LiveLobby Ltd is committed to full compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page explains how GDPR applies to our Service, the roles of each party, and your rights as a data subject.
Under UK GDPR, data protection roles depend on context:
A DPA is automatically incorporated into your subscription agreement. It sets out:
A copy of our standard DPA is available on request at privacy@livelobby.ai.
We rely on the following lawful bases under Article 6 UK GDPR:
Where call data contains health information (special category data under Article 9), processing is conducted under Article 9(2)(h) (healthcare administration) or Article 9(2)(a) (explicit consent), relying on the dental practice as Controller.
Request a copy of the personal data we hold about you (Art. 15).
Ask us to correct inaccurate or incomplete data (Art. 16).
Request deletion of your data where no overriding legal basis applies (Art. 17).
Ask us to pause processing while a dispute is resolved (Art. 18).
Receive your data in a structured, machine-readable format (Art. 20).
Object to processing based on legitimate interests or direct marketing (Art. 21).
If you are a patient whose data was processed in a call handled by LiveLobby, please contact the dental practice directly — they are your Data Controller for that data. We will assist practices in responding to data subject requests within our 30-day SLA.
We use the following categories of sub-processors, all bound by appropriate data processing agreements:
| Category | Purpose | Location |
|---|---|---|
| Cloud infrastructure | Hosting, compute, and storage | UK / EEA |
| AI model provider | Speech recognition and language processing | UK / USA (SCCs in place) |
| Payment processor | Subscription billing | USA (SCCs in place) |
| Telephony provider | Call routing and SIP connectivity | UK |
| Email platform | Transactional emails and call summaries | EEA |
We will notify customers of any changes to sub-processors with at least 14 days' advance notice.
Where data is transferred outside the UK or EEA (e.g. to US-based AI model providers), we rely on Standard Contractual Clauses (SCCs) adopted by the UK ICO or equivalent transfer mechanisms. We conduct transfer impact assessments where required.
We implement technical and organisational measures including: TLS 1.3 in transit, AES-256 at rest, role-based access control, audit logging, annual penetration testing, and staff data protection training. We maintain an incident response plan and will notify the ICO within 72 hours of a qualifying breach.
The supervisory authority for LiveLobby Ltd is the UK Information Commissioner's Office (ICO). You have the right to lodge a complaint with the ICO at ico.org.uk if you believe your data has been handled unlawfully.
For all GDPR and data protection enquiries:
privacy@livelobby.ai
LiveLobby Ltd, England & Wales