FlowDule
Trust Center

GDPR, Consents, and Operational Policies

This section describes how FlowDule handles consents, policies, data management, and documentation - so you can assess if the platform meets your compliance requirements.

GDPR, Consents, and Operational Policies (AI-genereret billede)AI-genereret indhold

GDPR support integrated into daily workflows

FlowDule processes personal data in bookings, records, communication, and payments on the customer's behalf: the clinic is the controller for client and record data, and FlowDule is the processor. Consent, policies, and data management are therefore built into the workflows already in use - not as a separate compliance process.

This page provides an overview of the processes and features that support GDPR compliance within the platform.

GDPR

Consents, Policies, and Data Management

The most important GDPR processes in the platform

Consent upon creation (AI-genereret billede)ConsentAI-genereret indhold

Consent upon creation

Consent and policy acknowledgements are recorded with customer, accepter, authority, version, document hash and time. Material changes are normally announced at least 30 days before they take effect, after which ordinary use is blocked until an authorised person accepts the new version; reading, support, export and termination remain open. Consent is not the legal basis for everything in the platform.

Operational Policies (AI-genereret billede)PoliciesAI-genereret indhold

Operational Policies

Chains can define versioned privacy, AI, cancellation, no-show, consent and communication texts within mandatory security and information boundaries.

Data Export and Portability (AI-genereret billede)RightsAI-genereret indhold

Data Export and Portability

The customer can export client, booking, record, file and configuration data with relations and metadata in commonly used, machine-readable formats. Export is available during the agreement and for at least 30 calendar days after the agreed transition period. PII can be anonymized when data needs to be used for analysis or shared with third parties.

Retention and Deletion (AI-genereret billede)LifecycleAI-genereret indhold

Retention and Deletion

There is no single retention period that applies to all customers. The customer selects and documents a profile based on country, profession, authorisation and purpose; an unlicensed psychotherapist has no automatic 5- or 10-year period, and FlowDule does not determine the customer's retention obligation. On an erasure request, secondary purposes and unnecessary sharing stop; necessary lawful use of the record remains logged.

Role-based access to personal data (AI-genereret billede)AccessAI-genereret indhold

Role-based access to personal data

Only users with the correct roles can access personally identifiable data. Access is controlled per chain, location, and processor.

Documentation and Traceability (AI-genereret billede)AuditAI-genereret indhold

Documentation and Traceability

Relevant actions on client and record data must be traceable to an identified user, including reading, modification, export and sharing. Log coverage is documented in the control evidence, and a control is described as verified only once it has been tested in operation.

Data Lifecycle and Retention in FlowDule (AI-genereret billede)AI-genereret indhold
Data Lifecycle

From creation to deletion - with traceability all the way

Data follows the lifecycle from collection through restriction, anonymisation, deletion and backup expiry. An approved deletion process must cover active records, files, shares, search indexes, queues, AI copies and export files, and backups are deleted through documented rotation. Each public claim is mapped to a control ID, and missing, expired or failed mandatory evidence will block publication.

Back to Trust Center
Next Steps

Review GDPR processes and policies in practice

Create a free account and see consents, policies, data export and retention in the running platform yourself. 30 days free, no credit card.