2. Two roles we play: controller and processor
It is important to understand that FirstVoice AI Ltd acts in two different capacities depending on the data involved.
2.1 As a data controller — When you (or your staff) visit our website, request a demo, create an account, or manage your subscription, we act as a data controller — we decide how and why that personal data (e.g. your name, work email, billing details) is processed. This Privacy Policy, in those respects, sets out our obligations as a controller.
2.2 As a data processor — When your practice activates the AI voice agent to handle inbound patient calls, manage appointments, or process patient emails, FirstVoice AI Ltd acts as a data processor (or sub-processor) on your instructions. Your practice remains the data controller for your patients' personal data, including any special category (health) data disclosed during a call.
The processing of patient data is governed by a separate Data Processing Agreement (DPA) entered into between FirstVoice AI Ltd and your practice, which forms part of your subscription agreement. Your practice is responsible for providing its own privacy notice to patients (for example, explaining that calls may be answered and recorded by an AI system). FirstVoice AI Ltd can provide template wording for this on request.
3. Information we collect
3.1 Website visitors and prospective customers
- Name, work email address, phone number, practice name and address, job title
- Information submitted through enquiry forms, demo bookings, or live chat
- Technical and usage data: IP address, browser/device type, pages visited, referral source — collected via cookies and analytics tools (see our Cookie Policy)
3.2 Subscribing practices (account holders)
- Practice and billing details (practice name, address, payment details — processed by our payment provider)
- Staff/admin user accounts: names, work email addresses, login credentials, role/permissions
- Configuration data: call scripts, opening hours, services offered, escalation contacts
- Dashboard usage and audit logs
3.3 Patient data (processed as a data processor, on your practice's instructions)
- Caller identification: name, telephone number, date of birth (where given)
- Appointment details: requested service, preferred times, existing appointment references
- Call recordings and AI-generated transcripts and summaries
- Information volunteered during a call that may constitute special category data under Article 9 UK GDPR — for example, references to symptoms, conditions, medication, or other health information
- Indicators used by the AI to flag urgent or emergency calls for human escalation
- Email content, where the Service is used to manage patient correspondence
4. How we use information
| Purpose | Data used | Who decides (controller) |
|---|---|---|
| Responding to enquiries, scheduling demos | Contact details | FirstVoice AI Ltd |
| Marketing communications (where permitted) | Contact details, usage data | FirstVoice AI Ltd |
| Providing, maintaining and improving the Service, billing, support | Account, billing, configuration, usage data | FirstVoice AI Ltd |
| Answering calls, booking and managing appointments, summarising calls, escalating urgent calls, managing patient emails | Patient data | Your practice (FirstVoice AI Ltd processes on instruction) |
| Improving AI accuracy and reliability | De-identified or aggregated call data, with safeguards | FirstVoice AI Ltd (as agreed in the DPA) |
| Security, fraud prevention, legal compliance | Account, usage, and patient data as necessary | FirstVoice AI Ltd / Your practice |
5. Our legal bases for processing
Where FirstVoice AI Ltd is the controller, we rely on:
- Performance of a contract (Article 6(1)(b)) — to provide the Service to your practice, including account management and billing
- Legitimate interests (Article 6(1)(f)) — to improve and secure the Service, prevent fraud, and respond to enquiries, balanced against your rights
- Consent (Article 6(1)(a)) — for marketing communications and non-essential cookies, which you can withdraw at any time
- Legal obligation (Article 6(1)(c)) — for example, retaining financial records
Where FirstVoice AI Ltd processes patient data as a processor, the applicable legal basis (typically Article 6(1)(e), or Article 9(2)(h) for health/social care purposes, or Article 9(2)(a) explicit consent) is determined and documented by your practice as the data controller. FirstVoice AI Ltd processes that data strictly in accordance with your instructions and the DPA.
7. International data transfers
Patient call data, transcripts, and recordings are processed and stored exclusively within the United Kingdom (Microsoft Azure UK). Where any other personal data (for example, website analytics or support tooling) is processed by providers located outside the UK, we ensure appropriate safeguards are in place, such as the UK International Data Transfer Agreement (IDTA) or an applicable adequacy decision.
8. How long we keep data
- Call recordings and transcripts: automatically deleted 90 days after the call by default, unless your practice configures a different retention period (subject to any minimum/maximum limits we set)
- Account and billing records: retained for the duration of your subscription and for 6 years afterwards, to meet tax and accounting obligations
- Website enquiry data: retained for up to 12 months, or until you ask us to delete it
- Marketing data: retained until you withdraw consent or unsubscribe
Deleted data is initially "soft-deleted" — marked as deleted and excluded from normal use, but retained for a short recovery window (for example, to recover from accidental deletion) before permanent erasure.
9. How we protect data
- Encryption of data in transit and at rest
- UK-only infrastructure for patient data (Microsoft Azure UK South)
- Role-based access controls and least-privilege access for our staff
- Full audit logging of access to patient data
- Soft-delete followed by scheduled permanent deletion
- Regular security reviews and staff training on data protection
10. Your rights
Under UK GDPR, individuals have the right to:
- be informed about how their data is used
- access a copy of their personal data
- request correction of inaccurate data
- request erasure ("right to be forgotten") in certain circumstances
- restrict or object to certain processing
- data portability
- not be subject to decisions based solely on automated processing that have legal or similarly significant effects, without human review
If you are a patient of a practice that uses FirstVoice AI Ltd, please contact your practice in the first instance, as they are the data controller responsible for your personal data. Your practice can contact us for assistance with any request.
If you are a website visitor, prospect, or practice staff member, you can exercise these rights by contacting us at privacy@firstvoice-ai.com.
12. Children's data
Our Service is intended for use by healthcare practices and their administrative staff, not by children directly. Where a patient is a child, any call handled by the Service will typically be made by a parent or guardian on the child's behalf. Practices are responsible for ensuring appropriate safeguards are in place when the Service is used in relation to a child's care.
13. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify subscribing practices by email and/or via a notice on our website. The "last updated" date at the top of this page indicates when it was last revised.
14. Complaints
If you have concerns about how we handle personal data, please contact us first at support@firstvoice-ai.com so we can try to resolve the issue. You also have the right to lodge a complaint with the UK's Information Commissioner's Office (ICO) at ico.org.uk.
15. Contact us
FirstVoice AI Ltd
4-6 Greatorex Street, London, E1 5NF
Email: support@firstvoice-ai.com