Security and Role-Based Access
Get an overview of how access, logging, traceability, and separation between companies and locations are publicly described today.
View SecurityHere, FlowDule collects public descriptions of security, GDPR, access, logging, and data management, so teams, clinics, and chains can evaluate the platform faster.

Booking, patient records, payments, messages, and access management must be integrated if the platform is to function in practice for multiple roles and locations.
The Trust Center collects the areas most frequently inquired about in the sales and approval process: access, separation between companies, audit logs, GDPR processes, and data management over time.
Get an overview of how access, logging, traceability, and separation between companies and locations are publicly described today.
View SecuritySee how consents, policies, and documentation are integrated into workflows for booking, patient records, and communication.
View GDPR & PoliciesUse the embed and booking page flow as public documentation for how booking per company, widget, and address code-based setup are connected.
View Website IntegrationSee how the customer's documented profile determines how long journals are kept, what happens when someone asks for deletion, and how backups are phased out through documented rotation.
View Journal dataSee what determines the periods for bookings, payments, logs and account data, and which start dates and deletion actions the customer's retention profile must cover.
See retentionThe public summary of the Article 32 measures: access, separation between chains, encryption, traceability and operations. The binding level of security follows from the accepted, version-bound TOMs annex.
See the measuresWhich AI services the platform can use after separate activation, that client and journal data must not be used for model training, and that a competent user has to actively approve AI drafts.
See AI transparencyThe Trust Center collects the control areas that typically determine whether a platform can be used across teams and locations: role-based access, audit logs, consents, export, retention, and which materials are publicly described versus reviewed in dialogue.
Read about GDPR Workflows
AI helps with structure, drafts, and summaries. AI output has to be approved by a person before it becomes documentation, and AI does not write to the record on its own.
View Records & NotesPatient records require role-based access, and important changes must be traceable. Roles only see what they need.
View SecurityConsents, export, and data management are part of the workflow around patient records, not a separate compliance project.
View GDPR & PoliciesUse the Trust Center in conjunction with the solution for clinics and chains when assessing management, access and responsibility, locations, and central control collectively.
View SolutionDive into the security architecture: encryption, separation between companies, role-based access, audit logs, and two-factor authentication.
View SecurityThe Data Processing Agreement and the sub-processor list are publicly available under Legal. If you need a more concrete review of controls, we'll handle it in writing - you don't need to book a meeting to move forward.
Contact UsCreate a free account and review roles, locations, logging, GDPR processes and the trust materials relevant to your specific evaluation yourself. 30 days free, no credit card and no sales meeting.