The companies we work with

Last updated on 9 Jul 2026

Why this page exists

When you have a conversation with Dora, Ufonia relies on a small number of specialist companies to help us run the service safely. We call these sub-processors — companies that handle some of your information on our behalf, under strict written agreements.

We publish this page so you can see, at a glance, who those companies are, what they do for us, and how your information is protected when it passes through them.

Our commitment

We assess sub-processors against Ufonia's security and confidentiality standards through our supplier governance process. For most vendors, this means reviewing their published security documentation, certifications, and terms of service before we engage them. Where a bespoke due-diligence review is possible, we do one.

Each sub-processor is bound by written data-protection terms with Ufonia. For some vendors this is a bespoke Data Processing Agreement; for most, it is the vendor's published data-protection terms or their Standard Terms and Conditions, which we accept when we engage the service. These terms are designed to reflect UK data protection law requirements.

Where our sub-processors process information outside the UK, we rely on UK-recognised transfer safeguards — most commonly the UK International Data Transfer Agreement or Standard Contractual Clauses with the UK addendum. For most vendors, these safeguards form part of their published data-protection terms which Ufonia accepts as a customer. Where a transfer is significant, we also carry out a transfer risk assessment.

We review this list at least every six months, and we update it whenever we add, remove, or materially change how we use a company.

Ufonia remains fully responsible to you for how these companies handle your information.

Companies that handle patient information

These companies process information about patients as part of the Dora service. This includes things like your name, phone number, NHS number, and the content of your conversation with Dora.

CompanyWhat they do for usWhere your information is processedProtections in place
Amazon Web Services (AWS)Cloud infrastructure and storage; some AI language processing during your conversation with Dora; sending emails.Mostly UK. Some real-time AI processing takes place in the USA (the specific AI model we use is not yet available in the UK).UK data storage as default. Standard UK data-protection safeguards for any US processing (see below).
Google (Google Cloud Platform)Cloud infrastructure and storage; speech-to-text, text-to-speech, and translation; conversation AI; email delivery.Mostly UK / EEA. Some conversation AI processing may route to the USA depending on availability.Standard UK data-protection safeguards.
MicrosoftAzure speech-to-text and text-to-speech; conversation AI (used only offline to check Dora is safe — not during live patient calls).UK / EEA.Standard UK data-protection safeguards.
DeepgramSpeech-to-text — turning what you say to Dora into a written transcript.EEA.Standard UK data-protection safeguards.
ElevenLabsVoice synthesis — creating Dora's voice.USA.Standard UK data-protection safeguards.
VonageMaking and receiving the phone calls with Dora, and sending SMS notifications.EEA.Standard UK data-protection safeguards.
FireTextSending SMS notifications to patients (using the "NHSNoReply" sender ID).UK.UK-based, no international transfer required.
EgressEncrypted email and secure file sharing.UK.UK-based, no international transfer required.

How your information is protected when it goes outside the UK

Some of the companies above are based outside the UK. When your information leaves the country, we rely on the safeguards that UK data-protection law recognises — most commonly the UK International Data Transfer Agreement or Standard Contractual Clauses with the UK's specific addendum. In plain terms, these are written commitments that require the receiving company to protect your information to the same standard as if it stayed in the UK. For most of our vendors these safeguards form part of their standard published data-protection terms, which Ufonia accepts as a customer. Where a transfer is significant, we also carry out a written check ("Transfer Risk Assessment") to check the safeguards are effective.

Changes to this list

We update this page whenever we add, remove, or materially change how we use a sub-processor. If a change materially affects how your information is processed, we'll also update the patient privacy notice.

Questions and complaints

If you have questions about any of the companies on this page, or you'd like more detail on the protections in place, please contact:

  • Email: DPO@ufonia.com
  • Post: Data Protection Officer, Ufonia Limited, 2nd Floor Percy House, 33 Gresse Street, London W1T 1QU

You also have the right to complain to the Information Commissioner's Office at any time — details are in our patient privacy notice.