Privacy Policy

Last updated: 23/08/2026

Article 1 - GeneralArticle 2 - What personal data does Dentascribe collect?2.1 Data we collect about YOU (As a Data Controller)2.2 Data we process on your behalf (As a Data Processor)Article 3 - The legal basis and purposes of data processing3.1 General purposes (User Data)3.2 Processing Patient Data3.3 Direct Marketing & Promotional CampaignsArticle 4 - Transfer to Third Parties and Sub-processors4.1 Artificial Intelligence Sub-processors4.2 International Transfers4.3 Business Transfers and Legal RequirementsArticle 5 - Cookies and AnalyticsArticle 6 - The duration of the processing (Data Retention)6.1 Retention of User Data6.2 Retention of Patient Data (Auto-Deletion)Article 7 - Security and Client-Side EncryptionArticle 8 - Your RightsArticle 9 - Changes to our Privacy PolicyArticle 10 - Contact and Complaints

Article 1 - General

Dentascribe (hereinafter, “we”, “us”, “our”, “Dentascribe”) provides an AI-powered clinical note-taking tool (hereinafter: “Tool”) for dental professionals.

To understand how we handle data, it is important to distinguish between two legal roles we fulfill under the UK General Data Protection Regulation (UK GDPR):

  1. As a Data Controller: We act as the Controller for the personal data of our users (dental professionals) regarding their account, billing, and platform usage.
  2. As a Data Processor: We act as the Processor for any patient data (ePHI) submitted to the Tool. We process this data strictly on the instructions of the user (the dental professional), who remains the Data Controller for their patients’ medical records.

The access to or use of our Tool implies your full and unreserved understanding of this Privacy Policy. Our websites and tools are not intended for children.

Article 2 - What personal data does Dentascribe collect?

2.1 Data we collect about YOU (As a Data Controller)

When you use Dentascribe, we collect the following data to manage your account and improve our services:

Data CategoryDetailsContext
Identification & AccountName, Email address, GDC number, Practice details.Collected when you create an account to use our Tool.
Marketing, Promotions & WaitlistsName, personal or work email, academic or practice affiliation (e.g., dental school, graduation year), referral source.Collected when you register for promotional offers (such as our Foundation Dentist programme), join a waitlist, or request updates.
Technical DataIP address, browser type, device metadata.Processed to protect against malicious use, ensure security, and provide technical support.
Payment InformationName, Email, Billing address, Payment details (processed via Stripe).Collected when you subscribe to a paid plan.
Usage DataPseudonymous user IDs, features used, session replays.We use analytics tools to understand how the Tool is used. Session recordings are strictly configured to mask and exclude all patient information and clinical text.

Note on Special Categories: Dentascribe does not collect any Special Categories of Personal Data about you as a user (e.g., your race, religious beliefs, or health data).

2.2 Data we process on your behalf (As a Data Processor)

When you use the Tool during clinical practice, we process the following data on your behalf:

Article 3 - The legal basis and purposes of data processing

3.1 General purposes (User Data)

We process your User Data based on the following lawful bases:

3.2 Processing Patient Data

We process Patient Data solely for the purpose of providing the transcription and note-generation service, based on our Terms of Service and Data Processing Agreement (DPA) with you. You, as the Controller, are responsible for ensuring a lawful basis (and patient consent, if applicable) exists for this processing.

3.3 Direct Marketing & Promotional Campaigns

Article 4 - Transfer to Third Parties and Sub-processors

Dentascribe treats Personal Data as confidential information. We do not sell or hire out your Personal Data to third parties. We only disclose data to third parties to the extent necessary to carry out our business activities (such as email delivery, payment processing, and cloud hosting).

4.1 Artificial Intelligence Sub-processors

To provide our AI features, we utilize highly vetted third-party sub-processors (e.g., Groq, AssemblyAI).

4.2 International Transfers

We may transfer data outside the UK/EU to facilitate our services. Any such transfers are safeguarded by UK GDPR Adequacy Decisions or Standard Contractual Clauses (SCCs) / the UK International Data Transfer Agreement (IDTA).

Article 5 - Cookies and Analytics

Our website and Tool use cookies and similar tracking technologies to track usage, remember your preferences, and secure your session. We use third-party analytics tools (such as PostHog) to gather and analyze information about your use of the Tool. For the avoidance of doubt, no Protected Health Information (PHI) or sensitive patient data is shared with or transmitted to these analytics tools. You can configure your browser to reject cookies, though this may limit the functionality of the Tool.

Article 6 - The duration of the processing (Data Retention)

6.1 Retention of User Data

6.2 Retention of Patient Data (Auto-Deletion)

Dentascribe is a clinical drafting tool, not a permanent Patient Management System (PMS). We enforce strict data minimisation:

Article 7 - Security and Client-Side Encryption

Dentascribe implements robust technical and organisational measures to protect data against unauthorised access, loss, or destruction.

Client-Side Encryption: As our primary safeguard, highly sensitive patient clinical data (including text notes and daylist images) is client-side encrypted before being stored in our cloud databases. This means the data is locked using keys held only on your local device. Dentascribe staff, administrators, and our sub-processors have zero-knowledge access and cannot read your plaintext patient data.

You share responsibility for security by maintaining strong passwords, enabling Two-Factor Authentication (2FA), and securing your local devices.

Article 8 - Your Rights

Under the UK GDPR, you have the following rights regarding your personal data:

Note regarding Patient Rights: If a patient wishes to exercise their data rights (e.g., a Data Subject Access Request), they must contact you (the dental professional) directly. Dentascribe cannot fulfill patient requests directly as we do not have the decryption keys to access their clinical data. We provide you with the in-app tools to export their data to fulfill your obligations.

Article 9 - Changes to our Privacy Policy

We reserve the right to change, modify, and update this Privacy Policy from time to time. We will notify you of any significant changes via email or an in-app notification. We recommend you regularly consult this policy to ensure you are aware of how we protect your data.

Article 10 - Contact and Complaints

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us at: Email: contact@dentascribe.uk

We aim to respond to all legitimate requests within 30 days. You also have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would appreciate the chance to deal with your concerns before you approach the ICO.