BookMyDentist
ServicesHow It WorksVirtual CareFor Practices
Legal

Privacy Policy

Last updated: 5 July 2026

On this page
This policy explains how Smile Connect Ltd, trading as BookMyDentist, collects, uses and protects your personal data when you use our platform. We are committed to handling your information — including your health data — securely and in line with UK data protection law.

1.Who We Are

BookMyDentist is a trading name of Smile Connect Ltd, a company registered in England and Wales (Company Number 16375461) with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.

For the purposes of UK data protection law (the UK GDPR and the Data Protection Act 2018), Smile Connect Ltd is the data controller responsible for your personal data when you use our platform at bookmydentist.co.uk.

If you have any questions about this policy or how we handle your data, please contact us at hello@bookmydentist.co.uk.

We are registered with the Information Commissioner's Office (ICO) under registration number ZC018473.

2.What Data We Collect

The data we collect depends on how you use BookMyDentist.

For patients:

  • Account data — your name, email address, phone number, date of birth and a hashed version of your password.
  • Medical data — medical history, allergies, medications and conditions that you enter yourself.
  • Booking data — appointments, booking references and your consultation history.
  • Triage data — your AI triage conversations, symptoms reported, photos uploaded, and voice notes and their transcripts.
  • Consultation data — virtual consultation records, pre-consultation briefs and clinical summaries.
  • Payment data — payments are processed by Semble via Stripe. We do not store your card numbers.
  • Usage data — pages visited, search queries, device information and IP address.
  • Communication data — secure messages and voice notes exchanged through the platform.
  • Identity verification data — the type of ID used and your verification status. We do not store copies of your ID.
  • Review data — ratings and reviews you leave.
  • Gravatar — an MD5 hash of your email address, used to retrieve your profile photo from Gravatar. This hash is not reversible.

For dentists:

  • Professional data — your name, GDC number, qualifications, biography, photo, languages spoken and services offered.
  • Practice linkage — the practice or practices you are associated with.
  • Virtual care application — indemnity insurance details, availability and the consultation types you offer.
  • Clinical data — consultation notes, triage summaries and prescriptions, stored in Semble.

For practices:

  • Practice data — practice name, address, GDC number, CQC number, phone, website, description and opening hours.
  • Connection data — practice management software type and encrypted API credentials (via Leyr).
  • Subscription data — plan type and billing contact.

3.How We Collect Data

We collect your personal data in the following ways:

  • Directly from you — when you create an account, book an appointment, complete triage or contact us.
  • From your practice management software — via the Leyr API, and only the data that the practice has granted us access to.
  • From AI triage interactions — as you use our AI triage tool.
  • Automatically — through cookies, analytics and device information as you browse the site.
  • From Gravatar — to retrieve a profile photo linked to your email address.

4.Why We Process Your Data (Lawful Bases)

We only process your personal data where we have a lawful basis to do so under the UK GDPR. The table below sets out our main purposes and the corresponding lawful basis.

PurposeLawful basis
Creating your accountContract performance
Booking appointmentsContract performance
AI triageLegitimate interest (guiding care)
Virtual consultationsContract + Vital interest
Processing medical historyExplicit consent (Art 9)
Sending booking confirmationsContract performance
Marketing emailsConsent (opt-in only)
Platform analyticsLegitimate interest
Fraud preventionLegitimate interest
CQC complianceLegal obligation
Identity verificationLegal obligation (CQC)

Special category (health) data is processed under Article 9(2)(h) UK GDPR — necessary for the provision of health care with appropriate safeguards. It is also processed on the basis of your explicit consent where you voluntarily enter your medical history.

5.How We Store and Protect Data

We take the security of your data seriously and apply the following measures:

  • Database — hosted on Supabase in the London, UK region.
  • Encryption — AES-256 at rest and TLS 1.2+ in transit.
  • Practice credentials — encrypted via Leyr using separate keys.
  • Payments — processed via Stripe (PCI DSS Level 1). We never see or store your card numbers.
  • Voice notes — held in private encrypted storage with signed URLs that expire when the consultation thread archives.
  • Photos — stored as encrypted clinical images.
  • Passwords — hashed with bcrypt.
  • Access controls — role-based access (patient, dentist, practice admin, platform admin).
  • Row Level Security — enforced at the database level.

6.Who We Share Data With

We share your data with the following trusted sub-processors, only as needed to run our service:

RecipientWhat we shareWhy
Leyr GmbHEncrypted practice credentialsConnect to practice management software
SemblePatient booking and consultation dataProcess virtual consultations and payments
StripePayment transaction dataProcess payments (via Semble)
Anthropic (Claude API)Triage conversation text, photo descriptionsPower AI triage (no data retained by Anthropic)
ResendEmail addresses, booking detailsSend transactional emails
VercelWebsite hosting and analyticsServe the website
SupabaseAll platform dataDatabase hosting (London region)
Gravatar (Automattic)MD5 hash of emailRetrieve profile photos

We NEVER sell your data.

We NEVER share your data with advertisers.

We NEVER share patient data between practices — each practice only sees their own patients.

7.AI Triage — Specific Disclosures

  • Triage is processed by Anthropic's Claude AI for symptom assessment.
  • Claude does not retain conversation data after processing.
  • Triage is not a medical diagnosis.
  • All sessions are logged for CQC clinical governance.
  • Photos are stored securely and shared only with the assigned dentist.
  • Voice notes are transcribed via speech-to-text, and both the audio and the transcript are stored.

8.Virtual Consultations — Specific Disclosures

  • Virtual consultations are provided under Smile Connect Ltd's CQC registration.
  • Consultation records are clinical records subject to healthcare retention requirements.
  • Identity verification takes place at the start of each consultation.
  • Secure messages between patient and dentist form part of the clinical record.

9.Data Retention

We keep your data only for as long as necessary. Our standard retention periods are:

Data typeRetention period
Patient account dataUntil account deletion + 30 days
Medical history10 years (NHS clinical records standard)
Consultation records10 years
Triage sessions10 years (clinical governance)
Booking records6 years (contractual/tax)
Messages and voice notes10 years
Photos (clinical)10 years
Payment records6 years (HMRC)
Analytics data26 months
Marketing consentUntil withdrawn

10.Your Rights (GDPR Articles 15-22)

Under the UK GDPR you have the following rights:

  • Right of access — request a copy of your data (a subject access request, or SAR).
  • Right to rectification — correct inaccurate or incomplete data.
  • Right to erasure — the "right to be forgotten". Note that clinical records may be exempt under our healthcare retention obligations.
  • Right to restrict processing — limit how we use your data.
  • Right to data portability — receive your data in a portable format.
  • Right to object — object to certain processing.
  • Rights regarding automated decision-making — note that AI triage involves automated processing but makes no binding clinical decisions; all clinical decisions are made by qualified dentists.
  • Right to withdraw consent — where we rely on your consent, you may withdraw it at any time.

To exercise any of these rights, email us at hello@bookmydentist.co.uk. We will respond within 30 days.

11.Cookies

We use cookies to run and improve our platform. For full details, please see our cookie policy.

  • Essential — authentication and security.
  • Analytics — anonymised usage.
  • Preferences — language and dark mode.

We do not use advertising or tracking cookies.

12.Children

BookMyDentist is not directed at children under 16. Children's appointments must be booked by a parent or legal guardian. We do not knowingly collect data from children under 16 without parental consent.

13.International Transfers

Your data is primarily stored in the UK (Supabase, London region). Some of our sub-processors may process data outside the UK. Where this occurs, we ensure appropriate safeguards are in place through Standard Contractual Clauses or UK adequacy decisions.

14.Changes to This Policy

We may update this policy from time to time. We will notify you of any material changes by email. Continued use of the platform after notification constitutes acceptance of the updated policy.

15.Complaints

If you have a concern about how we handle your data, please contact us first at hello@bookmydentist.co.uk so we can try to resolve it.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

BookMyDentist

The UK’s dental booking platform — connecting patients with GDC-registered dentists near them.

For Patients
  • Find a Dentist
  • Video Consultation
  • Emergency Care
  • FAQs
For Practices
  • Register a Practice
  • Practice Dashboard
  • Integrations
  • Support
Company
  • About Us
  • Blog
  • Careers
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy
  • Acceptable Use

© 2026 Smile Connect Ltd trading as BookMyDentist. Reg. 16375461.

ICO RegisteredGDPR Compliant