Skip to main content

Security or privacy questions? privacy@replyintelligencegroup.co.uk

Security & Trust Centre

Protecting practice and patient data

ReplyOS is designed for UK dental and aesthetics practices handling patient enquiries. The contracting party is Reply Intelligence Group Ltd (Company No. 17040048), registered office Flat 14, 2, Stewart Court, Colnhurst Road, Watford, United Kingdom, WD17 4BW. This page summarises how we protect data. For contractual detail, see our Data Processing Addendum and Privacy Policy.

At a glance

In transit

TLS (HTTPS)

Encrypted connections to ReplyOS

UK GDPR

Processor

Your practice stays the controller

ICO

ZC192287

Reply Intelligence Group Ltd

Access

RBAC

Role-based permissions and audit trail

At rest

Hosted

Cloud provider disk encryption

We do not sell patient or practice data. Your practice remains the data controller for enquiry data; ReplyOS processes it only to deliver the service.

Data protection

Patient and enquiry data is handled securely and in line with UK GDPR requirements.

  • ReplyOS acts as a data processor. Your practice remains in full control.
  • Secure infrastructure with encrypted data transmission
  • Role-based access and audit tracking
  • No data is ever sold or used outside your control

Encryption & transport

All data in transit is encrypted using industry-standard TLS (HTTPS). Data at rest is protected by our cloud hosting provider's disk encryption (typically AES-256). ReplyOS does not claim separate application-level encryption of every database field. We continue to strengthen controls as the platform matures.

Infrastructure security

ReplyOS is hosted on secure cloud infrastructure with:

  • Redundant backups and disaster recovery
  • DDoS protection
  • Monitoring and intrusion detection
  • Regular security review and targeted testing

Access control

We implement strict access controls including:

  • Role-based access control (RBAC)
  • Comprehensive audit logging
  • Session management and timeout policies

Compliance standards

ReplyOS is designed to support practices operating under:

  • UK GDPR and the Data Protection Act 2018
  • CQC information governance expectations
  • Industry best practices for healthcare-adjacent communication data

ICO registration ZC192287 is held by Reply Intelligence Group Ltd. We do not display unofficial “GDPR certified” badges. There is no UK GDPR certification scheme. Formal certifications (e.g. Cyber Essentials) may be pursued as the platform scales.

International transfers, where they occur, are governed by the UK IDTA or the UK Addendum to the EU SCCs, as set out in our DPA.

Subprocessors

We use trusted providers to deliver hosting, messaging, billing, and AI-assisted features. All are bound by appropriate data protection terms as described in our DPA.

ProviderPurpose
SupabaseDatabase, authentication, and serverless infrastructure
VercelApplication hosting and edge delivery
TwilioSMS and telephony messaging
StripeSubscription billing and payments
ResendTransactional email delivery, including staff notification emails
MetaWhatsApp, Facebook Messenger and Instagram (when connected by your practice)
OpenAIAI-drafted reply suggestions and workflow features (where enabled); inference only, no model training

Customer-connected integrations (for example CRM or PMS tools you enable) are controlled by your practice and governed by your agreements with those providers.

Data retention & deletion

We retain data only as long as needed to provide the service, meet legal obligations, and support secure deletion after contract end. Specific retention may depend on your configuration and agreement. Contact us for practice-specific questions.

Data breach response

In the unlikely event of a personal data breach affecting our processing, we will:

  • Notify affected customers within 72 hours of becoming aware of a breach affecting their data
  • Provide incident detail to support your regulatory obligations
  • Assist with ICO notification where applicable and agreed
  • Implement remediation and preventive measures

Your responsibility

ReplyOS supports, but does not replace, your compliance processes. Your practice remains responsible for:

  • Obtaining valid consent and lawful basis where required
  • Managing data subject access requests for patient data
  • Internal information governance and staff training
  • Configuring integrations and channel permissions appropriately

Security & privacy FAQ

Is ReplyOS GDPR compliant?
ReplyOS is designed for UK GDPR-aligned processing. Your practice remains the data controller for patient enquiry data; ReplyOS acts as a data processor under a signed Data Processing Addendum. See https://www.replyos.co.uk/security for full detail.
Where is patient data stored?
ReplyOS stores practice and enquiry data with encrypted data in transit (TLS) and provider-level encryption at rest. Subprocessor detail is published on the Security & Trust Centre at https://www.replyos.co.uk/security.
Does ReplyOS sell patient data?
No. ReplyOS does not sell patient or practice data. Data is processed only to deliver the service you configure for your practice.
What access controls does ReplyOS use?
ReplyOS implements role-based access control (RBAC), session management, and audit logging so only authorised staff can access practice data.

Questions

For security questionnaires, DPA copies, or compliance discussions: hello@replyos.co.uk