๐ŸŒธ
BloomSenzAI
Home/Compliance
๐Ÿ›ก๏ธCompliance-Ready Platform

Built for Security.
Designed for Compliance.

BloomSenzAI platforms handle sensitive health data for children, families, and pets. Compliance isn't an afterthought โ€” it's foundational to every line of code, every API endpoint, and every data flow in our systems.

HIPAA-ReadyGDPRSOC 2COPPAFERPAPCI DSSISO 27001DPDP Act
๐ŸŒCross-Platform

Shared Compliance Framework

These standards apply across both Innerwork and BloomPaws, ensuring every platform meets the same rigorous security and privacy bar.

๐Ÿ”
SOC 2 Type IIIn Progress

SOC 2 Type II

Our infrastructure and operations are built to meet SOC 2 Trust Service Criteria. We implement continuous monitoring of security controls, access management, change management, and incident response across all BloomSenzAI platforms.

  • โœ“Annual independent third-party audits
  • โœ“Continuous control monitoring via automated tooling
  • โœ“Least-privilege access with MFA enforcement
  • โœ“Encrypted data at rest (AES-256) and in transit (TLS 1.3)
  • โœ“Formal incident response and business continuity plans
๐Ÿ‡ช๐Ÿ‡บ
GDPRCompliant

General Data Protection Regulation (GDPR)

Both Innerwork and BloomPaws are designed with privacy-by-design principles. We provide full GDPR compliance for organisations operating in the EU/EEA or handling data of EU residents.

  • โœ“Lawful basis for processing (consent, contract, legitimate interest)
  • โœ“Right to access, rectification, erasure, and data portability
  • โœ“Data Processing Agreements (DPAs) available for all customers
  • โœ“Data residency options โ€” AU, EU, and US regions
  • โœ“Appointed Data Protection Officer (DPO)
  • โœ“72-hour breach notification procedures
๐Ÿ”’
ISO 27001Aligned

ISO 27001 Information Security

Our information security management system (ISMS) is aligned with ISO 27001 controls. We maintain documented policies, risk assessments, and security controls across all platforms.

  • โœ“Formal information security policy and risk register
  • โœ“Periodic risk assessments and treatment plans
  • โœ“Employee security awareness training
  • โœ“Vendor and third-party security assessments
  • โœ“Physical and logical access controls
๐Ÿ’ณ
PCI DSSCompliant

Payment Card Industry Data Security Standard

All payment processing across both platforms is handled via PCI DSS Level 1 certified providers (Razorpay, Stripe). No card data is ever stored, processed, or transmitted by BloomSenzAI servers.

  • โœ“Tokenized payment processing via certified gateways
  • โœ“No card data stored on BloomSenzAI infrastructure
  • โœ“Strong Customer Authentication (SCA) support
  • โœ“Secure webhook verification for payment events
๐Ÿง Innerwork โ€” Therapy Platform

Healthcare & Therapy Compliance

Innerwork handles Protected Health Information (PHI) for children and families. These regulations are specifically addressed in our therapy platform.

๐Ÿฅ
HIPAAReady

HIPAA โ€” Health Insurance Portability & Accountability Act

Innerwork is HIPAA-ready for therapy centres handling Protected Health Information (PHI). Our platform implements the full spectrum of HIPAA Technical, Administrative, and Physical Safeguards.

  • โœ“Business Associate Agreements (BAAs) for all customers
  • โœ“End-to-end encryption for PHI in transit and at rest
  • โœ“Role-based access control (RBAC) with audit trails
  • โœ“Automatic session timeouts and re-authentication
  • โœ“PHI access logging with tamper-evident audit logs
  • โœ“Secure messaging between therapists and parents
  • โœ“Data backup and disaster recovery procedures
๐ŸŽ“
FERPAReady

FERPA โ€” Family Educational Rights & Privacy Act

For therapy centres operating within educational settings (school-based therapy, early intervention), Innerwork supports FERPA compliance by protecting student education records and therapy progress data.

  • โœ“Parental consent management for student data access
  • โœ“Restricted access to student therapy records
  • โœ“Integration-ready with school district identity providers
  • โœ“Data deletion upon request from educational agencies
๐Ÿ‘ถ
COPPAReady

COPPA โ€” Children's Online Privacy Protection Act

Innerwork handles data of children under 13 through the parental consent model. The child never directly provides personal information โ€” all data flows through the authenticated parent or therapist.

  • โœ“Parental control system with policy enforcement
  • โœ“No direct data collection from children
  • โœ“Parent-controlled device mode with usage tracking
  • โœ“Verifiable parental consent before child data processing
  • โœ“Minimal data collection principle for child profiles
๐Ÿ‡ฎ๐Ÿ‡ณ
DPDP ActReady

India Digital Personal Data Protection Act, 2023

For therapy centres operating in India, Innerwork complies with the DPDP Act provisions for processing personal data of children and health-related data.

  • โœ“Consent-based data processing with purpose limitation
  • โœ“Right to correction and erasure of personal data
  • โœ“Guardian consent for processing child data (under 18)
  • โœ“Data localisation support for Indian customers
  • โœ“Grievance redressal mechanism
๐Ÿ‡ฆ๐Ÿ‡บ
Australian Privacy ActCompliant

Australian Privacy Act 1988 & APPs

As an Australian company, BloomSenzAI fully complies with the Australian Privacy Act and the 13 Australian Privacy Principles (APPs) governing the collection, use, and disclosure of personal information.

  • โœ“Compliance with all 13 Australian Privacy Principles
  • โœ“Transparent privacy policy and collection notices
  • โœ“Cross-border data transfer protections
  • โœ“Notifiable Data Breach (NDB) scheme compliance
๐ŸพBloomPaws โ€” Pet Care Platform

Veterinary & Pet Care Compliance

BloomPaws handles veterinary records, pet owner personal data, and pharmacy workflows โ€” each with specific regulatory requirements.

๐Ÿพ
Veterinary DataCompliant

Veterinary Record-Keeping Standards

BloomPaws maintains electronic veterinary records in accordance with veterinary board requirements across supported jurisdictions โ€” including vaccination histories, treatment records, and prescription logs.

  • โœ“Structured electronic medical records (EMR) for animals
  • โœ“Vaccination schedule tracking with regulatory compliance
  • โœ“Prescription and controlled substance audit trails
  • โœ“Record retention policies aligned with veterinary board requirements
๐Ÿ›ก๏ธ
Pet Owner PrivacyCompliant

Pet Owner Data Privacy

BloomPaws protects the personal information of pet owners โ€” contact details, payment information, and appointment history โ€” under GDPR, Australian Privacy Act, and applicable local privacy regulations.

  • โœ“Consent-based communication and marketing
  • โœ“Secure pet owner portals with individual authentication
  • โœ“Data minimisation โ€” only essential data collected
  • โœ“Owner-controlled data sharing with clinics
๐Ÿ’Š
Pharmacy ComplianceReady

Veterinary Pharmacy & E-Commerce

BloomPaws e-commerce and pet product shop modules are designed to comply with veterinary pharmacy regulations, ensuring that prescription products require verified veterinary authorisation.

  • โœ“Prescription product gating with vet authorisation workflow
  • โœ“Product classification and restricted item controls
  • โœ“Audit trail for prescription product orders
  • โœ“Age-appropriate product recommendations
๐Ÿ”Security Infrastructure

How We Keep Your Data Safe

Security controls that power compliance across every BloomSenzAI platform.

๐Ÿ”‘

Authentication

JWT + HttpOnly cookies, MFA support, session management, parent PIN for child device mode

๐Ÿ”

Encryption

AES-256 at rest, TLS 1.3 in transit, field-level encryption for sensitive health data

๐Ÿ“‹

Audit Logging

Immutable audit trails for every data access, policy change, and administrative action

๐Ÿ‘ค

Access Control

Role-based access (Admin, Therapist, Parent, Child) with granular permissions per entity

๐Ÿ—„๏ธ

Data Residency

Choose your data region โ€” AWS Sydney (AU), Frankfurt (EU), or Virginia (US)

๐Ÿ”„

Backup & Recovery

Automated daily backups with point-in-time recovery. 99.9% uptime SLA

๐Ÿงช

Penetration Testing

Annual third-party penetration testing with remediation SLAs

๐Ÿ“ก

Monitoring

24/7 infrastructure monitoring, anomaly detection, and automated alerting

Questions About Compliance?

Our security and compliance team is available to discuss your specific requirements, provide documentation, or set up a DPA for your organisation.

Contact Our Compliance TeamSecurity Documentation
Get in Touch

Start Your Free Trial or Book a Demo

Whether you run a therapy centre or a vet clinic โ€” we'd love to show you what BloomSenzAI can do.

๐Ÿ“ง
Email Us
hello@bloomsenz.com
๐Ÿ“…
Book a Call
calendly.bloomsenz.com
๐Ÿ“
Headquarters
Sydney, Australia
Quick Platform Links