EU-native · RODO/GDPR · AI Act Ready

Your patient data is safe. For real.

Flowright is the only dental AI receptionist built from the ground up for European data protection law.

Data Architecture

Most competitors route data through US servers. We don’t.

Patient
Phone / Chat
Flowright (EU servers)
Clinic Calendar
EU-only

ZERO transfers to the US. ZERO routing through non-EU servers.

Encryption

AES-256 encryption at rest, TLS 1.3 in transit. Voice recordings automatically deleted after scheduling data extraction.

GDPR & Health Data

Explained simply — for dentists, not lawyers

Did you know that dental appointment data may be classified as sensitive data? The Court of Justice of the EU in ruling C-21/23 confirmed that information allowing indirect determination of health status — including specialist appointment bookings — may constitute health data under Article 9 GDPR.

Basis: CJEU ruling C-21/23 — medical appointment data may constitute special category data (Art. 9 GDPR).

What this means for scheduling:

  • Even a dental appointment schedule can reveal information about a patient’s health
  • AI tools processing such data must meet elevated GDPR requirements (Art. 9)
  • Most general-purpose chatbots are not equipped for this

How Flowright addresses this:

Data minimization

We collect only the data necessary to book an appointment — nothing more.

Encryption at every stage

Data encrypted with AES-256 at rest and TLS 1.3 in transit.

Data Processing Agreement (DPA)

Every client receives a ready-made DPA compliant with Article 28 GDPR.

EU AI Act

New regulations that affect every clinic using AI

The EU AI Act is the world’s first comprehensive regulation governing artificial intelligence. Effective August 2026.

What this means for clinics:

  • Every AI system must disclose that you’re talking to AI, not a human
  • Synthetic voice must be labeled
  • Clinics must know what type of AI they’re using

Flowright is ready now:

AI identifies itself as artificial intelligence at the start of every conversation
Synthetic voice labeled in compliance with Art. 50 AI Act
AI system classification documentation included with the contract
Effective August 2026 — we’re ready now.

What You Get with Your Subscription

Complete compliance documentation — no need to hire a lawyer

  • DPA — Data Processing Agreement (Art. 28 GDPR)
  • Pre-filled DPIA template (Data Protection Impact Assessment)
  • GDPR patient information clause template — ready for your clinic
  • Sub-processor list with transfer safeguards
  • AI system classification documentation (not high-risk)

Market Comparison

Typical AI chatbot vs Flowright — on security & compliance

CriteriaTypical AI chatbotFlowright
EU servers
DPA Art. 28 GDPR
Health data protection (Art. 9)
AI Act readiness
DPIA template for clinic
Patient info clause
AI self-identification
Recording deletion after processing

Want to review our compliance documentation?

Schedule a call.

Schedule a call

Information on this page is general in nature and does not constitute legal advice. If in doubt, consult a lawyer specializing in data protection.