Dr Joseph Ogaga, trading as Teron Advisory (“we”, “us”, “our”) is committed to protecting your privacy and handling your data in an open and transparent manner. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use CliniVoice AI.
For your account data and service usage data, Teron Advisory is the data controller. Teron Advisory is the trading name of Dr Joseph Ogaga, a sole trader established in the United Kingdom.
For clinical/patient data processed through the Service, your employing healthcare Organisation is typically the data controller and CliniVoice AI acts as a data processor under a Data Processing Agreement.
chrome.storage.session — cleared when browser closes, never written to disk)Under UK GDPR, we process your data on the following legal bases:
| Data | Lawful Basis |
|---|---|
| Account data | Contract (Art. 6(1)(b)) — necessary to provide the Service |
| Clinical content | Contract (Art. 6(1)(b)) + Art. 9(2)(h) (healthcare provision) |
| Usage analytics | Legitimate interests (Art. 6(1)(f)) — service improvement |
| Payment data | Contract (Art. 6(1)(b)) — billing |
| Marketing emails | Consent (Art. 6(1)(a)) — opt-in only |
We do NOT use your Clinical Content to train AI models unless you provide explicit, informed opt-in consent.
Clinical Content may contain special category data (health data) as defined under Article 9 of UK GDPR. We process this data under Article 9(2)(h) — processing necessary for the provision of health or social care, subject to appropriate safeguards.
We implement enhanced protections for clinical data including:
Role: When a clinician uses CliniVoice AI to process patient information, CliniVoice AI acts as a data processor under UK GDPR Article 28 on behalf of the clinician or their employing organisation (the data controller). This relationship is governed by our Data Processing Agreement.
Patient health data is Special Category Data under Article 9 of UK GDPR. We process it only on instructions from the data controller (the clinician or their organisation) and only for the purpose of providing the Service.
Lawful basis: Article 9(2)(h) — processing necessary for the provision of health or social care by a health professional.
All of the above is provided by the clinician in the course of their dictation. CliniVoice does not independently collect patient data from any other source.
The Service includes a Batch Transcription feature that processes multiple audio or video files in a single session. Each file is transcribed individually and patient data is extracted to generate a clinical letter. Batch-processed audio files are subject to the same deletion schedule as single-file transcriptions. Batch results are stored against your account in the same manner as single-session letters.
Patient data included in clinical dictation is sent to Google Cloud Vertex AI (europe-west2, London) for AI-assisted letter generation — this route processes within the UK under Google Cloud’s signed Data Processing Agreement, and it is the only route. There is no fallback to the Google Gemini API or any other non-UK endpoint: if Vertex AI in europe-west2 is unavailable, letter generation fails rather than processing your data elsewhere. Transcription is handled by Groq (Whisper Large v3 Turbo) in the USA; a Data Processing Addendum with Groq is being finalised (see Section 9). We do not permit any provider to use patient data to train their models.
NHS numbers appear within the transcripts and letters you dictate and are stored encrypted at rest under row-level access controls — only your account can access them. Where NHS numbers are separately indexed for matching or search, a one-way cryptographic hash is used rather than the plaintext number.
Patient-linked clinical letters and transcripts are retained until you delete them, or automatically per the retention period you set in account settings (minimum 90 days — a floor that protects clinical records from premature deletion). No automatic deletion occurs unless you enable it. All patient-linked data is deleted immediately upon account deletion or upon the clinician’s explicit request.
CliniVoice allows you to optionally provide your own Groq API key, which is used for transcription only. We do not accept your own key for letter generation: formatting runs exclusively on Vertex AI in the United Kingdom (europe-west2), and a user-supplied Google key would move that processing to Google’s global infrastructure, outside the residency commitment described above.
If you choose to provide API keys:
You are responsible for managing the security of your API keys and for compliance with the terms of service of the respective third-party providers.
We share your data with the following categories of third parties, strictly for the purposes described:
| Provider | Purpose | Location | DPA Status |
|---|---|---|---|
| Google Cloud (Vertex AI) | AI letter generation — Vertex AI europe-west2 (London). This is the only route; there is no fallback outside the UK | UK only (London, europe-west2) | DPA signed |
| Groq, Inc. | Speech-to-text transcription (primary). Zero Data Retention is enabled on our account, so audio and transcripts are processed in memory and never written to Groq’s storage. Groq does not use audio to train models. Governed by Groq’s Privacy Policy; Groq’s Data Processing Addendum applies, incorporating the UK International Data Transfer Addendum and the EU Standard Contractual Clauses. | USA — UK IDTA in place; no data retained (ZDR); see Section 9 | DPA in place |
| Vercel | Application hosting — serverless functions pinned to lhr1 (London) | UK (London, lhr1) | DPA signed |
| Supabase | Database and authentication | UK (London, eu-west-2) | DPA signed |
| Stripe | Payment processing | USA (EU SCCs in place) | DPA signed |
| Resend / Email provider | Transactional email delivery | USA (EU SCCs in place) | DPA pending |
You may optionally connect Google Drive, Microsoft OneDrive or Dropbox and save letters to them. This is different from the sub-processors above: we are not choosing that destination, you are, and once a letter is written there it is held under your agreement with that provider, not ours. We ask for the narrowest access each provider offers — for Google Drive that is drive.file, which can only see files this app itself created, never the rest of your Drive.
Two consequences worth stating plainly. Filenames are metadata: they appear in your drive’s search results, share-link previews, notification emails and backup indexes, none of which a letter’s own permissions cover — so by default we name exported letters with patient initials and an NHS number rather than a full name, and using full names is a setting you must switch on deliberately. And we cannot reach a file once it has left: if you disconnect a provider we stop writing to it, but we cannot delete or recall what is already there. You can disconnect at any time in Settings → Cloud Backup.
We do not sell, rent, or trade your personal data to any third party.
Where data is transferred outside the UK, we ensure adequate protection through one or more of the following safeguards:
Groq (primary transcription provider)
Audio transcription is performed by Groq, Inc. (United States). This constitutes a restricted transfer of special category data (health data) from the UK to a third country. A Data Processing Addendum incorporating the UK International Data Transfer Agreement (UK IDTA) is being finalised with Groq; until it is executed, Groq processes audio transiently under its published privacy terms, and organisations with data-sovereignty requirements should use the BYOK option below. Current safeguards:
| Data Type | Retention Period |
|---|---|
| Account data | Duration of account + 12 months after deletion |
| Audio recordings | Deleted immediately after transcription |
| Transcriptions & letters | Until you delete them, or per your optional retention setting (minimum 90 days); deleted immediately on account deletion |
| Usage analytics | Aggregated after 90 days; raw data deleted after 12 months |
| Payment records | 7 years (UK tax/accounting requirements) |
| Security/audit logs | Duration of account; deleted with the account |
| CPD portfolio data | 5 years (NHS revalidation requirement) |
| Learning Space chat history | 90 days (patient context anonymised before storage) |
| Letter quality feedback | 2 years; personal identifiers anonymised after 90 days |
CPD portfolio data: CPD portfolio entries (reflections, activity logs, competency evidence) are retained for 5 years from the date of creation, in line with NHS revalidation and professional development record-keeping requirements. You may request deletion of individual CPD entries at any time via your account settings.
Learning Space: Learning Space chat sessions may contain patient context provided by you. All Learning Space conversations are automatically anonymised before storage — patient names, NHS numbers, and dates of birth are redacted. Chat history is retained for 90 days.
Letter quality feedback: Letter quality feedback is retained for 2 years to improve AI letter generation. Personal identifiers (user account links) are automatically anonymised after 90 days; the qualitative feedback text is retained in anonymised form.
Under UK GDPR, you have the following rights in relation to your personal data:
To exercise any of these rights, contact us at privacy@clinivoice.com. We will respond within one calendar month.
Patients whose data has been processed through CliniVoice AI may submit a Subject Access Request (SAR). Because CliniVoice acts as a data processor (not the data controller), patient SARs should be directed to the clinician or their employing organisation (the data controller).
Where a clinician or their organisation submits a SAR on behalf of a patient, CliniVoice AI will cooperate fully and provide all relevant data within 30 calendar days.
To submit a clinician-initiated SAR on behalf of a patient, contact us at privacy@clinivoice.com. Please include your organisation name, the patient’s hospital number or NHS number, and the date range of processing.
The Service is designed for use by adult healthcare professionals. We do not knowingly collect personal data from individuals under the age of 18. If we become aware that we have collected data from a child, we will delete it promptly.
We implement appropriate technical and organisational security measures including:
NHS Data Security and Protection Toolkit: a DSP Toolkit self-assessment is planned ahead of any NHS organisational deployment, and our practices are aligned with the Caldicott Principles (data minimisation, justified purpose, and need-to-know access). NHS organisations can request our current information-governance documentation via security@clinivoice.com.
Teron Advisory is in the process of registering with the Information Commissioner’s Office (ICO) as a data controller and data processor. Our registration is currently pending. Once confirmed, our ICO registration number will be published here.
In the meantime, you may raise data protection concerns directly with us at privacy@clinivoice.com.
For clinicians and organisations using CliniVoice AI to process patient data, a Data Processing Agreement (DPA) is presented and must be accepted on first use of the Service. This satisfies the requirements of UK GDPR Article 28, which requires a written contract between data controller and data processor.
The DPA sets out:
You can review the full DPA at /legal/dpa.
For all data protection enquiries, please contact:
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the UK’s supervisory authority:
We encourage you to contact us first so we can try to resolve your concern directly.
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service at least 30 days before the changes take effect. The “Last updated” date at the top of this page indicates when this policy was most recently revised.
Questions? Contact legal@clinivoice.com