Skip to Content
EnterpriseData Privacy (GDPR & HIPAA)

Data Privacy, GDPR & HIPAA Compliance

Omniflow is built to meet the data protection and privacy standards required by healthcare, financial services, and global enterprise organizations.


Automated PII & Sensitive Data Redaction

Omniflow automatically detects and masks Personally Identifiable Information (PII) and Payment Card Industry (PCI) data across voice audio, transcripts, and chat logs before storage:

Data TypeExample Redaction Behavior
Credit Card NumbersRedacted as [CARD_NUMBER_REDACTED] in transcripts; audio muted during number entry.
Social Security Numbers / National IDsRedacted as [SSN_REDACTED] across all logs.
Passwords & PINsMasked in real time; never stored in plaintext.
Customer Email & Phone NumbersMasked in public logs; accessible only to authorized agents with customer record view permissions.

Call Recording & Data Retention Policies

Configure retention schedules under Settings β†’ Security & Data Retention:

  • Automated Audio Purge: Automatically delete raw audio recordings after 30, 60, or 90 days while preserving anonymized transcripts and scorecards for reporting.
  • Workspace-Level Deletion Rules: Apply stricter retention limits for sensitive department queues (e.g., Billing records purged after 30 days).

HIPAA Compliance & Healthcare Safeguards

For healthcare organizations handling Protected Health Information (PHI):

  • Business Associate Agreements (BAAs): Omniflow signs enterprise BAAs covering all AI voice and chat channels.
  • End-to-End Encryption: Data encrypted in transit using TLS 1.3 and at rest using AES-256 with tenant-isolated database encryption keys.
  • Zero AI Model Training: Your customer voice calls and proprietary transcripts are never used to train public foundation models.

GDPR Data Subject Rights (DSR)

Omniflow provides built-in tools for European Union General Data Protection Regulation compliance:

  • Right of Access & Portability: Export all conversation history, audio files, and contact attributes for any user in standard JSON format.
  • Right to Erasure (Right to be Forgotten): Hard-delete all customer profile records, associated tickets, and voice recordings with one click under Contacts β†’ Delete Contact Data.

If you want to…Read
Manage team roles and permissionsRoles & Permissions
Configure Single Sign-On and 2FASSO & SCIM Provisioning
Explore deployment architecturesDeployment Options