Roch Solutions

Legal

Privacy Policy

This policy is under legal review. Items marked [TODO] are placeholders pending confirmation and will be completed before the policy is finalised.

Who we are

Roch Solutions (“we”, “us”, “our”) builds Susie, an AI telephone receptionist for physiotherapy clinics in the United Kingdom. This policy explains how we handle personal data on our website and through our service.

  • Business: Roch Solutions, [TODO: registered company name and number]
  • Registered address: [TODO: registered address]
  • Privacy contact: [TODO: privacy contact email address]
  • ICO registration: [TODO: ICO registration number]

We act in two different roles under UK data protection law, and it matters which one applies to you:

  • Data controller — for people who visit this website, make an enquiry, book a demo, or deal with us as a clinic customer. Here we decide how and why your data is used, and this policy applies directly.
  • Data processor — for patient call data we handle on a clinic’s behalf when Susie answers that clinic’s phone. The clinic is the data controller for its patients; we process call data only on the clinic’s documented instructions under a data processing agreement. Patients should read their clinic’s own privacy notice alongside this one.

What information we collect

(a) Website and business data — as controller. When you use this website or deal with us as a prospective or current customer, we may collect:

  • Your name, email address, and phone number
  • Your clinic’s name and your role there
  • Anything you send us through the enquiry or demo-booking form
  • Billing and payment records for clinic customers
  • Technical data such as IP address, browser type, and pages viewed, collected via cookies and similar technologies (see section 10)

(b) Patient call data — as processor. When Susie answers a clinic’s phone on its behalf, we process on the clinic’s instructions:

  • The caller’s name and contact details
  • The reason for the call and any message left for the clinic
  • Booking intent and appointment details
  • Call recordings and transcripts

Because callers are contacting a physiotherapy clinic, call content may include special-category health data — for example, a caller describing symptoms, pain, or an injury. We treat all call content with the safeguards that health data requires.

Call recording & AI processing

Calls answered by Susie are recorded and transcribed, and the transcript is processed by our AI so that Susie can understand the caller and respond. Callers are informed at the start of the call that they are speaking with an AI assistant and that the call is recorded. [TODO: confirm the final call-opening wording]

What the AI does:

  • Answers the phone and handles routine reception conversation
  • Captures the caller’s details, the reason for their call, and any booking request
  • Routes messages and booking requests to the clinic, and flags anything urgent for a human

What the AI does not do:

  • It never diagnoses a condition
  • It never gives clinical or medical advice
  • It never makes treatment decisions

Calls that are urgent, sensitive, or unclear are escalated to clinic staff, and a caller can ask for a human at any point. Susie captures and routes information — decisions about a patient’s care are always made by people at the clinic. We do not make any decision about you based solely on automated processing that has legal or similarly significant effects.

How we use your data & lawful bases

As a controller, we use website and business data for the following purposes, each with a lawful basis under Article 6 of the UK GDPR:

  • Responding to enquiries and demo requests — Article 6(1)(b) (steps at your request prior to entering a contract) and Article 6(1)(f) (our legitimate interest in responding to people who contact us)
  • Providing and administering the service to clinic customers — Article 6(1)(b) (performance of a contract)
  • Billing, accounting, and tax records — Article 6(1)(c) (legal obligation) and Article 6(1)(b)
  • Securing and improving the website and service — Article 6(1)(f) (our legitimate interest in running a safe, reliable service)
  • Marketing emails, where you have opted in — Article 6(1)(a) (consent), which you can withdraw at any time

For patient call data, the clinic is the controller and determines the lawful basis. For health data this will typically be Article 9(2)(h) UK GDPR (provision of health or social care), together with the corresponding condition in Schedule 1 of the Data Protection Act 2018. As processor, we do not decide these bases — we process patient call data only on the clinic’s documented instructions.

Who we share it with

We use a small number of service providers (sub-processors) to run the service. Each is bound by data-processing terms and processes data only to provide its service to us:

  • Telephony and call routing — Twilio
  • Speech-to-text transcription — [TODO: confirm provider]
  • Voice synthesis — [TODO: confirm provider]
  • AI / large-language-model provider — [TODO: confirm provider]
  • Cloud hosting — [TODO: confirm provider(s)]
  • Analytics — [TODO: confirm tooling, if any]
  • Payments — [TODO: confirm provider]

[TODO: confirm the final sub-processor list before publication]

Clinics receive call recordings, transcripts, and summaries relating to their own patients only — that is the service. We do not sell personal data, and we do not share it with anyone else unless required to by law.

International transfers

Some of our service providers may store or process data outside the United Kingdom (for example, in the United States). Where personal data leaves the UK, we will only transfer it with a recognised safeguard in place: [TODO: confirm which applies — UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses]

[TODO: confirm which providers process data outside the UK and document the safeguard for each]

Data retention

We keep personal data only as long as needed for the purposes above, then delete or anonymise it. Our intended retention periods are:

  • Enquiry and demo-request data — [TODO: retention period]
  • Call recordings — [TODO: retention period]
  • Call transcripts and summaries — [TODO: retention period]
  • Booking and appointment data — [TODO: retention period]
  • Billing and tax records — as long as required by UK law, then [TODO: retention period]

For patient call data we follow the retention periods set by each clinic as controller. When a clinic’s contract ends, its patient data is returned or deleted in line with the clinic’s instructions.

Storage & security

We take proportionate technical and organisational measures to protect personal data, including:

  • Encryption of data in transit (TLS)
  • Encryption of data at rest, where supported by our providers
  • Access controls, so data is only available to people who need it
  • Due diligence on the sub-processors listed in section 5

To be transparent: no system can be guaranteed completely secure, and we do not currently hold formal security certifications, so we do not claim any. If a breach ever put your rights at risk, we would notify affected clinics and the ICO as the law requires.

Your rights

Under the UK GDPR you have the right to:

  • Access a copy of the personal data we hold about you
  • Have inaccurate data corrected
  • Have your data erased in certain circumstances
  • Restrict how your data is processed
  • Receive your data in a portable format
  • Object to processing based on legitimate interests, and to direct marketing at any time
  • Withdraw consent, where consent is the basis we rely on
  • Not be subject to solely automated decisions with legal or similarly significant effects

To exercise any of these rights, contact us at [TODO: privacy contact email address]. We will respond within one month, and there is normally no fee.

If you called a clinic that uses Susie: your clinic is the controller of your health data, so please direct your request to the clinic. We support clinics in responding to patient rights requests.

Cookies

This website uses strictly necessary cookies and similar technologies to make the site work. These do not require consent.

Analytics: [TODO: confirm analytics tooling and the cookies it sets, if any]

Consent mechanism: [TODO: confirm the consent banner / cookie preference mechanism, or link to a separate cookie policy]

You can also block or delete cookies through your browser settings; doing so may affect how the site works.

Changes to this policy

We may update this policy as the service, our providers, or the law change. The current version is always published on this page with its “last updated” date. If a change materially affects how we handle personal data, we will notify clinic customers by email before it takes effect.

Version: 0.1 (draft) · Last updated: 17 July 2026

Contact us & complaints

Questions, requests, or concerns about this policy or your data:

  • Email: [TODO: privacy contact email address]
  • Post: [TODO: registered address]

If you are unhappy with how we have handled your data, we would like the chance to put it right first — but you also have the right to complain to the UK supervisory authority at any time:

  • Information Commissioner’s Office (ICO)
  • Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
  • Helpline: 0303 123 1113
  • ico.org.uk