to US healthcare providers. FlowLeads is designed for NZ and Australian allied health, where the relevant frameworks are the NZ Privacy Act 2020, the Health Information Privacy Code 2020, and the Australian Privacy Principles — all of which we're built to comply with.