Babblevoice
Fully hosted, cloud-based telephone system designed for the health industry, to free up practice staff to focus on delivering care.
Features
- Fully hosted, cloud based telephone system designed for health industry
- Full management of your phone system from the desktop
- Fully integrates with medical records (EMIS & SystmOne)
- Patient access module - appt automation
- Call recording
- Reporting suite
- Simple self management of call rules
- Dedicated, customer support
- No minimum contract
- Day/date checking within rules
Benefits
- Easy to use
- Frees up reception time
- Frees up doctors time
- Virtually unlimited concurrent calls
- Reduced call queues
- Improved patient satisfaction
- Improved training
- Reduced costs
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 3 9 4 6 7 7 7 6 5 1 0 4 3 1
Contact
BABBLE LIMITED
Antoine Lever
Telephone: 01442 299280
Email: info@babblevoice.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Other
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Helpdesk support is limited to Polycom E220 and E350. Yealink phones T42U, T54W, W73P and W52P
- System requirements
- Stable internet connection.
User support
- Email or online ticketing support
- Yes
- Support response times
-
Monday to Friday, 8 am to 6:30 pm
For normal priority issues, response is within 12 hours.
High priority issues, response is within 1 hour.
Critical priority issues, response within 15 minutes. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Clients report via email or phone.
Our helpdesk is staffed by our Engineers, Monday to Friday, 8 am to 6:30 pm.
Outside of these hours, we monitor our service and respond accordingly.
All remote support is provided free of charge. On site support may be chargeable. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We carry out several step in the set up process. This is dependant on customer needs and requirements
* Email chat
* Online meetings as required
* Onsite installation and training
* Free online training.
*Manual - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- Users can extract their data using our web console or our API.
- End-of-contract process
- There are no exit fees. Any service which incurs a regular fee will be terminated when the customer requests it to be stopped, and this request can be made through our helpdesk.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Available on our website or can be emailed out to customers as a pdf.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The cloud system allows access via mobile and desktop in the same way.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Configuration is all done under a self-service platform that we call the console.
- Accessibility standards
- None or don’t know
- Description of accessibility
-
Enlarge text for soft phones.
Outside of this, we rely on built-in browser accessibility features. - Accessibility testing
- Hearing aid testing for compatibility with desk phones, with their built in features.
- API
- Yes
- What users can and can't do using the API
-
We have an API which is typically used for reporting. It can be used to configure, however our web interface is generally used for this. There are no limitations as our own web tools use the identical API.
Anything that can be done in our console, desktop or Vibes can be accomplished using our API. - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Users can customise the phone system to their specific needs, by logging into the console.
Scaling
- Independence of resources
- The load is spread across several servers, and we have automatic load balancing in operation. We also closely monitor the service and have alerts in place for high usage.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Historic call statistics
Live statistics
Queueing statistics
Agent statistics
Call pathway statistics
Live queue
Live agent - Reporting types
-
- API access
- Real-time dashboards
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Call recordings can be exported via the console via mp3 or wav files. The call data record can be downloaded as a csv file.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Mp3
- Wav
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- Docker via an internally encrypted network
Availability and resilience
- Guaranteed availability
-
Our system will be available 24/7, 365 days a year with an uptime of >99.9%.
Users can make a complaint/raise the issue of availability via phone call or email and will be dealt with by our Customer Care Manager in line with our Complaints Policy. - Approach to resilience
- Available on request
- Outage reporting
- An outage can be communicated to customers via email, a banner placed on our website and a voice message placed on our phone system for incoming callers.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Identity federation with existing provider (for example Google Apps)
- Other
- Other user authentication
- We use Google single sign on, NHS login, and authenticate email addresses using email confirmation links.
- Access restrictions in management interfaces and support channels
- Role based permissions system that is configured by the User.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Identity federation with existing provider (for example Google Apps)
- Other
- Description of management access authentication
- Google single sign on, NHS login and email authentication via confirmation links.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- Less than 1 month
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- We have an Information Security Policy, Access Control Policy and Process, Business Continuity Plan, Capacity Management Process, Change Request Policy and Process, Cloud Computing Policy, Cloud Exit Strategy, Data Leakage Prevention Policy, Data Masking Policy, Data Protection Policy, Development Process, Document Management Policy, Hiring and Leaving Policy and Leaving Process, New Starter Process, Home Working Policy, Information Classification Policy, Information Exchange Policy, IT & Communications System Policy, Monitoring and Review Policy, Network Systems Policy, Personally Identifiable Data within Babblevoice Policy, Purchasing Policy, Remote Access Policy, Risk Management Policy and Process, Secure Development Policy, Security Incident Reporting Policy, Virus Protection Policy.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- All changes are required to be authorised by the Operations Director or part of the ISMS Management Team.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We receive threat reports which are reviewed by our Technical Lead and then communicated throughout the company as required. We have an incident reporting policy and all staff are responsible for identifying potential threats. Security updates are deployed within 14 days. AWS OS updates are applied within 14 days. We have an annual PEN Test conducted by an external provider.
We receive information about potential threats from the NHS High Severity Alert Service, NHS England CSOC, NCSC alerts, Google workspace reporting and Periculo. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We have a security incident reporting process in place, and all staff are required to report any potential incidents.
Incidents are also flagged by PEN Testing, EOL software scanning and CE.
The incidents are reviewed by the Technical Lead or Operations Director, and given a risk score and appropriate mitigation decided upon. - Incident management type
- Supplier-defined controls
- Incident management approach
-
There is a Security Incident reporting policy in place, and any threats/incidents must be reported on the incident reporting form, which is available to all staff. This is then reviewed by the Compliance Team and the Operations Director if required, any remediation is decided upon and long term solutions identified as appropriate. Personal data breaches must be reported within 72 hours, to the ICO through the DSPT reporting tool, unless it is unlikely to result in a risk to the rights and freedoms of individuals.
Users of the system can report incidents to our helpdesk via email or phone call - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- All the features are available to trial and we provide demo funds to try out all services.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 15%
- Between £1,000,001 and £2,500,000
- 20%
- Between £2,500,001 and £5,000,000
- 25%
- Over £5,000,001
- 30%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- LRQA
- ISO/IEC 27001 accreditation date
- Saturday 9 November 2024
- What the ISO/IEC 27001 doesn’t cover
- There are no exclusions to our 27001 certification.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- LRQA
- ISO 9001 accreditation date
- Friday 14 February 2025
- What the ISO 9001 doesn’t cover
- 7.1.5.2 Measurement Traceability, as babblevoice does not use any measuring equipment
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 83d36e88-fbfe-4b1b-86f0-c10d443cd92f
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- Yes
- Any other security certifications
-
- NHS Digital Data Security and Protection Toolkit
- NHS DTAC compliant
- Compliant with DCB0129 Clinical Risk Management standards
- Compliant with DCB0160 Clinical Risk Management standards
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-