Security and data protection
PlainAnswer is used by dental practices, clinics and professional services, so protecting data is not an afterthought. Here, in plain terms, is how we do it, and what we do and do not claim.
What the assistant collects
During ordinary questions, nothing about the visitor is collected. The assistant answers only from your own website content. A visitor's personal details are collected in just one case: when the visitor chooses to leave their name, phone or email so you can get back to them.
Where that data goes
When a visitor leaves their details, we send them straight to you by email and place them in your dashboard so the lead is not lost. That data belongs to you. Under UK GDPR you are the data controller and we are your processor: we handle it only to provide the service to you, never for our own purposes, and we never sell it or share it with other customers.
Isolation and internal access
Every business's data is isolated to its own account. No other customer can ever see your enquiries. Just as importantly, our own internal and admin tools show only counts and totals, for example how many leads a customer has received. They do not expose your visitors' names, phone numbers or emails. As the people who operate the database we have the same technical access any hosting provider has, which is exactly why our Data Processing Agreement legally binds us to access it only as needed to run and support the service.
Automatic deletion after 90 days
Visitor contact details that are captured through the widget are automatically deleted from our systems 90 days after they are captured. You keep your own copy, emailed to you at the moment of capture, so nothing is lost to you. We simply do not retain visitor contact details long-term. You can also ask us to delete data held for you at any time.
Passwordless, verified sign-in
There is no password to steal, guess or leak. Signing in uses a one-time link that works once and expires in 15 minutes, sent to your registered email. An account is only ever created after that link is clicked, so no one can create an account in your name simply by typing your address, and sign-in requests are rate-limited to prevent abuse of your inbox.
Encryption and hosting
All traffic between your visitors, your website and PlainAnswer is encrypted in transit using TLS (HTTPS). PlainAnswer runs on established, security-focused cloud infrastructure. If your organisation has specific data-residency requirements, please get in touch and we will be glad to discuss them.
Answers only from your content
Security is not only about storage; it is also about what the assistant says. PlainAnswer answers strictly from your own website and the information you give it, and it shows the source of each answer. It cannot invent a price, a policy or a clinical claim in your name. When it does not know, it says so and captures the enquiry rather than guessing.
Providers we rely on
We use a small number of established providers to run the service: cloud hosting, an AI model provider to generate answers, and an email provider to deliver notifications. Each receives only what it needs to do its job. Our full list of sub-processors is set out in our Data Processing Agreement.
Your rights and our commitments
You can ask us for a copy of, or the deletion of, the data we hold for you. If a personal data breach ever affected your data, we would notify you without undue delay, as the law requires. Culture & Clarity Ltd is registered with the UK Information Commissioner's Office (ICO), registration reference ZC161196.
Common questions
Can your staff see our patients' or customers' details?
Not through the product. Our internal dashboards show only counts, never contact details, and your data is isolated to your account. As the operator of the database we have the same technical access any host does, which our Data Processing Agreement restricts to running and supporting the service.
Where is our data stored?
On established cloud infrastructure that PlainAnswer operates. If you have a specific region or residency requirement, contact us and we will discuss the options.
How long do you keep the details a visitor leaves?
Contact details captured through the widget are automatically deleted from our systems after 90 days. You keep your own emailed copy. We can also delete data sooner on request.
Do you have a Data Processing Agreement?
Yes. It sets out the roles, the sub-processors, and how we handle your data as your processor. You can read it at /dpa.
Questions about security or data?
Email us at hello@plainanswer.co.uk. See also our Privacy Policy and Data Processing Agreement.
Read the DPA