Legal

Privacy notice

This notice explains how Motics handles personal information, the choices available to you, and the important difference between our role for our own business activities and our role when a healthcare provider uses Motics for patient care.

Last updated: 30 August 2026

1. Who we are

Motics Technologies Ltd (“Motics”, “we”, “us” or “our”) is a company registered in England and Wales under company number 12277558. Our registered office is 1 Canada Square, Motics, Fora Level 8, London, England, E14 5AB.

This notice is provided under the UK General Data Protection Regulation, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations, as amended. The EU GDPR and other privacy laws may also apply to particular processing.

Motics provides AI-enabled workflow software for healthcare organisations. This notice applies to our websites, public demos, customer account administration, support, marketing and other business relationships where Motics decides why and how personal information is used.

Our accountable privacy contact is the Privacy Lead, Motics Technologies Ltd. Questions or requests can be sent to support@motics.co.uk. Please use the subject line “Data protection” so we can route your message promptly.

Security, compliance and current service sub-processor information is available in our Trust Centre.

2. Scope and our roles

When Motics is a controller

Motics is normally the controller for information about website visitors, prospective customers, customer and supplier contacts, account administrators, job applicants, and people who contact our team or use a public demo. We decide the purposes described in this notice.

When Motics is a processor

A clinic or other healthcare customer normally remains the controller for patient and clinical information processed through the Motics service. Motics processes that information on the customer’s documented instructions and under a data processing agreement.

If your information was handled through a clinic’s use of Motics, that clinic’s privacy notice is the primary notice for the processing. Please contact the clinic first to exercise your rights. We support the clinic in responding as required by our contract and applicable law.

A customer’s contract, statement of work and data processing agreement may contain more specific instructions about service data, security, location, retention, return and deletion. Those documents govern our processor activities if they differ from this general explanation.

3. Information we use and where it comes from

We use only the information reasonably needed for the relevant purpose. Depending on how you interact with us, this may include:

  • Identity and business contact information, such as your name, work email address, telephone number, employer, role and professional details.
  • Enquiry, marketing and relationship information, such as messages, demo requests, event attendance, meeting details, feedback, communication preferences and records of our correspondence.
  • Account and service administration information, such as login and authentication details, permissions, organisation membership, configuration, support requests, training records, audit events and service usage metadata.
  • Commercial and billing information, such as contracts, billing contacts and addresses, invoices, payment status and transaction references.
  • Website and device information, such as IP address, browser and device type, approximate location, referring page, pages and features used, timestamps, campaign parameters, click identifiers and consent choices.
  • Public demo information, such as work contact details, organisation, the choices and fictional inputs you provide, microphone audio and generated content where a voice feature is requested, session and diagnostic information, and feedback.
  • Recruitment and supplier information, such as application, work history, professional, payment and due diligence information where relevant.
  • Patient and clinical information processed for a customer, which may include identifiers, contact and appointment details, call audio and transcripts, clinical notes, correspondence, billing information and health data. Motics handles this information as a processor unless the facts of a particular activity require a different role.

We collect information directly from you; from the customer or organisation you represent; from customer-authorised systems and integrations; automatically from devices and website technologies; from service providers such as booking, CRM and analytics providers; and, where appropriate, from professional networks, public business sources or referrals.

4. Why we use information and our lawful bases

The lawful basis depends on the purpose and our role. More than one basis may apply where the law permits it.

PurposeInformation typically involvedLawful basis
Respond to enquiries; arrange demos; provide requested website tools, accounts, onboarding and supportIdentity, contact, organisation, communications, account and demo informationSteps at your request before a contract; performance of a contract; and our legitimate interests in responding and providing our services
Manage customer, supplier and partner relationships, contracts, billing and recordsContact, commercial, account, billing and communication informationPerformance of a contract; legal obligations; and our legitimate interests in running and documenting our business
Operate, secure, troubleshoot and prevent misuse of our websites and servicesAccount, device, log, audit, security and limited service metadataOur legitimate interests in keeping systems reliable and secure; contract; and legal obligations
Measure and improve our websites, products and customer experienceWebsite usage, consent choices, feedback, support and de-identified or aggregated service informationOur legitimate interests where permitted, when the processing is necessary, proportionate and does not require consent; consent where required for optional device technologies
Send relevant business marketing and measure campaignsBusiness contact, relationship, preference, website and campaign informationConsent where required; otherwise our legitimate interests in promoting our services to relevant business contacts, subject to your right to object
Recruit people and manage applicationsIdentity, contact, career, assessment, eligibility and reasonable-adjustment informationSteps before a contract; legal obligations; and our legitimate interests in recruitment and defending claims
Meet legal, regulatory, audit and insurance requirements; establish or defend claims; and manage a corporate transactionInformation relevant to the obligation, audit, claim or transactionLegal obligations and our legitimate interests in compliance, risk management and protecting legal rights
Process patient and clinical information through the Motics service for a healthcare customerCustomer service data, including health information where relevantThe customer determines and documents the applicable Article 6 basis and Article 9 condition. Motics processes on the customer’s documented instructions under our data processing agreement.

Our legitimate interests include operating and improving a business-to-business service, securing our systems, supporting customers, understanding service performance, keeping records, communicating with relevant professional contacts and protecting legal rights. We assess those interests against the likely impact on individuals and do not rely on them where your rights and interests override ours.

Health information and other special-category information receive additional protection. When Motics acts as controller, we identify both a lawful basis and an applicable special- category condition before using it—for example, employment law obligations or the establishment, exercise or defence of legal claims. When Motics acts as processor, the healthcare customer is responsible for identifying and communicating its conditions for processing.

Where information is required to enter or perform a contract, comply with law, secure an account or provide a feature, we will indicate this or explain it on request. If it is not provided, we may be unable to open the account, provide the feature or enter the relationship. Other fields are optional.

5. AI and automated processing

Motics services use AI to transcribe information, generate draft clinical documentation and communications, support phone workflows, and assist with billing and audit tasks. The exact processing depends on the service selected and the customer’s configuration and instructions.

  • We do not use patient data to train, fine-tune or improve our AI models. We require sub-processors that handle patient data for us not to use it for their own model training.
  • Clinical outputs are drafts designed for review and approval by an appropriately qualified person. Motics does not autonomously diagnose a patient or prescribe treatment.
  • Motics does not use personal information in its controller capacity to make solely automated decisions that produce legal or similarly significant effects. If that changes, we will provide the information and safeguards required by law.

Customers are responsible for deploying the services in a lawful way, maintaining appropriate human oversight and providing their own notices where they determine the purposes of AI-assisted processing. Our data processing agreement and Trust Centre provide more information about service providers and safeguards.

6. Who receives personal information

Customer service data, including patient and clinical information. We disclose this information only:

  • on the customer's documented instructions, including to the customer and its authorised users;
  • to service sub-processors engaged in accordance with our data processing agreement where needed to provide, secure or support the services;
  • to customer-selected systems and integrations where the customer instructs us to connect or transfer data; or
  • where required by applicable law, a court order or a binding regulatory request.

We do not disclose patient or clinical information or other customer service content to advertisers, measurement platforms, investors, prospective buyers, lenders or other third parties for their own purposes, and we do not sell it. For transaction due diligence, we use aggregated, anonymised or redacted information wherever practicable. Any access to customer service data that is strictly necessary in connection with a financing, reorganisation or sale will be minimised, subject to confidentiality and lawful-use restrictions, and handled consistently with our customer contracts and data processing agreement.

Other personal information. For information Motics processes as a controller, such as account, website, support, marketing, supplier and business contact information, recipients may include:

  • the customer or organisation you represent and its authorised users;
  • CRM, booking, analytics, security, support and payment service providers acting for us;
  • professional advisers, auditors, certification bodies, insurers and financial institutions under confidentiality;
  • courts, regulators, law enforcement or other authorities where disclosure is required by applicable law, a court order or a binding regulatory request; and
  • potential investors, buyers or sellers and their advisers in connection with a financing, reorganisation or sale, subject to confidentiality, data minimisation and lawful-use restrictions.

We carry out due diligence, require appropriate contracts and restrict service-provider access to what is needed. Our Trust Centre provides current service sub-processor information. Customer-specific processing locations are confirmed through the applicable contract, statement of work or data processing agreement, or by the customer's account manager. Where our data processing agreement provides general authorisation for sub-processors, we notify customers of intended changes and allow objections in accordance with that agreement.

We do not sell personal information for money. Advertising and measurement platforms may receive website events, campaign and device information, online identifiers and, after a form or demo submission, hashed contact identifiers. We use this information to attribute and measure campaigns, not to provide healthcare services. This never includes patient or clinical information or customer service content. Hashing is a security measure and does not make personal information anonymous. Where applicable law treats this activity as “selling”, “sharing” or targeted advertising, you may submit an opt-out request by contacting us. We will also provide and honour any specific link-based or legally recognised opt-out preference mechanism required when that law applies.

7. International transfers

Motics is based in the United Kingdom, and some providers or recipients may process information in other countries. Primary customer service data is stored in the region agreed in the customer contract, statement of work or data processing agreement. Where reasonably available and consistent with the customer's instructions, we also select processing locations aligned with that storage region.

Limited processing or support may take place in other countries to provide a customer-authorised function, security or technical support. This does not by itself change the agreed primary storage region. Any temporary handling and retention by a service provider is limited by its purpose, our contract with that provider and the applicable customer terms; customer-specific commitments govern where they are more restrictive.

Where a transfer is restricted by data protection law, we use an available legal mechanism such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, or EU Standard Contractual Clauses where the EU GDPR applies. We complete the required transfer assessment or data protection test and add supplementary measures where appropriate.

Your account manager can confirm the arrangements agreed for a specific customer, or you can email support@motics.co.uk. Our Trust Centre provides current sub-processor information; the customer's contract governs its specific service-data locations and other arrangements.

8. How long we keep information

We do not keep all information for one fixed period. We use documented criteria based on the purpose, the amount and sensitivity of the information, legal and contractual requirements, security needs and the risk of harm from further retention.

  • Customer service data is retained, returned or deleted according to the customer’s configuration, instructions and contract, subject to legal holds and limited records we must keep for audit or compliance.
  • Account, contract, billing and business records are kept for the relationship and then for the period needed to meet tax, accounting, audit and limitation requirements.
  • Enquiry, support and demo records, including work contact details and operational demo status, are kept while we respond, manage the relationship, improve safety and quality, and address disputes or follow-up, then deleted or anonymised when no longer needed.
  • Public voice-demo content is processed to provide the live simulation. Motics does not keep an audio recording in its own operational systems. We retain the automatically redacted text transcript and related contact, status and technical records under the enquiry and demo criteria above. The AI service provider may temporarily retain inputs, context and outputs for a limited period under its contracted terms for security, abuse prevention and required legal or regulatory disclosures. This information is not used to train or improve general AI models. Contact us for the current maximum provider-retention period.
  • Marketing contact information is kept while relevant to our business relationship or until you object. We may keep a minimal suppression record so we continue to honour an opt-out.
  • Security logs and website records are kept for periods proportionate to detecting incidents, preventing abuse, demonstrating choices and analysing performance.

Deletion may take time to flow through encrypted backups. Data in backups is isolated from ordinary use and expires through a controlled backup lifecycle unless a legal hold applies. Where appropriate, we irreversibly anonymise information instead of deleting it.

9. How we protect information

We use technical and organisational measures designed for the nature and risk of the processing. Depending on the system and risk, these may include access controls and least privilege, encryption in transit and at rest, logging and monitoring, secure development and change controls, supplier due diligence, staff confidentiality and training, resilience measures, incident response and periodic review. No internet service can eliminate every risk, so we continually review and improve these controls.

More information is available on our Security page and in our Trust Centre. Service-specific commitments are set out in the applicable customer contract and Trust Centre materials; the Security page provides a high-level overview and does not replace them.

10. Cookies and similar technologies

Our website uses cookies, local storage, pixels, tags and similar technologies. Necessary technologies operate to provide the site and features you request. Analytics and marketing technologies may currently operate when the site loads.

CategoryPurpose and informationTypical durationControl
NecessaryMaintains requested sessions, provides requested features, protects forms and supports security and network delivery. If delivery of a demo transcript fails, local storage temporarily queues the redacted transcript and delivery status for another attempt.Session technologies usually end when the browser or tab closes. Browser-held demo transcript and delivery status may remain until successfully delivered or you clear browser data.Required where strictly necessary; blocking these technologies may prevent the site or a requested feature from working
Analytics and experimentationMeasures visits and interactions, diagnoses performance and tests website content. This may use online identifiers, device and network information, pages viewed and campaign information. We do not intentionally include submitted form contents or live voice content.From the browser session up to 24 months, depending on the technology and purpose. Local experiment state may remain until browser data is cleared.Use browser or device controls to block or clear storage; contact us to exercise applicable rights or object
MarketingAttributes campaigns, measures advertising, matches form conversions where permitted and limits how often a promotional offer appears. This may use campaign, device, network and online identifiers and, after a submission, hashed contact identifiers.From the browser session up to 24 months, depending on the technology and purpose. A Motics dismissal record lasts up to 14 days. Campaign attribution information stored by Motics in your browser, and some provider-set items, may remain until you clear browser data.Use browser or device controls and contact us to object or request an applicable opt-out
Third-party featuresProvides a feature you explicitly request, such as viewing meeting availability, opening a support form or running an interactive demo. The service receives the information you submit and ordinary network and device information.Session technologies ordinarily end when the browser or tab closes. Some persistent items may remain until you or your browser delete them; the external service's linked notice and controls explain its current settings.Ordinarily loaded after you activate the feature or follow its direct link

This table is our primary overview of website technologies and uses functional categories so the notice remains readable without publishing an internal provider inventory. Technologies and settings may change as our website develops. For more information about a category or to exercise an applicable right, email support@motics.co.uk.

You can use browser or device controls to block or delete cookies and local storage and limit some tracking, and contact us to object or request an opt-out where applicable law provides one. Blocking or deleting technologies may affect site features, does not necessarily stop every network request, and does not reverse processing that was lawful before your request. Items already set may remain until they expire or are deleted under the relevant retention arrangements.

11. Marketing choices

We may send relevant information about Motics to professional contacts where the law permits. You can object at any time by using the unsubscribe link in a message or emailing us. You can also contact us to object to website advertising technologies where applicable law provides that right. We will stop direct marketing to you, although we may still send service, security or contractual messages that are not marketing.

12. Your data protection rights

Depending on the law, our role, the lawful basis and the facts, you may have rights to:

  • receive information about how your data is used;
  • access personal information and receive a copy;
  • correct incomplete or inaccurate information;
  • ask for deletion or restriction in qualifying cases;
  • receive or transfer certain information in a portable format;
  • object to processing based on legitimate interests;
  • object at any time to direct marketing;
  • withdraw consent at any time where processing relies on consent; and
  • request human intervention, express your view and challenge a qualifying significant automated decision.

Rights are not absolute and lawful exemptions may apply. We normally do not charge a fee, but the law may allow a reasonable fee or refusal for a request that is manifestly unfounded or excessive. We may ask for proportionate information to verify your identity and protect data from unauthorised disclosure.

To exercise a right concerning information Motics controls, email support@motics.co.uk. If Motics holds the information only for a healthcare customer, please contact that customer; we will assist them as required.

13. Additional regional disclosures

The following information supplements the rest of this notice where the law in the relevant region applies to our processing.

Ireland and the EEA

The EU GDPR applies where its territorial scope is met, including relevant processing connected with offering services to, or monitoring the behaviour of, people in Ireland or elsewhere in the European Economic Area. In those circumstances, the rights described in section 12 apply. You may also complain to a supervisory authority in the country where you live or work, or where you believe an infringement occurred. People in Ireland can raise a concern with the Irish Data Protection Commission.

United States

Where an applicable US state consumer privacy law applies, the categories collected in the preceding 12 months may include identifiers and customer-record information; commercial information; internet or other electronic network activity; approximate geolocation; audio, electronic or visual information; professional or employment information; and inferences drawn from website activity or our business relationship. Depending on the interaction, sensitive personal information may include account access credentials and health information handled for a healthcare customer. Sections 3 and 4 describe the sources and purposes, section 6 describes the recipients to whom relevant categories may be disclosed for business purposes, and section 8 describes retention.

Depending on your state and the circumstances, you may have the right to confirm whether we process your information; know, access, correct or delete it; receive a portable copy; opt out of sale, sharing or targeted advertising; limit certain uses or disclosures of sensitive personal information; appeal a refusal; and use an authorised agent. We will not discriminate against you for exercising an applicable right. We may take reasonable steps to verify your identity, authority and state of residence. Submit a request to support@motics.co.uk.

We do not sell personal information for money. Advertising and measurement providers may receive identifiers and website, device and campaign activity to measure and attribute campaigns; some state laws may treat this as selling, sharing or targeted advertising. You may submit an opt-out request at the address above. Where an applicable law requires a specific opt-out link or legally recognised opt-out preference signals, we will provide and honour those mechanisms. In our own business activities, we do not use or disclose sensitive personal information to infer characteristics about you for advertising or consumer profiling, and we do not sell or share customer patient information for advertising. Health information processed for a healthcare customer is handled under that customer's documented instructions and notice and, where applicable, a Business Associate Agreement.

Before any US deployment handles protected health information, an appropriate customer-specific Business Associate Agreement must be in place and Motics and the customer must complete the service-readiness steps for that deployment. If a US healthcare customer is a covered entity and Motics acts as its business associate, protected health information is governed by applicable law, the customer's notice and that agreement. This general notice does not replace those documents or expand Motics' role.

Canada

Motics does not currently offer the service in Québec, and this subsection does not provide Québec-specific disclosures. Where Canadian privacy law otherwise applies, our Privacy Lead is accountable for Motics' compliance with that law. Subject to lawful exceptions, you may ask to access or correct information about you, withdraw consent where the processing relies on consent, and challenge our compliance. We may take reasonable steps to verify your identity before responding.

Personal information may be processed outside Canada or your province and, while there, may be subject to the laws of the country where it is processed, including lawful access by courts, law enforcement or other authorities. Motics remains accountable for personal information under its control and uses contractual and other safeguards appropriate to the processing. Sections 6 and 7 explain recipients and international transfers.

Contact the Privacy Lead at support@motics.co.uk with a request or concern. You may also contact the Office of the Privacy Commissioner of Canada or an applicable provincial privacy regulator.

Jersey

Where the Data Protection (Jersey) Law 2018 applies, you may exercise the rights described in section 12 and the transfer safeguards in section 7 apply as required. You may raise a concern with the Jersey Office of the Information Commissioner.

14. Children

Our website, business communications and account administration are directed to healthcare organisations and authorised professional users, not directly to children. A healthcare customer may lawfully use Motics to process information about a child patient. In that situation the customer is responsible for the care purpose, lawful basis, notices and any consent or authority required, and Motics processes the information under the customer’s instructions.

15. Complaints and contact details

You can raise a data protection concern electronically by emailing support@motics.co.uk with the subject “Data protection complaint”, or by writing to our registered office. Please explain what happened, which information or service is involved, and the outcome you are seeking. We will acknowledge a complaint promptly, investigate it appropriately and communicate an outcome without undue delay.

You also have the right to complain to the Information Commissioner’s Office (ICO), the UK data protection regulator. See the ICO’s complaint guidance. If another supervisory authority has jurisdiction—for example, where the EU GDPR applies—you may contact that authority instead. You do not need to contact us first.

16. Changes to this notice

We review this notice as our services, providers and legal obligations change. We will publish the updated version here and change the date above. If a change is material, we will take reasonable steps to bring it to the attention of affected people, such as through the service or a direct customer communication where appropriate.