AutomatedFront provides Alex, an AI phone assistant that answers the calls a dental practice's team can't take and books appointments in the practice's calendar. This policy explains what data we process about practices (our clients), the patients and other people who call them, and visitors to this website; why we process it; which providers help us; and your rights under the GDPR and, where applicable, US state law.
INFORMATION WE COLLECT
1.1 — Business Client Data
When a practice becomes a client, we collect:
- Practice name, owner or contact person name, and contact details (email address, phone number)
- Practice address, city and timezone
- Services offered, opening hours and booking rules configured for the practice
- Access to the practice calendar shared with us for booking (we do not store calendar passwords)
- Subscription and billing status; card and bank details are handled by Stripe, not stored by us
1.2 — Caller Data (via Alex)
When someone calls a practice and the call is forwarded to Alex, we may process:
- Caller's name and phone number
- The reason for the call and the requested service or appointment time
- Whether the request is urgent, as described by the caller
- Audio recording of the call, where enabled
- Machine-generated transcript and summary of the call
- Metadata: call time, duration and outcome
1.3 — Website Data
- Demo request form: name, practice name, email, phone number and city, plus a Cloudflare Turnstile check to block automated abuse.
- Client support page: the account email you enter and the messages you write. Access requires a matching client account.
- Bug report page: the description you write and any contact details you choose to include.
- Analytics: if you accept analytics cookies, Google Analytics 4 records pages visited and anonymous interaction events (for example, that a demo request was submitted). We do not send form contents, names, emails or phone numbers to Google Analytics.
- Technical data: IP address, browser type and request logs processed by our hosting and security providers.
HOW WE USE INFORMATION
- Service Delivery: answering forwarded calls, checking availability and booking appointments in the practice calendar.
- Practice Notifications: telling the practice by email when a call needs a person (for example an urgent case or a request Alex cannot complete).
- Client Dashboard: showing the practice its calls, transcripts, recordings (where enabled) and bookings.
- Demo Requests: recording your request in our CRM and notifying our team so we can contact you. Website forms do not trigger automated phone calls.
- Support and Bug Reports: answering your request and forwarding it to our team when it needs checking.
- Billing: managing subscriptions and invoices via Stripe.
- Quality and Security: monitoring the service, reviewing calls to fix errors, and preventing abuse.
- Legal Compliance: tax and accounting records, and honouring opt-out and data-protection requests.
AutomatedFront does not sell, rent, or trade personal information — whether from business clients, callers or website visitors — to any third party for advertising or marketing purposes.
AI VOICE & AUDIO RECORDING
Alex is an artificial intelligence voice assistant, not a human. By default, Alex introduces itself as an automated assistant at the start of the call, and confirms it is an AI to any caller who asks.
3.1 — Call Recording and Transcripts
Calls handled by Alex are transcribed, and may be recorded where the practice has enabled recording and it is permitted. Recordings and transcripts are available to the practice in its AutomatedFront dashboard and to authorised AutomatedFront personnel, and are kept for up to 90 days by default before automatic deletion (see section 8).
3.2 — Role of the Practice
For caller data, the practice decides why and how its calls are handled; AutomatedFront processes that data on the practice's behalf to provide the service. The practice is responsible for informing its patients, including about call recording where required by local law.
CALLS, EMAILS & OPT-OUTS
4.1 — Inbound Calls Only
Alex answers inbound calls that a practice forwards to it. Alex does not place outbound calls to patients or callers.
4.2 — No Calls from Website Forms
Submitting a form on this website does not trigger an automated phone call. If you request a demo, a member of our team contacts you.
4.3 — Emails
Emails related to the service (for example notifications to the practice, invoices and replies to support requests) are transactional. Business emails we send for marketing purposes include an unsubscribe link.
4.4 — Opt-Out
If you ask us not to contact you again — by replying to an email, through the unsubscribe link, or by writing to privacy@automatedfront.com — we record the request and stop further contact. Opt-out records are kept so that we do not contact you again by mistake.
THIRD-PARTY PROCESSORS
To provide our services, AutomatedFront uses the following providers, each only for the purpose described:
CCPA / CPRA RIGHTS
If you are a California resident, the CCPA as amended by the CPRA may grant you specific rights regarding your personal information.
6.1 — Categories Collected
- Identifiers: name, email, phone number, IP address
- Commercial Information: subscription status, billing history
- Audio Data: call recordings and transcripts, where enabled
- Internet Activity: browser and device information, page visits (analytics only with consent)
- Inferences: requested service and urgency, derived from call content
6.2 — Your Rights
6.3 — How to Submit a Request
Email privacy@automatedfront.com with subject line CCPA Privacy Request. We may need to verify your identity before acting on the request.
GDPR & EU/UK RIGHTS
If you are located in the EU, EEA, UK, or Switzerland, the General Data Protection Regulation (GDPR) and equivalent laws grant you rights regarding your personal data. AutomatedFront is based in Pisogne (BS), Italy.
7.1 — Lawful Basis for Processing
- Contract (Art. 6(1)(b)): delivering the service to client practices, and handling a demo request you send us
- Consent (Art. 6(1)(a)): analytics cookies on this website
- Legitimate interests (Art. 6(1)(f)): service security, abuse prevention and quality improvement
- Legal obligation (Art. 6(1)(c)): tax and accounting records
7.2 — Your GDPR Rights
7.3 — International Data Transfers
Some providers listed above are based outside the EEA (for example in the United States). Where personal data is transferred outside the EEA/UK, the transfer relies on the safeguards offered by the provider, such as the European Commission's Standard Contractual Clauses or an adequacy decision.
7.4 — How to Exercise Your GDPR Rights
Email privacy@automatedfront.com with subject line GDPR Request — [type]. We respond within one month, as required by the GDPR (extendable where the law allows). We may need to verify your identity. If you are a patient of a client practice, you can also contact the practice directly.
DATA RETENTION
- Business client data: for the duration of the subscription, then deleted or anonymised on request, except where we must keep it by law.
- Call recordings and transcripts: kept for up to 90 days by default and then deleted automatically, unless a longer period is required by law or for a legal claim; the practice can ask us to delete them earlier. Call summaries in the practice's records are kept while the service is active.
- Demo requests: kept while we are in contact with you; you can ask us to delete them at any time.
- Invoices and accounting records: for the period required by Italian tax law.
- Opt-out records: kept so that we do not contact you again.
SECURITY
- Encryption in transit (HTTPS/TLS) for the website, dashboard and integrations
- Encrypted off-site backups
- Calendar access through sharing with our service account — no calendar passwords stored
- Secrets kept out of the website code and public pages
- Access limited to authorised personnel
- Abuse protection on public forms (Cloudflare Turnstile)
In the event of a breach affecting personal data, we will notify the competent authority and affected parties within the timeframes required by applicable law (for the GDPR, within 72 hours to the authority where required).
CHILDREN'S PRIVACY
AutomatedFront's services are intended for dental practices and are not directed at children. This website does not knowingly collect personal information from children. A practice's callers may include parents calling on behalf of a child; that data is processed only to handle the appointment request. Contact us at privacy@automatedfront.com with any concerns.
CHANGES TO THIS POLICY
When we make material changes, we will:
- Update the "Last Updated" date at the top of this page
- Inform active business clients by email before the change takes effect
CONTACT US
Data controller for website and client data: AutomatedFront · P.IVA 04798730984 · Piazza Mercanti 3, 25055 Pisogne (BS), Italy. For privacy inquiries, rights requests or data deletion: