Back to home

Security or privacy questions? privacy@replyintelligencegroup.co.uk

Security & Trust Centre

Protecting practice and patient data

ReplyOS is designed for UK dental and aesthetics practices handling patient enquiries. This page summarises how we protect data. For contractual detail, see our Data Processing Addendum and Privacy Policy.

At a glance

In transit

TLS (HTTPS)

Encrypted connections to ReplyOS

UK GDPR

Processor

Your practice stays the controller

Access

RBAC

Role-based permissions and audit trail

At rest

Hosted

Cloud provider disk encryption

We do not sell patient or practice data. Your practice remains the data controller for enquiry data; ReplyOS processes it only to deliver the service.

Data protection

Patient and enquiry data is handled securely and in line with UK GDPR requirements.

  • ReplyOS acts as a data processor — your practice remains in full control
  • Secure infrastructure with encrypted data transmission
  • Role-based access and audit tracking
  • No data is ever sold or used outside your control

Encryption & transport

All data in transit is encrypted using industry-standard TLS (HTTPS). Data at rest is protected by our cloud hosting provider's disk encryption (typically AES-256). ReplyOS does not claim separate application-level encryption of every database field — we continue to strengthen controls as the platform matures.

Infrastructure security

ReplyOS is hosted on secure cloud infrastructure with:

  • Redundant backups and disaster recovery
  • DDoS protection
  • Monitoring and intrusion detection
  • Regular security review and targeted testing

Access control

We implement strict access controls including:

  • Role-based access control (RBAC)
  • Multi-factor authentication (MFA)
  • Comprehensive audit logging
  • Session management and timeout policies

Compliance standards

ReplyOS is designed to support practices operating under:

  • UK GDPR and the Data Protection Act 2018
  • CQC information governance expectations
  • Industry best practices for healthcare-adjacent communication data

We do not display unofficial “GDPR certified” badges — there is no UK GDPR certification scheme. Formal certifications (e.g. Cyber Essentials) may be pursued as the platform scales.

Subprocessors

We use trusted providers to deliver hosting, messaging, billing, and AI-assisted features. All are bound by appropriate data protection terms as described in our DPA.

ProviderPurpose
SupabaseDatabase, authentication, and serverless infrastructure
VercelApplication hosting and edge delivery
TwilioSMS and telephony messaging
StripeSubscription billing and payments
MetaWhatsApp and Messenger (when connected by your practice)
AI providersAssisted replies and workflow features (where enabled)

Customer-connected integrations (e.g. CRM or PMS tools you enable) are controlled by your practice and governed by your agreements with those providers.

Data retention & deletion

We retain data only as long as needed to provide the service, meet legal obligations, and support secure deletion after contract end. Specific retention may depend on your configuration and agreement — contact us for practice-specific questions.

Data breach response

In the unlikely event of a personal data breach affecting our processing, we will:

  • Notify affected customers without undue delay where required
  • Provide incident detail to support your regulatory obligations
  • Assist with ICO notification where applicable and agreed
  • Implement remediation and preventive measures

Your responsibility

ReplyOS supports — but does not replace — your compliance processes. Your practice remains responsible for:

  • Obtaining valid consent and lawful basis where required
  • Managing data subject access requests for patient data
  • Internal information governance and staff training
  • Configuring integrations and channel permissions appropriately

Security & privacy FAQ

Is ReplyOS GDPR compliant?
ReplyOS is designed for UK GDPR-aligned processing. Your practice remains the data controller for patient enquiry data; ReplyOS acts as a data processor under a signed Data Processing Addendum. See https://www.replyos.co.uk/security for full detail.
Where is patient data stored?
ReplyOS is hosted on secure cloud infrastructure with encrypted data in transit (TLS) and provider-level encryption at rest. Subprocessor detail is published on the Security & Trust Centre at https://www.replyos.co.uk/security.
Does ReplyOS sell patient data?
No. ReplyOS does not sell patient or practice data. Data is processed only to deliver the service you configure for your practice.
What access controls does ReplyOS use?
ReplyOS implements role-based access control (RBAC), multi-factor authentication (MFA), session management, and audit logging so only authorised staff can access practice data.

Questions

For security questionnaires, DPA copies, or compliance discussions: hello@replyos.co.uk