Privacy Policy
Last updated: 7 July 2026
DentConsentUK handles special category health data. We take our obligations under UK GDPR seriously. This policy explains exactly what we collect, why, and how it is protected.
1. Who we are
DentConsentUK Ltd ("we", "us", "our") operates the DentConsentUK platform at dentconsentuk.co.uk. We are registered in England and Wales.
For data protection purposes, we act in two capacities:
• As a Data Controller in respect of information about dentists and practices who subscribe to our platform
• As a Data Processor on behalf of dental practices in respect of patient personal data processed through the platform
ICO Registration: DentConsentUK Ltd is registered with the Information Commissioner's Office (ICO) as required under UK GDPR.
Contact: hello@dentconsentuk.co.uk
2. What data we collect
About dentists and practices (as Data Controller):
• Name, GDC number, email address, password (hashed)
• Practice name, address, phone number
• Billing information (processed by Stripe — we do not store card details)
• Usage data including consent sessions created, login activity, and platform interactions
About patients (as Data Processor on behalf of the dental practice):
• Name, date of birth, mobile number, postcode
• NHS number (where provided)
• Sex at birth (as required for the FP17PR NHS declaration)
• Treatment options reviewed and decisions made
• FP17PR patient declaration data including entitlement status
• Digital signature (drawn image)
• IP address and device information at time of signing
• Timestamp of form completion
Patient data is processed on the instructions of, and on behalf of, the dental practice. The dental practice is the Data Controller for patient data.
3. Legal basis for processing
For dentist and practice data (Data Controller):
• Contract performance — to provide the subscription service you have signed up for
• Legitimate interests — to improve the platform, prevent fraud, and maintain security
For patient data (Data Processor):
Patient data constitutes special category data under UK GDPR Article 9 (health data). We process it under Article 9(2)(h) — processing necessary for the provision of health or social care — on behalf of the dental practice as Data Controller.
The dental practice is responsible for establishing and documenting their own lawful basis for collecting and using patient data via our platform.
4. How we use your data
Dentist and practice data is used to:
• Provide and maintain your subscription
• Process payments and manage billing
• Send service notifications (subscription updates, consent completions)
• Respond to support enquiries
• Improve and develop the platform
Patient data is used to:
• Generate and deliver consent session links to patients
• Record and store consent responses, FP17PR declarations, and digital signatures
• Generate PDF consent records and email them to the subscribing dental practice
• Maintain audit logs for regulatory compliance
5. Data sharing and third-party processors
We share data with the following trusted third-party processors who act under our instructions and are bound by data processing agreements:
• Supabase (database and storage) — data stored in AWS eu-west-2, London, UK
• Stripe (payment processing) — for subscription billing; no patient data is shared with Stripe
• Twilio (SMS delivery) — patient mobile numbers are used to send consent links; Twilio processes data under their GDPR-compliant terms
• Resend (email delivery) — used to email consent PDFs to dental practices
We do not sell, rent, or share personal data with third parties for marketing purposes.
Patient consent records and all stored data are hosted in the United Kingdom (AWS London, eu-west-2). Two sub-processors used to deliver messages — Twilio (SMS) and Resend (email) — may process limited personal data (a patient's mobile number, or a practice email address) on infrastructure outside the UK. Where this occurs, the transfer is covered by appropriate safeguards such as Standard Contractual Clauses and the UK International Data Transfer Addendum, in accordance with UK GDPR.
6. Data retention
Dentist and practice account data: Retained for the duration of your subscription plus 7 years for billing and tax records.
Patient consent records: Retained for a minimum of 10 years from creation date, in line with GDC guidance on clinical record retention for adults. Records for patients treated as children are retained until the patient's 25th birthday.
Incomplete or expired consent sessions: Patient-identifiable data is purged after 30 days.
Waitlist data: Email addresses collected via the waitlist are retained until you request removal or until the purpose for collection has been fulfilled.
Contact form submissions: Retained for 2 years.
7. Your rights
As an individual whose data we hold, you have the following rights under UK GDPR:
• Right of access — to obtain a copy of your personal data
• Right to rectification — to correct inaccurate data
• Right to erasure — to request deletion of your data (subject to retention obligations)
• Right to restriction — to restrict how we process your data
• Right to data portability — to receive your data in a structured, machine-readable format
• Right to object — to object to processing based on legitimate interests
For patient data held on behalf of a dental practice: patients should exercise their rights directly with the dental practice (the Data Controller). We will assist the practice in responding to such requests.
To exercise your rights, contact us at: hello@dentconsentuk.co.uk
We will respond within one calendar month. If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
8. Cookies
DentConsentUK uses the following cookies:
Essential cookies (no consent required):
• Authentication session cookies — required to keep you logged in to the dentist dashboard
• Security cookies — used to prevent cross-site request forgery
We do not use advertising, tracking, or analytics cookies on this site. We do not use Google Analytics or any similar third-party analytics services.
The patient portal (dcpp.dentconsentuk.co.uk) uses only essential session cookies required for the consent process to function.
9. Security
We implement appropriate technical and organisational measures to protect personal data, including:
• All data encrypted in transit (TLS 1.2+) and at rest
• Database stored in UK data centres with access controls
• Patient consent links expire after 72 hours
• Patient identity verified via date of birth before accessing consent forms
• All access to production data is logged and audited
• Stripe handles all payment card data — we never handle or store card numbers
In the event of a personal data breach affecting patient data, we will notify the dental practice (as Data Controller) without undue delay and no later than 72 hours after becoming aware, in accordance with UK GDPR Article 33.
10. Children's data
Our dentist platform is not intended for use by persons under 18. For patients who are under 18, the consent process may be completed by a parent, guardian, or other appropriate representative. In such cases, the representative's details are recorded alongside the patient's details in the consent record.
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Where changes are material, we will notify you by email with at least 14 days' notice before the changes take effect.
12. Contact and complaints
For any privacy-related queries, to exercise your rights, or to request our Data Processing Agreement:
DentConsentUK Ltd
hello@dentconsentuk.co.uk
dentconsentuk.co.uk
Please mark your email "Data Protection" and we will respond within one calendar month.
If you are not satisfied with how we handle your request, you have the right to lodge a complaint with the ICO:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
ico.org.uk | 0303 123 1113