← AutomateFlow

Privacy Policy

AutomateFlow is a service of E.A.E Enterprise Ltd (Company No. 16890393), United Kingdom. Last updated: June 2026.

This policy explains how AutomateFlow ("we", "us") handles personal data when a dental practice uses our AI reception service, and when a patient interacts with the assistant on a practice's website or booking page. We process personal data in line with the UK GDPR and the Data Protection Act 2018.

Who is responsible for your data

When a patient uses the assistant, the dental practice is the data controller — it decides why the data is collected and is the patient's first point of contact. AutomateFlow acts as a data processor, handling that data only to provide the service to the practice. Our agreement with each practice is set out in our Data Processing Agreement.

What we collect

DataWhy
Name, phone, emailTo take an enquiry, book an appointment, and send confirmations and reminders.
What the patient types in the chatTo answer questions, book the right appointment, and pass an accurate summary to the practice.
Appointment details (treatment, time, dentist)To manage the booking diary.
Practice account details (contact, billing)To run the practice's account and take payment.

The assistant is designed not to give clinical or medical advice and to hand any health or symptom question to the practice team. Patients should not enter detailed medical information into the chat; where they do, it is treated as confidential and is only used to route the enquiry to the practice.

Lawful basis

The practice relies on its own lawful bases (typically performance of a contract and legitimate interests for handling enquiries, and the relevant health-data conditions for providing dental care). We process the data on the practice's documented instructions.

Who we share it with (sub-processors)

We use a small number of trusted providers strictly to run the service. They process data on our behalf under their own data-protection terms and do not use it for their own purposes:

ProviderPurpose
Google (Firebase / Google Cloud)Secure database and hosting of bookings and enquiries.
Google (Gemini API)Generates the assistant's replies. Data sent to the API is not used to train Google's models under the paid API terms.
StripeCard payments and deposits. We do not store card details.
TwilioOptional SMS confirmations and alerts.
Email delivery providerSending confirmations, reminders and alerts.

Some providers may process data outside the UK. Where they do, appropriate safeguards (such as the UK International Data Transfer Addendum or equivalent) are in place.

How long we keep it

We keep enquiry and booking data for as long as the practice's account is active and the practice instructs us to. If a practice closes its account, we delete or return its data within 30 days, except where we must keep records to meet a legal obligation.

Your rights

Patients can ask to access, correct, or delete their data. As these requests concern the practice's records, please contact the practice directly; we will assist them in responding. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.

Security

Data is encrypted in transit, access is restricted and authenticated, and private dashboards are protected by per-practice tokens. We keep our systems patched and review access regularly.

Contact

Questions about this policy or your data: eydan@automateflow.uk, E.A.E Enterprise Ltd, United Kingdom.