Privacy Notice

Privacy Notice
EricaAI and Regulated Healthcare Professional Live Chat
Effective: 21 July 2026

PRIVACY AT A GLANCE

Epical Global Ltd is responsible for the personal information processed within EricaAI. You can use the chat without giving us your name or email, although technical identifiers such as an IP address may still be personal information. EricaAI generates an automated response from a controlled knowledge base using OpenAI's API, configured for European regional processing and Zero Data Retention. Every EricaAI response is reviewed by an appropriately regulated healthcare professional before the conversation is resolved. Business Customers do not receive identifiable chats; they receive only anonymous and aggregated reporting. |


1. Who we are

EricaAI is operated by Epical Global Ltd (company number 12065790), registered office: 82A James Carter Rd, Mildenhall, Suffolk, IP28 7DE.
Epical Global Ltd is registered with the Information Commissioner's Office under registration number ZA784751.
For personal information processed within EricaAI - including the clinical chat process, automated response generation, professional review, clinical governance and retention of the chat record - Epical Global Ltd acts as the data controller. This means we decide why and how that information is used.
Where EricaAI is accessed through another organisation's website or platform (a "Business Customer"), that Business Customer is separately responsible for personal information it collects through its own website or services. It does not have access to identifiable EricaAI conversations and cannot instruct Epical Global Ltd to alter, access, retain or delete an individual clinical conversation. Business Customers receive only anonymous and aggregated reports.

2. Who this notice applies to

This Privacy Notice applies to people who use EricaAI and our regulated healthcare professional live chat ("End Users"), and to representatives of organisations that purchase, integrate or administer the service ("Business Customers").
The service is intended for people aged 16 and over. It is not intended for use by children under 16. Adult End Users may provide information about their baby or child where relevant to their question; that information is also protected under this Privacy Notice.

3. Personal information we collect

Information from End Users

You may use the chat without providing your name or email address. If you choose to identify yourself, we may collect your name and email address. Even where you do not provide identifying details, technical information such as an IP address may still constitute personal information.
Depending on what you choose to tell us, we may process:
·   chat messages, conversation history, timestamps and the subject of your question;
·   pregnancy stage or estimated due date;
·   a baby's date of birth or age;
·   medical, pregnancy and birth history relevant to the conversation;
·   photographs, documents or test results that you choose to upload;
·   feedback, satisfaction scores and comments about the service;
·   IP address, device and browser information, session information and approximate country or regional location; and
·   the EricaAI automated response, the professional review, any amendment or correction, and the final resolution of the conversation.
We do not ask for telephone number, date of birth, NHS number, GP or maternity-team details, medication details, login credentials or payment information as standard End User fields. However, if you voluntarily include any of this information in a free-text message or upload, it will form part of the chat record.

Information from Business Customers

For Business Customers and their representatives, we may collect:
·   organisation name, business contact details and authorised representative information;
·   contract, service configuration and account-administration information;
·   billing, transaction and accounting information; and
·   correspondence, support requests and service-management records.

4. Special category health information

Information about pregnancy, maternal health, medical history, birth and infant health is health information and is treated as special category personal data under UK data protection law.
We process this information where it is necessary to provide healthcare advice and support, to review EricaAI responses, to maintain an appropriate clinical record, and to manage the quality and safety of the healthcare service. This processing is carried out by, or under the responsibility of, regulated healthcare professionals who are subject to professional confidentiality obligations.
Our principal special-category condition for this processing is Article 9(2)(h) UK GDPR (health or social care), together with Schedule 1 condition 2 of the Data Protection Act 2018. Other conditions may apply where necessary, for example for legal claims, vital interests or where disclosure is required by law.

5. How EricaAI and professional review work

EricaAI generates a written automated response using information retrieved from our secure, private and controlled knowledge base. It is configured to answer only within its defined knowledge scope.
To generate the response, the relevant user query and necessary knowledge-base content are securely sent to OpenAI's API. Our OpenAI environment is configured for European regional processing and Zero Data Retention. OpenAI does not use the submitted customer content to train its models.
You may see EricaAI's response before it has been reviewed by a healthcare professional. Every EricaAI response is reviewed, without exception, by an appropriately regulated healthcare professional before the conversation can be marked as resolved. Reviewers include NMC-registered midwives and, where appropriate, professionals regulated by the Health and Care Professions Council (HCPC).
The reviewer can see the full conversation and may confirm, clarify, add to, amend or correct the automated response. Any amendment or correction is communicated through the same chat. The original automated response, the review and any correction are retained as part of the audit trail. Our target is for professional review to take place within 24 hours, although this is not an emergency or time-critical service.

6. Automated processing

EricaAI uses automated processing to generate a written response. It does not classify clinical urgency or risk, triage symptoms, prioritise conversations, create a clinical score or flag, route a person to a particular service, or make decisions about whether or how a person receives healthcare.
We do not use EricaAI to make solely automated decisions that produce legal effects or similarly significant effects on you. Every response is subject to meaningful professional review before the conversation is resolved.

7. Why we use personal information and our lawful bases

We only use personal information where we have a lawful basis. The principal bases relevant to EricaAI are set out below.

Purpose

UK GDPR Article 6 basis

Health-data condition where relevant

Provide EricaAI and live-chat healthcare support; generate responses; carry out mandatory professional review and maintain the clinical record.

Legitimate interests - providing the healthcare support requested through the service and operating that service safely and effectively.

Article 9(2)(h) - health or social care; DPA 2018 Schedule 1 condition 2.

Clinical governance, quality assurance, audit, complaints, incidents and service safety.

Legitimate interests and, where applicable, legal obligation.

Article 9(2)(h), and where applicable Article 9(2)(f) for legal claims or another applicable condition.

Security, fraud prevention, technical operation and service administration.

Legitimate interests in protecting users, systems and the service; legal obligation where applicable.

Normally not applicable unless health information is necessarily involved.

Anonymise information, evaluate service quality, identify knowledge gaps and improve the controlled knowledge base.

Legitimate interests in improving the quality, safety and usefulness of the service.

Article 9(2)(h) where health information is processed before effective anonymisation.

Business Customer contracting, account administration, billing and support.

Contract where the individual is a contracting party; otherwise legitimate interests in managing business relationships; legal obligation for accounting/tax records.

Not normally applicable.

Where we rely on legitimate interests, we assess the purpose, necessity and impact on your rights and freedoms. You may contact our Data Protection Lead if you would like more information about this assessment.

We do not rely on consent as the principal UK GDPR lawful basis for providing direct healthcare support. This is separate from any clinical or professional consent that may be relevant to care itself.

8. How we use information to improve EricaAI

Identifiable chat conversations are not used to train or fine-tune EricaAI or OpenAI's models.
We may use anonymised or aggregated information to identify recurring questions, knowledge gaps, service-quality issues and areas where our controlled knowledge base can be improved. Where information is processed in order to anonymise it, access is restricted and the minimum information necessary is used.
Business Customers may receive anonymous and aggregated maternal-health insights, trend information and service-usage analytics. They do not receive identifiable chat transcripts or information that is intended to identify an individual End User.

9. Who we share personal information with

Personal information is only shared where necessary for the purposes described in this notice. Recipients may include:
·   NMC-registered midwives, HCPC-regulated professionals and authorised Epical Global Ltd personnel who need access to provide, review, govern or support the service;
·   Crisp IM SAS, our chat-platform provider, which processes chat content and related technical information on our behalf. Crisp Enrich and Crisp's optional AI features are disabled;
·   OpenAI, which processes the relevant query and necessary knowledge-base content solely to generate an EricaAI response through our configured API environment;
·   professional advisers, insurers, auditors and legal advisers where necessary for governance, complaints, incidents, claims or legal obligations; and
·   regulators, courts, law-enforcement bodies, emergency services or other authorities where disclosure is required or permitted by law.
Crisp hosts and processes chat information on our instructions. Its personnel do not routinely access End User conversations; any access by Crisp personnel is contractually restricted to authorised access necessary to provide or support the platform and is subject to confidentiality and security controls.
Where you ask us to share information, or give consent to sharing with your healthcare team or another service, we will only share information that is reasonably necessary. In exceptional safeguarding or emergency circumstances, we may disclose information where we are legally permitted or required to do so. Our ability to take action may be limited if you have used the chat anonymously or we do not know your location.

10. International processing and transfers

Our core customer content is hosted and processed within Europe. Crisp IM SAS is based in France, with encrypted backup infrastructure described by Crisp as being located in Ireland.
Customer content submitted to OpenAI for response generation is configured for European regional processing and Zero Data Retention. OpenAI's regional controls apply to customer content; certain system, account, usage or administrative data may be handled separately by OpenAI under its service terms.
Where personal information is transferred outside the UK to a country that is not covered by UK adequacy regulations, we use an appropriate lawful transfer mechanism, such as the UK International Data Transfer Agreement, the UK Addendum to approved Standard Contractual Clauses, or another safeguard permitted by UK data protection law.

11. How long we keep information

We keep personal information only for as long as necessary for the purpose for which it was collected and to meet clinical, professional, legal, insurance and regulatory requirements.

Record

Retention period

End User chat conversations, EricaAI responses, professional reviews and corrections

Minimum of 7 years from closure of the conversation. Longer only where there is a documented clinical, legal, regulatory, insurance, complaints or litigation reason.

Complaints and incident records

Minimum of 7 years, with longer retention where necessary for an active matter, legal claim or regulatory requirement.

Business Customer account and service-management information

For the duration of the contract and 12 months after the contract ends, unless longer retention is required for a specific legal or operational reason.

Billing and accounting records

Normally 6 years from the end of the relevant financial year, or longer where required by law.

Business marketing/contact data

Until the Business Customer relationship or relevant contract ends, unless we are required to retain a suppression record or another lawful reason applies.

Backups

Subject to the same applicable retention periods as the underlying information and protected from routine use except for recovery and continuity purposes.

If information is fully anonymised so that it can no longer identify an individual, it is no longer personal information and may be retained for statistical, research, governance or service-improvement purposes.

12. Security

We use technical and organisational measures designed to protect personal information against unauthorised access, loss, misuse, alteration or disclosure.
Measures relevant to the service include:
·   encryption of data in transit and at rest;
·   role-based and need-to-know access controls;
·   confidentiality requirements for personnel with access to health information;
·   background checks for personnel with sensitive-data access where appropriate;
·   formal incident-response and personal-data-breach procedures;
·   security and contractual controls applying to Crisp, OpenAI and other authorised processors; and
·   a maintained Data Protection Impact Assessment (DPIA) covering EricaAI and the clinical chat service.
No online service can guarantee absolute security. We regularly review our safeguards and update them where necessary to reflect risk, technology and legal requirements.

13. Your data protection rights

Depending on the circumstances, you may have the right to ask us to:
·   give you access to the personal information we hold about you;
·   correct inaccurate or incomplete information;
·   erase personal information where the right to erasure applies;
·   restrict the way we use your information;
·   provide certain information in a portable format where the right to data portability applies;
·   object to processing based on legitimate interests; and
·   explain how automated processing is used and provide human involvement where required by law.
Some rights are not absolute. In particular, we may need to retain healthcare, complaint, legal or regulatory records even where you ask for deletion. We will explain any restriction that applies when we respond to your request.
If you used the chat without providing identifying information, we may need enough information to locate the relevant record, such as an email address you provided, a conversation reference or approximate date and time. We will not ask for more information than reasonably necessary to verify your identity and locate the record.
To exercise your rights, contact our Data Protection Lead at joanne.parkington@ericaai.co.uk. We normally respond within one month, subject to any lawful extension for complex or multiple requests.

14. Data protection complaints

If you are concerned about how we have used your personal information, you can make a data protection complaint directly to our Data Protection Lead at joanne.parkington@ericaai.co.uk.
We will acknowledge a data protection complaint within 30 days of receiving it. We will take appropriate steps to investigate and respond without undue delay, keep you informed where appropriate, and tell you the outcome.
You also have the right to complain to the Information Commissioner's Office (ICO), the UK regulator for data protection. Information about making a complaint is available at www.ico.org.uk.

15. Children

EricaAI is intended for users aged 16 and over. We do not knowingly offer the service directly to children under 16.
An adult End User may discuss a baby or child and may provide information about that child where relevant. We will process that information only where necessary for the service and in accordance with this Privacy Notice.
If we become aware that a person under 16 has provided personal information through the service, we will assess the appropriate action in light of the circumstances, the individual's safety and any legal, clinical or record-keeping obligations.

16. Changes to this Privacy Notice

We may update this Privacy Notice where our service, technology, suppliers, legal obligations or data-processing practices change. The effective date at the beginning of the notice shows when this version took effect. Material changes will be brought to users' attention in an appropriate way.

17. Contact us

Data Protection Lead
Epical Global Ltd
82A James Carter Rd, Mildenhall, Suffolk, IP28 7DE
Email: joanne.parkington@ericaai.co.uk
ICO registration number: ZA784751

Updated on: 24/07/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!