Security and privacy by design
AIGEN is configured around the client’s approved services, questions, escalation rules and permitted data use. The system is intended to capture only the information needed to understand an enquiry and pass it securely to the appropriate team.
1. Controller and processor roles
For live calls handled for a client, the client will normally be the data controller because it decides why the caller information is needed and how the enquiry should be handled. AIGEN will normally act as a data processor, operating the service under the client’s documented instructions.
AIGEN remains a controller for its own business administration, account security, support correspondence, billing and website enquiries.
2. How call data moves through the service
- A caller rings the client’s existing number and, where configured, the call is forwarded to AIGEN.
- The automated receptionist follows the client-approved call flow and can provide an opening notice configured for the use case.
- The system captures the information required for the enquiry, such as name, callback number, reason for calling, urgency and preferred next step.
- Where enabled, the call may be recorded and transcribed.
- A summary and relevant details are stored in the client workspace and delivered to authorised staff through configured channels.
- The client’s team follows up, books, transfers or closes the enquiry.
- Data is retained or deleted according to the agreed settings and legal requirements.
3. Types of information processed
- caller name, phone number and contact preferences;
- the reason for calling and requested service;
- appointment preferences, urgency and required next action;
- call metadata, recording, transcript and summary where enabled;
- CRM status, assigned team member and follow-up history;
- technical, security and diagnostic logs.
4. Recording, transcription and caller notices
Recording and transcription can be enabled or disabled according to the client’s requirements and the capabilities of the underlying platform. The client is responsible for deciding whether recording is necessary and lawful for its use case.
AIGEN can configure an opening notice explaining that the call is handled by an automated receptionist and, where relevant, that the call may be recorded or transcribed. The final wording and lawful basis should be approved by the client.
Where a caller requests a person, the system can capture a callback request or transfer the call where a human handoff has been configured.
5. Technical and organisational measures
6. Technology providers and sub-processors
AIGEN relies on specialist providers for functions such as CRM and automation, website forms and calendars, telephony, messaging, cloud hosting, AI processing, transcription, email and technical support. HighLevel/LeadConnector is used for core CRM, booking and automation functions.
Providers are selected based on the service required and the safeguards available. Where AIGEN acts as a processor, sub-processor use and relevant contractual safeguards should be covered by the client’s data-processing terms. A current service-provider summary can be supplied during onboarding.
7. International data transfers
Some service providers may process data outside the EEA. Where a restricted transfer takes place, AIGEN and/or the relevant client rely on a recognised transfer mechanism where required, such as an adequacy decision or standard contractual clauses, together with appropriate supplementary measures where necessary.
8. Retention
There is no single retention period that is suitable for every client. AIGEN agrees a practical retention approach based on the type of business, the sensitivity of the enquiries, the need for follow-up, legal requirements and the client’s own records policy.
- Public demonstration data is normally retained for a short period.
- Live call recordings and transcripts should be kept only for as long as they are genuinely required.
- CRM enquiry records may need a different retention period from audio files.
- Security and audit records may be retained separately to investigate misuse or incidents.
9. Clinical and safety boundaries
- AIGEN is an administrative reception and enquiry-handling system, not a clinician.
- It is not intended to diagnose, prescribe, provide medical advice or replace emergency services.
- Urgency questions and escalation rules must be approved by the client.
- Where the system cannot answer confidently, it should capture the details and hand the enquiry back to the team.
- The client remains responsible for clinical decisions, appointment suitability and patient care.
10. What happens during a 14-day pilot
The pilot is configured around a limited, agreed call flow. AIGEN tests realistic scenarios before live forwarding begins, limits access to the people involved, monitors performance and adjusts the system based on approved feedback.
Before live patient or customer calls are handled, the parties should confirm the controller/processor roles, caller notice, recording choice, users, notification channels, retention and deletion process.
11. Rights requests, audits and incidents
Where AIGEN acts as processor, it assists the client within the agreed scope with data-subject requests, deletion, retrieval, security enquiries and incident investigation. The client remains responsible for responding to the individual unless the parties agree otherwise.
For a security or privacy enquiry, contact [email protected] or call 01 912 8761.
This page is a public operational summary, not a substitute for the client’s own privacy notice, lawful-basis assessment, DPIA where required, or a signed controller-processor agreement.