Novoflow procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | unknown | “ Novoflow is not a medical provider and does not provide medical advice, diagnosis, or treatment. Customers are responsible for clinical decisions and patient care. When required for healthcare customers, Novoflow will process protected health information under a Business Associate Agreement. The BAA controls Novoflow's obligations for protected health information if it conflicts with these Terms.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ We retain information for as long as needed to provide the services, meet contractual and legal obligations, maintain security and audit records, resolve disputes, and enforce agreements. Retention periods may vary by customer configuration, data type, and applicable Business Associate Agreement.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Either party may terminate use of the services as allowed by the applicable written agreement. Novoflow may suspend or terminate access for material breach, non-payment, security risk, unlawful use, or misuse of the services. Upon termination, customer data handling will follow the applicable agreement and legal requirements.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ The services may connect to EHRs, telephony providers, messaging providers, cloud services, AI model providers, authentication systems, and other third-party services. Novoflow is not responsible for third-party systems outside its control, and customers are responsible for maintaining the accounts, permissions, and contracts needed for those systems.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ The public website voice demo sends microphone audio and generated transcripts to an AI model provider to run the live scheduling demonstration. The demo starts only after a visitor selects the microphone control and can be stopped at any time. It is intended for fictional information only. Visitors must not provide real patient information, protected health information, or other sensitive personal information.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ We may share information with the customer that configured the workflow, authorized users, service providers and subprocessors that help us operate the services, security and infrastructure vendors, telephony and messaging providers, professional advisers, and government or legal authorities when required. We may also transfer information in connection with a merger, financing, acquisition, or sale of assets.” | Captured 2026-09-25Open source →Finding permalink → |
| Tier differences | All applicable tiers | unknown | “ Fees, payment terms, subscription details, usage limits, renewals, and cancellation rights are set out in the applicable order form, statement of work, invoice, or other written agreement. Fees are non-refundable except as expressly stated in the applicable agreement or required by law.” | Captured 2026-09-25Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.