Privacy Policy
This policy explains what personal data Wren collects, why we collect it, how we protect it, and the rights you have over it — whether you're a clinic owner, a website visitor, or a patient who has called a clinic that uses Wren.
1Who we are
Wren is an AI voice receptionist for healthcare and wellness clinics that use Cliniko and Jane App. Wren answers inbound calls, books and manages appointments, and takes messages on a clinic's behalf.
The Wren service and the website at wrenaivoice.com are operated by [Legal Entity Name], a company registered in [Ireland] under company number [Registration No.], with its registered office at [Registered Address] ("Wren", "we", "us", "our").
For any privacy question, or to exercise your rights, contact us at [email protected].
2Two roles: when we're a "controller" and when we're a "processor"
Data-protection law (including the EU and UK GDPR) treats us differently depending on whose data we're handling and why. This distinction runs through the whole policy, so it's worth stating up front.
| We are the controller | For data about clinic owners and staff who buy or enquire about Wren, and about visitors to our website — e.g. your name, email, the questions you send us, and workshop sign-ups. Here, we decide how the data is used, and this policy governs it. |
|---|---|
| We are a processor | For personal data about a clinic's patients and callers that Wren handles while answering that clinic's calls — e.g. call audio, transcripts, and appointment details. Here, the clinic is the controller: it decides the purposes, and we act only on its documented instructions under a Data Processing Agreement (DPA). |
3The data we collect
a. Information you give us (we are controller)
- Enquiry & contact details — your name, email address, phone number (if you provide one), clinic name, and the content of any question or message you send through our forms.
- Workshop registrations — the details you submit to register interest in a workshop or waitlist.
- Account & billing details — if you become a customer: business details, the plan you choose, and billing information. Card payments are handled by our payment provider; we do not store full card numbers.
- Consent choices — whether you opted in to SMS updates and/or marketing emails, and when.
b. Patient & caller data we handle for clinics (we are processor)
- Call content — audio of the call, a transcript, and any details a caller gives (such as their name, phone number, the reason for calling, and appointment preferences).
- Appointment data — bookings, reschedules, and cancellations written to the clinic's Cliniko or Jane App calendar.
- Health-related context — a caller may mention health information (a "special category" of data). We process it only to carry out the clinic's instruction — for example, to book the right appointment — never for our own purposes.
c. Information we collect automatically
- Usage & device data — pages viewed, approximate location (from IP), browser and device type, and referring links, collected when you visit our website.
- Cookies & similar technologies — see section 7.
d. Information from third parties
- Integration data — where a clinic connects Wren to Cliniko or Jane App, we receive the calendar and availability data needed to book appointments, under that clinic's authorisation.
- Telephony metadata — call routing information (such as caller ID and call times) from the telephony providers that carry the calls.
4How we use data — and our legal basis
Where we are the controller, we rely on one of the following legal bases under Article 6 of the GDPR for each use:
| What we do | Legal basis |
|---|---|
| Respond to your enquiry and record a video answer to your question | Our legitimate interest in answering prospective customers (and, for any phone contact, your consent) |
| Provide, operate, and support the Wren service you've bought | Performance of our contract with you |
| Take payment and keep accounting records | Contract, and our legal obligation to keep financial records |
| Send you SMS reminders or marketing emails | Your consent (which you can withdraw at any time) |
| Improve, secure, and troubleshoot our website and service | Our legitimate interest in running a safe, reliable service |
| Comply with law and respond to lawful requests | Our legal obligations |
Where we act as a processor for a clinic, our legal basis for handling patient data is the clinic's instruction under our DPA; the clinic is responsible for having its own lawful basis and for giving patients the required privacy information.
5Calls, recording, and AI processing
Wren is an automated, AI-powered receptionist. When it answers a call it may record the audio, convert it to text, and use automated language models to understand the request and take the right action (such as booking an appointment or taking a message).
- Recording notice is the clinic's responsibility. The clinic decides its greeting and is responsible for telling callers that the call may be recorded and handled by an automated assistant, and for obtaining consent where the law requires it.
- No automated decisions with legal effect. Wren schedules and routes calls; it does not make decisions that produce legal or similarly significant effects about a caller within the meaning of Article 22 GDPR.
- Model providers. The AI language and speech providers we use process call content solely to deliver the service and, under our agreements, are not permitted to use clinic or patient data to train their general models.
6SMS and email marketing
We only send you text messages or marketing emails if you have opted in. These consents are separate, optional, and never bundled into agreeing to our terms — you can use our forms and become a customer without ticking either.
- SMS. If you opt in to texts, message and data rates may apply and frequency varies. You can stop at any time by replying STOP; reply HELP for help. We manage SMS consent in line with carrier and A2P 10DLC requirements.
- Email. Every marketing email has an unsubscribe link. Unsubscribing stops marketing email but not essential service messages (such as billing or security notices) while you remain a customer.
- Withdrawing consent does not affect the lawfulness of anything we did before you withdrew it.
9International data transfers
Some of our providers may process data outside your country, including outside the EEA or UK. Where they do, we put in place a lawful transfer mechanism — such as the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant) — together with any additional safeguards needed to protect your data to an equivalent standard. You can ask us for details of these safeguards.
10How long we keep data
We keep personal data only as long as we need it for the purpose we collected it, or as the law requires.
- Enquiries and leads — kept while we're in contact and for a reasonable period afterwards, then deleted or anonymised. [Confirm your retention period, e.g. 24 months.]
- Customer & billing records — kept for the life of the contract and then for the period required by tax and accounting law.
- Call recordings and transcripts — retained on behalf of the clinic for the period set in its configuration or DPA, then deleted. The clinic sets this retention. [Confirm the default retention window.]
11How we protect data
We use appropriate technical and organisational measures to protect personal data, including encryption of data in transit and at rest, access controls on a need-to-know basis, and vendor due diligence. No system can be guaranteed perfectly secure, but we work to protect your data and, where the law requires, we will notify you and the relevant authority of a qualifying data breach without undue delay.
12Your rights
Subject to the conditions in the law, you have the right to:
- Access the personal data we hold about you;
- Rectify data that is inaccurate or incomplete;
- Erase your data ("right to be forgotten") in certain circumstances;
- Restrict or object to our processing, including direct marketing;
- Portability — receive certain data in a portable format;
- Withdraw consent at any time, where we rely on consent;
- Complain to a supervisory authority.
To exercise any of these, email [email protected]. We'll respond within the time the law allows (usually one month). If your request relates to data we process for a clinic, we'll direct you to that clinic as the controller, or help them respond.
If you are in the EU, you can complain to your local Data Protection Authority; in Ireland this is the Data Protection Commission. If you are in the UK, this is the Information Commissioner's Office. [Confirm your lead supervisory authority.]
13Children's data
Our website and marketing are directed at clinic owners, not children. Wren may, however, handle appointment details for patients of any age when acting for a clinic — for example, a parent booking for a child. In that case the clinic is the controller and is responsible for the lawful basis and any parental consent required. We do not knowingly collect data directly from children through our own website.
14Changes to this policy
We may update this policy from time to time. When we make material changes, we'll update the "last updated" date above and, where appropriate, tell you directly. Please check back periodically.
15Contact us
Questions, requests, or concerns about privacy? We're glad to help.
- Email: [email protected]
- Post: [Legal Entity Name, Registered Address]
- Data Protection contact: [Name / role, if you appoint a DPO or privacy lead]