UK GDPR compliance by design
Patient data handled by Agent IA Vocal is processed under a signed Data Processing Agreement that meets UK GDPR Article 28 requirements. All recordings and transcripts are encrypted, stored on infrastructure meeting UK GDPR transfer requirements, and never used for AI training. ICO-aligned data retention policies apply by default.
- ✓Signed DPA for every healthcare customer
- ✓Encryption in transit (TLS 1.3) and at rest (AES-256)
- ✓Role-based access controls with full audit log
- ✓Data retention configurable to your retention policy
- ✓No patient data used for AI model training