Direct answer: Healthcare call automation is not inherently secure. Before buying or expanding it, clinics should evaluate data flows, lawful basis, controller/processor roles, subprocessors, storage location and transfers, encryption, access control, retention and deletion, recordings and transcripts, audit logs, incident response, backups, model-training uses, DPIA support and contract terms. Treat security, privacy, clinical safety and operational resilience as separate workstreams.
This article is a high-trust due-diligence guide for UK clinics. It is not legal advice. Use current primary sources and your own advisers for decisions. Clero-specific statements below are limited to what is stated in Clero’s published Privacy Policy and Terms of Service, plus observable product behaviour such as call transcripts and audio access in the platform. Claims that cannot be evidenced that way are framed as buyer questions, not as product guarantees.
Four domains clinics should separate
1. Privacy
Who is the controller? What personal data is processed? What is the lawful basis? How are callers informed? How long is data kept? How are rights requests handled?
Health-related information can be special category data under UK GDPR, which attracts higher protection. Clinics should identify both an Article 6 lawful basis and, where special category data is processed, an Article 9 condition. Do not assume consent is always required or always sufficient without checking the purpose.
2. Information security
How is data protected in transit and at rest? Who can access dashboards, transcripts or audio? How are credentials managed? What monitoring and logging exist? What happens after a suspected incident?
3. Clinical and patient safety
Can the system diagnose or give clinical advice? How are urgent phrases handled? How does human escalation work if nobody answers? Safety failures can occur even when privacy paperwork looks tidy.
4. Operational resilience
What happens if telephony, internet, the practice system or the vendor path fails? Is there a fallback that still protects urgent callers? Continuity design is covered further in the healthcare call-handling resilience guide.
Simple data-flow description to document
Every clinic should draw its own version of this flow and fill in the real systems:
- Caller dials the practice number.
- Telephony provider delivers or overflows the call into the AI / voice path.
- Voice AI provider processes speech and returns transcripts or events (Clero’s privacy policy names ElevenLabs as an example voice AI provider).
- Clero platform applies clinic rules, stores operational records such as call and booking data, and may retain voice transcripts where applicable.
- Practice management / calendar systems receive booking or patient updates when integrations are connected.
- Clinic staff may review summaries, transcripts or audio through the practice dashboard, subject to access controls and provider retention settings.
- Optional tools (for example payment links or messaging) may handle out-of-band actions outside the voice channel.
Document for your deployment: which systems are in the path, what each stores, retention periods, who can access what, and what is written back to the PMS.
What Clero’s published privacy policy does say
From Clero’s Privacy Policy (last updated February 2026 on that page):
- Clero AI Ltd operates the platform and related services, including AI voice agents and integrations, in accordance with its Data Processing Agreement.
- Information collected can include account details, business and contact information, call and booking data, usage and logs, voice transcripts where applicable, and technical data.
- Voice and call data may be processed to deliver and improve AI voice services.
- Clero states it does not use customer data to train third-party or general-purpose AI models without consent.
- Trusted third parties used to run the platform include infrastructure and authentication (for example Supabase), voice AI (for example ElevenLabs), and optional integrations (for example Google Calendar).
- Data is stored and processed in UK-based regions where possible, with appropriate technical and organisational measures and access limited to people who need it to operate and support the services.
- UK/EEA users may have rights to access, correct, delete or restrict personal data, and to complain to a supervisory authority.
From Clero’s Terms of Service:
- Customers must ensure their use complies with applicable laws.
- Third-party integrations remain subject to those providers’ terms and privacy policies.
- Services are provided “as is”; uninterrupted or error-free operation is not guaranteed.
Observable product behaviour also matters for diligence: the Clero app can surface call transcripts and, where available, conversation audio via provider APIs. Audio availability depends on provider settings such as audio saving and retention. That is why absolute “zero raw audio forever” claims are unsafe unless your specific configuration and contracts say so in writing.
Vendor due-diligence table
Use this table in procurement and annual review. Prefer written answers and contract schedules over sales copy.
| Diligence area | Questions to ask | Evidence to request |
|---|---|---|
| Data flows | What data moves from telephony → voice AI → platform → PMS → staff tools? | Architecture diagram for your deployment |
| Lawful basis | Which Article 6 basis applies? Is special category data processed, and under which Article 9 condition? | DPIA inputs / processing description |
| Controller / processor roles | Who is controller for patient calls? Who is processor? Any joint-controller edges? | DPA / schedule of processing |
| Subprocessors | Which vendors process call, transcript, booking or auth data? | Current subprocessor list and notice process |
| Location / transfers | Where is data stored and processed? Any transfers outside the UK? | Region statement and transfer safeguards |
| Encryption | What protects data in transit and at rest? Who holds keys? | Security summary from vendor, not slogans |
| Access control | Who in the clinic and vendor can see transcripts/audio? MFA? Role permissions? | Access matrix and admin controls |
| Retention / deletion | How long are transcripts, audio, logs and booking metadata kept? How is deletion executed? | Retention schedule and deletion process |
| Recordings / transcripts | Is audio stored? By which provider? How are callers informed? | Recording policy and notice script |
| Audit logs | Can you see who accessed a call record and when? | Sample audit log / SIEM summary |
| Incident response | How are incidents detected, contained, notified and reviewed? | Incident response overview and contacts |
| Backups | What is backed up, where, and how restore is tested? | Backup and restore note |
| Model training | Is customer data used to train models? Whose models? Opt-out? | Contract clause matching privacy promises |
| DPIA support | Will the vendor help with DPIA questionnaires and risk narratives? | Completed security questionnaire |
| Contract terms | Confidentiality, breach notification timelines, audit rights, exit/deletion | Signed DPA and MSA schedules |
UK GDPR and PECR, with qualification
UK clinics remain responsible for complying with UK data protection law when patient and caller information is processed. Useful starting points from the Information Commissioner’s Office include:
- ICO guidance for organisations
- Special category data guidance
- PECR overview for electronic and telephone marketing
Qualification: this section summarises themes clinics commonly need to investigate. It is not legal advice and does not determine the correct lawful basis, PECR position or recording notice for your clinic. If you run outbound marketing or automated marketing calls, PECR rules can be stricter than many teams expect; take advice before enabling those workflows.
NHS standards: ask, do not assume
Standards such as the NHS Data Security and Protection Toolkit (DSPT) or clinical safety standards (for example DCB0129 / DCB0160) may be relevant for some NHS or NHS-facing deployments. Relevance depends on the service being provided, the contracting arrangement and the clinic’s own clinical-safety duties.
This article does not claim that Clero holds any specific NHS certification, DSPT status or DCB0129/DCB0160 approval. If those standards matter to your tender or governance board, ask for current evidence in writing and map it to the exact product scope you are buying.
Clinical safety and human escalation
Information security does not replace clinical governance.
Ask:
- Can the assistant diagnose, prescribe or give clinical advice?
- What language triggers urgent redirection?
- How does live transfer work, and what happens if nobody answers?
- Who owns review of missed escalations?
A usable escalation design is part of security and safety. See the human escalation guide.
Payments over the phone
Reading card numbers aloud on a voice call increases exposure risk. Prefer out-of-band payment methods such as secure payment links when deposits are required. Do not treat “we send a link” as proof of PCI certification unless the relevant provider attestations are reviewed for your exact flow.
Breach and incident-response checklist
Before go-live, confirm the clinic can answer:
- Who is the internal incident owner for telephony / AI call systems?
- How do staff report a suspected privacy or security incident within minutes?
- How is access revoked quickly (user, API keys, integrations)?
- How are affected call recordings, transcripts or booking records identified?
- When and how are patients, the ICO or other parties notified if required?
- Who contacts the vendor and telephony provider, and with what severity levels?
- How is the service paused or diverted to a human-only fallback?
- What evidence is preserved for investigation without spreading access further?
- How is the post-incident review recorded and used to change controls?
- When was the last tabletop rehearsal of this plan?
Availability and escalation questions to add to security review
- What is the documented fallback if the AI path is unavailable?
- Can staff disable a broken workflow without waiting for a vendor business day?
- Are urgent callers protected during vendor or PMS outages?
- Are audit trails available after an incident, or only during happy-path demos?
Claims this article will not make
Unless evidenced in current Clero legal documents or a signed customer schedule, do not rely on marketing language such as:
- “100% secure”
- “fully GDPR compliant by default”
- “guaranteed protection”
- “zero retention of all audio in every configuration”
- “AES-256 / TLS 1.3 everywhere” without a current security pack
- implied NHS DSPT or DCB certification
Ask for the current artefact instead.
Frequently asked questions
Is healthcare call automation automatically secure?
No. Security depends on configuration, vendors, contracts, retention settings, access control and how the clinic governs urgent or sensitive calls. Clinics should evaluate each deployment rather than assume automation is inherently safe.
What personal data can clinic call automation process?
Depending on configuration, systems may process names, phone numbers, booking details, call metadata, transcripts and, where enabled, audio. Some calls may also include health-related information that needs higher protection under UK GDPR.
Does Clero keep voice transcripts?
Clero's privacy policy states that voice transcripts may be collected where applicable, and that voice and call data may be processed to deliver and improve AI voice services. Clinics should confirm the live retention settings for their deployment.
Where does Clero store data?
Clero's privacy policy says data is stored and processed in UK-based regions where possible, with access limited to people who need it to operate and support the services. Ask for the current subprocessor and transfer details in writing.
Does Clero use clinic data to train general-purpose AI models?
Clero's privacy policy states that it does not use customer data to train third-party or general-purpose AI models without consent. Confirm any improvement or analytics uses in the contract and Data Processing Agreement.
What should clinics ask about call recordings?
Ask whether audio is stored, by whom, for how long, who can access it, how callers are informed, and how deletion or subject-access requests are handled. Recording settings can vary by telephony and voice-provider configuration.
Is this article legal advice?
No. It is an operational due-diligence guide. Clinics should take advice from their Data Protection Officer or legal adviser for their specific processing, contracts and clinical governance duties.
Next step
If you are preparing a DPIA or board pack, start with the due-diligence table and your own data-flow diagram, then compare answers against Clero’s Privacy Policy, Terms and the written DPA for your organisation. A security review conversation is most useful when you bring those documents and your intended call workflows, not a generic feature list.