Vetspeaking

Privacy and Cookies Policy

Last updated: 2026-08-16

This privacy and cookies policy explains how Frominbox, MB (Vetspeaking) collects, uses, stores and secures personal data when you use our website vetspeaking.com and our AI phone-answering service for veterinary practices. We serve practices in the United Kingdom and Ireland, so we process personal data in accordance with the UK GDPR and the Data Protection Act 2018 for people in the UK, and the EU GDPR for people in Ireland and the rest of the EEA. Cookies are governed by the Privacy and Electronic Communications Regulations (PECR) in the UK - see section 14.

1. Who we are and how to contact us

Data controller:

  1. 1.1Frominbox, MB (mažoji bendrija), trading as Vetspeaking
  2. 1.2Company code: 307162506
  3. 1.3VAT number: LT100019538712
  4. 1.4Registered address: A. Juozapavičiaus g. 28, LT-09311 Vilnius, Lithuania
  5. 1.5Email: paul@vetspeaking.com
  6. 1.6Phone: +370 612 52085

For anything about how we handle personal data - including a rights request or a complaint - write to paul@vetspeaking.com.

We have not appointed a data protection officer. We assessed this against Article 37 of the UK GDPR and concluded one is not required: we are not a public authority, we do not carry out large-scale monitoring of individuals, and we do not process special category data on a large scale. We keep that decision under review and will appoint one if the position changes. You can raise any data protection question with us at the address above.

2. Our role: controller and processor

Depending on the situation, Vetspeaking acts in two different roles:

  1. 2.1As data controller - when we process the data of website visitors, prospective and existing customers (account holders), billing contacts, and participants in the demo call. In these cases we decide the purposes and means of processing ourselves, and this policy applies to them.
  2. 2.2As data processor - when, on behalf of our customer (a veterinary practice), we process the data of people calling that practice: call recordings, transcripts and contacts. Here the data controller is the practice, and we act on their instructions under the Data Processing Agreement. If you called a practice, that practice’s own privacy notice applies first to how your data is handled, and they are the right people to contact about it.

3. What data we process

3.1. Website visitors

  • Technical data: IP address, browser type, device information, visit date and time.
  • Usage data: pages viewed, links clicked, interactions.
  • Messages sent through the website’s chat widget, the page you were on, and browser information - so we can respond to your query. The conversation is handled by an AI assistant, and messages may be read by our team.
  • Cookies and similar technologies (see section 14).

3.2. Prospective and existing customers

  • Identity and contact data: first and last name, email, phone number, practice name, job role.
  • Account data: login information, settings, knowledge-base and scenario configuration.
  • Data from signing in with Google: if you choose to connect a Google account, we receive your name and email address from Google to create and identify your account.
  • Integration data: access tokens for calendar or practice-management systems you connect yourself, and the sync scope you configure.
  • Billing data: subscription plan, invoices, payment history. We do not store card details ourselves - these are handled by our payment service provider.
  • Correspondence: enquiries, support requests, and a record of any objection or opt-out you send us.

Where we got your details, if you did not give them to us.If we contacted you before you were a customer, we obtained your business contact details from a publicly available source - typically your practice’s own website, a public professional or company register, or your public professional profile. We use them to introduce a service relevant to your practice, on the basis of our legitimate interest (section 4). This paragraph is the information we owe you under Article 14 of the UK GDPR. You can tell us to stop at any time, using the link in any message we send or by writing to paul@vetspeaking.com, and we will add you to a suppression list so we do not contact you again.

3.3. Demo call participants

  • The phone number you enter yourself for the demo.
  • The audio recording and transcript of the demo call.

3.4. Special category data

We do not seek to collectspecial category (sensitive) personal data, and the AI agent is configured not to ask for more than the practice’s stated purpose requires.

Because we serve veterinary practices, this is a lighter picture than it would be for a human healthcare provider, and it is worth being precise about why. Information about an animal’s health is not health data about a person and is not special category data under Article 9. A call about a dog’s symptoms, a vaccination schedule or a surgery date does not engage Article 9.

What can happen is that a caller volunteers something about their own health or circumstances while explaining their situation - for example that they cannot drive, are housebound, or have just come out of hospital. We do not ask for this, we do not extract or analyse it, and it is deleted with the rest of the call at the end of the retention period. Where it occurs, the practice is the controller and remains responsible for its own lawful basis. A practice can reduce what is collected in its settings, or turn off transcript storage entirely.

4. Purposes and lawful basis

We process personal data for the following purposes, on the following lawful basis (Article 6 of the UK GDPR, and the same article of the EU GDPR in Ireland):

  1. 4.1Providing the service and performing the contract (account administration, service operation) - performance of a contract, Art. 6(1)(b).
  2. 4.2Billing and accounting - performance of a contract and legal obligation, Art. 6(1)(b) and (c).
  3. 4.3The demo call - your consent, Art. 6(1)(a), given by entering your number and pressing call.
  4. 4.4Running and securing the website - legitimate interest in a safe and reliable service, Art. 6(1)(f).
  5. 4.5Communication and support - legitimate interest in responding to enquiries, Art. 6(1)(f).
  6. 4.6Service-related notices (call summaries, transcripts, trial reminders, usage and billing notices, team invitations) - performance of a contract, Art. 6(1)(b), or legitimate interest in keeping you informed about the service, Art. 6(1)(f). Every such email includes an unsubscribe link.
  7. 4.7Introducing our service to veterinary practices - legitimate interest in marketing a relevant business service to a business audience, Art. 6(1)(f). We have carried out and documented a legitimate interests assessment for this, and we comply with PECR when we call, email or message you: see section 12 for how to stop it.
  8. 4.8Defending legal claims - legitimate interest or legal obligation.

5. The demo call

On the website you can try the service by entering your phone number, and our AI system then calls you. For this, Vetspeaking is the data controller and the lawful basis is your consent.

  1. 5.1We use your number only to place this demo call.
  2. 5.2We keep the demo call’s recording and transcript for 30 days to maintain service quality, then delete them.
  3. 5.3You can withdraw your consent at any time by contacting paul@vetspeaking.com.

6. Call recording

When we answer calls for a practice, those calls may be recorded and transcribed so we can provide summaries, pass on contact details, and maintain service quality.

Callers are always told.The greeting states that the caller is speaking with an AI assistant and, where recording is on, that the call is recorded. This is not left to a reminder: our system will not save a greeting that omits the AI disclosure, and if the greeting stops mentioning recording, recording switches itself off. In the UK this supports the practice’s duties under Articles 5(1)(a) and 13 of the UK GDPR, and the requirement in regulation 3 of the Telecommunications (Lawful Business Practice) (Interception of Communications) Regulations 2000 to make all reasonable efforts to inform people that calls may be recorded.

For these calls the practice is the data controller. It is responsible for its lawful basis and for informing its clients; we act as processor under the Data Processing Agreement.

7. Who we share data with

We do not sell personal data, and we do not use it to train AI models. We disclose data only to service providers (sub-processors) who help us deliver the service and who process it on our instructions, under their own data processing terms:

  1. 7.1Telephony and SMS providers (for answering calls, routing them, and sending texts);
  2. 7.2AI voice, transcription and language-model providers (for understanding calls, generating responses and summaries);
  3. 7.3Database, authentication and storage providers;
  4. 7.4Email delivery providers (for service-related notices);
  5. 7.5Payment processing providers;
  6. 7.6The Google sign-in provider and our integration broker;
  7. 7.7Hosting and infrastructure providers.

We provide the current list of specific sub-processors, with each one’s location and the safeguards applied, on request to paul@vetspeaking.com - within 5 working days, under section 6 of the Data Processing Agreement.

7.1. Integrations you connect yourself

If, as our customer, you connect your own calendar or practice-management system, data collected during calls (contacts, bookings) is sent to that system only on your instruction and within the scope you configure. For those third-party systems you are the data controller, and you are responsible for your own lawful basis and your relationship with their providers. Currently supported:

  • Google Calendar
  • HubSpot
  • Salesforce
  • Pipedrive
  • Zoho CRM
  • Close
  • Copper
  • Freshsales (Freshworks)
  • monday.com

Integrations are optional. If one isn’t connected, no data is sent to that system.

We may also disclose data to competent authorities where required by law.

8. International data transfers

Where your data is held. Our primary database, call recordings and transcripts are stored in the United Kingdom (London). Real-time voice recognition and synthesis are provided by a partner processing in the United States; on their side, calls are kept for only 7 days.

If you are in the UK, your call recordings, transcripts and account data are stored on infrastructure inside the UK. That is domestic processing, not an international transfer, so no additional safeguard is needed for storage. The only leg that leaves the UK is real-time voice processing, which goes to the United States and is covered as follows:

  1. 8.1To the United States - covered by the UK Extension to the EU-US Data Privacy Framework(the “UK-US data bridge”) where the provider holds an active certification covering the UK Extension. Where a provider is not certified under the UK Extension, we use the ICO’s International Data Transfer Agreement, or the UK Addendum to the European Commission’s Standard Contractual Clauses, and we carry out and record a transfer risk assessment (the “data protection test”) for that transfer.

If you are in Ireland or elsewhere in the EEA, the position is different, because our own company is established in the EU (Lithuania) and remains subject to the EU GDPR for everything it processes, wherever that happens. Storing your data on UK-based infrastructure is therefore an international transfer from our company’s perspective - covered by the European Commission’s adequacy decision for the United Kingdom (renewed December 2025, valid to December 2031), so no further safeguard is needed for that leg either. Transfers to the United States for real-time voice processing rely on the EU-US Data Privacy Frameworkwhere the provider is certified, and otherwise on the European Commission’s Standard Contractual Clauses with supplementary technical and organisational measures.

The route applied to each individual provider is set out in the sub-processor list, which we provide on request to paul@vetspeaking.com.

9. Retention periods

We keep data no longer than necessary for its purpose:

  1. 9.1Account and configuration data - for as long as the service is in use.
  2. 9.2Call recordings and transcripts - for the period the practice chooses: 30, 90, 180 or 365 days; 90 days by default. Once that period ends, the audio recording, transcript, summary, and the caller’s name and phone number are deleted automatically. Only the call’s date and duration remain, for billing. There is no unlimited-retention option.
  3. 9.3Bookings made during a call (caller name, phone number and reason) - deleted on the same schedule as the call they came from.
  4. 9.4Call recordings on the voice-technology provider’s side - 7 days.
  5. 9.5Contacts - not deleted automatically, since these are the practice’s own business records. Contacts created from calls and not contacted again for over 24 months are marked inactive, so the practice can review and remove them.
  6. 9.6Website chat widget messages - 12 months.
  7. 9.7Demo call data and the consent record - 30 days.
  8. 9.8Records of data exports and of our staff accessing an account - 24 months. These exist so we can answer the question of who saw or sent what, and when.
  9. 9.9Consent records - for as long as the account exists, as proof of consent; the IP address attached to them is erased after 24 months.
  10. 9.10Suppression list (people who have told us not to contact them) - kept indefinitely, because deleting it is the only way we could contact you again by mistake.
  11. 9.11Billing and accounting records - for as long as required by law (typically 10 years).
  12. 9.12Correspondence - for as long as relevant to resolving the enquiry, and a reasonable time after.

10. Confidentiality and security

We treat all data belonging to you and your clients as strictly confidential. Only authorised staff and sub-processors who need it to provide the service have access, and they are bound by confidentiality obligations.

We apply technical and organisational security measures, including:

  1. 10.1encrypting data in transit (TLS) and at rest;
  2. 10.2access control on a least-privilege basis;
  3. 10.3authentication and activity logging;
  4. 10.4regular backups and recovery procedures;
  5. 10.5a written breach-management process. Where we are the controller, we notify the ICO within 72 hours of becoming aware of a reportable breach, and tell affected people where the law requires it. Where we are a processor, we notify the practice without undue delay so they can decide.

10.1. Our staff’s access to your account

Although you normally set up your own account and AI agent, our authorised staff may access your accountand view and manage the data in it in two cases: (a) providing technical support and troubleshooting when something isn’t working; and (b) at your request, to build or configure the agent on your behalf (this may be a separately charged service). We only grant such access to the extent needed for that purpose (lawful basis - Art. 6(1)(b) and (f)), applying least privilege, and our staff are bound by confidentiality obligations.

Every such access is logged - which staff member accessed which account, and when. You can request this access history at any time by writing to paul@vetspeaking.com.

11. Deleting data

Once deleted, it’s gone. When you delete your data or close your account, we permanently remove your personal data and call recordings from our database and audio storage. Some service providers may retain data briefly under their own retention schedules, after which it is deleted.
  1. 11.1You can delete your account and its associated data in your account settings, or by contacting paul@vetspeaking.com.
  2. 11.2We carry out deletion without undue delay; data in backups is removed through the normal backup rotation cycle.
  3. 11.3We may retain only the minimum information we’re required to keep by law (e.g. accounting records) or to defend legal claims - held separately, and only for the applicable period.
  4. 11.4When acting as a processor, we carry out deletion on the practice’s instructions and under the Data Processing Agreement.

12. Your rights

Under the UK GDPR (and the EU GDPR in Ireland) you have the right to:

  1. 12.1access your data;
  2. 12.2request correction of inaccurate data;
  3. 12.3request erasure of data (“the right to be forgotten”);
  4. 12.4restrict processing;
  5. 12.5object to processing based on legitimate interest;
  6. 12.6object to direct marketing at any time - this one is absolute. If you tell us to stop, we stop, and we keep a record so it does not happen again;
  7. 12.7data portability;
  8. 12.8withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.

To exercise any of these, contact paul@vetspeaking.com. We respond within one month. If your request is complex or you have made several, we may extend that by up to two further months, and we will tell you if so.

If you called a veterinary practice and want to exercise your rights over that call, the practice is the data controller. Contact them first - we will help them respond, and if you come to us directly we will point you to them and let them know.

13. Complaints

If you are unhappy with how we have handled your personal data, please tell us first at paul@vetspeaking.com. You do not need to use any particular form or wording - an email saying you want to complain is enough.

  1. 13.1We will acknowledge your complaint within 30 days.
  2. 13.2We will investigate and tell you the outcome without undue delay.

You also have the right to complain to a supervisory authority at any time, without coming to us first:

  1. 13.1In the UK - the Information Commissioner's Office (ICO). You can complain at https://ico.org.uk/make-a-complaint/ or call 0303 123 1113.
  2. 13.2In Ireland - the Data Protection Commission (DPC), at https://www.dataprotection.ie/en/individuals/raising-concern-commission.

14. Cookies

On the website vetspeaking.com we use cookies and similar technologies. Cookies are small text files placed on your device as you browse; they help the site function, remember your choices, and, with your consent, gather statistics. In the UK their use is governed by the Privacy and Electronic Communications Regulations 2003 (PECR) and the UK GDPR; in Ireland, by the ePrivacy Regulations 2011 and the EU GDPR.

14.1. Categories of cookies

  • Necessary cookies - required for the site’s core operation (maintaining your session, secure sign-in, billing). No consent is needed, and they can’t be turned off.
  • Analytics cookies - help us understand how the site is used, so we can improve it. Only used once you have given consent.
  • Marketing cookies - used to show relevant content or advertising and measure its effectiveness. Only used once you have given consent.

Non-essential cookies are not set until you consent in the cookie banner. Refusing is as easy as accepting - the banner offers a single “Reject non-essential” button alongside “Accept all”. You can change or withdraw your choice at any time.

14.2. Cookies we use

At present we set only necessary cookies. We run no analytics, advertising or tracking technology of any kind on this site:

  • Session and authentication (necessary) - to maintain a secure sign-in to your account.
  • Billing and payments (necessary) - set by our payment provider for fraud protection during checkout.
  • Cookie consent record (necessary) - remembers your cookie choice so you are not asked again.

Website fonts are hosted on our own servers, so they set no third-party cookies. If we add analytics or marketing technology in future, it will only run once you have consented, and we will update this list first.

14.3. Managing cookies

You can change your choice at any time using the button below, or in your browser settings. Some site features may not work without necessary cookies.

15. Changes to this policy

We may update this policy. We will tell you about significant changes on the website or by email. The current version and its update date are always shown at the top of this page.