Privacy Notice

Effective: 10 May 2026  |  Version: 2.0  |  Last reviewed: 13 May 2026

This notice explains how Fluora Ltd ("Fluora", "we") collects, uses and protects personal data when you visit fluora.co.uk, sign up to our service, or interact with us. We are committed to processing personal data lawfully, fairly and transparently in accordance with the UK GDPR and the Data Protection Act 2018.

1. Who we are

Fluora Ltd is a company registered in England and Wales (company number 17044783) with registered office at Suite A, 82 James Carter Road, Mildenhall, Bury St. Edmunds, IP28 7DE. We are registered with the UK Information Commissioner's Office (ICO), registration number ZC095058.

For privacy questions, contact our Data Protection contact at privacy@fluora.co.uk.

2. Two roles, two notices

Fluora plays two distinct roles depending on whose data is being processed:

3. What data we collect (as controller)

CategoryExamplesSource
Identity & contactName, work email, phone, practice name, roleYou give us this when enquiring or signing up
Account & subscriptionPlan tier, billing dates, payment statusGenerated by your use of our portal & GoCardless
CommunicationsEmails, SMS messages, support ticketsDirect correspondence
Technical & usageIP address, browser type, pages visited, referrerAutomatically when you visit fluora.co.uk
MarketingWhether you opted into our newsletter or follow-up sequencesYour consent

4. Why we use it & lawful basis

PurposeLawful basis (UK GDPR Art. 6)
Responding to enquiries & demosLegitimate interests (running our business)
Providing the Service to subscribersContract performance
Billing & financial recordsLegal obligation (HMRC) & contract
Service improvements (analytics, error logs)Legitimate interests, balanced against your rights
Marketing communicationsConsent (you can withdraw at any time)
Fraud prevention & securityLegitimate interests & legal obligation

5. How we use AI

Our voice agent uses large language models (LLMs) and text-to-speech models from ElevenLabs to handle inbound calls. Audio is streamed to ElevenLabs' US servers in real time, transcribed, and a response is generated and spoken back to the caller. We do not use call data to train any third-party model. Call transcripts are retained for 90 days and then deleted (the transcript field is nulled; the call record itself is kept for audit and billing purposes). Audio recordings are not stored by Fluora.

The LLM is constrained by a strict system prompt to: (a) book appointments, (b) answer common practice FAQs from a knowledge base supplied by the practice, (c) escalate clinical or emergency questions to the practice's human staff. It does not give clinical advice.

6. Cookies & similar technologies

Our website uses a small number of cookies and similar storage. You will see a cookie notice on first visit allowing you to accept or reject non-essential cookies. Categories:

CategoryPurposeSet byRetention
Strictly necessaryCookie-consent state, session securityFluora1 year
PerformanceAnonymised page-view analytics (Google Analytics 4 — when activated)Google14 months
FunctionalForm-progress preservationFluora30 days

You can change your cookie preferences anytime by clearing your browser's localStorage or contacting privacy@fluora.co.uk.

7. Sharing & sub-processors

We share data with carefully vetted service providers who help us deliver the Service. Each is bound by data-processing agreements requiring at least the same protections as this notice.

For the current, authoritative list of sub-processors we use, see our Sub-processors page. We will notify all customers at least 30 days before any change.

We do not sell or rent personal data to anyone.

8. International transfers

Where any sub-processor processes data outside the UK or EEA, we rely on the UK International Data Transfer Addendum or appropriate Standard Contractual Clauses. We carry out a Transfer Risk Assessment for each such transfer.

9. How long we keep it

Data typeRetention
Enquiry / lead data (no signup)12 months from last contact
Subscriber account & billing recordsActive period + 6 years (HMRC)
Marketing email subscribersUntil withdrawal of consent
Website analytics (anonymised)14 months
Support emails3 years

10. Your rights

Under UK GDPR you have the right to:

To exercise any right, email privacy@fluora.co.uk. We respond within one calendar month.

11. Security

We implement organisational and technical measures including TLS encryption in transit, encryption at rest for all databases, role-based access control, automated audit logging, and time-limited retention of sensitive content (e.g. call transcripts purged after 90 days). Passwords are hashed; secrets are stored in encrypted vaults. We carry out regular security reviews of our infrastructure.

12. Changes to this notice

We may update this notice when our practices change. The "Effective" date at the top reflects the latest version. Material changes are notified to active subscribers by email at least 14 days before they take effect.

13. Contact

Privacy questions: privacy@fluora.co.uk
General contact: hello@fluora.co.uk
Postal: Fluora Ltd, Suite A, 82 James Carter Road, Mildenhall, Bury St. Edmunds, IP28 7DE