Privacy policy
How Conversico handles personal data.
This policy explains how Conversico Ltd handles information when Greeta supports a dental practice, and when someone visits our website or sends us an enquiry.
- Last updated
- 29 July 2026
- Service data
- Processor for the Practice
- Website enquiries
- Conversico is the Controller
1. Overview
Conversico Ltd provides AI-powered communication tools for dental practices. We are committed to protecting personal data and handling it responsibly and transparently.
2. Our role
For data processed through our services, Conversico acts as a Data Processor on behalf of the Practice.
3. Data we process on behalf of practices
When delivering our AI receptionist services, Conversico processes personal data, including patient contact details and enquiry information, strictly on behalf of dental practices.
- The Practice is the Data Controller.
- Conversico acts as a Data Processor.
- Conversico processes this data solely on the Practice's documented instructions, as set out in our Data Processing Agreement with the Practice.
For website visitors and enquiry data, Conversico acts as a Data Controller.
4. Data we process
- Contact details, such as phone numbers.
- Call data, including recordings and transcripts where enabled.
- Enquiry and booking information.
- Conversico software usage data.
5. How data is used
Service data processed on behalf of Practices is used:
- To provide AI receptionist services on behalf of Practices.
- To manage patient enquiries and booking requests.
- To monitor system uptime, reliability, and feature usage, and to support our customers.
Conversico does not use patient or call data to train, fine-tune, or otherwise improve any AI or machine learning model. The legal basis for this processing is determined by the Practice as Data Controller.
Website and enquiry data, for which Conversico acts as Controller, is used:
- To respond to enquiries and demo requests — legal basis: performance of a contract, or steps taken at your request prior to entering into one.
- To operate, secure, and improve our website — legal basis: legitimate interests.
- To send marketing communications where you have opted in — legal basis: consent.
6. AI and call handling
Calls may be:
- Handled by an AI assistant.
- Recorded and transcribed.
- Analysed to support administrative workflows and efficiencies, and to monitor service quality and reliability.
This analysis does not involve training or fine-tuning any AI model on patient or call data. Conversico does not provide medical or dental advice.
7. Data sharing
We use trusted third-party providers, such as telephony, voice synthesis, AI processing, and cloud infrastructure providers, to deliver our services. Conversico remains responsible for data protection obligations regarding these providers.
- Twilio Ireland Ltd — telephony, SMS, recording capture (UK/EEA hosting where available).
- ElevenLabs Ltd — voice synthesis and conversational AI inference; data-processing terms must be recorded in the workspace evidence pack.
- Anthropic, PBC — large-language-model inference where enabled; no-training and contractual controls must be recorded in the workspace evidence pack.
- Microsoft Ireland Operations Ltd — Azure hosting (UK South) for backend compute, storage, data, secrets, and monitoring.
- Vercel Inc. — frontend hosting and edge delivery (London origin) for the practice dashboard and public site.
- Clerk Inc. — workforce identity for the practice dashboard (practice users only; not patient data).
- Stripe Payments Europe Ltd — billing and card processing for the practice.
- Functional Software, Inc. (Sentry) — error monitoring and session replay with PII scrubbed before transmission.
- PostHog Inc. — product analytics and rollout controls on the EU (Frankfurt) instance.
- Upstash Inc. — Redis Serverless transient runtime state for cache, rate-limits, live-feed pub/sub, worker heartbeat state, and Copilot staged-write TTLs.
- ilert GmbH — on-call paging and incident notifications (EU Frankfurt) before engagement.
Where personal data is transferred outside the UK, including to the United States where certain providers are located, such transfers are made under a valid transfer mechanism recognised under the UK GDPR. This will be the UK International Data Transfer Agreement, the UK Addendum to the European Commission's Standard Contractual Clauses, or a UK adequacy regulation, as applicable.
The current register, including optional providers that are not engaged for every practice, is published at /legal/sub-processors.
8. Cookies and website data
We use cookies and browser storage for the purposes below. Essential storage is used to operate and secure the site. PostHog, Google Analytics, and Google Ads are not loaded unless you choose the corresponding consent option.
- Essential — Conversico consent preferences are stored in local storage until you change them or clear browser data. A same-site CSRF security cookie may be stored for up to 24 hours when you submit a form or make another write request.
- Analytics — if you choose Analytics, PostHog EU Cloud receives explicitly named website events and stores an anonymous identifier in local storage until you withdraw consent or clear browser data. We disable autocapture and session replay and remove query strings and fragments before events are sent.
- Analytics — if a Google Analytics property is configured and you choose Analytics, Google may set _ga cookies for up to two years to distinguish visitors and retain session state. Browser controls may shorten this period.
- Advertising — if you choose Analytics & advertising, Google Ads may store first-party advertising-click identifiers and receive confirmed conversion events for campaign measurement. Google Ads cookies expire no later than 90 days after the relevant ad click.
- Booking measurement — non-PII booking intent and conversion identifiers may be kept in session storage until you close the browser tab or withdraw consent.
PostHog and Google act as recipients for the consented measurement purposes described above. We do not send lead-form field values, patient information, call content, transcripts, query strings, or URL fragments to website analytics or advertising tools.
You can choose Essential only, Analytics, or Analytics & advertising in the consent panel. You can reopen Cookie settings from the footer at any time. Withdrawing consent stops future collection and clears the analytics and advertising storage that Conversico controls.
9. Data retention
- Call recordings and transcripts: retained for 6 months to support quality assurance, dispute resolution, and consent verification.
- Appointment data: retained in line with the relevant practice management system's retention policy, typically as part of the clinical record.
- Audit logs and trust receipts: retained for 7 years.
- Escalation records: retained for 3 years for clinical governance purposes.
- Website and enquiry data, such as contact-form submissions and demo requests: retained for 24 months from your last interaction with us, unless you ask us to delete it sooner.
10. Your data rights
For service-related data, individuals should contact the relevant Practice, who can assist with requests to access, correct, or delete data. Conversico will support the Practice in fulfilling these requests where required.
For website and enquiry data, where Conversico acts as Controller, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request erasure of your data.
- Restrict or object to certain processing.
- Request portability of your data.
- Withdraw consent at any time, where processing is based on consent.
To exercise these rights, contact us using the details in Section 12.
Conversico is registered with the Information Commissioner's Office with registration reference ZC105329. You have the right to lodge a complaint with the ICO if you believe your data has been mishandled.
11. Security
We implement appropriate technical and organisational measures to protect personal data, including encryption of data in transit and at rest, access controls, and monitoring of access to systems.
12. Contact
Dr Sheliza Darvesh — Co-Founder and COO
sheliza.darvesh@conversico.com
Contact us about your data.
Contact Dr Sheliza Darvesh, Co-Founder and COO, to exercise your rights or ask a privacy question.
Conversico Ltd · ICO registration reference ZC105329