The short version: A dental practice chooses the patients and campaign. Recall uses the practice’s data to place approved calls, capture what happened, and return follow-up information to the practice.
1. Who this notice covers
This notice covers website visitors, people who register for or use a practice account, practice contacts, and patients whose dental practice provides information for a recall campaign.
For patient recall information, the dental practice decides why the information is used and who should be contacted. Recall handles that information to provide the service on the practice’s instructions. The practice’s written agreement should confirm the parties’ precise data-protection roles. Recall separately handles account, security, website, and service-administration information needed to operate the product.
This notice does not replace a dental practice’s own patient privacy notice or its agreement with Recall.
2. Information Recall handles
Website and account information
- practice name, contact name, work email, and optional phone number supplied through the public practice registration form;
- registration and identity details supplied through Kinde, including user ID, email address, organisation, roles, and sign-in information;
- an anonymous website visitor ID stored in local storage, page route, current URL, referring host, CTA and ROI interactions, coarse error and friction signals, masked public-site session recordings, and an optional short answer shown before meeting booking; and
- technical request, session, security, and error information needed to deliver and protect the website and portal. Typed form content is masked in public-site recordings, and booking feedback is capped at 240 characters.
Practice, campaign, and patient information
- practice name, organisation code, calling number configuration, approved messages, voice and booking settings, pricing, availability, and selected webhook settings;
- uploaded recall and booking CSV content, original file names, and raw rows;
- patient name, telephone number, practice reference, recall type, price band, appointment details, site or clinician information, and inclusion or exclusion settings; and
- campaign status, attempts, timestamps, outcomes, notes, agreed appointment records, and handoff information.
Call information
Call records can include telephone numbers, call time and duration, messages, transcript, recording, outcome flags, structured summaries, costs, and tool results. The exact content depends on what the practice supplies and what is said during the call.
Because this is a dental recall service, practice-provided files or call content may reveal health-related information. Practices should provide only what is needed for the approved campaign.
3. How the information is used
Recall uses information to:
- register and authenticate practice users;
- configure a practice, assistant, call flow, voice, knowledge, and permitted calling window;
- match recall and booking lists, exclude already-booked or opted-out contacts, and control call attempts;
- place approved calls, present relevant availability or pricing, and record agreed appointment times;
- show recordings, transcripts, outcomes, costs, campaign progress, and follow-up information to authorised practice users;
- complete the practice's configured booking handoff through a webhook or staff email;
- operate, secure, troubleshoot, support, and improve the service; and
- understand anonymous public-site usage and booking interest.
The practice is responsible for choosing and documenting the lawful reason for its patient recall campaign. Recall handles practice-provided patient data under the practice’s instructions. Other account and service information is used as needed to provide the requested service, protect it, and meet applicable contractual or legal obligations. Ask us if you need the basis for a particular use confirmed in context.
4. Providers and sharing
Recall uses service providers only for the roles needed to run the product:
- Kinde for registration, identity, and access management;
- Supabase for the application database;
- Vapi for outbound calling, call records, recordings, transcripts, and structured outcomes;
- OpenAI for language processing and outcome extraction within the Vapi call workflow;
- ElevenLabs for the configured call voice within that workflow;
- Google Cloud for application hosting, deployment, and storage of assistant knowledge and settings;
- PostHog for anonymous public-site analytics, masked session recording, and optional booking feedback; and
- Brevo to hold public practice registrations, support meeting booking, and manage related communications.
Recall sends selected call or booking events through the handoff chosen during practice setup. This can be a configured webhook or staff email. Recall also returns campaign and call information to authorised practice users. Information may be disclosed where required to protect people, the service, or comply with a valid legal requirement.
5. Retention and deletion
Recall does not publish one fixed retention period for every data type. Information is kept while needed to provide and secure the service, support the practice, keep necessary records, and follow the applicable written agreement or legal requirements.
The portal does not currently offer self-service account deletion. Removing a practice currently deactivates its practice mapping but does not automatically erase historic campaign or call information. Deleting a campaign removes its related campaign records from the application database; provider-held call or account records may follow separate provider and contract settings.
To ask about retention or request deletion for a particular account, campaign, or patient record, email recall@mail.tin.computer. We will confirm what can be deleted, what must be retained, and which organisation needs to act.
6. Security and processing locations
Recall uses authenticated access, practice-scoped records, role checks, and cloud-provider controls to limit access. No internet service can promise absolute security, so practices should avoid supplying information the campaign does not need and should report suspected access problems promptly.
Some providers operate infrastructure or support services in more than one country. Processing locations and transfer terms depend on the provider and the practice’s current agreement. Contact us for the current details relevant to your practice before a campaign starts.
7. Your choices and requests
Practice users can ask about their account information or request correction, access, restriction, objection, or deletion where that right applies. We may need to verify identity and the relevant practice before acting.
Patients should normally contact their dental practice first because the practice selected the recall list and campaign. Patients can tell their dental practice that they do not want further recall calls. An authorised practice user can mark that campaign contact as excluded so the campaign will avoid further calls to that contact.
You can clear the public site’s anonymous visitor ID by deleting this site’s local storage in your browser. Questions or requests can be sent to recall@mail.tin.computer.
8. Updates and contact
We may update this notice when the service or its providers change. The date at the top shows the latest version.
Contact: recall@mail.tin.computer. If your question is about a patient recall campaign, include the dental practice and enough context to identify the relevant record, but do not email unnecessary clinical information.