Privacy Policy

1. Who we are

Veeya is the trading name of the company behind AVA — a Digital Front Desk product for private dental clinics.

If you have any questions about this policy or how we handle your data, contact us at:

Email: hello@veeya.studio

2. What data we collect and why

Website visitors

When you visit our website we may collect standard analytics data — pages visited, time on site, device type. This data is anonymous and used only to understand how the website is used.

Demo enquirers

When you submit a demo request we collect your name, clinic name and email address. We use this to arrange and conduct your demo and to follow up afterwards. We do not share this data with third parties. We do not add you to marketing lists without your consent.

Clinic customers

When a dental clinic uses AVA, patient booking data flows through our system. In this context Veeya acts as a Data Processor and the clinic acts as the Data Controller. A Data Processing Agreement is signed with every clinic before any patient data is handled.

Patient data collected through AVA includes: name, contact details (email and/or phone) and appointment information. This data is collected only for the purpose of completing a booking and is never used for any other purpose.

3. Our lawful basis for processing

We process personal data on the following lawful bases under UK GDPR:

  • Demo enquirer data: legitimate interest — to respond to a business enquiry you have initiated.

  • Clinic customer data: contractual necessity — processing is required to deliver the service agreed under contract.

  • Patient booking data (processed on behalf of clinics): legitimate interest and contractual necessity, as directed by the clinic as Data Controller.

4. How long we keep your data

  • Demo enquiry data: retained for 12 months from the date of enquiry, then deleted.

  • Booking attempt records: retained for 12 months.

  • Audit event records: retained for 24 months.

  • Patient records: retained until erasure is requested by the clinic or the patient.

We do not retain data for longer than is necessary for the purpose it was collected.

5. Your rights

  • Under UK GDPR you have the following rights:

  • Right to access — you can request a copy of the personal data we hold about you.

  • Right to rectification — you can ask us to correct inaccurate data.

  • Right to erasure — you can ask us to delete your data, subject to legal obligations.

  • Right to restrict processing — you can ask us to limit how we use your data.

  • Right to data portability — you can ask for your data in a structured, machine-readable format.

  • Right to object — you can object to processing based on legitimate interest.

To exercise any of these rights, contact us at the email address above. We will respond within 30 days.

6. Cookies

Our website uses cookies for basic analytics. We do not use advertising cookies or track you across other websites.

7. Third-party services

We use a small number of third-party services to operate our business. These include:

Airtable for data storage, Render for hosting, Voiceflow for conversation processing, Calendly for demo booking.

Each of these services is selected for compliance with UK GDPR. We do not sell your data to any third party.

8. Data security

All data transmitted to and from our systems is encrypted in transit using HTTPS. Access to patient and clinic data is restricted and authenticated. We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss or disclosure.

9. ICO registration and complaints

ICO registration number: ZC105918

If you have a concern about how we handle your personal data you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

We would always prefer to resolve concerns directly first — please contact us before escalating to the ICO.

10. Changes to this policy

We may update this policy from time to time. When we do, we will update the date at the top of the page. If changes are significant we will notify clinic customers directly.