FAQs

Find answers to many frequently asked questions about RECEPTIO.

If you can’t find what you’re looking for, feel free to contact us through RECEPTIO.

Customer data is securely stored within our CRM platform, which is hosted on Google Cloud infrastructure in the United States.

This platform complies with UK GDPR, SOC 2, ISO 27001, and HIPAA standards. All data is encrypted in transit and at rest.

No — we do not share customer data with third parties for sales, marketing, or profiling. Data collected through the AI assistant is stored only within the client’s secure CRM account.

We do use third-party systems strictly for processing purposes (e.g. powering the AI and configuration), but these systems do not independently store, use, or control the data.

No — we do not use any external data sources to supplement or enrich the user’s responses. The AI only processes information that is directly provided by the user during the conversation or configured internally based on your business.

Yes — If the client wants their users can offered the option to request a callback or have someone follow up directly.

This can be made available at the start of the conversation or triggered at any point if the user expresses a preference for speaking with someone.

Access is strictly limited to authorised personnel involved in setting up or supporting your account. Permissions are managed through role-based access controls, protected by two-factor authentication (2FA), and logged through internal activity monitoring.

Once the system is handed over, ongoing access is typically restricted to your own team.

Yes — the CRM provides detailed activity logs that track access and updates. In addition, chat interactions are temporarily logged within our AI platform for quality control and support purposes. These logs can be deleted upon request and are never shared with third parties.

Our internal team is not currently ISO27001 certified, but all infrastructure providers and platforms we use — including those that support the AI logic and CRM — are fully compliant with ISO27001, SOC 2, and UK GDPR.

We also adhere to strict data protection practices and conduct internal risk assessments regularly.

We’ve had no data breaches to date. However, we have a comprehensive incident response plan in place should an incident occur. This includes immediate investigation, client notification, containment, and reporting procedures.

The AI assistant is configured with a clear scope, focused only on your business and services. If it receives unrelated or off-topic questions, it will politely respond with a fallback message such as:

That’s a great question — I’ll pass it on to the team so they can follow up directly.

This ensures that conversations remain relevant and that unexpected queries don’t result in confusing or misleading responses.

Additional note on AI model providers and data handling:

Our AI platform uses trusted, enterprise-grade language models to generate responses. These models act solely as data processors, receiving temporary input and returning a response in real time. They do not store personal data, do not use it for training, and all processing is fully encrypted and compliant with UK data protection regulations.