LiveLobby ← Back to LiveLobby.ai
Legal

GDPR & Data Processing

Effective date: 1 January 2026  ·  LiveLobby Ltd  ·  UK GDPR Compliant

LiveLobby Ltd is committed to full compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page explains how GDPR applies to our Service, the roles of each party, and your rights as a data subject.

1. Roles: Controller and Processor

Under UK GDPR, data protection roles depend on context:

  • LiveLobby as Data Controller — for personal data of our customers (practice administrators, account holders), LiveLobby determines the purposes and means of processing. This includes account information, billing data, and support communications.
  • LiveLobby as Data Processor — for patient call data handled through the Service on behalf of your practice, your practice is the Data Controller and LiveLobby processes data only on your documented instructions. A Data Processing Agreement (DPA) is available and must be in place before processing patient data.

2. Data Processing Agreement

A DPA is automatically incorporated into your subscription agreement. It sets out:

  • The subject matter, duration, nature, and purpose of processing.
  • The type of personal data and categories of data subjects.
  • Our obligations as a processor, including confidentiality and security.
  • Sub-processor authorisation and notification requirements.
  • Data subject rights assistance obligations.
  • Deletion or return of data on contract termination.

A copy of our standard DPA is available on request at privacy@livelobby.ai.

3. Legal Bases for Processing

We rely on the following lawful bases under Article 6 UK GDPR:

  • Article 6(1)(b) — Contract: processing necessary to deliver the subscribed Service.
  • Article 6(1)(c) — Legal obligation: retaining financial records as required by law.
  • Article 6(1)(f) — Legitimate interests: improving service quality, preventing fraud, and ensuring security.
  • Article 6(1)(a) — Consent: for optional marketing communications, which may be withdrawn at any time.

Where call data contains health information (special category data under Article 9), processing is conducted under Article 9(2)(h) (healthcare administration) or Article 9(2)(a) (explicit consent), relying on the dental practice as Controller.

4. Your Rights as a Data Subject

Right of Access

Request a copy of the personal data we hold about you (Art. 15).

Right to Rectification

Ask us to correct inaccurate or incomplete data (Art. 16).

Right to Erasure

Request deletion of your data where no overriding legal basis applies (Art. 17).

Right to Restrict

Ask us to pause processing while a dispute is resolved (Art. 18).

Right to Portability

Receive your data in a structured, machine-readable format (Art. 20).

Right to Object

Object to processing based on legitimate interests or direct marketing (Art. 21).

If you are a patient whose data was processed in a call handled by LiveLobby, please contact the dental practice directly — they are your Data Controller for that data. We will assist practices in responding to data subject requests within our 30-day SLA.

5. Sub-Processors

We use the following categories of sub-processors, all bound by appropriate data processing agreements:

CategoryPurposeLocation
Cloud infrastructureHosting, compute, and storageUK / EEA
AI model providerSpeech recognition and language processingUK / USA (SCCs in place)
Payment processorSubscription billingUSA (SCCs in place)
Telephony providerCall routing and SIP connectivityUK
Email platformTransactional emails and call summariesEEA

We will notify customers of any changes to sub-processors with at least 14 days' advance notice.

6. International Transfers

Where data is transferred outside the UK or EEA (e.g. to US-based AI model providers), we rely on Standard Contractual Clauses (SCCs) adopted by the UK ICO or equivalent transfer mechanisms. We conduct transfer impact assessments where required.

7. Data Retention

  • Call recordings and transcripts: 90 days by default (configurable per practice in the dashboard).
  • Account data: retained for the duration of the contract plus 7 years.
  • Anonymised analytics: retained indefinitely for service improvement.

8. Security Measures

We implement technical and organisational measures including: TLS 1.3 in transit, AES-256 at rest, role-based access control, audit logging, annual penetration testing, and staff data protection training. We maintain an incident response plan and will notify the ICO within 72 hours of a qualifying breach.

9. Supervisory Authority

The supervisory authority for LiveLobby Ltd is the UK Information Commissioner's Office (ICO). You have the right to lodge a complaint with the ICO at ico.org.uk if you believe your data has been handled unlawfully.

10. Contact Our Data Protection Contact

For all GDPR and data protection enquiries:
privacy@livelobby.ai
LiveLobby Ltd, England & Wales

© 2026 LiveLobby Ltd — Registered in England & Wales Privacy · Terms · GDPR · Status