Data Privacy, GDPR & HIPAA Compliance
Omniflow is built to meet the data protection and privacy standards required by healthcare, financial services, and global enterprise organizations.
Automated PII & Sensitive Data Redaction
Omniflow automatically detects and masks Personally Identifiable Information (PII) and Payment Card Industry (PCI) data across voice audio, transcripts, and chat logs before storage:
| Data Type | Example Redaction Behavior |
|---|---|
| Credit Card Numbers | Redacted as [CARD_NUMBER_REDACTED] in transcripts; audio muted during number entry. |
| Social Security Numbers / National IDs | Redacted as [SSN_REDACTED] across all logs. |
| Passwords & PINs | Masked in real time; never stored in plaintext. |
| Customer Email & Phone Numbers | Masked in public logs; accessible only to authorized agents with customer record view permissions. |
Call Recording & Data Retention Policies
Configure retention schedules under Settings β Security & Data Retention:
- Automated Audio Purge: Automatically delete raw audio recordings after 30, 60, or 90 days while preserving anonymized transcripts and scorecards for reporting.
- Workspace-Level Deletion Rules: Apply stricter retention limits for sensitive department queues (e.g., Billing records purged after 30 days).
HIPAA Compliance & Healthcare Safeguards
For healthcare organizations handling Protected Health Information (PHI):
- Business Associate Agreements (BAAs): Omniflow signs enterprise BAAs covering all AI voice and chat channels.
- End-to-End Encryption: Data encrypted in transit using TLS 1.3 and at rest using AES-256 with tenant-isolated database encryption keys.
- Zero AI Model Training: Your customer voice calls and proprietary transcripts are never used to train public foundation models.
GDPR Data Subject Rights (DSR)
Omniflow provides built-in tools for European Union General Data Protection Regulation compliance:
- Right of Access & Portability: Export all conversation history, audio files, and contact attributes for any user in standard JSON format.
- Right to Erasure (Right to be Forgotten): Hard-delete all customer profile records, associated tickets, and voice recordings with one click under Contacts β Delete Contact Data.
Related Guides
| If you want to⦠| Read |
|---|---|
| Manage team roles and permissions | Roles & Permissions |
| Configure Single Sign-On and 2FA | SSO & SCIM Provisioning |
| Explore deployment architectures | Deployment Options |