🌸
BloomSenz
Home/Compliance
🛡️Compliance-Ready Platform

Built for Security.
Designed for Compliance.

BloomSenzAI platforms handle sensitive health data for children, families, and pets. Compliance isn't an afterthought — it's foundational to every line of code, every API endpoint, and every data flow in our systems.

HIPAA-ReadyGDPRSOC 2COPPAFERPAPCI DSSISO 27001DPDP Act
🌐Cross-Platform

Shared Compliance Framework

These standards apply across the Innerwork platform, ensuring every workflow meets the same rigorous security and privacy bar.

🔐
SOC 2 Type IIIn Progress

SOC 2 Type II

Our infrastructure and operations are built to meet SOC 2 Trust Service Criteria. We implement continuous monitoring of security controls, access management, change management, and incident response across all BloomSenzAI platforms.

  • ✓Annual independent third-party audits
  • ✓Continuous control monitoring via automated tooling
  • ✓Least-privilege access with MFA enforcement
  • ✓Encrypted data at rest (AES-256) and in transit (TLS 1.3)
  • ✓Formal incident response and business continuity plans
🇪🇺
GDPRCompliant

General Data Protection Regulation (GDPR)

Innerwork is designed with privacy-by-design principles. We provide full GDPR compliance for organisations operating in the EU/EEA or handling data of EU residents.

  • ✓Lawful basis for processing (consent, contract, legitimate interest)
  • ✓Right to access, rectification, erasure, and data portability
  • ✓Data Processing Agreements (DPAs) available for all customers
  • ✓Data residency options — AU, EU, and US regions
  • ✓Appointed Data Protection Officer (DPO)
  • ✓72-hour breach notification procedures
🔒
ISO 27001Aligned

ISO 27001 Information Security

Our information security management system (ISMS) is aligned with ISO 27001 controls. We maintain documented policies, risk assessments, and security controls across all platforms.

  • ✓Formal information security policy and risk register
  • ✓Periodic risk assessments and treatment plans
  • ✓Employee security awareness training
  • ✓Vendor and third-party security assessments
  • ✓Physical and logical access controls
💳
PCI DSSCompliant

Payment Card Industry Data Security Standard

All payment processing is handled via PCI DSS Level 1 certified providers (Razorpay, Stripe). No card data is ever stored, processed, or transmitted by BloomSenzAI servers.

  • ✓Tokenized payment processing via certified gateways
  • ✓No card data stored on BloomSenzAI infrastructure
  • ✓Strong Customer Authentication (SCA) support
  • ✓Secure webhook verification for payment events
🧠Innerwork — Therapy Platform

Healthcare & Therapy Compliance

Innerwork handles Protected Health Information (PHI) for children and families. These regulations are specifically addressed in our therapy platform.

🏥
HIPAAReady

HIPAA — Health Insurance Portability & Accountability Act

Innerwork is HIPAA-ready for therapy centres handling Protected Health Information (PHI). Our platform implements the full spectrum of HIPAA Technical, Administrative, and Physical Safeguards.

  • ✓Business Associate Agreements (BAAs) for all customers
  • ✓End-to-end encryption for PHI in transit and at rest
  • ✓Role-based access control (RBAC) with audit trails
  • ✓Automatic session timeouts and re-authentication
  • ✓PHI access logging with tamper-evident audit logs
  • ✓Secure messaging between therapists and parents
  • ✓Data backup and disaster recovery procedures
🎓
FERPAReady

FERPA — Family Educational Rights & Privacy Act

For therapy centres operating within educational settings (school-based therapy, early intervention), Innerwork supports FERPA compliance by protecting student education records and therapy progress data.

  • ✓Parental consent management for student data access
  • ✓Restricted access to student therapy records
  • ✓Integration-ready with school district identity providers
  • ✓Data deletion upon request from educational agencies
👶
COPPAReady

COPPA — Children's Online Privacy Protection Act

Innerwork handles data of children under 13 through the parental consent model. The child never directly provides personal information — all data flows through the authenticated parent or therapist.

  • ✓Parental control system with policy enforcement
  • ✓No direct data collection from children
  • ✓Parent-controlled device mode with usage tracking
  • ✓Verifiable parental consent before child data processing
  • ✓Minimal data collection principle for child profiles
🇮🇳
DPDP ActReady

India Digital Personal Data Protection Act, 2023

For therapy centres operating in India, Innerwork complies with the DPDP Act provisions for processing personal data of children and health-related data.

  • ✓Consent-based data processing with purpose limitation
  • ✓Right to correction and erasure of personal data
  • ✓Guardian consent for processing child data (under 18)
  • ✓Data localisation support for Indian customers
  • ✓Grievance redressal mechanism
🇦🇺
Australian Privacy ActCompliant

Australian Privacy Act 1988 & APPs

As an Australian company, BloomSenzAI fully complies with the Australian Privacy Act and the 13 Australian Privacy Principles (APPs) governing the collection, use, and disclosure of personal information.

  • ✓Compliance with all 13 Australian Privacy Principles
  • ✓Transparent privacy policy and collection notices
  • ✓Cross-border data transfer protections
  • ✓Notifiable Data Breach (NDB) scheme compliance
🔐Security Infrastructure

How We Keep Your Data Safe

Security controls that power compliance across every BloomSenzAI platform.

🔑

Authentication

JWT + HttpOnly cookies, MFA support, session management, parent PIN for child device mode

🔐

Encryption

AES-256 at rest, TLS 1.3 in transit, field-level encryption for sensitive health data

📋

Audit Logging

Immutable audit trails for every data access, policy change, and administrative action

👤

Access Control

Role-based access (Admin, Therapist, Parent, Child) with granular permissions per entity

🗄️

Data Residency

Choose your data region — AWS Sydney (AU), Frankfurt (EU), or Virginia (US)

🔄

Backup & Recovery

Automated daily backups with point-in-time recovery. 99.9% uptime SLA

🧪

Penetration Testing

Annual third-party penetration testing with remediation SLAs

📡

Monitoring

24/7 infrastructure monitoring, anomaly detection, and automated alerting

Questions About Compliance?

Our security and compliance team is available to discuss your specific requirements, provide documentation, or set up a DPA for your organisation.

Contact Our Compliance TeamSecurity Documentation
Get in Touch

Start Your Free Trial or Book a Demo

Run a therapy centre or work as an independent therapist? We'd love to show you what BloomSenzAI can do.

📧
Email Us
hello@bloomsenz.com
📅
Book a Call
calendly.bloomsenz.com
📍
Headquarters
Sydney, Australia
Quick Platform Links