Last updated: 18 July 2026
This policy explains how Volofio ("we", "us") handles personal data. Volofio provides an AI receptionist service that answers calls and messages, books appointments and sends reminders on behalf of clinics ("Clinics").
There are two different relationships to be clear about:
Volofio is operated by [Legal entity name], registered in England & Wales ([company number]), registered office [registered address]. ICO registration [ICO registration number]. Contact: hello@volofio.com.
Call content may occasionally reveal health-related information. We do not ask for or require clinical details, and the agent is instructed not to give medical advice or triage.
| Purpose | Legal basis (UK GDPR) |
|---|---|
| Providing and operating your account and the service | Performance of a contract |
| Handling calls, bookings and messages for a Clinic | Processed for the Clinic under their legal basis; we act on their instructions |
| Billing, fraud prevention, security and support | Legitimate interests; legal obligation |
| Service emails (e.g. summaries, reminders you configure) | Performance of a contract / legitimate interests |
| Improving reliability and troubleshooting | Legitimate interests |
We use carefully selected providers to run the service. They process data on our instructions under contract, and only as needed to provide their part of the service:
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication and file storage |
| Vercel | Application hosting |
| ElevenLabs | Conversational AI voice and speech-to-text |
| Twilio | Telephone calls and SMS messages |
| Calendar availability and booking (where a Clinic connects it) | |
| Anthropic | Large-language-model responses (where enabled) |
| Resend | Transactional and summary emails |
Some providers may process data outside the UK/EEA. Where they do, transfers are protected by appropriate safeguards such as the UK International Data Transfer Agreement / Addendum or an adequacy decision. A current list of sub-processors is available on request.
We do not sell personal data or use call content to train our own models for unrelated purposes.
Account data is kept for as long as you have an account and a reasonable period afterwards. Call, booking and message data is retained per the Clinic's instructions and their own retention rules; when a Clinic closes their account we delete or return their data as set out in our Data Processing Agreement. We keep the minimum needed to meet legal, accounting and security obligations.
Under UK GDPR you have the right to access, correct, delete or restrict use of your data, to object to certain processing, and to data portability. To exercise these:
You can also complain to the Information Commissioner's Office (ICO) at ico.org.uk.
We protect data with encryption in transit, encryption of sensitive credentials at rest, role-based access controls, per-Clinic data isolation, and least-privilege access to systems. No system is perfectly secure, but we take reasonable and appropriate measures and review them.
See our Cookie Policy for details of the cookies we use.
We may update this policy from time to time. We will change the "last updated" date above and, for material changes, notify Clinic account holders.