Security & privacy
Security and privacy, in plain words
How Velvet Lead protects clinic and patient information, what we record, and what we don't claim.
Each clinic has its own database
Your clinic's data isn't mixed in with other clinics' data. Each clinic has its own separate database, so bookings, leads and patient details stay with your clinic.
Permissions enforced by the database
Team members sign in with a role: admin, manager or staff. What each person can see and change is enforced by the database itself, using row-level security in Postgres, not just by hiding buttons in the admin panel.
That means even if someone tried to request data their role doesn't allow, the database wouldn't return it. When someone leaves, you remove their access instantly. See team access.
Consent is recorded, not assumed
When patients submit a form or book, their acceptance of the privacy notice is recorded. Marketing consent is recorded separately, with the time and the source, so you can tell who agreed to hear from you and how.
WhatsApp messages only go to patients who opted in when they booked. Before-and-after photos in your gallery carry a record that the patient consented to their use.
We watch for problems
Automatic error alerts go to the Velvet Lead team, so we usually see an issue before your clinic does. The dashboard in your admin panel shows the status of email, WhatsApp, background jobs and the assistant.
Where it runs
Velvet Lead is built with Next.js and deployed to Vercel. Data is stored in a Postgres database on Supabase. Both run on accounts in your clinic's own name, billed to you directly, so you own the infrastructure and the data on it. Emails are sent through a transactional email provider, and WhatsApp messages through Meta's official WhatsApp Business Cloud API.
The AI assistant has limits built in
The assistant answers from your clinic's own information and documents. It doesn't give medical advice, it can't book on a patient's behalf, and it's protected against abuse with rate limits and a daily limit. You can switch it off at any time.
FAQ
Security questions
Do you have security certifications?
We don't currently hold independent security certifications, and we won't claim ones we don't have. This page describes how the system is actually built.
What about HIPAA?
We don't claim HIPAA compliance. Velvet Lead is built for appointment booking and enquiries, not clinical records. US practices that need a HIPAA Business Associate Agreement should talk to our team first.
Do you store medical records?
No. There are no clinical notes, prescriptions, medical records, insurance billing or telehealth. Velvet Lead handles enquiries, bookings and the details needed to manage them.
Who owns the data?
Your clinic owns its patient and lead data, and your website runs on your own domain.
Have a security question we haven't answered? Contact us.
Book a 15-minute demo
See the patient side and the admin panel on our demo clinic. We'll tell you honestly whether Velvet Lead fits your clinic.