Legal

Privacy Policy

Last updated: 4 June 2025

1. Who we are

RingLoop (“we”, “us”, “our”) is a software service that provides an AI voice receptionist — answering forwarded calls, booking appointments, and sending appointment reminders — for medical institutes and appointment-based businesses. Our website is ringloop.net.

For questions about this policy, contact us at hello@ringloop.net.

2. What data we collect

We collect personal data in two contexts:

  • Website visitors: When you fill in the contact or demo request form we collect your name, clinic name, email address, and phone number (if provided).
  • End-patients of our clinic clients: When a patient calls a clinic that uses RingLoop, our system may process their phone number and the content of their WhatsApp conversation (name, appointment request, preferred times). This data is processed on behalf of the clinic operator, who is the data controller for their patients.
  • Analytics: We collect standard server logs and, where you consent, anonymised usage analytics via cookies.

3. Legal basis for processing (GDPR)

  • Contract performance (Art. 6(1)(b)): Processing necessary to provide the RingLoop service to clinic clients.
  • Legitimate interests (Art. 6(1)(f)): Processing enquiry data to respond to demo requests.
  • Consent (Art. 6(1)(a)): Non-essential cookies and analytics, collected only when you accept via the cookie banner.

4. How we use your data

  • To respond to demo requests and sales enquiries.
  • To operate the AI missed-call recovery service for clinic clients.
  • To send appointment confirmation messages via WhatsApp on behalf of clinic clients.
  • To improve our product using aggregated, anonymised analytics.

We do not sell your data to any third party.

5. Third-party processors

To deliver the service we share data with the following processors, each bound by a Data Processing Agreement:

ProcessorPurposeLocation
Twilio Inc.SMS & WhatsApp messagingUSA (SCCs)
Anthropic PBCAI conversation processingUSA (SCCs)
Vercel Inc.Website & API hostingUSA (SCCs)

SCCs = EU Standard Contractual Clauses ensure GDPR-compliant transfers outside the EEA.

6. Data retention

  • Lead/enquiry data: Retained for 12 months after last contact, then deleted.
  • WhatsApp conversation data: Retained for the duration of the clinic's subscription plus 30 days, then deleted.
  • Server logs: Retained for 90 days.

7. Your rights under GDPR

If you are in the EEA or UK you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate personal data.
  • Request erasure (“right to be forgotten”).
  • Restrict or object to processing.
  • Data portability.
  • Withdraw consent at any time (without affecting prior processing).
  • Lodge a complaint with your local supervisory authority (in Croatia: AZOP).

To exercise any of these rights, email hello@ringloop.net with the subject “Data Rights Request”. We will respond within 30 days.

8. Cookies

We use the following types of cookies:

  • Essential cookies: Required for the website to function. No consent needed.
  • Analytics cookies: Anonymised data to understand how visitors use the site. Only set with your consent.

You can update your cookie preferences at any time by clearing your browser’s cookies or clicking “Cookie Settings” in the footer.

9. Security

All data is transmitted over TLS (HTTPS). We apply access controls, keep dependencies up to date, and follow industry-standard security practices. Despite this, no system is completely secure; if you discover a vulnerability, please report it to hello@ringloop.net.

10. Changes to this policy

We may update this policy from time to time. Material changes will be notified via the website. The “Last updated” date at the top of this page always reflects the most recent version.

Talk to the AI