Who this policy covers
This policy explains how Vesora handles personal data when practices enquire about, trial, configure, or use Vesora. It covers practice contacts, staff users, callers, patients, and prospective customers where their data is processed through the service.
ICO registration: [number pending].
Information we collect
We collect contact details, account details, practice or group information, location counts, demo availability, support messages, authentication and security data, usage data, and technical logs.
When enabled for a practice workflow, the service also processes call recordings, call audio, transcripts, AI-generated summaries, call outcomes, appointment preferences, reason-for-call information, caller contact details, and escalation notes. Some information may be health data or otherwise sensitive personal data.
Call recording and transcription
Calls handled by Vesora are recorded and transcribed so that practices can review conversations, follow up enquiries, and maintain accurate records. Callers are informed at the start of each call, before any personal details are collected, that the call is recorded. Calls are answered by automated call-handling technology operated on behalf of the practice, as described in this policy.
Recordings and transcripts are made available to the relevant practice through its dashboard and are processed on that practice's instructions.
How we use information
We use information to provide and improve the service, manage demo and pilot requests, configure voice AI workflows, route and summarise calls, support practices, maintain security, troubleshoot issues, monitor service quality, and comply with legal obligations.
We do not need patient data to arrange a demo. Practices should avoid sharing patient-identifiable information in demo forms, sales emails, or support requests unless there is a clear agreed reason.
Controller and processor roles
For practice call-handling workflows, the practice decides why and how patient and caller data is processed. In that context, Vesora acts as a processor on the practice's documented instructions, under a Data Processing Agreement.
Vesora acts as a controller for its own website, sales, billing, product analytics, security, and customer administration data.
Lawful bases and UK GDPR rights
Depending on the context, processing relies on contract performance, legitimate interests, legal obligation, consent, or another lawful basis under UK GDPR. Where special category data is processed, an additional condition is documented by the relevant controller.
Individuals may have rights to access, rectification, erasure, restriction, portability, objection, and complaint to the Information Commissioner's Office (ico.org.uk). Some rights may be limited by legal retention, clinical record, safeguarding, complaint, or legal-claims obligations.
Data processing, subprocessors, and transfers
Vesora uses a small number of vetted subprocessors to run the service. Our current subprocessors, their roles, and the safeguards applied to any transfers outside the UK are:
- Retell AI — Voice AI platform that carries calls and produces call recordings and transcripts. United States — safeguarded by the UK IDTA / UK Addendum to the EU Standard Contractual Clauses.
- Vercel — Website and application hosting. May process data outside the UK — UK IDTA / UK Addendum safeguards in place.
- Neon — Managed database hosting. May process data outside the UK — UK IDTA / UK Addendum safeguards in place.
- Stripe — Subscription billing and payment processing. May process data outside the UK — UK IDTA / UK Addendum safeguards in place.
- Resend — Transactional email delivery. May process data outside the UK — UK IDTA / UK Addendum safeguards in place.
- Upstash — Rate limiting and abuse protection. May process data outside the UK — UK IDTA / UK Addendum safeguards in place.
- Cloudinary — Image storage and delivery. May process data outside the UK — UK IDTA / UK Addendum safeguards in place.
- Google — Optional sign-in with Google (OAuth), where a user chooses it. May process data outside the UK — UK IDTA / UK Addendum safeguards in place.
Where personal data is transferred outside the UK, we rely on UK adequacy regulations where available, and otherwise on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with any additional measures needed. We will notify customers of subprocessor changes in line with their Data Processing Agreement.
Retention
Call recordings and transcripts are retained for up to 24 months by default, or for a different period agreed with the practice in its service agreement or Data Processing Agreement. Practices can request shorter retention where their governance requires it.
Demo request data is kept only as long as needed to manage the enquiry and related business records. Account records, summaries, logs, and billing data have retention periods set out in the customer agreement or DPA. Backups and security logs may be retained for a limited additional period where necessary for resilience, audit, or legal reasons.
Security
Vesora uses technical and organisational measures appropriate to the sensitivity of the data processed, including access controls, encryption in transit, operational logging, least privilege access, and supplier review. No system can be guaranteed completely secure.
Clinical and emergency limitations
The service is not an emergency service, diagnostic service, or replacement for professional clinical judgement. Practices are responsible for configuring safe escalation routes and ensuring that urgent callers are directed to appropriate emergency or out-of-hours care.
Contact and requests
Privacy questions and rights requests can be sent to contactus@vesora.co.uk. If your data was handled on behalf of a dental or healthcare practice, we may need to refer your request to that practice as the controller.