Home

Last updated July 5, 2026

Privacy Policy

How Vesora handles personal data across its website, demo requests, and managed voice AI service for dental and healthcare practices.

Who this policy covers

This policy explains how Vesora handles personal data when practices enquire about, trial, configure, or use Vesora. It covers practice contacts, staff users, callers, patients, and prospective customers where their data is processed through the service.

ICO registration: [number pending].

Information we collect

We collect contact details, account details, practice or group information, location counts, demo availability, support messages, authentication and security data, usage data, and technical logs.

When enabled for a practice workflow, the service also processes call recordings, call audio, transcripts, AI-generated summaries, call outcomes, appointment preferences, reason-for-call information, caller contact details, and escalation notes. Some information may be health data or otherwise sensitive personal data.

Call recording and transcription

Calls handled by Vesora are recorded and transcribed so that practices can review conversations, follow up enquiries, and maintain accurate records. Callers are informed at the start of each call, before any personal details are collected, that the call is recorded. Calls are answered by automated call-handling technology operated on behalf of the practice, as described in this policy.

Recordings and transcripts are made available to the relevant practice through its dashboard and are processed on that practice's instructions.

How we use information

We use information to provide and improve the service, manage demo and pilot requests, configure voice AI workflows, route and summarise calls, support practices, maintain security, troubleshoot issues, monitor service quality, and comply with legal obligations.

We do not need patient data to arrange a demo. Practices should avoid sharing patient-identifiable information in demo forms, sales emails, or support requests unless there is a clear agreed reason.

Controller and processor roles

For practice call-handling workflows, the practice decides why and how patient and caller data is processed. In that context, Vesora acts as a processor on the practice's documented instructions, under a Data Processing Agreement.

Vesora acts as a controller for its own website, sales, billing, product analytics, security, and customer administration data.

Lawful bases and UK GDPR rights

Depending on the context, processing relies on contract performance, legitimate interests, legal obligation, consent, or another lawful basis under UK GDPR. Where special category data is processed, an additional condition is documented by the relevant controller.

Individuals may have rights to access, rectification, erasure, restriction, portability, objection, and complaint to the Information Commissioner's Office (ico.org.uk). Some rights may be limited by legal retention, clinical record, safeguarding, complaint, or legal-claims obligations.

Cookies

Our website and application use only strictly necessary cookies — those required for sign-in, session management, and security. We do not use advertising, marketing, or third-party analytics cookies on the public website.

Because strictly necessary cookies are exempt from consent requirements under the Privacy and Electronic Communications Regulations (PECR), we do not show a cookie banner. If we introduce non-essential cookies in future, we will update this policy and ask for consent first.

Data processing, subprocessors, and transfers

Vesora uses a small number of vetted subprocessors to run the service. Our current subprocessors, their roles, and the safeguards applied to any transfers outside the UK are:

  • Retell AI Voice AI platform that carries calls and produces call recordings and transcripts. United States — safeguarded by the UK IDTA / UK Addendum to the EU Standard Contractual Clauses.
  • Vercel Website and application hosting. May process data outside the UK — UK IDTA / UK Addendum safeguards in place.
  • Neon Managed database hosting. May process data outside the UK — UK IDTA / UK Addendum safeguards in place.
  • Stripe Subscription billing and payment processing. May process data outside the UK — UK IDTA / UK Addendum safeguards in place.
  • Resend Transactional email delivery. May process data outside the UK — UK IDTA / UK Addendum safeguards in place.
  • Upstash Rate limiting and abuse protection. May process data outside the UK — UK IDTA / UK Addendum safeguards in place.
  • Cloudinary Image storage and delivery. May process data outside the UK — UK IDTA / UK Addendum safeguards in place.
  • Google Optional sign-in with Google (OAuth), where a user chooses it. May process data outside the UK — UK IDTA / UK Addendum safeguards in place.

Where personal data is transferred outside the UK, we rely on UK adequacy regulations where available, and otherwise on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with any additional measures needed. We will notify customers of subprocessor changes in line with their Data Processing Agreement.

Retention

Call recordings and transcripts are retained for up to 24 months by default, or for a different period agreed with the practice in its service agreement or Data Processing Agreement. Practices can request shorter retention where their governance requires it.

Demo request data is kept only as long as needed to manage the enquiry and related business records. Account records, summaries, logs, and billing data have retention periods set out in the customer agreement or DPA. Backups and security logs may be retained for a limited additional period where necessary for resilience, audit, or legal reasons.

Security

Vesora uses technical and organisational measures appropriate to the sensitivity of the data processed, including access controls, encryption in transit, operational logging, least privilege access, and supplier review. No system can be guaranteed completely secure.

Clinical and emergency limitations

The service is not an emergency service, diagnostic service, or replacement for professional clinical judgement. Practices are responsible for configuring safe escalation routes and ensuring that urgent callers are directed to appropriate emergency or out-of-hours care.

Contact and requests

Privacy questions and rights requests can be sent to contactus@vesora.co.uk. If your data was handled on behalf of a dental or healthcare practice, we may need to refer your request to that practice as the controller.