Summary: We are BosseyAI LTD, a registered UK company. We process personal data to deliver AI receptionist services to dental clinics. We are registered with the ICO (ZC108524), GDPR compliant, and we never sell your data.

1. Who We Are

BosseyAI LTD ("BosseyAI", "we", "us") provides AI-powered patient pipeline services for dental clinics, including our AI receptionist Sarah.

2. What This Policy Covers

This policy applies to:

If you are a dental patient, the clinic is the Data Controller of your data. BosseyAI processes it on their behalf as a Data Processor. For questions about your data, contact the clinic directly.

3. What Data We Collect

Website visitors: IP address, browser type, pages visited, referral source — used only for site analytics.

Clinic clients: Name, business name, email, phone, billing information.

Dental patients (via clinic):

We do not collect clinical records, diagnoses, treatment history, payment card data, or identity documents.

4. How We Use Your Data

We never use patient data for our own marketing, model training, or sell it to third parties.

5. Sub-Processors

ProviderPurposeLocation
VAPI Inc.AI voice call handling (Sarah)USA
Twilio Inc.SMS and WhatsApp deliveryUSA / EU
Railway Corp.Server infrastructureEU West
Supabase Inc.Database storageEU West
n8n GmbHWorkflow automationEU
OpenAI LPAI language processingUSA

International transfers to US-based providers are covered by Standard Contractual Clauses (SCCs) approved by the ICO.

6. Data Retention

Data TypeRetention
Patient contact recordsDuration of clinic contract + 30 days
Call transcripts & SMS logs90 days (auto-deleted)
Call metadata12 months
Client business dataContract duration + 6 years

7. Your Rights

Under UK GDPR you have the right to: access your data, correct inaccurate data, request erasure, restrict processing, data portability, and object to processing.

To exercise any right: hello@bosseyai.com — we respond within 30 days.

You can also complain to the ICO: ico.org.uk · 0303 123 1113

8. Cookies

This website uses only essential cookies required for it to function. We do not use tracking or advertising cookies without your consent. You can manage cookie preferences via your browser settings.

9. Security

We use TLS encryption for all data in transit, row-level database security, and strict access controls. In the event of a data breach we notify affected parties and the ICO within the required timeframes.

10. Changes

We may update this policy. Changes are published here with an updated date. Material changes are notified to clients by email.

11. Contact

BosseyAI LTD · hello@bosseyai.com · 86–90 Paul Street, London EC2A 4NE · ICO: ZC108524