Privacy Policy
Last updated: 23/08/2026
Article 1 - General
Dentascribe (hereinafter, “we”, “us”, “our”, “Dentascribe”) provides an AI-powered clinical note-taking tool (hereinafter: “Tool”) for dental professionals.
To understand how we handle data, it is important to distinguish between two legal roles we fulfill under the UK General Data Protection Regulation (UK GDPR):
- As a Data Controller: We act as the Controller for the personal data of our users (dental professionals) regarding their account, billing, and platform usage.
- As a Data Processor: We act as the Processor for any patient data (ePHI) submitted to the Tool. We process this data strictly on the instructions of the user (the dental professional), who remains the Data Controller for their patients’ medical records.
The access to or use of our Tool implies your full and unreserved understanding of this Privacy Policy. Our websites and tools are not intended for children.
Article 2 - What personal data does Dentascribe collect?
2.1 Data we collect about YOU (As a Data Controller)
When you use Dentascribe, we collect the following data to manage your account and improve our services:
| Data Category | Details | Context |
|---|---|---|
| Identification & Account | Name, Email address, GDC number, Practice details. | Collected when you create an account to use our Tool. |
| Marketing, Promotions & Waitlists | Name, personal or work email, academic or practice affiliation (e.g., dental school, graduation year), referral source. | Collected when you register for promotional offers (such as our Foundation Dentist programme), join a waitlist, or request updates. |
| Technical Data | IP address, browser type, device metadata. | Processed to protect against malicious use, ensure security, and provide technical support. |
| Payment Information | Name, Email, Billing address, Payment details (processed via Stripe). | Collected when you subscribe to a paid plan. |
| Usage Data | Pseudonymous user IDs, features used, session replays. | We use analytics tools to understand how the Tool is used. Session recordings are strictly configured to mask and exclude all patient information and clinical text. |
Note on Special Categories: Dentascribe does not collect any Special Categories of Personal Data about you as a user (e.g., your race, religious beliefs, or health data).
2.2 Data we process on your behalf (As a Data Processor)
When you use the Tool during clinical practice, we process the following data on your behalf:
- Patient Health Data (Special Category Data): Audio recordings of consultations, generated clinical notes, and dental history.
- Patient Media: Uploaded images of daily appointment schedules (daylists).
- Patient Contact Data: Patient email addresses (strictly for the delivery of generated letters/secure links).
Article 3 - The legal basis and purposes of data processing
3.1 General purposes (User Data)
We process your User Data based on the following lawful bases:
- Performance of a Contract: To create your profile, provide the Tool, and process subscription payments.
- Legitimate Interests: To analyze usage (via pseudonymised IDs) to improve our services, troubleshoot bugs, and maintain platform security.
- Legal Obligation: To retain financial records for tax and accounting purposes.
3.2 Processing Patient Data
We process Patient Data solely for the purpose of providing the transcription and note-generation service, based on our Terms of Service and Data Processing Agreement (DPA) with you. You, as the Controller, are responsible for ensuring a lawful basis (and patient consent, if applicable) exists for this processing.
3.3 Direct Marketing & Promotional Campaigns
- Registered Users: If you are a registered user, we may use your email to send you updates regarding Dentascribe features or similar services, based on our legitimate interests. You can opt out at any time by clicking “unsubscribe” in any email or by contacting us. We never use Patient Data for marketing.
- Promotions & Offers (e.g., Foundation Dentist / DFT Programme): When you register for a promotional offer, waitlist, or educational campaign (such as the DFT offer at dentascribe.uk/dft), we process your name, contact email, academic affiliation, and graduation year based on your consent. We use this data to deliver your promotional credits or vouchers (e.g., the £60 post-DFT credit) and send emails about the offer. You can withdraw your consent at any time via the unsubscribe link in our emails or by emailing contact@dentascribe.uk. Joining these lists is optional; you can also request promotional credits directly by email without subscribing. Promotional lists are kept strictly separate from Dentascribe application accounts and patient data.
Article 4 - Transfer to Third Parties and Sub-processors
Dentascribe treats Personal Data as confidential information. We do not sell or hire out your Personal Data to third parties. We only disclose data to third parties to the extent necessary to carry out our business activities (such as email delivery, payment processing, and cloud hosting).
4.1 Artificial Intelligence Sub-processors
To provide our AI features, we utilize highly vetted third-party sub-processors (e.g., Groq, AssemblyAI).
- Zero-Retention AI: Our AI partners process audio, daylists, and text ephemerally. They do not retain your audio, images, or transcripts after the request is completed.
- No Model Training: We strictly prohibit our AI partners from using any User Data or Patient Data to train, improve, or fine-tune their AI models.
4.2 International Transfers
We may transfer data outside the UK/EU to facilitate our services. Any such transfers are safeguarded by UK GDPR Adequacy Decisions or Standard Contractual Clauses (SCCs) / the UK International Data Transfer Agreement (IDTA).
4.3 Business Transfers and Legal Requirements
- Business Transfers: In the event of a total or partial reorganisation, merger, or sale of Dentascribe’s assets, your Personal Data may be transferred to the new entity. We will inform you in advance of such a transfer.
- Legal Requirements: In extraordinary circumstances, Dentascribe may be obliged to transfer your Personal Data following a court order or to comply with imperative laws and regulations. We will, if reasonably possible, try to inform you beforehand unless legally constrained.
Article 5 - Cookies and Analytics
Our website and Tool use cookies and similar tracking technologies to track usage, remember your preferences, and secure your session. We use third-party analytics tools (such as PostHog) to gather and analyze information about your use of the Tool. For the avoidance of doubt, no Protected Health Information (PHI) or sensitive patient data is shared with or transmitted to these analytics tools. You can configure your browser to reject cookies, though this may limit the functionality of the Tool.
Article 6 - The duration of the processing (Data Retention)
6.1 Retention of User Data
- Account and Billing Data: We store your account and billing data for as long as you have an active account. Upon account deletion, financial records may be retained for up to 7 years to comply with statutory accounting and tax laws.
- Marketing & Promotional Lists: We retain your promotional contact information until you unsubscribe or withdraw consent, or for the active duration of the relevant campaign (typically up to 6 months after the applicable training/graduation year, or 12 months from signup), after which your details are permanently removed from our mailing lists.
6.2 Retention of Patient Data (Auto-Deletion)
Dentascribe is a clinical drafting tool, not a permanent Patient Management System (PMS). We enforce strict data minimisation:
- Standard Purge: All appointments, clinical notes, daylists, and generated letters are permanently and automatically purged from our servers after 3 months.
- Local Privacy Mode: If enabled, clinical data is purged from the application after 14 days.
- Secure Links: Links sent to patients automatically expire after 30 days.
Article 7 - Security and Client-Side Encryption
Dentascribe implements robust technical and organisational measures to protect data against unauthorised access, loss, or destruction.
Client-Side Encryption: As our primary safeguard, highly sensitive patient clinical data (including text notes and daylist images) is client-side encrypted before being stored in our cloud databases. This means the data is locked using keys held only on your local device. Dentascribe staff, administrators, and our sub-processors have zero-knowledge access and cannot read your plaintext patient data.
You share responsibility for security by maintaining strong passwords, enabling Two-Factor Authentication (2FA), and securing your local devices.
Article 8 - Your Rights
Under the UK GDPR, you have the following rights regarding your personal data:
- Right of Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can ask us to correct or update inaccurate or incomplete data.
- Right to Erasure: You can ask us to delete your personal data, provided it is no longer necessary for the purposes it was collected and we are not legally required to retain it.
- Right to Restrict or Object: You can object to our processing of your data (e.g., for direct marketing) or ask us to restrict processing under certain conditions.
- Right to Data Portability: You can request your data in a structured, commonly used, and machine-readable format.
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw it at any time.
Note regarding Patient Rights: If a patient wishes to exercise their data rights (e.g., a Data Subject Access Request), they must contact you (the dental professional) directly. Dentascribe cannot fulfill patient requests directly as we do not have the decryption keys to access their clinical data. We provide you with the in-app tools to export their data to fulfill your obligations.
Article 9 - Changes to our Privacy Policy
We reserve the right to change, modify, and update this Privacy Policy from time to time. We will notify you of any significant changes via email or an in-app notification. We recommend you regularly consult this policy to ensure you are aware of how we protect your data.
Article 10 - Contact and Complaints
If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us at: Email: contact@dentascribe.uk
We aim to respond to all legitimate requests within 30 days. You also have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would appreciate the chance to deal with your concerns before you approach the ICO.
