CliniVoice AI Ltd (“we”, “us”, “our”) is committed to protecting your privacy and handling your data in an open and transparent manner. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use CliniVoice AI.
For your account data and service usage data, CliniVoice AI Ltd is the data controller. We are registered in England and Wales.
For clinical/patient data processed through the Service, your employing healthcare Organisation is typically the data controller and CliniVoice AI acts as a data processor under a Data Processing Agreement.
chrome.storage.session — cleared when browser closes, never written to disk)Under UK GDPR, we process your data on the following legal bases:
| Data | Lawful Basis |
|---|---|
| Account data | Contract (Art. 6(1)(b)) — necessary to provide the Service |
| Clinical content | Contract (Art. 6(1)(b)) + Art. 9(2)(h) (healthcare provision) |
| Usage analytics | Legitimate interests (Art. 6(1)(f)) — service improvement |
| Payment data | Contract (Art. 6(1)(b)) — billing |
| Marketing emails | Consent (Art. 6(1)(a)) — opt-in only |
We do NOT use your Clinical Content to train AI models unless you provide explicit, informed opt-in consent.
Clinical Content may contain special category data (health data) as defined under Article 9 of UK GDPR. We process this data under Article 9(2)(h) — processing necessary for the provision of health or social care, subject to appropriate safeguards.
We implement enhanced protections for clinical data including:
Role: When a clinician uses CliniVoice AI to process patient information, CliniVoice AI acts as a data processor under UK GDPR Article 28 on behalf of the clinician or their employing organisation (the data controller). This relationship is governed by our Data Processing Agreement.
Patient health data is Special Category Data under Article 9 of UK GDPR. We process it only on instructions from the data controller (the clinician or their organisation) and only for the purpose of providing the Service.
Lawful basis: Article 9(2)(h) — processing necessary for the provision of health or social care by a health professional.
All of the above is provided by the clinician in the course of their dictation. CliniVoice does not independently collect patient data from any other source.
The Service includes a Batch Transcription feature that processes multiple audio or video files in a single session. Each file is transcribed individually and patient data is extracted to generate a clinical letter. Batch-processed audio files are subject to the same deletion schedule as single-file transcriptions. Batch results are stored against your account in the same manner as single-session letters.
Patient data included in clinical dictation is sent to Google Cloud Vertex AI (europe-west2, London) for AI-assisted letter generation — all processing occurs within the UK under Google Cloud’s signed Data Processing Agreement. Transcription is handled by Groq (Whisper Large v3 Turbo) under Groq’s Data Processing Addendum. We do not permit any provider to use patient data to train their models.
Where NHS numbers are included in transcripts or letters, they are stored in our database as a one-way cryptographic hash. The plaintext NHS number is never retained after processing. This ensures we cannot reconstruct or expose NHS numbers in the event of a data breach.
Patient-linked clinical letters and transcripts are retained for the period set by the clinician in their account settings (default: 24 months of account activity). All patient-linked data is deleted immediately upon account deletion or upon the clinician’s explicit request.
CliniVoice allows you to optionally provide your own third-party API keys (for example, a Groq, Google Gemini, or OpenAI API key) to use for transcription and letter generation.
If you choose to provide API keys:
You are responsible for managing the security of your API keys and for compliance with the terms of service of the respective third-party providers.
We share your data with the following categories of third parties, strictly for the purposes described:
| Provider | Purpose | Location | DPA Status |
|---|---|---|---|
| Google Cloud (Gemini API / Vertex AI) | AI letter generation — routed via Vertex AI europe-west2 (London) when available | UK (London, europe-west2) | DPA signed |
| Groq, Inc. | Speech-to-text transcription (primary). Audio is processed transiently and deleted immediately after transcription. Groq does not use audio to train models. Governed by Groq’s Privacy Policy and Data Processing Addendum. | USA — UK IDTA & EU SCCs (UK Addendum) in place | DPA pending |
| OpenAI (Whisper API) | Speech-to-text transcription (fallback, opt-in BYOK only) | USA — UK IDTA & EU SCCs (UK Addendum) in place | DPA pending |
| Vercel | Application hosting — serverless functions pinned to lhr1 (London) | UK (London, lhr1) | DPA signed |
| Supabase | Database and authentication | UK (London, eu-west-2) | DPA signed |
| Stripe | Payment processing | USA (EU SCCs in place) | DPA signed |
| Resend / Email provider | Transactional email delivery | USA (EU SCCs in place) | DPA pending |
We do not sell, rent, or trade your personal data to any third party.
Where data is transferred outside the UK, we ensure adequate protection through one or more of the following safeguards:
Groq (primary transcription provider)
Audio transcription is performed by Groq, Inc. (United States). This constitutes a restricted transfer of special category data (health data) from the UK to a third country. We rely on the UK International Data Transfer Agreement (UK IDTA) and EU Standard Contractual Clauses with UK Addendum (ICO approved, February 2022) as the lawful transfer mechanism under UK GDPR Article 46. Key safeguards in place:
| Data Type | Retention Period |
|---|---|
| Account data | Duration of account + 12 months after deletion |
| Audio recordings | Deleted automatically after 30 days, or immediately on user request |
| Transcriptions & letters | Duration of account + 30 days after deletion |
| Usage analytics | Aggregated after 90 days; raw data deleted after 12 months |
| Payment records | 7 years (UK tax/accounting requirements) |
| Security/audit logs | 12 months |
| CPD portfolio data | 5 years (NHS revalidation requirement) |
| Learning Space chat history | 90 days (patient context anonymised before storage) |
| Letter quality feedback | 2 years; personal identifiers anonymised after 90 days |
CPD portfolio data: CPD portfolio entries (reflections, activity logs, competency evidence) are retained for 5 years from the date of creation, in line with NHS revalidation and professional development record-keeping requirements. You may request deletion of individual CPD entries at any time via your account settings.
Learning Space: Learning Space chat sessions may contain patient context provided by you. All Learning Space conversations are automatically anonymised before storage — patient names, NHS numbers, and dates of birth are redacted. Chat history is retained for 90 days.
Letter quality feedback: Letter quality feedback is retained for 2 years to improve AI letter generation. Personal identifiers (user account links) are automatically anonymised after 90 days; the qualitative feedback text is retained in anonymised form.
Under UK GDPR, you have the following rights in relation to your personal data:
To exercise any of these rights, contact us at privacy@clinivoice.com. We will respond within one calendar month.
Patients whose data has been processed through CliniVoice AI may submit a Subject Access Request (SAR). Because CliniVoice acts as a data processor (not the data controller), patient SARs should be directed to the clinician or their employing organisation (the data controller).
Where a clinician or their organisation submits a SAR on behalf of a patient, CliniVoice AI will cooperate fully and provide all relevant data within 30 calendar days.
To submit a clinician-initiated SAR on behalf of a patient, contact us at privacy@clinivoice.com. Please include your organisation name, the patient’s hospital number or NHS number, and the date range of processing.
The Service is designed for use by adult healthcare professionals. We do not knowingly collect personal data from individuals under the age of 18. If we become aware that we have collected data from a child, we will delete it promptly.
We implement appropriate technical and organisational security measures including:
CliniVoice AI Ltd is in the process of registering with the Information Commissioner’s Office (ICO) as a data controller and data processor. Our registration is currently pending. Once confirmed, our ICO registration number will be published here.
In the meantime, you may raise data protection concerns directly with us at privacy@clinivoice.com.
For clinicians and organisations using CliniVoice AI to process patient data, a Data Processing Agreement (DPA) is presented and must be accepted on first use of the Service. This satisfies the requirements of UK GDPR Article 28, which requires a written contract between data controller and data processor.
The DPA sets out:
You can review the full DPA at /legal/dpa.
For all data protection enquiries, please contact:
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the UK’s supervisory authority:
We encourage you to contact us first so we can try to resolve your concern directly.
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service at least 30 days before the changes take effect. The “Last updated” date at the top of this page indicates when this policy was most recently revised.
Questions? Contact legal@clinivoice.com