Patient Privacy Notice

Last updated on 13 Jul 2026

About this notice

This notice explains how Ufonia Limited uses information about you when you receive a call, text, or automated conversation from Dora — Ufonia's clinical assistant — as part of the care commissioned for you by the NHS. It tells you what information we hold, why we hold it, who we share it with, and the rights you have.

We take great care with your information. We handle it in line with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the common law duty of confidentiality, and the NHS Records Management Code of Practice.

Who we are

Ufonia Limited is a company registered in England and Wales (company number 10692039), based at 2nd Floor Percy House, 33 Gresse Street, London W1T 1QU.

We are registered with the Information Commissioner's Office (ICO), registration ZA563562.

Dora is a UKCA-marked Class I medical device registered with the Medicines and Healthcare products Regulatory Agency (MHRA).

Our clinical service is registered with the Care Quality Commission (CQC).

We publish our annual submission to the NHS Data Security and Protection Toolkit (Organisation Code 8KH36).

We hold Cyber Essentials Plus certification. We also use appropriate technical and organisational measures to protect your information. These include encryption, secure access controls, audit logging, staff training, regular security testing and monitoring to help keep your information secure.

Ufonia Limited is an independent data controller for the personal information it processes through the service. The NHS organisations involved in your care, such as your hospital or treatment provider, are also independent data controllers for the personal information they hold. We share relevant information with each other where this is necessary to provide your care, fulfil our respective legal and regulatory obligations, and ensure the safe operation of the Dora service. That means Ufonia decides how and why your information is used, and is legally responsible for keeping it safe.

About Dora

Dora is an automated clinical assistant that holds telephone conversations with patients, usually before or after a procedure, to check your status, gather clinical information, and alert your clinical team if needed. NHS Trusts and independent providers commissioned by the NHS use Dora, mainly along cataract pathways. Dora uses artificial intelligence to conduct conversations and identify information relevant to your care. Dora does not make solely automated decisions; rather provides information to the hospital services making treatment decisions and diagnoses.

What information we use

We use the following types of information about you:

  • Basic details — your name, date of birth, NHS number, medical record number, phone number, and postcode. Your NHS number helps us make sure we identify the correct patient and safely match information to your healthcare record.
  • Clinical information — the specialty, condition or procedure you are being seen for, the pathway you are on, and the date of your procedure.
  • The conversation itself — the audio recording of your call with Dora, a written transcript, and the structured summary of what you told us. Recording conversations allows us to maintain an accurate clinical record, investigate patient safety concerns, improve the quality of the service and meet our regulatory obligations as a medical device manufacturer.

We do not use your information for advertising, we do not sell your information, and we do not share your information with anyone for their commercial purposes.

Where your information comes from

Your basic and clinical information comes from the organisations involved in your NHS care, which may include:

  • The NHS Trust or independent provider treating you (for example, the hospital where you had your cataract surgery);
  • The clinician who referred you into the pathway — for example, your GP or optometrist;
  • A Single Point of Access service or shared referral system operated by the NHS in your area.

We only receive the information that is necessary to provide the Dora service and support your care.

Why we use your information

We use your information for the following purposes:

  • To provide your care. So that Dora can call you, ask you the right clinical questions, and pass the answers back to the clinical team looking after you.
  • For patient safety and follow-up. Where a patient's answers indicate follow-up is needed, this is carried out by the clinical team at the NHS Trust or independent provider treating you. In addition our own CQC-registered, nurse-led clinical team may review conversations and carries out follow-up calls where a patient's answers indicate this is needed.
  • For quality assurance and staff training. Authorised members of our trained quality assurance team review relevant conversations to monitor the quality and safety of the Dora service, investigate issues where necessary and help us improve our service.
  • To meet our legal, regulatory and clinical safety obligations. As a medical device manufacturer and regulated healthcare provider, we are required to monitor how Dora performs, investigate incidents where appropriate and continually improve patient safety. This helps us comply with our obligations to organisations such as the MHRA, CQC, NHS England, the ICO and, where required, the courts or other public authorities.
  • To improve the service — for example, to understand how well Dora is working across the NHS. Wherever possible, we use anonymous information that no longer identifies individual patients. Where this is not possible, we only use the minimum personal information necessary and apply appropriate safeguards including pseudonymisation to protect your data.

Our lawful basis for using your information

We rely on the following legal grounds under the UK GDPR:

  • UK GDPR Article 6(1)(e) — the use of your information is necessary for a task carried out in the public interest, being the provision of NHS-commissioned healthcare.
  • UK GDPR Article 9(2)(h) — the use of your information is necessary for the provision of health or social care or treatment.
  • The common law duty of confidentiality — we rely on implied consent for the use of your information as part of your direct care, on the basis that you would reasonably expect the healthcare team looking after you to use it in this way.

The National Data Opt-Out

The National Data Opt-Out allows you to choose whether your confidential patient information can be used for planning and research purposes beyond your individual care. It does not apply to the use of your information for your own direct care.

Because Ufonia uses your information to provide direct care, and only uses fully anonymised information for service improvement, the National Data Opt-Out does not restrict the way Ufonia uses your information. You can find out more, and change your choice, at nhs.uk/your-nhs-data-matters.

Who we share your information with

We share your information with:

  • The NHS Trust or provider treating you — we return a conversation summary and any clinical flags to them so that your clinical team can act on it and update your medical record. They are the controller of your primary clinical record.
  • Other health and care organisations — where it is necessary for your care (for example, if a different Trust or provider takes over your care under NHS-commissioned pathways such as a Single Point of Access).
  • Our technical suppliers ("sub-processors") — organisations that host or process information on our behalf under strict contractual controls. Examples include cloud infrastructure providers (such as Amazon Web Services and Google Cloud Platform), speech-to-text and voice services (such as Deepgram, ElevenLabs, and Microsoft Azure), telephony and SMS providers (such as Vonage and FireText), and monitoring tools (such as Sentry). Our full and up-to-date sub-processor register is available at ufonia.com/uk/privacy/sub-processors.
  • Regulators and safeguarding bodies — where we are required to by law, or where we need to raise a safeguarding concern about you or someone else.

We do not share your information with anyone else without a lawful reason.

International transfers

Some of our technical suppliers are based outside the United Kingdom. Where your information is transferred outside the UK, we use protections recognised by UK data protection law — such as the UK's International Data Transfer Agreement or Standard Contractual Clauses with the UK addendum. Where required, we carry out transfer risk assessments and implement supplementary safeguards where appropriate.

How long we keep your information

We normally keep your information for eight years from your last contact with the service, in line with the NHS Records Management Code of Practice. In some circumstances we may keep some information for longer where it is required by law, or where it is needed for clinical/patient safety, medical device surveillance, or the exercise or defence of a legal claim.

After the retention period ends, we securely destroy or fully anonymise your information.

Your rights

You have the following rights over your personal information under UK GDPR:

  • The right to be informed — this notice tells you how we use your information.
  • The right of access — you can ask us for a copy of the information we hold about you.
  • The right to rectification — you can ask us to correct information that is wrong or incomplete.
  • The right to erasure — you can ask us to delete your information in certain circumstances. This right is limited where we are required by law to keep records, or where we need the information to defend a legal claim.
  • The right to restrict processing — you can ask us to pause using your information while an issue is resolved.
  • The right to object — you can object to us using your information for particular purposes.
  • Rights in relation to automated decision-making. Dora uses automated technology to have conversations with patients and collect information about their health. Dora does not make decisions about your care or treatment on its own, and Ufonia does not make decisions based solely on automated processing that produce legal or similarly significant effects. Clinical decisions are made by appropriately qualified healthcare professionals, including your treating NHS clinical team and, where appropriate, Ufonia's CQC-registered clinical team.

To exercise any of these rights, contact us using the details below. We will normally respond within one calendar month.

How to contact us

Data Protection Officer

  • Name: Trust Keith
  • Email: DPO@ufonia.com
  • Post: Data Protection Officer, Ufonia Limited, 2nd Floor Percy House, 33 Gresse Street, London W1T 1QU

For general questions about Dora that are not about your data, please contact the NHS Trust or provider treating you in the first instance.

How to complain

If you are unhappy with how we have handled your personal information, please contact our DPO first at DPO@ufonia.com and we will do our best to put it right.

You also have the right to complain to the Information Commissioner's Office (ICO):

  • Website: ico.org.uk/make-a-complaint
  • Phone: 0303 123 1113
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF