Security or privacy questions? privacy@replyintelligencegroup.co.uk
Security & Trust Centre
Protecting practice and patient data
ReplyOS is designed for UK dental and aesthetics practices handling patient enquiries. This page summarises how we protect data. For contractual detail, see our Data Processing Addendum and Privacy Policy.
Privacy Policy
How ReplyOS collects and uses account, billing, and service data.
Data Processing Addendum
Processor terms for patient and enquiry data handled on your behalf.
Terms of Service
Commercial terms for using the ReplyOS platform.
Cookie policy
How we use cookies and similar technologies on the marketing site.
At a glance
In transit
TLS (HTTPS)
Encrypted connections to ReplyOS
UK GDPR
Processor
Your practice stays the controller
Access
RBAC
Role-based permissions and audit trail
At rest
Hosted
Cloud provider disk encryption
We do not sell patient or practice data. Your practice remains the data controller for enquiry data; ReplyOS processes it only to deliver the service.
Data protection
Patient and enquiry data is handled securely and in line with UK GDPR requirements.
- ReplyOS acts as a data processor — your practice remains in full control
- Secure infrastructure with encrypted data transmission
- Role-based access and audit tracking
- No data is ever sold or used outside your control
Encryption & transport
All data in transit is encrypted using industry-standard TLS (HTTPS). Data at rest is protected by our cloud hosting provider's disk encryption (typically AES-256). ReplyOS does not claim separate application-level encryption of every database field — we continue to strengthen controls as the platform matures.
Infrastructure security
ReplyOS is hosted on secure cloud infrastructure with:
- Redundant backups and disaster recovery
- DDoS protection
- Monitoring and intrusion detection
- Regular security review and targeted testing
Access control
We implement strict access controls including:
- Role-based access control (RBAC)
- Multi-factor authentication (MFA)
- Comprehensive audit logging
- Session management and timeout policies
Compliance standards
ReplyOS is designed to support practices operating under:
- UK GDPR and the Data Protection Act 2018
- CQC information governance expectations
- Industry best practices for healthcare-adjacent communication data
We do not display unofficial “GDPR certified” badges — there is no UK GDPR certification scheme. Formal certifications (e.g. Cyber Essentials) may be pursued as the platform scales.
Subprocessors
We use trusted providers to deliver hosting, messaging, billing, and AI-assisted features. All are bound by appropriate data protection terms as described in our DPA.
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication, and serverless infrastructure |
| Vercel | Application hosting and edge delivery |
| Twilio | SMS and telephony messaging |
| Stripe | Subscription billing and payments |
| Meta | WhatsApp and Messenger (when connected by your practice) |
| AI providers | Assisted replies and workflow features (where enabled) |
Customer-connected integrations (e.g. CRM or PMS tools you enable) are controlled by your practice and governed by your agreements with those providers.
Data retention & deletion
We retain data only as long as needed to provide the service, meet legal obligations, and support secure deletion after contract end. Specific retention may depend on your configuration and agreement — contact us for practice-specific questions.
Data breach response
In the unlikely event of a personal data breach affecting our processing, we will:
- Notify affected customers without undue delay where required
- Provide incident detail to support your regulatory obligations
- Assist with ICO notification where applicable and agreed
- Implement remediation and preventive measures
Your responsibility
ReplyOS supports — but does not replace — your compliance processes. Your practice remains responsible for:
- Obtaining valid consent and lawful basis where required
- Managing data subject access requests for patient data
- Internal information governance and staff training
- Configuring integrations and channel permissions appropriately
Security & privacy FAQ
- Is ReplyOS GDPR compliant?
- ReplyOS is designed for UK GDPR-aligned processing. Your practice remains the data controller for patient enquiry data; ReplyOS acts as a data processor under a signed Data Processing Addendum. See https://www.replyos.co.uk/security for full detail.
- Where is patient data stored?
- ReplyOS is hosted on secure cloud infrastructure with encrypted data in transit (TLS) and provider-level encryption at rest. Subprocessor detail is published on the Security & Trust Centre at https://www.replyos.co.uk/security.
- Does ReplyOS sell patient data?
- No. ReplyOS does not sell patient or practice data. Data is processed only to deliver the service you configure for your practice.
- What access controls does ReplyOS use?
- ReplyOS implements role-based access control (RBAC), multi-factor authentication (MFA), session management, and audit logging so only authorised staff can access practice data.
Questions
For security questionnaires, DPA copies, or compliance discussions: hello@replyos.co.uk