Volofio← Back to site

Privacy Policy

Last updated: 18 July 2026

This policy explains how Volofio ("we", "us") handles personal data. Volofio provides an AI receptionist service that answers calls and messages, books appointments and sends reminders on behalf of clinics ("Clinics").

1. Who is responsible for your data

There are two different relationships to be clear about:

  • Website visitors and Clinic account holders. When you visit our website or hold a Volofio account, Volofio is the data controller for your information.
  • Patients and callers of a Clinic. When our service handles a call, booking or message for a Clinic, the Clinic is the data controller and Volofio acts as their data processor, processing that data only on the Clinic's documented instructions under a Data Processing Agreement. If you are a patient, please contact the Clinic to exercise your rights; we will assist them in responding.

Volofio is operated by [Legal entity name], registered in England & Wales ([company number]), registered office [registered address]. ICO registration [ICO registration number]. Contact: hello@volofio.com.

2. What we collect

From Clinic account holders

  • Account details: name, email address, password (stored hashed), role.
  • Clinic configuration you enter: services, providers, opening hours, greeting, phone numbers.
  • Usage and billing information relating to your subscription.

On behalf of Clinics, when we handle a call or message (Clinic is controller)

  • Caller's phone number, name and any details they give to book or leave a message.
  • Appointment details (service, provider, date and time).
  • Call recordings, transcripts and summaries, and message content.
  • Optional patient email address where provided for confirmations.

Call content may occasionally reveal health-related information. We do not ask for or require clinical details, and the agent is instructed not to give medical advice or triage.

3. Why we use it and our legal basis

PurposeLegal basis (UK GDPR)
Providing and operating your account and the servicePerformance of a contract
Handling calls, bookings and messages for a ClinicProcessed for the Clinic under their legal basis; we act on their instructions
Billing, fraud prevention, security and supportLegitimate interests; legal obligation
Service emails (e.g. summaries, reminders you configure)Performance of a contract / legitimate interests
Improving reliability and troubleshootingLegitimate interests

4. Who we share it with (sub-processors)

We use carefully selected providers to run the service. They process data on our instructions under contract, and only as needed to provide their part of the service:

ProviderPurpose
SupabaseDatabase, authentication and file storage
VercelApplication hosting
ElevenLabsConversational AI voice and speech-to-text
TwilioTelephone calls and SMS messages
GoogleCalendar availability and booking (where a Clinic connects it)
AnthropicLarge-language-model responses (where enabled)
ResendTransactional and summary emails

Some providers may process data outside the UK/EEA. Where they do, transfers are protected by appropriate safeguards such as the UK International Data Transfer Agreement / Addendum or an adequacy decision. A current list of sub-processors is available on request.

We do not sell personal data or use call content to train our own models for unrelated purposes.

5. How long we keep it

Account data is kept for as long as you have an account and a reasonable period afterwards. Call, booking and message data is retained per the Clinic's instructions and their own retention rules; when a Clinic closes their account we delete or return their data as set out in our Data Processing Agreement. We keep the minimum needed to meet legal, accounting and security obligations.

6. Your rights

Under UK GDPR you have the right to access, correct, delete or restrict use of your data, to object to certain processing, and to data portability. To exercise these:

  • If Volofio is the controller (your account), email hello@volofio.com.
  • If you are a patient/caller of a Clinic, contact that Clinic (the controller); we will support them.

You can also complain to the Information Commissioner's Office (ICO) at ico.org.uk.

7. Security

We protect data with encryption in transit, encryption of sensitive credentials at rest, role-based access controls, per-Clinic data isolation, and least-privilege access to systems. No system is perfectly secure, but we take reasonable and appropriate measures and review them.

8. Cookies

See our Cookie Policy for details of the cookies we use.

9. Changes

We may update this policy from time to time. We will change the "last updated" date above and, for material changes, notify Clinic account holders.

← HomePrivacyTermsCookiesDPAContact