1. Home
  2. Privacy Policy & Data Protection

Denturaa policies

Privacy Policy & Data Protection

Last updated: September 2026. This policy document reflects Denturaa’s clinical and operational standards across all UK clinic locations in accordance with UK GDPR, ICO, and ASA healthcare regulations.

On this page

  • 1. Data Controller & Clinic Practice Network
  • 2. Information Commissioner’s Office (ICO) Registration & Supervision
  • 3. Lawful Bases for Processing (UK GDPR Article 6)
  • 4. Special Category Health Data & Clinical Confidentiality (Article 9)
  • 5. Information We Collect and Process
  • 6. Google Calendar, Practice Systems & Sub-Processors
  • 7. Information Sharing with Third Parties, Rented Sites & Non-Employed Professionals
  • 8. Advertising, Marketing & Advertising Standards (ASA/CAP)
  • 9. Data Retention Periods & Clinical Records Schedules
  • 10. Your Statutory Rights Under UK GDPR
  • 11. Clinical Information Security & Governance
  • 12. Contact Our Data Compliance Team

1. Data Controller & Clinic Practice Network

UK GDPR & DPA 2018

This Privacy Policy explains how Denturaa Dental Systems and its affiliated clinic practices (operating in Birmingham, London, Manchester, Bristol, Nottingham, and Leeds) collect, hold, process, and protect your personal and healthcare information.

Depending on where you attend your consultation, the legal entity operating the local dental practice acts as the Data Controller (or joint controller) for your clinical records and in-person patient care. Denturaa acts as the controller for general website operations, direct appointment requests, and brand communications.

For any data protection inquiries, Subject Access Requests (DSAR), or to contact our Data Compliance Lead, please email contact@denturaa.com or write to our registered clinical compliance office.

  • Network Clinic Locations: Birmingham, London, Manchester, Bristol, Nottingham, Leeds.
  • Data Compliance Lead Contact: contact@denturaa.com
  • Scope: Applies to all website visitors, prospective patients booking consultations, and patients undergoing denture assessments.

2. Information Commissioner’s Office (ICO) Registration & Supervision

ICO Compliance

Denturaa and its operating dental clinics comply with the Data Protection (Charges and Information) Regulations 2018 and are registered with the UK Information Commissioner's Office (ICO), the statutory supervisory authority for data protection in the United Kingdom.

You have the unconditional statutory right to lodge a complaint at any time with the ICO if you believe your personal data has been handled unlawfully or your data protection rights have been infringed. We encourage patients to contact our compliance team first so we can promptly address any concern.

  • Supervisory Authority: Information Commissioner's Office (ICO)
  • Postal Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
  • Telephone Helpline: 0303 123 1113 (Mon–Fri)
  • Official Website & Live Portal: https://ico.org.uk

3. Lawful Bases for Processing (UK GDPR Article 6)

Article 6 UK GDPR

Under the UK General Data Protection Regulation (UK GDPR), we must have a valid lawful basis to process your personal data. We rely on the following legal grounds:

  • Contract & Pre-Contractual Steps (Article 6(1)(b)): Processing your name, contact details, clinic choice, and booking request to schedule your complimentary clinical denture consultation and send appointment reminders.
  • Consent (Article 6(1)(a)): Used for voluntary marketing communications, opt-in newsletter updates, and non-essential website cookies (which you can withdraw at any time).
  • Legal Obligation (Article 6(1)(c)): Retaining clinical treatment records, financial transactions, and statutory notifications required by healthcare legislation, tax authorities, and regulators.
  • Legitimate Interests (Article 6(1)(f)): Securing our website against cyber threats, managing fraud prevention, maintaining operational efficiency, and analyzing aggregated feedback to enhance patient services.

4. Special Category Health Data & Clinical Confidentiality (Article 9)

Article 9(2)(h) & Confidentiality

Personal data concerning health (including dental records, clinical photographs, oral impressions, edentulous status, medical histories, and treatment notes) constitutes 'Special Category Data' under UK GDPR Article 9.

We process health data strictly under UK GDPR Article 9(2)(h), which permits processing necessary for the provision of healthcare, medical diagnosis, dental treatment, or the management of healthcare systems.

All clinical data is handled by or under the direct supervision of registered dental professionals (Clinical Dental Technicians and Dental Surgeons) who are legally and ethically bound by statutory Standards for the Dental Team (Principle 4: Maintain and protect patients' information).

Security Notice: Please never submit sensitive diagnostic details, medical histories, or private dental photographs through general website inquiry fields or Google Calendar notes. Clinical histories are recorded securely in person during your clinical consultation.

5. Information We Collect and Process

To provide safe and responsive dental consultation services, we may collect the following categories of information:

  • Contact & Identity Details: Full name, telephone number, email address, preferred clinic location (e.g. Birmingham, London, Manchester, Bristol, Nottingham, or Leeds), and communication preferences.
  • Appointment & Booking Data: Selected appointment date, time, clinic venue, attendance records, and booking confirmation notes.
  • Clinical Consultation Records: Oral health assessments, denture history, impression models, and clinician notes recorded within the dental practice during your appointment.
  • Technical & Browsing Data: IP address, device type, browser information, pages visited, and interaction data collected via strictly necessary or consented cookies.

6. Google Calendar, Practice Systems & Sub-Processors

Our online consultation scheduling utilizes Google Calendar (Google Workspace). When you select an appointment slot, your booking is scheduled directly through Google's appointment scheduling infrastructure (https://calendar.app.google/9xSETLeBFFvqsvAYA).

Google operates as a data processor on our behalf, bound by strict Data Processing Agreements (DPAs) incorporating UK International Data Transfer Addendums and Standard Contractual Clauses (SCCs) to ensure equivalent protection for data transferred outside the UK.

In-clinic records, dental charts, and patient files are maintained inside dedicated dental practice management systems compliant with statutory healthcare governance rules, featuring encrypted databases, audit logging, and multi-factor authentication.

7. Information Sharing with Third Parties, Rented Sites & Non-Employed Professionals

Clinical Delivery & Third Parties

In accordance with our Booking Policy, we expressly advise that Denturaa operates alongside third-party clinical sites, rented surgeries, and partner dental companies. Clinical consultations and denture procedures may be carried out by independent professionals who are not directly employed by Denturaa.

To schedule your appointment, verify medical suitability, and provide custom dental prosthetics, your personal and health information is shared with and received by:

  • Non-Employed Treating Clinicians: Self-employed Clinical Dental Technicians (CDTs), associate dentists, dental surgeons, and locum practitioners carrying out examinations, impressions, and fittings.
  • Host Third-Party Dental Practices: Receptionists, practice managers, and clinical staff operating the third-party sites or rented surgeries where your consultation occurs.
  • Independent Dental Laboratories: Certified dental technicians manufacturing custom-made dental appliances, cobalt-chromium frames, and acrylic prostheses.
  • Commercial Introductions: As disclosed in our Booking Policy, Denturaa may receive an introduction fee, commission, or payment from third-party clinics or practitioners for introducing patients and facilitating bookings.
  • Statutory Safeguards: All non-employed clinicians and third-party partner entities are bound by statutory patient confidentiality regulations and strict data protection agreements.

8. Advertising, Marketing & Advertising Standards (ASA/CAP)

ASA / CAP Code

In strict adherence to Advertising Standards Authority (ASA) CAP Code guidelines and PECR rules, Denturaa ensures total transparency across all marketing and promotional communications.

We strictly enforce a policy prohibiting the upload, sharing, or targeting of special-category clinical health data or dental diagnoses with advertising platforms (such as Google Ads, Meta, or third-party ad networks).

Any marketing conversion tracking requires your explicit, prior consent via our Cookie Settings banner. You may opt out of promotional messages at any time by clicking the unsubscribe link or contacting us directly.

9. Data Retention Periods & Clinical Records Schedules

NHS / Dental Guidelines

We retain personal and clinical information only for as long as necessary to fulfill the purposes for which it was collected, and to comply with statutory healthcare retention requirements:

  • Adult Dental Records & Study Models: Retained for a minimum of 11 years following the completion of treatment or the date of last attendance, in accordance with Department of Health and Social Care / NHS dental guidelines.
  • Children and Young Persons (under 18): Retained for 11 years after treatment completion or until the patient reaches their 25th birthday, whichever is longer.
  • Online Booking Requests (Non-attending): Retained for up to 2 years from submission for administrative follow-up, after which they are securely deleted.
  • Financial & Billing Records: Retained for 7 years to satisfy statutory HMRC and accounting compliance.

10. Your Statutory Rights Under UK GDPR

Patient Rights

Under the UK GDPR and the Data Protection Act 2018, you possess key rights regarding your personal information:

  • Right of Access (Article 15): You may submit a Subject Access Request (DSAR) to obtain a copy of your personal and dental records free of charge within one calendar month.
  • Right to Rectification (Article 16): You may request the correction of inaccurate or incomplete personal information.
  • Right to Erasure (Article 17): You may request deletion of your data, except where statutory health retention obligations require the ongoing retention of clinical dental records.
  • Right to Restriction of Processing (Article 18): You may request limitation of processing under specific legal conditions.
  • Right to Data Portability (Article 20): You may request a machine-readable copy of data you provided to us under consent or contract.
  • Right to Object (Article 21): You have an absolute right to object to direct marketing at any time.
  • Automated Decisions (Article 22): We do not use automated decision-making or profiling to determine clinical eligibility or treatment outcomes.

11. Clinical Information Security & Governance

Information Governance

In compliance with healthcare governance and NHS Information Governance principles, we maintain robust organizational and technical safeguards.

All electronic communications and website transactions are encrypted using Transport Layer Security (TLS 1.3). Digital clinical records are backed up offsite in encrypted UK-based data centers, and physical records are stored in secure, locked clinical filing environments accessible only by authorized dental staff.

12. Contact Our Data Compliance Team

To exercise any of your data protection rights, request a copy of your records, or discuss our compliance policies, please contact:

Data Compliance Lead: contact@denturaa.com Denturaa Dental Systems — Clinical Operations Network Clinics: Birmingham, London, Manchester, Bristol, Nottingham, Leeds

Questions or compliance enquiries? Contact contact@denturaa.com|Booking Policy·Privacy Policy (GDPR & ICO)·Terms of Service·Compliance Charter·Cookie Policy·Complaints Procedure