1. Who we are
Motics Technologies Ltd (“Motics”, “we”, “us” or “our”) is a company registered in England and Wales under company number 12277558. Our registered office is 1 Canada Square, Motics, Fora Level 8, London, England, E14 5AB.
This notice is provided under the UK General Data Protection Regulation, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations, as amended. The EU GDPR and other privacy laws may also apply to particular processing.
Motics provides AI-enabled workflow software for healthcare organisations. This notice applies to our websites, public demos, customer account administration, support, marketing and other business relationships where Motics decides why and how personal information is used.
Our accountable privacy contact is the Privacy Lead, Motics Technologies Ltd. Questions or requests can be sent to support@motics.co.uk. Please use the subject line “Data protection” so we can route your message promptly.
Security, compliance and current service sub-processor information is available in our Trust Centre.
2. Scope and our roles
When Motics is a controller
Motics is normally the controller for information about website visitors, prospective customers, customer and supplier contacts, account administrators, job applicants, and people who contact our team or use a public demo. We decide the purposes described in this notice.
When Motics is a processor
A clinic or other healthcare customer normally remains the controller for patient and clinical information processed through the Motics service. Motics processes that information on the customer’s documented instructions and under a data processing agreement.
If your information was handled through a clinic’s use of Motics, that clinic’s privacy notice is the primary notice for the processing. Please contact the clinic first to exercise your rights. We support the clinic in responding as required by our contract and applicable law.
A customer’s contract, statement of work and data processing agreement may contain more specific instructions about service data, security, location, retention, return and deletion. Those documents govern our processor activities if they differ from this general explanation.
3. Information we use and where it comes from
We use only the information reasonably needed for the relevant purpose. Depending on how you interact with us, this may include:
- Identity and business contact information, such as your name, work email address, telephone number, employer, role and professional details.
- Enquiry, marketing and relationship information, such as messages, demo requests, event attendance, meeting details, feedback, communication preferences and records of our correspondence.
- Account and service administration information, such as login and authentication details, permissions, organisation membership, configuration, support requests, training records, audit events and service usage metadata.
- Commercial and billing information, such as contracts, billing contacts and addresses, invoices, payment status and transaction references.
- Website and device information, such as IP address, browser and device type, approximate location, referring page, pages and features used, timestamps, campaign parameters, click identifiers and consent choices.
- Public demo information, such as work contact details, organisation, the choices and fictional inputs you provide, microphone audio and generated content where a voice feature is requested, session and diagnostic information, and feedback.
- Recruitment and supplier information, such as application, work history, professional, payment and due diligence information where relevant.
- Patient and clinical information processed for a customer, which may include identifiers, contact and appointment details, call audio and transcripts, clinical notes, correspondence, billing information and health data. Motics handles this information as a processor unless the facts of a particular activity require a different role.
We collect information directly from you; from the customer or organisation you represent; from customer-authorised systems and integrations; automatically from devices and website technologies; from service providers such as booking, CRM and analytics providers; and, where appropriate, from professional networks, public business sources or referrals.
4. Why we use information and our lawful bases
The lawful basis depends on the purpose and our role. More than one basis may apply where the law permits it.
| Purpose | Information typically involved | Lawful basis |
|---|---|---|
| Respond to enquiries; arrange demos; provide requested website tools, accounts, onboarding and support | Identity, contact, organisation, communications, account and demo information | Steps at your request before a contract; performance of a contract; and our legitimate interests in responding and providing our services |
| Manage customer, supplier and partner relationships, contracts, billing and records | Contact, commercial, account, billing and communication information | Performance of a contract; legal obligations; and our legitimate interests in running and documenting our business |
| Operate, secure, troubleshoot and prevent misuse of our websites and services | Account, device, log, audit, security and limited service metadata | Our legitimate interests in keeping systems reliable and secure; contract; and legal obligations |
| Measure and improve our websites, products and customer experience | Website usage, consent choices, feedback, support and de-identified or aggregated service information | Our legitimate interests where permitted, when the processing is necessary, proportionate and does not require consent; consent where required for optional device technologies |
| Send relevant business marketing and measure campaigns | Business contact, relationship, preference, website and campaign information | Consent where required; otherwise our legitimate interests in promoting our services to relevant business contacts, subject to your right to object |
| Recruit people and manage applications | Identity, contact, career, assessment, eligibility and reasonable-adjustment information | Steps before a contract; legal obligations; and our legitimate interests in recruitment and defending claims |
| Meet legal, regulatory, audit and insurance requirements; establish or defend claims; and manage a corporate transaction | Information relevant to the obligation, audit, claim or transaction | Legal obligations and our legitimate interests in compliance, risk management and protecting legal rights |
| Process patient and clinical information through the Motics service for a healthcare customer | Customer service data, including health information where relevant | The customer determines and documents the applicable Article 6 basis and Article 9 condition. Motics processes on the customer’s documented instructions under our data processing agreement. |
Our legitimate interests include operating and improving a business-to-business service, securing our systems, supporting customers, understanding service performance, keeping records, communicating with relevant professional contacts and protecting legal rights. We assess those interests against the likely impact on individuals and do not rely on them where your rights and interests override ours.
Health information and other special-category information receive additional protection. When Motics acts as controller, we identify both a lawful basis and an applicable special- category condition before using it—for example, employment law obligations or the establishment, exercise or defence of legal claims. When Motics acts as processor, the healthcare customer is responsible for identifying and communicating its conditions for processing.
Where information is required to enter or perform a contract, comply with law, secure an account or provide a feature, we will indicate this or explain it on request. If it is not provided, we may be unable to open the account, provide the feature or enter the relationship. Other fields are optional.
5. AI and automated processing
Motics services use AI to transcribe information, generate draft clinical documentation and communications, support phone workflows, and assist with billing and audit tasks. The exact processing depends on the service selected and the customer’s configuration and instructions.
- We do not use patient data to train, fine-tune or improve our AI models. We require sub-processors that handle patient data for us not to use it for their own model training.
- Clinical outputs are drafts designed for review and approval by an appropriately qualified person. Motics does not autonomously diagnose a patient or prescribe treatment.
- Motics does not use personal information in its controller capacity to make solely automated decisions that produce legal or similarly significant effects. If that changes, we will provide the information and safeguards required by law.
Customers are responsible for deploying the services in a lawful way, maintaining appropriate human oversight and providing their own notices where they determine the purposes of AI-assisted processing. Our data processing agreement and Trust Centre provide more information about service providers and safeguards.
7. International transfers
Motics is based in the United Kingdom, and some providers or recipients may process information in other countries. Primary customer service data is stored in the region agreed in the customer contract, statement of work or data processing agreement. Where reasonably available and consistent with the customer's instructions, we also select processing locations aligned with that storage region.
Limited processing or support may take place in other countries to provide a customer-authorised function, security or technical support. This does not by itself change the agreed primary storage region. Any temporary handling and retention by a service provider is limited by its purpose, our contract with that provider and the applicable customer terms; customer-specific commitments govern where they are more restrictive.
Where a transfer is restricted by data protection law, we use an available legal mechanism such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, or EU Standard Contractual Clauses where the EU GDPR applies. We complete the required transfer assessment or data protection test and add supplementary measures where appropriate.
Your account manager can confirm the arrangements agreed for a specific customer, or you can email support@motics.co.uk. Our Trust Centre provides current sub-processor information; the customer's contract governs its specific service-data locations and other arrangements.
8. How long we keep information
We do not keep all information for one fixed period. We use documented criteria based on the purpose, the amount and sensitivity of the information, legal and contractual requirements, security needs and the risk of harm from further retention.
- Customer service data is retained, returned or deleted according to the customer’s configuration, instructions and contract, subject to legal holds and limited records we must keep for audit or compliance.
- Account, contract, billing and business records are kept for the relationship and then for the period needed to meet tax, accounting, audit and limitation requirements.
- Enquiry, support and demo records, including work contact details and operational demo status, are kept while we respond, manage the relationship, improve safety and quality, and address disputes or follow-up, then deleted or anonymised when no longer needed.
- Public voice-demo content is processed to provide the live simulation. Motics does not keep an audio recording in its own operational systems. We retain the automatically redacted text transcript and related contact, status and technical records under the enquiry and demo criteria above. The AI service provider may temporarily retain inputs, context and outputs for a limited period under its contracted terms for security, abuse prevention and required legal or regulatory disclosures. This information is not used to train or improve general AI models. Contact us for the current maximum provider-retention period.
- Marketing contact information is kept while relevant to our business relationship or until you object. We may keep a minimal suppression record so we continue to honour an opt-out.
- Security logs and website records are kept for periods proportionate to detecting incidents, preventing abuse, demonstrating choices and analysing performance.
Deletion may take time to flow through encrypted backups. Data in backups is isolated from ordinary use and expires through a controlled backup lifecycle unless a legal hold applies. Where appropriate, we irreversibly anonymise information instead of deleting it.
9. How we protect information
We use technical and organisational measures designed for the nature and risk of the processing. Depending on the system and risk, these may include access controls and least privilege, encryption in transit and at rest, logging and monitoring, secure development and change controls, supplier due diligence, staff confidentiality and training, resilience measures, incident response and periodic review. No internet service can eliminate every risk, so we continually review and improve these controls.
More information is available on our Security page and in our Trust Centre. Service-specific commitments are set out in the applicable customer contract and Trust Centre materials; the Security page provides a high-level overview and does not replace them.
11. Marketing choices
We may send relevant information about Motics to professional contacts where the law permits. You can object at any time by using the unsubscribe link in a message or emailing us. You can also contact us to object to website advertising technologies where applicable law provides that right. We will stop direct marketing to you, although we may still send service, security or contractual messages that are not marketing.
12. Your data protection rights
Depending on the law, our role, the lawful basis and the facts, you may have rights to:
- receive information about how your data is used;
- access personal information and receive a copy;
- correct incomplete or inaccurate information;
- ask for deletion or restriction in qualifying cases;
- receive or transfer certain information in a portable format;
- object to processing based on legitimate interests;
- object at any time to direct marketing;
- withdraw consent at any time where processing relies on consent; and
- request human intervention, express your view and challenge a qualifying significant automated decision.
Rights are not absolute and lawful exemptions may apply. We normally do not charge a fee, but the law may allow a reasonable fee or refusal for a request that is manifestly unfounded or excessive. We may ask for proportionate information to verify your identity and protect data from unauthorised disclosure.
To exercise a right concerning information Motics controls, email support@motics.co.uk. If Motics holds the information only for a healthcare customer, please contact that customer; we will assist them as required.
13. Additional regional disclosures
The following information supplements the rest of this notice where the law in the relevant region applies to our processing.
Ireland and the EEA
The EU GDPR applies where its territorial scope is met, including relevant processing connected with offering services to, or monitoring the behaviour of, people in Ireland or elsewhere in the European Economic Area. In those circumstances, the rights described in section 12 apply. You may also complain to a supervisory authority in the country where you live or work, or where you believe an infringement occurred. People in Ireland can raise a concern with the Irish Data Protection Commission.
United States
Where an applicable US state consumer privacy law applies, the categories collected in the preceding 12 months may include identifiers and customer-record information; commercial information; internet or other electronic network activity; approximate geolocation; audio, electronic or visual information; professional or employment information; and inferences drawn from website activity or our business relationship. Depending on the interaction, sensitive personal information may include account access credentials and health information handled for a healthcare customer. Sections 3 and 4 describe the sources and purposes, section 6 describes the recipients to whom relevant categories may be disclosed for business purposes, and section 8 describes retention.
Depending on your state and the circumstances, you may have the right to confirm whether we process your information; know, access, correct or delete it; receive a portable copy; opt out of sale, sharing or targeted advertising; limit certain uses or disclosures of sensitive personal information; appeal a refusal; and use an authorised agent. We will not discriminate against you for exercising an applicable right. We may take reasonable steps to verify your identity, authority and state of residence. Submit a request to support@motics.co.uk.
We do not sell personal information for money. Advertising and measurement providers may receive identifiers and website, device and campaign activity to measure and attribute campaigns; some state laws may treat this as selling, sharing or targeted advertising. You may submit an opt-out request at the address above. Where an applicable law requires a specific opt-out link or legally recognised opt-out preference signals, we will provide and honour those mechanisms. In our own business activities, we do not use or disclose sensitive personal information to infer characteristics about you for advertising or consumer profiling, and we do not sell or share customer patient information for advertising. Health information processed for a healthcare customer is handled under that customer's documented instructions and notice and, where applicable, a Business Associate Agreement.
Before any US deployment handles protected health information, an appropriate customer-specific Business Associate Agreement must be in place and Motics and the customer must complete the service-readiness steps for that deployment. If a US healthcare customer is a covered entity and Motics acts as its business associate, protected health information is governed by applicable law, the customer's notice and that agreement. This general notice does not replace those documents or expand Motics' role.
Canada
Motics does not currently offer the service in Québec, and this subsection does not provide Québec-specific disclosures. Where Canadian privacy law otherwise applies, our Privacy Lead is accountable for Motics' compliance with that law. Subject to lawful exceptions, you may ask to access or correct information about you, withdraw consent where the processing relies on consent, and challenge our compliance. We may take reasonable steps to verify your identity before responding.
Personal information may be processed outside Canada or your province and, while there, may be subject to the laws of the country where it is processed, including lawful access by courts, law enforcement or other authorities. Motics remains accountable for personal information under its control and uses contractual and other safeguards appropriate to the processing. Sections 6 and 7 explain recipients and international transfers.
Contact the Privacy Lead at support@motics.co.uk with a request or concern. You may also contact the Office of the Privacy Commissioner of Canada or an applicable provincial privacy regulator.
Jersey
Where the Data Protection (Jersey) Law 2018 applies, you may exercise the rights described in section 12 and the transfer safeguards in section 7 apply as required. You may raise a concern with the Jersey Office of the Information Commissioner.
14. Children
Our website, business communications and account administration are directed to healthcare organisations and authorised professional users, not directly to children. A healthcare customer may lawfully use Motics to process information about a child patient. In that situation the customer is responsible for the care purpose, lawful basis, notices and any consent or authority required, and Motics processes the information under the customer’s instructions.
15. Complaints and contact details
You can raise a data protection concern electronically by emailing support@motics.co.uk with the subject “Data protection complaint”, or by writing to our registered office. Please explain what happened, which information or service is involved, and the outcome you are seeking. We will acknowledge a complaint promptly, investigate it appropriately and communicate an outcome without undue delay.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK data protection regulator. See the ICO’s complaint guidance. If another supervisory authority has jurisdiction—for example, where the EU GDPR applies—you may contact that authority instead. You do not need to contact us first.
16. Changes to this notice
We review this notice as our services, providers and legal obligations change. We will publish the updated version here and change the date above. If a change is material, we will take reasonable steps to bring it to the attention of affected people, such as through the service or a direct customer communication where appropriate.