← ReceptionistAI

Privacy Policy

Last updated 8 September 2026 · Applies to receptionistai.health and the AI reception service

Plain-English summary. If you are a patient calling a dental practice that uses this service, your call is answered by an automated system acting for that practice. What you say is used to book, reschedule or triage your call, and to create a record the practice can see. The practice — not us — decides how long that record is kept and who at the practice sees it. We do not sell anything about you to anyone, ever, and we do not use your call to train AI models.

1. Who we are

The service is operated by Laiba Hamayl, trading as ReceptionistAI, of Mansehra, Khyber Pakhtunkhwa, Pakistan. Contact: privacy@receptionistai.health.

Our role, stated precisely

When a dental practice uses this service, the practice is the controller of patient information and we are its processor. Under US health privacy law the equivalent terms are covered entity and Business Associate. We handle patient information only on the practice's documented instructions.

On HIPAA, honestly. There is no such thing as being "HIPAA certified", and we do not claim to be. What is true and verifiable is this: the service is designed to operate as a Business Associate, and we will execute a Business Associate Agreement with any practice before real patient calls reach the system. As of the date at the top of this page, none of the subprocessors listed in section 6 has executed a BAA with us yet — that table is kept current and states the position for each one. No practice should route live patient calls to the service until every subprocessor in that chain is covered. We would rather lose the sale than mislead you on this point.

2. Information we handle

CategoryExamplesWhy
Caller identity Name, phone number, date of birth where the practice asks for it To identify an existing patient and attach the booking to the right record
Call content Audio, and a written transcript of what was said To carry out the request, and so the practice can review what happened
Reason for calling Symptoms described, appointment type requested To triage urgency and book the correct appointment length
Triage records Which warning signs were detected and what the caller was told Safety. These are kept as an audit record for seven years — see section 4
Practice information Hours, services, staff names, calendar availability To answer accurately. This is not patient information
Website visitors Page requests and approximate location, from server logs Security and basic traffic counts. The site sets no advertising or analytics cookies

Some of what a caller says will be health information. That is unavoidable in a dental context — the reason for the call is usually clinical. It is treated accordingly.

3. What we never do

4. Call recording, and the part that is your decision

The service can record calls and can produce written transcripts. Whether recording is switched on is controlled by the practice.

Practices must decide this before going live. Consent to record a phone call is governed by state law, and states differ: some require only one party to consent, others require all parties. This is a legal question specific to where your practice operates, and we are not able to answer it for you. Where recording is enabled, the system can play a spoken disclosure at the start of the call. We recommend it everywhere and require it where all-party consent applies.

Emergency triage records are different

Where the system identifies a potential emergency, it writes an audit entry retained for seven years — what the caller said, which warning signs were detected, what they were told, and when. These entries are not deleted on request, because their purpose is to evidence that a caller in danger was told to seek care. This is a deliberate exception to the deletion rights in section 8, and it exists to protect callers and practices alike.

5. How long we keep it

WhatKept for
Call transcripts and recordings90 days by default, then redacted automatically. A practice may set a different window, subject to a 7-day minimum.
Appointment and patient recordsFor as long as the practice remains a client, then returned or deleted at the practice's direction
Emergency triage audit entries7 years (2,555 days) — see section 4
Website server logsShort-term, for security purposes only

6. Who else processes the information

We use the following subprocessors. Each receives only what it needs to perform its function. Retell runs the whole speech pipeline, so the speech-to-text, language and speech-generation vendors it uses in turn sit under its agreement rather than contracting with us directly.

SubprocessorFunctionBAA status
RetellTelephony, converting the caller's speech to text, understanding and generating the conversation, and generating the spoken replyNot yet signed
TelnyxAppointment confirmations and reminders by textNot yet signed
RenderRunning the applicationNot yet signed
NeonStoring appointment and call recordsNot yet signed

Where the information goes

Our infrastructure is located in the United States. The service is operated from Pakistan, which means personal information — including call audio and transcripts — may be accessed from outside the country where the practice and its patients are located. We state this plainly rather than bury it, because a practice is entitled to decide whether it is acceptable before any patient calls are routed, not after.

Where that transfer requires a safeguard, we rely on the Business Associate Agreement executed with the practice, which binds us to the same obligations over that information wherever it is accessed from. A practice with patients in the EEA or the UK should tell us before signing, because those regimes require an additional transfer mechanism that would have to be put in place first. A practice that requires all processing and access to remain within a single jurisdiction should also tell us before signing, because that is a configuration decision and not always possible.

7. How it is protected

No system is perfectly secure. If a breach affects a practice's patient information we will notify that practice without undue delay and within the timeframe our agreement with them requires.

8. Rights over the information

Patients should contact their dental practice, not us. The practice holds the relationship and the record, and it decides these requests; we act on its instruction. If you contact us directly we will pass your request to the practice and tell you we have done so.

Depending on where you live, those rights may include access to a copy, correction, deletion, restriction, portability, and objection to certain processing — and the right to complain to a regulator. Exercising them will not cause you to be treated differently. The one exception is the emergency triage audit record described in section 4.

9. Children

Dental practices treat children, so the service will handle information about minors when a parent or guardian calls to arrange care. It is not directed at children and does not knowingly collect information directly from a child.

10. Changes

Material changes will be notified to practices in advance of taking effect. The date at the top of this page always reflects the current version.

11. Contact

Privacy questions: privacy@receptionistai.health
Security reports and BAA requests: security@receptionistai.health
Postal: Mansehra, Khyber Pakhtunkhwa, Pakistan