Skip to content

Security & privacy

Security and privacy, in plain words

How Velvet Lead protects clinic and patient information, what we record, and what we don't claim.

Each clinic has its own database

Your clinic's data isn't mixed in with other clinics' data. Each clinic has its own separate database, so bookings, leads and patient details stay with your clinic.

Permissions enforced by the database

Team members sign in with a role: admin, manager or staff. What each person can see and change is enforced by the database itself, using row-level security in Postgres, not just by hiding buttons in the admin panel.

That means even if someone tried to request data their role doesn't allow, the database wouldn't return it. When someone leaves, you remove their access instantly. See team access.

Consent is recorded, not assumed

When patients submit a form or book, their acceptance of the privacy notice is recorded. Marketing consent is recorded separately, with the time and the source, so you can tell who agreed to hear from you and how.

WhatsApp messages only go to patients who opted in when they booked. Before-and-after photos in your gallery carry a record that the patient consented to their use.

We watch for problems

Automatic error alerts go to the Velvet Lead team, so we usually see an issue before your clinic does. The dashboard in your admin panel shows the status of email, WhatsApp, background jobs and the assistant.

Where it runs

Velvet Lead is built with Next.js and deployed to Vercel. Data is stored in a Postgres database on Supabase. Both run on accounts in your clinic's own name, billed to you directly, so you own the infrastructure and the data on it. Emails are sent through a transactional email provider, and WhatsApp messages through Meta's official WhatsApp Business Cloud API.

The AI assistant has limits built in

The assistant answers from your clinic's own information and documents. It doesn't give medical advice, it can't book on a patient's behalf, and it's protected against abuse with rate limits and a daily limit. You can switch it off at any time.

FAQ

Security questions

Do you have security certifications?

We don't currently hold independent security certifications, and we won't claim ones we don't have. This page describes how the system is actually built.

What about HIPAA?

We don't claim HIPAA compliance. Velvet Lead is built for appointment booking and enquiries, not clinical records. US practices that need a HIPAA Business Associate Agreement should talk to our team first.

Do you store medical records?

No. There are no clinical notes, prescriptions, medical records, insurance billing or telehealth. Velvet Lead handles enquiries, bookings and the details needed to manage them.

Who owns the data?

Your clinic owns its patient and lead data, and your website runs on your own domain.

Have a security question we haven't answered? Contact us.

Book a 15-minute demo

See the patient side and the admin panel on our demo clinic. We'll tell you honestly whether Velvet Lead fits your clinic.

Book a demo