Vetspeaking

How We Handle Your Data

Last updated: 2026-08-16

This page is for practices who want to check how we handle data before signing up. We’ve written it in plain language, but specifically enough that whoever handles this at your end can actually evaluate it, not just read nice words. The legally binding documents are the Privacy Policy and the Data Processing Agreement; this page explains them.

1. The short version

  1. 1.1You are the data controller. We are your processor, and we sign an Article 28 Data Processing Agreement with you.
  2. 1.2Our database, call recordings and transcripts are stored in the United Kingdom (London) - for a UK practice, that’s domestic storage, not a transfer at all.
  3. 1.3Calls are kept for 90 days (you can choose anywhere from 30 to 365). There is no “keep forever” option.
  4. 1.4Callers always hear that they’re speaking with an AI. Recording silently is technically not possible.
  5. 1.5For new accounts, call recording is off by default.
  6. 1.6Every time one of our staff accesses your account, it’s logged, and we provide the history on request.
  7. 1.7You can download your own data at any time; once deleted, it’s gone from both our systems and the voice-technology provider’s.

2. Our role and yours

This is the most important thing to understand - it determines who is responsible for what.

  1. 2.1You are the data controller for your clients’ data (the people calling you). You decide why it’s collected, what is collected, and how long it’s kept.
  2. 2.2We are the data processor - we process that data on your behalf and only on your instructions. We don’t use it for our own purposes.

In practice: we provide the tools and the safeguards, and the decisions are yours. This split is set out in the Data Processing Agreement, which we sign with every practice.

Separately, we are the controller for our own data - website visitors, account holders and billing. That’s covered in the Privacy Policy.

Which law applies.You are in the UK or Ireland, so your clients’ data is protected by the UK GDPR and the Data Protection Act 2018, or by the EU GDPR in Ireland. Our documents are written to those laws, and your regulator is the ICO or the Data Protection Commission - not ours.

3. Where data is held

The question we get asked most - so here’s the exact answer, no hedging.

  1. 3.1In the United Kingdom (London) we store the database, call audio recordings, transcripts, contacts and your account settings. This is the primary and permanent home for the data. For a UK practice, this is domestic storage - not an international transfer at all, so there’s no adequacy mechanism to rely on because none is needed. For a practice established in Ireland or elsewhere in the EEA, it is a transfer, because our own company is established in the EU (Lithuania) and remains subject to the EU GDPR wherever it processes data - that transfer is covered by the European Commission’s adequacy decision for the United Kingdom (renewed December 2025, valid to December 2031), so still no extra paperwork is needed.
  2. 3.2In the United States, real-time voice recognition and synthesis take place - that is, the call itself, as it happens. This is the one leg that leaves the UK regardless of who you are. It is covered by the UK Extension to the EU-US Data Privacy Framework, the arrangement the UK government put in place in October 2023 for transfers to certified US businesses. Our voice provider holds an active certification covering that UK Extension. On their side, the call is kept for only 7 days, then deleted.

Where a US provider is not certified under the UK Extension, we put the ICO’s International Data Transfer Agreement or the UK Addendum to the standard clauses in place instead, and complete a transfer risk assessment. Which route applies to which provider is set out in the sub-processor list we give you on request.

We’re deliberately not saying “all data stays in the UK” - that would be inaccurate. Permanent storage is in the UK; real-time voice processing isn’t. If your internal policy requires UK-only or EU-only processing for the voice leg too, get in touch - our voice provider offers an EU-resident option and we can discuss it.

4. How long we keep it

Article 5 of the UK GDPR prohibits keeping personal data longer than necessary. So our retention periods are real and run automatically - cleanup happens daily.

  1. 4.1Call recordings and transcripts - 90 days.In your account you can choose 30, 90, 180 or 365 days. Once the period ends, the audio recording, the call text, the summary, the caller’s name and phone number, and any booking created from that call are deleted. Only the call’s date and duration remain - needed for billing, and no longer personal data.
  2. 4.2On the voice-technology provider’s side - 7 days. This period applies across the whole chain, not just our own database.
  3. 4.3Contacts - not deleted automatically. Your contact list is your business record, so the decision is left to you. Contacts created from calls and not contacted again for over 24 months are marked inactive, so you can review and remove them.
  4. 4.4Website chat widget messages - 12 months.
  5. 4.5Demo call data - 30 days.
  6. 4.6Records of data exports, and of our staff accessing your account - 24 months. These exist so we can answer the question of who saw or sent what, and when.
  7. 4.7Accounting records are kept for as long as required by law (typically 10 years), held separately from call data.

There is no “keep forever” option, and there won’t be. Unlimited retention breaches the storage limitation principle, so we simply haven’t built that switch into the product - even if a practice asked for it.

5. What the caller hears

Someone calling you needs to know two things: that they’re talking to a machine, and that the call is being recorded. Both are enforced by the system itself, not left to a reminder for the user.

  1. 5.1The AI disclosure is mandatory.A greeting that doesn’t state the caller is speaking with an AI simply can’t be saved- the system won’t allow it. In the UK this supports your transparency and fairness duties under Articles 5(1)(a) and 13 of the UK GDPR; in Ireland and the rest of the EU it is also required by Article 50 of the EU AI Act, and the duty to design the system this way falls on us, not you.
  2. 5.2Remove the recording notice, and recording turns off.You’re free to edit the greeting. But if it no longer mentions recording, call recording is switched off automatically. That makes it impossible to record silently, even by accident. In the UK, telling callers that calls may be recorded is also what regulation 3 of the Telecommunications (Lawful Business Practice) (Interception of Communications) Regulations 2000 requires, and a spoken announcement is the way regulators expect it to be done.
  3. 5.3For new accounts, recording is off by default. You turn it on deliberately, and at that moment we remind you of your duty to inform callers.

This is easy to check yourself: get a trial account, try removing the AI disclosure from the greeting, and try to save. It won’t let you.

6. Client confidentiality and the RCVS Code

Practice managers ask us this before they ask about anything technical, so we answer it directly.

The RCVS Code of Professional Conduct requires that a veterinary surgeon must not disclose information about a client or a client’s animals to a third party without the client’s permission, and that any disclosure is limited to the minimum necessary. Engaging us does not sit awkwardly with that, for three reasons:

  1. 6.1We are not a third party in the relevant sense. We are your processor. We act only on your instructions, under a written Article 28 agreement, and we have no right to use the information for our own purposes.
  2. 6.2You control the minimum. You decide which fields the agent collects, whether transcripts are stored at all, whether calls are recorded, and for how long anything is kept.
  3. 6.3Confidentiality is contractual and indefinite. Our staff are bound by it, access is least-privilege, and every access to your account is logged and disclosed to you on request.

If your indemnity insurer or practice group wants this in writing, ask us - we have a short note covering it, and we’re happy to answer a security questionnaire.

7. Who has access

Other practices - never

Every customer’s data is separated both in the database itself and at the application level. One practice cannot see another practice’s calls, transcripts or contacts - not even in theory, not even if they tried.

Our staff - only in two cases, and always logged

Access to account data is only granted in two cases, and only to the extent needed:

  • When we’re providing technical support. When something isn’t working and we need to find out why - the agent isn’t answering, an integration has stopped, a notification isn’t arriving. We only look at the part needed to fix that specific problem.
  • When you ask us to configure the agent for you. Only after we’ve received your request, and only to the extent that request requires.

We don’t go into your account for any other reason.We don’t browse calls out of curiosity, and we don’t use them for marketing, product improvement, statistics, or training AI models. Only staff who need access to do their job have it, and they’re bound by indefinite confidentiality obligations.

Every access is logged- which staff member, when, which practice account, from which address. The log can’t be skipped or deleted, and we provide the history on request, with no need to explain why you’re asking. That means you can verify us, rather than take our word for it.

8. Technical and organisational measures

This list is deliberately kept general: we don’t disclose the specific architecture, since that itself is security-sensitive. We provide fuller detail for audits on request.

  1. 8.1Data is encrypted both in transit and at rest.
  2. 8.2Call audio is held in private storage, reachable only through short-lived links that expire quickly, and only after verifying the requester is entitled to hear it.
  3. 8.3Daily database backups with a 7-day recovery window, covering call transcripts, contacts and account settings. We have tested the recovery process, not just assumed it works.
  4. 8.4Every staff account with access to our systems is protected by two-factor authentication.
  5. 8.5Access follows least-privilege and role-based principles - you can grant your own team members only some permissions.
  6. 8.6Passwords are subject to minimum-length requirements and checked against known public breaches.
  7. 8.7Every inbound notification from an external service is verified against its signature - forged ones can’t be accepted.
  8. 8.8Personal data is not written to system logs. Diagnostics use only technical identifiers and metrics.
  9. 8.9We keep records of processing activities under Article 30, including a log of access to supplier systems.

9. Deletion and getting your data back

Once deleted, it’s gone.Deletion covers our database, our audio storage, and the calls held on the voice-technology provider’s side.
  1. 9.1We warn you before final deletion. When the service ends, we send notices 14 and 3 days beforehand, and once the period is up the data remains recoverable for a further 30 days. An accidental cancellation shouldn’t turn into permanent loss.
  2. 9.2You can download your own data at any time - calls with transcripts, and contacts, in CSV format, directly from your account settings.
  3. 9.3Every data export is logged, so we can answer the question of who sent which data, and when.
  4. 9.4We may retain only the minimum we’re required to keep by law (e.g. accounting records).

10. Data subject rights

When someone who has called you wants to access, correct or delete their data, you handle that request as data controller. Our job is to make it possible.

  1. 10.1You can see, download or delete all calls, transcripts and contacts in your account.
  2. 10.2You can edit contact data directly.
  3. 10.3If a caller contacts us directly, we refer them to you and let you know.
  4. 10.4Where needed, we provide the information you need to prepare your response - including the specific recipients of the data.

11. What happens if there's a breach

We have a written breach-management process and a breach log - not just a promise to have one.

  1. 11.1On becoming aware of a breach, we notify you without undue delay - every breach, not only serious ones. The decision on whether to notify the regulator is yours, as controller.
  2. 11.2We provide all the information we have: what happened, what data, how many people affected, and what we’ve already done.
  3. 11.3As controller, you report to the the Information Commissioner's Office (ICO) in the UK, or the the Data Protection Commission (DPC) in Ireland, within 72 hours where the breach is reportable.
  4. 11.4Where we are the controller ourselves, we report to the ICO within the same 72 hours.
  5. 11.5We log every incident - including ones we decide not to report, with the reasoning. That is what Article 33(5) requires.

12. Service providers we use

We use a number of specialised providers to deliver the service. We publish their categories openly:

  1. 12.1telephony and SMS infrastructure;
  2. 12.2AI voice and transcription technology;
  3. 12.3AI language models;
  4. 12.4database, authentication and file storage;
  5. 12.5email delivery;
  6. 12.6payment processing;
  7. 12.7website and application hosting.

We provide the specific list, with each provider’s name, location and the transfer safeguard relied on, if you contact us at paul@vetspeaking.com - under section 6 of the Data Processing Agreement, within 5 working days of the request.

We don’t publish it openly, not because we have anything to hide from customers, but because it’s commercial information about our technology stack. For a practice assessing compliance, we provide it in full.

We notify you at your account’s email address of any intended change or new provider at least 30 days in advance, so you have time to review and reasonably object if needed.

13. What we don't do

  1. 13.1We don’t sell personal data. To anyone, in any form.
  2. 13.2We don’t use your or your clients’ data to train AI models.
  3. 13.3We don’t offer unlimited retention - even if a practice asked for it.
  4. 13.4We don’t collect more information than you tell us to. You can turn off any field we collect.
  5. 13.5We don’t write call content to system logs or anywhere else not covered by our retention periods.
  6. 13.6We don’t use the AI agent to make marketing calls, and our terms forbid you from doing so either. Automated marketing calls need specific prior consent under PECR.

14. Documents we provide

For practices assessing compliance, on request we provide:

  1. 14.1a signable Data Processing Agreement (Article 28);
  2. 14.2the specific list of service providers, with location and transfer safeguards;
  3. 14.3our transfer risk assessment for transfers to the United States;
  4. 14.4a pre-filled data protection impact assessment (DPIA) template for veterinary practices, prepared so you can rely on it in your own assessment;
  5. 14.5a note on client confidentiality and the RCVS Code;
  6. 14.6your account’s access history - who accessed it, and when;
  7. 14.7answers to your security questionnaire.

Write to paul@vetspeaking.com. If anything on this page reads as too general for you, ask specifically - we’ll answer specifically.

Frominbox, MB, company code 307162506, A. Juozapavičiaus g. 28, LT-09311 Vilnius, Lithuania. For data protection questions, paul@vetspeaking.com. Your supervisory authority is the Information Commissioner’s Office in the UK, or the Data Protection Commission in Ireland.