Data Security
Enterprise-grade infrastructure.
Simple to understand.
ReloFlow is built on Notion — a SOC 2 Type II certified platform used by thousands of organisations globally. Your data benefits from enterprise security standards without enterprise complexity or cost.
🔐
UK GDPR Compliant
Your organisation is the data controller. ReloFlow acts as a data processor on your behalf, processing resident data only as you instruct. A Data Processing Agreement is available on request.
🏛️
SOC 2 Type II Infrastructure
Your data is hosted on Notion's SOC 2 Type II certified infrastructure — the same standard used by enterprise organisations worldwide. Security controls are independently audited annually.
👥
Role-Based Access Control
You control who sees what. Sensitive databases — welfare logs, incident records, safeguarding notes — are restricted to named staff only. Access can be added or removed instantly by your admin.
📋
Full Audit Trail
Every action in ReloFlow is logged — who viewed, edited, or deleted a record, and when. This provides a complete, timestamped audit trail for commissioner reviews, regulatory inspections, and safeguarding inquiries.
🌐
UK GDPR Data Transfer Protections
Notion's infrastructure operates with Standard Contractual Clauses and UK GDPR data transfer protections in place. A Data Processing Addendum covering GDPR obligations is available at notion.so/privacy.
🔑
Password & Authentication
All users access the system via secure, password-protected accounts. Multi-factor authentication is available and recommended for all staff with access to sensitive resident records.
AI Usage Policy
AI assists your team.
It never replaces their judgement.
ReloFlow uses AI to help frontline staff with documentation — turning rough notes into professional case records. It does not make decisions, assess risk autonomously, or take any action without human review.
The most important thing to understand
AI in ReloFlow is a documentation tool, not a decision-making system. Every AI output is a draft for a human to review, edit, and approve. No automated action is triggered by AI output alone. Your staff remain responsible for all professional judgements.
AI does NOT do
Make safeguarding decisions
Trigger referrals automatically
Replace professional judgement
Retain resident data for model training
Access data beyond the specific note submitted
AI DOES do
Rewrite rough notes into professional case notes
Flag records for manager review
Summarise compliance status daily
Save frontline staff time on documentation
Improve consistency of written records
🤖
Zero-Retention AI Processing
ReloFlow uses the OpenAI API — not ChatGPT. Data submitted via the API is not used to train OpenAI models. API inputs are not retained beyond 30 days for abuse monitoring purposes only.
📝
What is sent to AI
Only the text content of staff-written notes is processed. We recommend staff use initials or reference numbers rather than full resident names in notes — further reducing identifiable data in AI processing.
Client Ownership
You own the system.
We configure it.
ReloFlow does not host your data on its own servers. Your workspace is a private environment owned and controlled by your organisation from day one.
🏠
Your data never lives in ReloFlow's infrastructure
When we implement ReloFlow for your organisation, we set it up under your own Notion account. You are the workspace owner from the moment it goes live. ReloFlow operates as an invited administrator during setup and support — and can be removed from your workspace at any time without losing access to any of your data.
01
What happens if ReloFlow ceases trading
Your workspace continues to operate independently. Because you are the workspace owner, there is no dependency on ReloFlow remaining in business. Your system, your data, your control — always.
02
Data exportability
All data is exportable at any time in CSV, PDF, and Markdown formats — no proprietary format, no export fees. Your records are always accessible and portable.
03
Documentation handover
All system configurations, automations, and workflows are fully documented and handed over to your organisation. Another operator or internal team member could manage the system without ReloFlow's involvement.
04
Contract end and offboarding
At contract end, all ReloFlow admin access is removed, all data is exported and provided to your organisation, and the workspace is transferred to full client ownership. No data is retained by ReloFlow after contract end.
"Boring, safe, and reliable.
Exactly what your operation needs."
Have more questions about security or compliance? We'll answer them directly.