GDPR & Compliance

How Recareo handles patient data in compliance with UK GDPR

Short version: Recareo only handles patient data after a DPA is signed. The practice remains responsible for confirming the lawful basis, opt-out status, and patient-list suitability.

Legal basis for calls

Patient recall may be handled under legitimate interest (UK GDPR Article 6(1)(f)) where the practice has an existing patient relationship and no opt-out applies. The practice decides the lawful basis and confirms this before any list is shared.

Roles & responsibilities

  • Your practice = Data Controller. You determine which patients to contact and for what purpose.
  • Recareo = Data Processor. We process data only on your documented instructions.
  • We sign a Data Processing Agreement (DPA) with every client before any data is shared.

What we do with the data

  • We use patient name and phone number only to make recall calls
  • Calls are identified as being from your practice by name
  • Patients who opt out are flagged and never called again
  • Data is deleted within 30 days of campaign completion
  • We do not sell, share, or use patient data for any other purpose

Ofcom compliance

Recareo’s AI agents are configured to disclose they are AI-assisted when directly asked, in accordance with Ofcom guidance on AI calling services.

Sub-processors

We use Retell AI Inc. (USA) as our voice infrastructure provider. Data transfers to the US are covered by Standard Contractual Clauses (SCCs) as approved by the ICO.

Questions?

Email yegor@recareo.uk — we respond within 1 business day.