Vocca attaches great importance to the protection of your personal data and to respecting your privacy. This policy is intended to inform you of our practices regarding the collection, processing and sharing of the data you provide to us.

Vocca operates in France and in the United States. Where the applicable rules, the hosting location or your rights differ between the two, both are set out side by side under the headings France and the European Union and United States.

Preamble

We consider your personal data to be confidential information to which we give particular attention.

Personal data includes, in particular:

  • your name,
  • your telephone number,
  • your email address,
  • your IP address,
  • any other data communicated directly by you or generated by your browsing activity.

In accordance with legal and regulatory obligations, we collect, use, share and retain this information under enhanced security conditions and for limited periods that are proportionate to the purposes for which you provided it to us.

Table of contents

  1. Data collection
  2. Nature of data and processing purposes
  3. Our role: processor and Business Associate
  4. Disclosure of personal data to third parties
  5. Data hosting and international transfers
  6. Data retention period
  7. Rights of data subjects
  8. Mobile information and SMS messages
  9. IT security
  10. Changes to the Privacy Policy
  11. Contact
  12. Cookie management

1. Data collection

You entrust us with the processing of your data, and we strive to be transparent about how we collect it.

We collect the data you provide when using our online services, in particular when you:

  • browse and view our website;
  • request a product demonstration;
  • provide your information to contact us;
  • provide your information to apply for a position at Vocca;
  • use our Vocca management platform;
  • use our Voicebot solution.

We never automatically collect your email address without a deliberate action on your part.

Certain information is mandatory, indicated by an asterisk when requesting a demonstration. Without it, we will not be able to process your request.

2. Nature of data and processing purposes

The data is used according to the purposes you yourself initiate, based on one of the following legal grounds:

  • performance of services;
  • consent;
  • legitimate interests;
  • legal, regulatory, judicial or administrative obligation.

The concept of a “legal basis” is a requirement of European law. For processing subject only to U.S. law, the corresponding entry indicates the purpose and the limits we apply to it.

Detailed purposes

Purpose: responding to a demonstration request
Data: last name, first name, professional email, professional phone number, company
Legal basis: legitimate interest of the data controller (Vocca)

Purpose: responding to a contact request
Data: identity, professional phone number, professional email, company, subject of the request, history of requests
Legal basis: legitimate interest of the data controller (Vocca)

Purpose: responding to a job application
Data: identity, contact details, social media links, desired salary, city, CV, career information
Legal basis: legitimate interest of the data controller (Vocca)

Purpose: managing B2B prospects and customers
Data: identity, professional phone number, professional email, company, position
Legal basis: legitimate interest of the data controller (Vocca)

Purpose: quotes, billing, contracts
Data: identity, professional contact details, company, position, and the applicable business identifier — SIREN/SIRET in France, EIN or other tax identification number in the United States
Legal basis: pre-contractual or contractual measures

Purpose: operation of the Voicebot
Data: last name, first name, phone number, email, date of birth, voice recording, transcription, date/time/location of appointment, name of practitioner, purpose of appointment
Legal basis: determined by the client. Vocca acts on the client’s instructions — as a processor in France and the European Union, and as a Business Associate in the United States (see section 3).

3. Our role: processor and Business Associate

When you interact with a healthcare practice that uses Vocca, the practice decides what data is processed and why. Vocca acts on that practice’s instructions. The legal name for that role, and the obligations attached to it, differ by jurisdiction.

France and the European Union

Vocca acts as a processor (sous-traitant) within the meaning of the GDPR, and the healthcare practice acts as the data controller. The relationship is governed by a data processing agreement (DPA) entered into under article 28 GDPR, which sets out the documented instructions, the security measures, the use of sub-processors and the assistance Vocca provides to the controller.

United States

Where Vocca creates, receives, maintains or transmits Protected Health Information (“PHI”), it acts as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), and the healthcare provider acts as the Covered Entity.

Business Associate Agreement. Vocca enters into a BAA with each U.S. healthcare provider customer before any PHI is processed. In the event of conflict between the BAA and this policy, the BAA prevails with respect to PHI.

Permitted use. Vocca uses and discloses PHI only as permitted by the BAA, as directed by the Covered Entity, as necessary to provide and support the service, or as required by law. Vocca does not use or disclose PHI for its own marketing purposes and does not sell PHI.

Safeguards. Vocca maintains administrative, physical and technical safeguards designed to protect the confidentiality, integrity and availability of PHI in accordance with the HIPAA Security Rule, including role-based access controls, encryption of data in transit and at rest, audit logging of access to PHI, application of the minimum necessary standard, and periodic workforce training.

Subcontractors. Any subcontractor handling PHI on Vocca’s behalf is bound by a written agreement imposing obligations no less protective than those to which Vocca is subject.

Breach notification. In the event of a breach of unsecured PHI, Vocca notifies the affected Covered Entity without unreasonable delay and no later than sixty (60) days following discovery, with the information required under the HIPAA Breach Notification Rule.

Individual rights in PHI. HIPAA rights over PHI — access to, amendment of, and an accounting of disclosures of a designated record set — are exercised with the healthcare provider, not with Vocca. Where a patient contacts Vocca directly, the request is referred to the relevant provider.

4. Disclosure of personal data to third parties

Your personal data collected through our services may be transmitted to third parties within the limits provided for by applicable regulations and in accordance with this policy.

4.1 Processors and subcontractors

Your personal data may be transmitted to external service providers who process it on our behalf, according to our instructions. The transmission of your data to these providers is supervised to ensure its security. These include third-party companies providing support services, technology providers, and hosting providers.

In France and the European Union, these providers are bound by article 28 GDPR sub-processing agreements. In the United States, any provider handling PHI is bound by a Business Associate Agreement with flow-down obligations no less protective than our own.

We do not sell your personal data.

4.2 National authorities

To comply with legal, regulatory, judicial or administrative obligations, or to respond to requests from administrative or judicial authorities, we may be required to disclose your data to such authorities whenever we are legally obliged to do so.

5. Data hosting and international transfers

Platform data is hosted in the region corresponding to the customer’s location.

France and the European Union

Data of European customers is hosted in the European Union, with Amazon Web Services (Paris region, with redundancy in Frankfurt) and Microsoft Azure (France Central region). These providers hold HDS certification (Hébergeur de Données de Santé), required under article L. 1111-8 of the French Public Health Code for hosting personal health data.

Any transfer of personal data outside the EEA is governed by:

  • adequacy decisions (Art. 45 GDPR);
  • Standard Contractual Clauses (Art. 46 GDPR);
  • the appropriate safeguards provided under Chapter V of the GDPR.

United States

Data of U.S. customers is hosted in the United States. Vocca’s hosting providers for this region are bound as subcontractors under HIPAA through Business Associate Agreements entered into before any PHI is processed. There is no U.S. equivalent of HDS certification; protection rests on the HIPAA Security Rule and on the contractual chain of Business Associate Agreements.

Vocca is a company established in France. Certain corporate, support and engineering functions — including customer support, billing and engineering — are carried out by Vocca personnel or providers located in France or elsewhere in the European Union, which may involve access to U.S. customer data from outside the United States. Such access is covered by the applicable Business Associate Agreement and by the safeguards listed above.

6. Data retention period

6.1 Clients

We retain data for the duration of our business relationship and for a maximum of 3 years after the last interaction with the client. Beyond the retention period, your data will no longer be used to send marketing communications after a period of three years from your last interaction with us.

Billing-related data is retained:

  • France and the European Union — for 10 years, in accordance with article L. 123-22 of the French Commercial Code.
  • United States — for the period required by applicable federal and state law.

6.2 Prospects

We retain data for a maximum of three years after the last interaction with a prospect who has expressed interest in our products and/or services.

6.3 End users of a Vocca Voicebot

The maximum retention period for personal data of users interacting with a Voicebot provided by Vocca is:

  • 6 months for audio recordings;
  • 5 years for other data.

These are maximum durations. The client defines the applicable retention period according to the purposes of the processing — as data controller under the GDPR in France and the European Union, and as Covered Entity in the United States, subject to any record-retention obligations imposed by federal or state law.

7. Rights of data subjects

France and the European Union

The use of your data is possible:

  • due to the performance and monitoring of our contractual relationship,
  • because you have expressly consented to it,
  • to meet our legitimate interests,
  • or to comply with a legal obligation.

You have the following rights at any time over your personal data:

  • right of access,
  • right to data portability,
  • right to rectification,
  • right to erasure,
  • right to restriction of processing.

You may exercise these rights under the conditions provided by law by sending an email to: dpo@vocca.com

You may also object, for legitimate reasons, to your personal data being processed or stored in our customer files when processing is based on the legitimate interest of Vocca; and exercise your right to object to marketing activities without having to justify legitimate grounds.

If you have given your consent for us to use your data — for example to send newsletters — you may withdraw that consent at any time.

If, for any reason, you consider our response unsatisfactory, you may lodge a complaint with the CNIL (Commission Nationale de l’Informatique et des Libertés), the authority responsible for personal data protection in France, via: https://www.cnil.fr/fr/plaintes

United States

Rights over PHI are exercised with your healthcare provider, as set out in section 3.

For personal data that is not PHI — for example data collected when you browse the website, request a demonstration or apply for a position — residents of certain states have rights of access, correction, deletion and portability, and the right to opt out of the sale or sharing of personal data and of targeted advertising. Vocca does not sell personal data. These requests may be addressed to dpo@vocca.com and are answered within the timeframe set by the applicable state law.

You will not be discriminated against for exercising any of these rights.

8. Mobile information and SMS messages

When a patient gives their mobile telephone number to a healthcare practice using Vocca, that number is processed in order to send them messages relating to their care: appointment confirmations, reminders, changes and cancellations, practical information, and follow-up reminders. Messages are sent within an existing care relationship, and each message is generated for one patient in connection with that patient’s own appointment or request. The platform is not used for bulk or campaign-based messaging.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Mobile information will not be sold or shared with third parties for promotional or marketing purposes.

Text messaging originator opt-in data and consent will not be shared with any third parties.

Mobile information may be disclosed only to the technical providers strictly necessary to deliver the messages, namely telecommunications carriers and messaging platform providers, acting as processors and with no right to use it for their own purposes.

No promotional or marketing message is sent to patients through the platform. Message frequency may vary depending on the activity of the practice and the patient’s appointments. Message and data rates may apply. A patient may ask at any time to stop receiving messages, by replying to a message or by contacting the practice directly. The request is free of charge and is acted on by the practice.

France and the European Union

The sending of messages relies on the legal basis established by the practice as data controller, and on the patient’s rights under the GDPR and the French Postal and Electronic Communications Code.

United States

Messages are transactional and care-related, not marketing. The patient’s mobile number is provided by the patient to the practice for the management of their own appointments, and is never purchased, rented or obtained from a third party. The practice, as the Covered Entity, is responsible for the patient relationship and for any consent its own obligations require. A request to stop receiving messages is acted on free of charge.

Full terms are set out in section 6 of the Terms of Service.

9. IT security

9.1 General principle

We implement all appropriate technical and organizational measures to ensure the security, integrity and confidentiality of your personal data and to prevent any destruction, loss, alteration, disclosure, intrusion or unauthorized access to such data, whether accidental or unlawful.

These measures include encryption of communications in transit and of data at rest, access control and strong authentication, access logging, regular review of permissions, and periodic penetration testing by an external firm.

9.2 Management of security breaches

We have implemented a procedure for preventing, managing and correcting security vulnerabilities, as well as for notifying personal data breaches.

This procedure enables us to remedy vulnerabilities effectively, manage potential data breaches, and ensure notification in compliance with applicable requirements.

France and the European Union

We commit to notifying personal data breaches as soon as possible, and no later than 72 hours after becoming aware of them, to the competent supervisory authority, the CNIL, where the breach is likely to result in a risk to your rights and freedoms; and to informing you as soon as possible where the breach is likely to result in a high risk to your rights and freedoms.

United States

Where the breach involves unsecured PHI, we notify the affected Covered Entity without unreasonable delay and no later than sixty (60) days following discovery, in accordance with the HIPAA Breach Notification Rule. Notification to individuals and, where applicable, to the Department of Health and Human Services, is made by the Covered Entity. Where a breach involves personal data that is not PHI, we notify affected individuals as required by the applicable state breach notification law.

In all cases we will communicate the measures taken to remedy the breach, including measures aimed at mitigating its consequences.

10. Changes to the Privacy Policy

We may modify this policy.

If such modifications result in a reduction of your rights, we will inform you directly through the contact methods you have provided.

11. Contact

For any questions, you can contact our customer service at: contact@vocca.com

You may also write to dpo@vocca.com, specifically for:

  • filing a complaint regarding privacy and confidentiality;
  • questions relating to this privacy policy.

Vocca has appointed a data protection officer, registered with the CNIL under number DPO-158853. The same contact address serves for requests under U.S. state privacy laws.

Postal address: VOCCA, 7 rue Mariotte, 75017 Paris, France.

12. Cookie management

12.1 What is a cookie?

A cookie is a file stored on your device (computer, mobile or tablet) when visiting a website or viewing an advertisement.

Its purpose is to:

  • collect information relating to your browsing,
  • provide services and offers tailored to your device,
  • propose content aligned with your interests.

When you visit our website for the first time:

  • cookies may be placed, subject to your cookie preferences;
  • we inform you of this placement through the banner that appears on the visited page.

Your choices are not final and can be modified at any time by adjusting your cookie settings.

12.2 Why does Vocca use cookies?

Cookies serve different purposes and store and/or read files to obtain information relating to your interaction with the site, including your browsing activity and behavior. In this context, subject to your consent and/or your device settings, Vocca collects and processes all or part of the information detailed below.

Functional cookies essential to navigation

These cookies make it possible to:

  • remember your cookie preferences,
  • remember customer account data,
  • ensure storage of the shopping cart, etc.

Marketing cookies

We may use partner companies to enable:

  • the display of advertisements,
  • targeted content based on your interests,
  • highlighting products you may like, displayed on other sites during your browsing (ad banners).

Analytics and audience measurement cookies

We may also include and collect information that allows us to:

  • conduct analyses,
  • measure website traffic and visits,
  • establish statistics,
  • perform verifications to optimize our services and/or improve customer knowledge.

12.3 Detailed list of cookies used

AWSALBTG
Category: necessary
Purpose: AWS load balancing cookie enabling persistent sessions by directing a client to the same group of servers.
Retention period: 7 days

AWSALBTGCORS
Category: necessary
Purpose: AWS load balancing cookie ensuring visitor page requests are routed to the same server within any browsing session.
Retention period: 7 days

tf_respondent_cc
Category: necessary
Purpose: cookie used to allow Typeform users to accept or refuse cookies in the form.
Retention period: 6 months

_cf_bm
Category: necessary
Purpose: cookie used by Cloudflare to detect and limit bot traffic.
Retention period: session

attribution_user_id
Category: statistical
Purpose: cookie used by Typeform to conduct anonymous client analyses.
Retention period: 1 year

_ga
Category: statistical
Purpose: Google Analytics cookie distinguishing unique users through a randomly generated identifier. Used to compute visitor, session and campaign data for analytics reports.
Retention period: 1 year and 1 month

_ga_MKNVXHKG
Category: statistical
Purpose: cookie used by Google Analytics to maintain session state.
Retention period: 1 year and 1 month

_ga_NYYBGLSXYD
Category: statistical
Purpose: cookie used by Google Analytics to maintain session state.
Retention period: 1 year and 1 month

_gcl_au
Category: marketing
Purpose: cookie used by Google Ads to measure ad campaign effectiveness.
Retention period: 3 months

intercom-device-id-ra7oz01b
Category: necessary
Purpose: cookie storing the user’s device ID for Intercom messaging.
Retention period: 9 months

intercom-id-ra7oz01b
Category: necessary
Purpose: anonymous visitor identification cookie received during visits.
Retention period: 9 months

intercom-session-ra7oz01b
Category: necessary
Purpose: cookie tracking user session data for Intercom messaging.
Retention period: 7 days

12.4 What information is collected by cookies?

Information on your browsing of our site, such as:

  • statistics on viewing different pages of our site (e.g. categories of goods or services displayed, time spent on pages, etc.);
  • complete URL paths to, through and from our site.

12.5 Preference settings

You have several options to define your cookie preferences.

You may configure cookies by:

  • adjusting your browser settings (Internet Explorer, Chrome, Safari, Mozilla, etc.) to allow or block cookies;
  • clicking the cookie policy on the cookie banner or within the cookie settings at the bottom of the page.

France and the European Union

Cookies that are not strictly necessary are placed only after your consent, in accordance with article 82 of the French Data Protection Act. Consent may be withdrawn at any time, as easily as it was given.

United States

Cookie preferences operate on an opt-out basis. You may opt out of analytics and marketing cookies at any time through the cookie settings link in the website footer. Where required by state law, this also constitutes the mechanism for opting out of the sharing of personal data for targeted advertising.

Related documents

The Legal notice, Terms of Service and cookie settings are available from the footer of the website.

Less time on the phone, more time on care

Book a demo and see how Vocca handles your calls, bookings and reminders 24/7.