HomePrivacy Policy

Privacy Policy

This Privacy Policy explains how INTOUCHNOW SERVICES LIMITED (“InTouchNow AI”, “we,” “us,” “our”) collects, uses, and protects your personal information. As a company, we are committed to maintaining the privacy and security of data in compliance with applicable data protection laws. To support this commitment, InTouchNow maintains independently certified management systems, including ISO/IEC 27001 (Information Security Management), ISO 9001 (Quality Management), and ISO 22301 (Business Continuity Management), demonstrating our commitment to protecting information, delivering quality services, and ensuring operational resilience.

    Company information

        • 1.1 Company Name: INTOUCHNOW SERVICES LIMITED

        • 1.2 Company Number: 12140083

        • 1.3 Registered Address: 5 Elstree Gate, Elstree Way, Borehamwood, Hertfordshire, United Kingdom, WD6 1JD

        • 1.4 ICO registration: ZB496965

        • 1.5 Data protection contact: info@intouchnow.ai

       

      Personal data we process

          • 2.1 As a data controller (our own business activities):
                • Contact details of prospective and existing customers, suppliers and partners (name, role, practice or organisation, email, phone).

                • Website usage data (IP address, browser type, pages visited) – see Section 10.

                • Correspondence with us (emails, support tickets, meeting notes).

            • 2.2 As a data processor (on behalf of GP practice customers)

              When a patient calls a GP practice using our AI Receptionist, we process:

                  • Call audio recordings of the patient’s interaction with the AI receptionist.

                  • Transcripts generated from those recordings.

                  • Call metadata (caller phone number, call time, duration, outcome).

                  • Information the caller provides during the call, which may include name, date of birth, contact details, symptoms, medication references and appointment preferences.

             

            Lawful basis for processing

                • 3.1 Controller processing
                      • Article 6(1)(b) – performance of a contract (e.g. delivering our services to customers).

                      • Article 6(1)(f) – legitimate interests (e.g. business development, service improvement, security), balanced against your rights.

                      • Article 6(1)(c) – legal obligation (e.g. tax, accounting, regulatory).

                  • 3.2 Processor processing (patient data)

                     

                    Our GP practice customers rely on:

                        • Article 6(1)(e) – task carried out in the public interest or official authority (NHS primary care).

                        • Article 9(2)(h) – provision of health or social care.

                          We process this data only on their instructions.

                   

                  How we use personal data

                      • To provide, operate and improve the AI Receptionist service.

                      • To route calls, generate transcripts, and pass appointment requests into practice clinical systems (e.g. EMIS).

                      • To monitor quality, safety and clinical-adjacent accuracy (e.g. medication recognition).

                      • To meet legal, regulatory and NHS assurance obligations (e.g. DSPT, ISO 27001).

                      • To communicate with customers and prospects about our services.

                        We do not use patient data for advertising, and we do not train third-party public AI models on patient data.

                     

                    International data transfers

                    Where personal data is transferred outside the UK, we rely on:

                        • UK adequacy regulations, where available; or

                        • The UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses with the UK Addendum; and

                        • Supplementary technical measures including encryption in transit and at rest.

                       

                      Data retention

                          • Patient call recordings and transcripts: retained for 30 daysunless the GP practice instructs otherwise, then securely deleted.

                          • Business contact data: retained for the duration of the relationship and up to 6 years thereafter for legal and accounting purposes.

                          • Website analytics: retained for 14 months.

                            GP practices can request earlier deletion of patient data at any time under their Data Processing Agreement.

                         

                        Security

                        We maintain a formal information security programme aligned to:

                            • ISO/IEC 27001 for Information Security Management Systems

                            • NHS Data Security and Protection Toolkit (DSPT)

                            • Cyber Essentials

                              Controls include encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access controls, MFA on administrative access, audit logging, staff training, and regular penetration testing and reviews.

                           

                          Cookies and website analytics

                          Our website uses cookies for essential functionality and, with your consent, for analytics. You can manage cookie preferences via the banner on your first visit or by clearing cookies in your browser.

                           

                          Your rights

                          Under UK GDPR you have the right to:

                              • Access the personal data we hold about you.

                              • Request correction of inaccurate data.

                              • Request erasure in certain circumstances.

                              • Restrict or object to processing.

                              • Data portability.

                              • Withdraw consent where processing is based on consent.

                                To exercise any right, contact info@intouchnow.ai. We will respond within one month.

                                Note for patients: if your request relates to a call made to a GP practice, the practice is the data controller. We will either forward your request to them or assist them in responding.

                             

                            Complaints

                            If you are unhappy with how we handle your personal data, please contact us first at info@intouchnow.ai. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO):

                                • Helpline: 0303 123 1113

                               

                              Changes to this policy

                              We review this policy at least annually and update it when our practices or the law change. Material changes will be highlighted at the top of this page.

                               

                              Contact

                                  • Email: info@intouchnow.ai

                                  • Phone: 020 3929 3700

                                  • Address: 5 Elstree Gate, Elstree Way, Borehamwood, Hertfordshire, WD6 1JD