Privacy Policy

Visitly · Last updated: 6 July 2026

This policy explains how Visitly processes personal data: of Specialists who hold accounts, of people who call the numbers our assistant answers, and of visitors to this website.

1. Who we are and what we are responsible for

The Visitly service is provided by Marcin Zajączkowski, trading as Marcin Zajączkowski IT Services, with its registered office in Warsaw, Poland (ul. Srebrna 3/61, 00-810 Warszawa), entered in the Polish CEIDG business register, NIP: 7011281265, REGON: 542948311 ("we", "Visitly"). Contact for data matters: contact@visitly-app.com.

For Specialist account data and website visitor data, we are the data controller.

Patient data, meaning data of people who call a practice and book visits, is processed on behalf of the Specialist who runs that practice. The Specialist is the controller of that data and Visitly acts as a processor (Article 28 GDPR). The Terms of Service set out that processing arrangement.

2. What data we process

Specialist accounts:

  • name, email address, phone number (verified by SMS code),
  • password, stored only as a cryptographic hash,
  • billing details needed to issue an invoice and process payment (payments are handled by Tpay),
  • practice details: services, prices, working hours,
  • device identifiers needed for push notifications.

Phone calls handled by the assistant:

  • the caller's phone number (unless withheld),
  • call audio, processed in real time to understand speech and hold the conversation,
  • a transcript of the call and details given during it: name, chosen service, appointment time,
  • if health-related information comes up in a call (for example the reason for a visit), it is processed solely to handle the booking on behalf of the Specialist.

A caller may decline to share a phone number; the visit can then be recorded without one.

Website: your language preference (a cookie) and basic server logs (IP address, request time) needed for security and to keep the service running.

3. Why we process data and on what legal basis

  • running accounts, providing the service and billing Specialists: Article 6(1)(b) GDPR (contract),
  • answering calls and managing the calendar on a Specialist's behalf: on their documented instructions, under a processing agreement (Article 28 GDPR); the legal basis towards Patients is provided by the Specialist as controller, and for health data it is as a rule Article 9(2)(h) GDPR (healthcare),
  • service security, abuse prevention and error diagnostics: Article 6(1)(f) GDPR (legitimate interest),
  • legal obligations, for example tax and accounting: Article 6(1)(c) GDPR.

We do not use the data for advertising and we do not sell it to anyone.

4. Calls with the AI assistant

Calls are answered by an automated system (an AI voice assistant). Callers are told they are talking to an automated assistant at the start of the call.

Each call produces a text transcript, which the Specialist sees in their app. We do not store audio recordings of calls after they end; the audio is processed in real time and only the text transcript and the visit details are retained.

The assistant does not make decisions with legal effects for callers. It books, reschedules or cancels visits only within the rules set by the Specialist, who keeps full control of their calendar.

5. How long we keep data

  • account data and billing data: for as long as the account exists, and after closure for the period required by tax law and needed to defend against claims, no longer than 6 years,
  • call transcripts and visit data: for the duration of the service for a given Specialist, and after the contract ends deleted or returned within 30 days, unless the Specialist requests earlier deletion,
  • technical logs: up to 90 days.

6. Who we share data with

We use processors under data processing agreements:

  • Google Cloud: application and database hosting (region europe-west1, European Union),
  • Telnyx: telephone calls and SMS,
  • OpenAI: real-time speech processing needed to hold the conversation,
  • Google Firebase: sign-in and phone number verification,
  • Vercel: hosting of this website,
  • OneSignal: push notifications for Specialists,
  • Tpay (Krajowy Integrator Płatności S.A., Poznan): Specialist payment processing.

Data may be disclosed to competent public authorities where the law requires it.

7. Transfers outside the EEA

The database and application servers run in the European Union. Some of our providers (including telephony and speech processing) may process data in the United States. In those cases the transfer relies on an adequacy decision (the EU-US Data Privacy Framework) or the EU standard contractual clauses. More information: contact@visitly-app.com.

8. Your rights

You have the right to:

  • access your data and receive a copy of it,
  • rectification, erasure or restriction of processing,
  • data portability,
  • object to processing based on legitimate interest,
  • complain to a supervisory authority; in Poland this is the President of the Personal Data Protection Office (PUODO, ul. Stawki 2, 00-193 Warsaw).

We handle requests at no charge: write to contact@visitly-app.com. If you contacted a practice as a patient, the Specialist is the controller of your data and your request is best addressed to them; on their instruction we will help carry it out.

9. Cookies

  • visitly-lang: remembers your chosen site language (12 months), set only after you use the language switcher,
  • sign-in session cookies: necessary for your account, set when you log in,
  • we use no analytics or advertising cookies.

10. Security

Our measures include encryption in transit (TLS), data storage in EU data centres, access controls, passwords stored only as hashes, and separation of production and test environments.

11. Changes to this policy and contact

We may update this policy as the service evolves. We will announce material changes on this page, and to Specialists also by email. Questions: contact@visitly-app.com.