Who this policy covers
This policy explains how Vesora handles personal data when practices enquire about, trial, configure, or use Vesora. It covers practice contacts, staff users, callers, patients, and prospective customers where their data is processed through the service.
Contact us using the details below for privacy questions and the applicable clinic processing schedule.
Information we collect
We collect contact details, account details, practice or group information, location counts, demo availability, support messages, authentication and security data, usage data, and technical logs.
When enabled for a practice workflow, the service also processes call recordings, call audio, transcripts, AI-generated summaries, call outcomes, appointment preferences, reason-for-call information, caller contact details, and escalation notes. Some information may be health data or otherwise sensitive personal data.
Patient reactivation and replies
The clinic provides the minimum approved contact and campaign information, including names, contact addresses, relevant attendance dates where needed, and evidence of marketing permissions. Vesora records campaign delivery, replies, opt-outs and booking outcomes on the clinic's instructions. Clinical notes and treatment records are not required for campaign imports.
Marketing eligibility is reviewed separately for each channel and intended use. Existing patient status or a recent visit does not itself establish permission. When health information is used for marketing, the clinic must separately address the applicable health-data and confidentiality requirements.
Routine campaign operation uses patient references. Identifiable conversations require clinic-authorised access. Patient replies may contain health information; they are handled by authorised people, with clinical matters referred to the clinic. Automated patient reply drafting is disabled in this release. Patient information is not supplied to the business lead-nurture AI.
We do not sell patient information, use it for Vesora's own marketing or use it to train the business nurture model. A minimal suppression record may be retained to respect an objection even after campaign records are erased. Deletion of supplier and backup copies is tracked separately from deletion in the application.
Call recording and transcription
Calls handled by Vesora are recorded and transcribed so that practices can review conversations, follow up enquiries, and maintain accurate records. Callers are informed at the start of each call, before any personal details are collected, that the call is recorded. Calls are answered by automated call-handling technology operated on behalf of the practice, as described in this policy.
Recordings and transcripts are made available to the relevant practice through its dashboard and are processed on that practice's instructions.
How we use information
We use business information to provide and improve the service, manage demo and pilot requests, configure voice AI workflows, route and summarise calls, support practices, maintain security, troubleshoot issues, monitor service quality, and comply with legal obligations.
We do not need patient data to arrange a demo. Practices should avoid sharing patient-identifiable information in demo forms, sales emails, or support requests unless there is a clear agreed reason.
Controller and processor roles
For clinic-directed patient campaigns and call-handling workflows, the practice decides why and how patient and caller data is processed. In that context, Vesora acts as a processor on the practice's documented instructions, under a Data Processing Agreement.
Vesora acts as a controller for its own website, sales, billing, product analytics, security, and customer administration data.
Lawful bases and UK GDPR rights
Depending on the context, processing relies on contract performance, legitimate interests, legal obligation, consent, or another lawful basis under UK GDPR. Where special category data is processed, an additional condition is documented by the relevant controller.
Individuals may have rights to access, rectification, erasure, restriction, portability, objection, and complaint to the Information Commissioner's Office (ico.org.uk). Some rights may be limited by legal retention, clinical record, safeguarding, complaint, or legal-claims obligations.
Data processing, subprocessors, and transfers
The platform supports the services listed below. A clinic's processing schedule must identify the suppliers actually enabled, their roles, processing locations and transfer arrangements before patient processing starts. Listing a supplier here does not mean a transfer review is complete.
- Twilio — Clinic text messaging and optional telephone services. Deployment, subaccount, retention and transfer arrangements must be confirmed before clinic use.
- Cloudflare Stream — Videos used in business onboarding forms; patient campaign uploads are not stored here. Confirm the applicable processing locations and safeguards for the enabled business service.
- OpenAI — Vesora business-enquiry nurture where enabled; not patient reply drafting. Separate business-data supplier review required; patient data must not be supplied to this integration.
- Meta — Optional advertising measurement on business enquiry forms, after cookie consent. This is separate from clinic patient processing; applicable advertising terms and transfer arrangements require review.
- Retell AI — Voice AI platform that carries calls and produces call recordings and transcripts. Processing locations and required transfer safeguards must be confirmed before activation.
- Vercel — Website, application hosting and durable workflow execution. Processing locations and required transfer safeguards must be confirmed for the selected service.
- Neon — Managed database hosting, authentication storage and abuse-prevention counters. Processing locations and required transfer safeguards must be confirmed for the selected service.
- Stripe — Subscription billing and payment processing. Processing locations and required transfer safeguards must be confirmed for the selected service.
- Resend — Account email, clinic campaign delivery and inbound email handling. Processing locations and required transfer safeguards must be confirmed for the selected service.
- Cloudinary — Image storage and delivery. Processing locations and required transfer safeguards must be confirmed for the selected service.
- Google — Optional sign-in with Google (OAuth), where a user chooses it. Processing locations and required transfer safeguards must be confirmed for the selected service.
Any restricted international transfer requires an applicable transfer route and the associated assessment and safeguards. These must be documented before activation. Contact us for the applicable schedule and how to obtain copies of safeguards. Subprocessor changes are handled under the clinic's Data Processing Agreement.
Retention
The clinic's processing schedule must specify retention for campaign records, conversations, recordings where enabled, permissions, audit records, supplier copies and backups. Different datasets may need different periods; there is no blanket 24-month period for patient data. Contact us or your clinic for the applicable schedule.
Demo request data is kept only as long as needed to manage the enquiry and related business records. Account records, summaries, logs, and billing data have retention periods set out in the customer agreement or DPA. Backups and security logs may be retained for a limited additional period where necessary for resilience, audit, or legal reasons.
Security
Vesora uses technical and organisational measures appropriate to the sensitivity of the data processed, including access controls, encryption in transit, operational logging, least privilege access, and supplier review. No system can be guaranteed completely secure.
Clinical and emergency limitations
The service is not an emergency service, diagnostic service, or replacement for professional clinical judgement. Practices are responsible for configuring safe escalation routes and ensuring that urgent callers are directed to appropriate emergency or out-of-hours care.
Contact and requests
Privacy questions and rights requests can be sent to contactus@vesora.co.uk. If your data was handled on behalf of a dental or healthcare practice, we may need to refer your request to that practice as the controller.