Privacy Policy

Last updated: July 2026

1. Introduction

This Privacy Policy explains how Vansora Studio Private Limited, trading as Relaya ("we", "us", "our"), collects, uses, stores, and protects personal data when you use the Relaya platform.

We are committed to protecting personal data and operating controls intended to support applicable privacy requirements, including UK GDPR where it applies. Actual obligations depend on the parties, deployment, purposes, and governing law.

2. Data Controller

The data controller for personal data collected through the Relaya platform is:

Vansora Studio Private Limited (trading as Relaya)
Contact: support@relaya.one

3. Data We Collect

3.1 Practice Information

  • Practice name, address, and contact details
  • Business registration information
  • Billing and payment information (processed by Paddle)
  • Service configuration and preferences

3.2 Staff Information

  • Names and professional roles
  • Email addresses and phone numbers
  • Login credentials (passwords stored in hashed form only)
  • Usage data and activity logs

3.3 Patient Data

Patient data is processed by Relaya on behalf of your dental practice. In this context, your practice is the data controller and Relaya acts as the data processor. Patient data may include:

  • Patient names and contact details
  • Appointment history and scheduling information
  • Communication records (calls, messages)
  • Any other data your practice inputs into the system

3.4 Technical Data

  • IP addresses and browser information
  • Device type and operating system
  • Usage patterns and feature interactions
  • Error logs and performance data

4. Legal Bases for Processing

We process personal data under the following legal bases:

  • Contract performance: Processing necessary to provide the Relaya service as agreed in our Terms of Service.
  • Legitimate interest: Processing for service improvement, security, fraud prevention, and analytics, where our interests do not override your rights.
  • Consent: Processing for marketing communications and optional features, where you have given explicit consent. You may withdraw consent at any time.
  • Legal obligation: Processing required to comply with applicable laws and regulations.

5. How We Use Your Data

  • To provide, maintain, and improve the Relaya platform
  • To process payments and manage subscriptions (via Paddle)
  • To communicate with you about your account and the service
  • To provide customer support
  • To ensure the security and integrity of our systems
  • To comply with legal obligations
  • To send marketing communications (with your consent)

6. Sub-processors

We use the following third-party sub-processors to deliver our service:

Sub-processorPurposeLocation
PaddlePayment processing, billing, invoicingUK/EU
AWS (Amazon Web Services)Cloud hosting and data storageDeployment-specific region
TwilioSMS and voice communicationsUK/US
VapiAI voice processingUS
SendGridTransactional email deliveryUS

Sub-processor terms, transfer safeguards, and available regions are reviewed for the selected deployment and documented in the applicable agreement.

7. Data Storage and Security

  • Primary hosting region is selected and documented during implementation; UK-only residency is not guaranteed.
  • Data is encrypted at rest and in transit using industry-standard encryption protocols.
  • We implement appropriate technical and organisational measures to protect against unauthorised access, loss, or destruction of data.
  • Access to personal data is restricted to authorised personnel on a need-to-know basis.

8. Data Retention

  • Account data: Retained while your subscription is active, plus 30 days after cancellation to allow for reactivation or data export.
  • Patient data: Retained according to the data retention schedule agreed with your practice. Upon account cancellation, patient data is deleted after the 30-day retention period unless a longer period is required by law.
  • Technical logs: Retained for up to 12 months for security and troubleshooting purposes.
  • Marketing data: Retained until you withdraw consent or unsubscribe.

9. Your Rights

Under UK GDPR, you have the following rights regarding your personal data:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request correction of inaccurate or incomplete data.
  • Right to erasure: Request deletion of your personal data where there is no compelling reason for continued processing.
  • Right to data portability: Request your data in a structured, commonly used, machine-readable format.
  • Right to object: Object to processing based on legitimate interest or for direct marketing purposes.
  • Right to restrict processing: Request that we limit how we use your data in certain circumstances.
  • Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, contact us at support@relaya.one. We will respond within 30 days of receiving your request.

10. Patient Data and Your Practice

When your dental practice uses Relaya to manage patient information, your practice remains the data controller for that patient data. Relaya acts as a data processor, processing patient data solely on your instructions and in accordance with our Data Processing Agreement.

Your practice is responsible for ensuring that appropriate legal bases exist for processing patient data and that patients are informed about how their data is used.

11. International Transfers

Some of our sub-processors operate outside the UK. Where data is transferred internationally, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the ICO, or transfers to countries with an adequacy decision.

12. Cookies

Our website and platform use cookies and similar technologies to provide functionality, remember your preferences, and analyse usage. For detailed information about the cookies we use, please refer to our cookie banner settings.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or an in-app notification. The "Last updated" date at the top of this page indicates when the policy was last revised.

14. Complaints

If you are unhappy with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office
Website: ico.org.uk
Helpline: 0303 123 1113

We encourage you to contact us first at support@relaya.one so we can try to resolve any concerns directly.

15. India — Digital Personal Data Protection Act (DPDP), 2023

For users and practices in India, Relaya complies with the Digital Personal Data Protection Act, 2023 (DPDP Act). The following provisions apply:

Data Principal Rights (Sections 11–14)

  • Right to access: You may request a summary of your personal data being processed and the processing activities undertaken.
  • Right to correction and erasure: You may request correction of inaccurate or misleading data, completion of incomplete data, or erasure of data no longer necessary for the purpose it was collected.
  • Right to grievance redressal: You may raise grievances regarding data processing with our Grievance Officer (see Section 16 below).
  • Right to nominate: You may nominate another individual to exercise your rights in the event of your death or incapacity.

Purpose Limitation (Section 4)

Personal data is processed only for the lawful purposes stated in this Privacy Policy and for which consent was obtained or which are deemed legitimate under the DPDP Act. We do not process personal data for purposes incompatible with those for which it was collected.

Storage Limitation (Section 8(7))

Personal data is retained only for as long as necessary to fulfil the purpose for which it was collected. Once the purpose is no longer being served and retention is not required by law, the data shall be erased. Specific retention periods are outlined in Section 8 (Data Retention) above.

Cross-Border Transfers (Section 16)

Personal data may be transferred to countries outside India except those specifically restricted by the Central Government under Section 16 of the DPDP Act. Transfers are subject to appropriate contractual safeguards and security measures.

16. Grievance Officer

In accordance with the DPDP Act, 2023 and the Information Technology Act, 2000, we have appointed a Grievance Officer to address your concerns regarding data processing:

Grievance Officer: Abhishek Jha
Email: ceo@vansora.in
Address: Vansora Studio Private Limited, India
Response time: Within 7 business days of receipt

17. United States — HIPAA Compliance

For healthcare providers in the United States subject to the Health Insurance Portability and Accountability Act (HIPAA):

  • Relaya operates as a Business Associate under HIPAA when processing Protected Health Information (PHI) on behalf of Covered Entities.
  • A Business Associate Agreement (BAA) is available upon request. Contact legal@relaya.one to initiate.
  • PHI is encrypted at rest using AES-256-GCM and in transit using TLS 1.3.
  • All access to PHI is logged and auditable per §164.312(b) (Audit Controls).
  • In the event of a breach involving unsecured PHI, notification will be provided within 60 days per §164.410 (Notification by a Business Associate).

18. EU/UK GDPR — Additional Information

For data subjects in the European Economic Area (EEA) or United Kingdom, the following additional information applies under the General Data Protection Regulation (GDPR) and UK GDPR:

  • Data Controller: Vansora Studio Private Limited, India.
  • Lawful Basis: Contract performance (Article 6(1)(b)) for providing the service; Explicit consent for processing health data (Article 9(2)(a)) where applicable.
  • Exercising GDPR Rights: Data subjects may exercise their rights (access, rectification, erasure, portability, restriction, objection) by emailing privacy@relaya.one. We will respond within 30 days.
  • International Transfers: Where personal data is transferred outside the UK/EEA, Standard Contractual Clauses (SCCs) approved by the European Commission and/or the ICO are applied.
  • Data Retention: Clinical records are retained for a minimum of 5 years (or longer per local regulation). Account data is retained until a deletion request is made and processed.

19. Children's Data

Relaya does not knowingly collect or process personal data of children under the age of 18 without verifiable parental or guardian consent.

Where a healthcare practice creates patient records for minors (patients under 18), the treating healthcare professional is responsible for obtaining and documenting appropriate parental or guardian consent before entering personal data into the Relaya platform.

If we become aware that personal data of a child has been collected without appropriate consent, we will take steps to delete such data promptly.

20. Contact

For any questions or requests regarding this Privacy Policy or your personal data:

Email: support@relaya.one
Privacy inquiries: privacy@relaya.one
Phone: +1 951 629 9011
Company: Vansora Studio Private Limited (trading as Relaya)