Privacy Policy
This Privacy Policy explains how Clarive AI Ltd collects, uses, stores, and protects personal data when you visit our website, contact us, or use our services.
1. Our Role: Data Controller and Data Processor
1.1 When We Act as Data Controller
Clarive AI Ltd acts as Data Controller for personal data we collect directly, including website visitors, demo requests, sales enquiries, and business communications.
1.2 When We Act as Data Processor
When providing AI receptionist services to clinics, the clinic is the Data Controller and Clarive AI Ltd acts as a Data Processor. We process caller and patient data only on the documented instructions of the clinic. A Data Processing Agreement governs this relationship.
If you are a patient who interacted with a clinic using our service, that clinic is the Data Controller responsible for your personal data. Please contact the clinic directly for data subject requests.
2. Personal Data We Collect
2.1 Website and Enquiry Data
- →Name and job title
- →Email address and phone number
- →Organisation or practice name
- →Message content and demo scheduling details
- →IP address, browser type, and device information
- →Cookie and analytics data where consent is given
2.2 Website Demo Call Data
When you use the live AI demo on clariveai.com, we process the audio of your demo call, the AI-generated transcript of the interaction, and call session metadata. Demo audio and transcripts are retained for a maximum of 30 days and then permanently deleted.
2.3 AI Receptionist Service Data (Processor)
- →Caller phone number and name if provided during the call
- →Call metadata: date, time, duration, and outcome
- →Appointment details and enquiry category
- →Information voluntarily provided by the caller during the interaction
2.4 Structured Call Summaries
By default, Clarive stores a structured summary of each call including call outcome, appointment type, and enquiry category. Structured summaries do not contain full transcripts and are retained for up to 12 months.
2.5 Optional Call Transcripts
Full call transcripts are disabled by default. Where enabled by the clinic, transcripts are retained for a maximum of 30 days and then automatically deleted.
3. Legal Bases for Processing
3.1 Controller Data
- →Contract or pre-contractual steps — responding to demo requests and enquiries
- →Legitimate interests — operating and improving our services and the website AI demo
- →Consent — where required, including for analytics cookies
- →Legal obligation — where required by applicable law
3.2 Processor Data
When acting as Data Processor, we rely on the clinic's lawful basis. For health-adjacent call content, clinics must satisfy a special category condition under Article 9 UK GDPR, typically Article 9(2)(h) — provision of health or social care.
4. Special Category Data
5. Subprocessors and Service Providers
We use the following third-party subprocessors. All operate under contractual Data Processing Agreements and are required to implement appropriate security safeguards.
| Subprocessor | Purpose | Location |
|---|---|---|
| Retell AI | AI voice conversation engine | United States |
| OpenAI | Language model processing | United States |
| Twilio | Telephony infrastructure and call routing | United States |
| Cal.com | Appointment scheduling | United States |
| Supabase | Database and secure data storage | EU West (Ireland) |
| Vercel | Dashboard hosting and deployment | United States / EU |
| Formspree | Web form submission and routing | United States |
We will provide clinics with at least 30 days prior written notice of any intended changes to our subprocessor list.
6. International Data Transfers
Several subprocessors are based in the United States. Where personal data is transferred outside the United Kingdom, we ensure appropriate safeguards are in place:
- →UK Addendum to the EU Standard Contractual Clauses
- →EU Standard Contractual Clauses where applicable
- →Adequacy decisions where recognised by the UK
Details of specific transfer mechanisms are available on request at legal@clariveai.com.
7. Data Retention
| Data Type | Retention Period | Method |
|---|---|---|
| Website demo call audio and transcripts | 30 days | Automatic deletion |
| Structured call summaries | Up to 12 months | Automated deletion |
| Call transcripts (if enabled by clinic) | 30 days from call | Automated deletion |
| Call metadata | Up to 12 months | Automated deletion |
| Website enquiries and demo requests | Up to 24 months | Manual review |
| Financial and contractual records | 7 years | Secure deletion |
8. Security Measures
- →Encryption in transit (TLS) and at rest
- →Role-based access controls limiting data access to authorised personnel
- →Secure cloud infrastructure hosted within the EU where possible
- →Monitoring, logging, and incident response procedures
- →Data minimisation — we collect only what is necessary
- →Regular review of subprocessor security practices
9. Data Subject Rights
9.1 If You Interact with Clarive Directly
Where Clarive acts as Data Controller, you may exercise the rights of access, rectification, erasure, restriction, data portability, and objection. Contact legal@clariveai.com. We will respond within one calendar month.
9.2 If You Are a Patient of a Clinic
The clinic is the Data Controller for your data. Please contact the clinic directly. Clarive will assist the clinic in responding to your request as required under our Data Processing Agreement.
10. Data Breach Notification
In the event of a personal data breach affecting Controller data, we will notify the ICO within 72 hours where the breach is likely to result in a risk to individuals rights and freedoms.
When acting as Data Processor, we will notify the affected clinic within 48 hours of becoming aware of the breach.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Any updates will be posted on our website with a revised effective date. We will notify clinic clients of material changes via email with at least 30 days notice.
13. Contact and Complaints
- →Email: legal@clariveai.com
- →Company: Clarive AI Ltd, Northern Ireland, NI739625
You have the right to lodge a complaint with the Information Commissioners Office (ICO):
- →Website: ico.org.uk
- →Helpline: 0303 123 1113