Skip to content
CliniVoiceAI
Sign in
Trust Centre

Built to NHS and global healthcare standards

CliniVoice AI is designed from the ground up for the security requirements of UK healthcare. Your patients' data never leaves UK infrastructure.

Compliance

Our certifications and compliance framework

ICO Registration
In Progress
GDPR Art. 9(2)(h)
Health data lawful basis
Active
NHS Records Code
8-year retention
Active
UK DPA 2018
Full compliance
Active

Data Processing

How your patient data flows through our system

Audio

Audio files are sent to Groq Whisper (SOC 2 Type II certified) for transcription. They are deleted from Groq's servers immediately after transcription. Audio is never stored on our servers.

Transcripts & Letters

Clinical transcripts and formatted letters are stored encrypted in Supabase's EU West (London) region. Data is protected by row-level security — only you can access your records.

Retention

Letters are retained for 8 years per the NHS Records Management Code of Practice. You can delete your data at any time from Settings. Account deletion purges all data within 30 days.

Security

Technical measures protecting your data

TLS 1.3 encryption in transit
AES-256 encryption at rest (Supabase)
Row-Level Security on all database tables
httpOnly cookies — no XSS token theft
Content Security Policy (CSP) headers
Rate limiting on all API endpoints
Input validation and sanitisation
No audio stored server-side
Audit logs for all data access
MFA support (TOTP)

AI Infrastructure

The AI models we use and how patient data is handled in each

ServicePurposeData SentLocation
Groq Whisper Large v3 TurboSpeech-to-text (primary)Audio — deleted immediately per Groq DPAUSA (SCCs)
Google GeminiText formatting onlyText transcript only — no audioGlobal
SupabaseDatabase & AuthTranscripts, letters, user accountsEU-West (London)

Certifications

Our certification roadmap

CertificationDetailsStatus
ICO RegistrationApplication in progressRoadmap
GDPR Article 9(2)(h)Health data processing for medical purposesActive
NHS Records Management Code8-year clinical record retentionActive
UK GDPR / Data Protection Act 2018Full complianceActive
Cyber EssentialsPlanned certificationRoadmap
ISO 27001Information security managementRoadmap
NHS DSP ToolkitData Security and ProtectionRoadmap
DTAC AssessmentDigital Technology Assessment CriteriaRoadmap

Frequently Asked Questions

Common compliance and security questions

Need a DPA or security questionnaire?

We respond to procurement and information governance requests within 2 business days.

Contact IG Team
Terms of ServicePrivacy PolicyTrust CentreAcceptable Use