1.Who We Are
BookMyDentist is a trading name of Smile Connect Ltd, a company registered in England and Wales (Company Number 16375461) with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.
For the purposes of UK data protection law (the UK GDPR and the Data Protection Act 2018), Smile Connect Ltd is the data controller responsible for your personal data when you use our platform at bookmydentist.co.uk.
If you have any questions about this policy or how we handle your data, please contact us at hello@bookmydentist.co.uk.
We are registered with the Information Commissioner's Office (ICO) under registration number ZC018473.
2.What Data We Collect
The data we collect depends on how you use BookMyDentist.
For patients:
- Account data — your name, email address, phone number, date of birth and a hashed version of your password.
- Medical data — medical history, allergies, medications and conditions that you enter yourself.
- Booking data — appointments, booking references and your consultation history.
- Triage data — your AI triage conversations, symptoms reported, photos uploaded, and voice notes and their transcripts.
- Consultation data — virtual consultation records, pre-consultation briefs and clinical summaries.
- Payment data — payments are processed by Semble via Stripe. We do not store your card numbers.
- Usage data — pages visited, search queries, device information and IP address.
- Communication data — secure messages and voice notes exchanged through the platform.
- Identity verification data — the type of ID used and your verification status. We do not store copies of your ID.
- Review data — ratings and reviews you leave.
- Gravatar — an MD5 hash of your email address, used to retrieve your profile photo from Gravatar. This hash is not reversible.
For dentists:
- Professional data — your name, GDC number, qualifications, biography, photo, languages spoken and services offered.
- Practice linkage — the practice or practices you are associated with.
- Virtual care application — indemnity insurance details, availability and the consultation types you offer.
- Clinical data — consultation notes, triage summaries and prescriptions, stored in Semble.
For practices:
- Practice data — practice name, address, GDC number, CQC number, phone, website, description and opening hours.
- Connection data — practice management software type and encrypted API credentials (via Leyr).
- Subscription data — plan type and billing contact.
3.How We Collect Data
We collect your personal data in the following ways:
- Directly from you — when you create an account, book an appointment, complete triage or contact us.
- From your practice management software — via the Leyr API, and only the data that the practice has granted us access to.
- From AI triage interactions — as you use our AI triage tool.
- Automatically — through cookies, analytics and device information as you browse the site.
- From Gravatar — to retrieve a profile photo linked to your email address.
4.Why We Process Your Data (Lawful Bases)
We only process your personal data where we have a lawful basis to do so under the UK GDPR. The table below sets out our main purposes and the corresponding lawful basis.
| Purpose | Lawful basis |
|---|---|
| Creating your account | Contract performance |
| Booking appointments | Contract performance |
| AI triage | Legitimate interest (guiding care) |
| Virtual consultations | Contract + Vital interest |
| Processing medical history | Explicit consent (Art 9) |
| Sending booking confirmations | Contract performance |
| Marketing emails | Consent (opt-in only) |
| Platform analytics | Legitimate interest |
| Fraud prevention | Legitimate interest |
| CQC compliance | Legal obligation |
| Identity verification | Legal obligation (CQC) |
Special category (health) data is processed under Article 9(2)(h) UK GDPR — necessary for the provision of health care with appropriate safeguards. It is also processed on the basis of your explicit consent where you voluntarily enter your medical history.
5.How We Store and Protect Data
We take the security of your data seriously and apply the following measures:
- Database — hosted on Supabase in the London, UK region.
- Encryption — AES-256 at rest and TLS 1.2+ in transit.
- Practice credentials — encrypted via Leyr using separate keys.
- Payments — processed via Stripe (PCI DSS Level 1). We never see or store your card numbers.
- Voice notes — held in private encrypted storage with signed URLs that expire when the consultation thread archives.
- Photos — stored as encrypted clinical images.
- Passwords — hashed with bcrypt.
- Access controls — role-based access (patient, dentist, practice admin, platform admin).
- Row Level Security — enforced at the database level.
7.AI Triage — Specific Disclosures
- Triage is processed by Anthropic's Claude AI for symptom assessment.
- Claude does not retain conversation data after processing.
- Triage is not a medical diagnosis.
- All sessions are logged for CQC clinical governance.
- Photos are stored securely and shared only with the assigned dentist.
- Voice notes are transcribed via speech-to-text, and both the audio and the transcript are stored.
8.Virtual Consultations — Specific Disclosures
- Virtual consultations are provided under Smile Connect Ltd's CQC registration.
- Consultation records are clinical records subject to healthcare retention requirements.
- Identity verification takes place at the start of each consultation.
- Secure messages between patient and dentist form part of the clinical record.
9.Data Retention
We keep your data only for as long as necessary. Our standard retention periods are:
| Data type | Retention period |
|---|---|
| Patient account data | Until account deletion + 30 days |
| Medical history | 10 years (NHS clinical records standard) |
| Consultation records | 10 years |
| Triage sessions | 10 years (clinical governance) |
| Booking records | 6 years (contractual/tax) |
| Messages and voice notes | 10 years |
| Photos (clinical) | 10 years |
| Payment records | 6 years (HMRC) |
| Analytics data | 26 months |
| Marketing consent | Until withdrawn |
10.Your Rights (GDPR Articles 15-22)
Under the UK GDPR you have the following rights:
- Right of access — request a copy of your data (a subject access request, or SAR).
- Right to rectification — correct inaccurate or incomplete data.
- Right to erasure — the "right to be forgotten". Note that clinical records may be exempt under our healthcare retention obligations.
- Right to restrict processing — limit how we use your data.
- Right to data portability — receive your data in a portable format.
- Right to object — object to certain processing.
- Rights regarding automated decision-making — note that AI triage involves automated processing but makes no binding clinical decisions; all clinical decisions are made by qualified dentists.
- Right to withdraw consent — where we rely on your consent, you may withdraw it at any time.
To exercise any of these rights, email us at hello@bookmydentist.co.uk. We will respond within 30 days.
12.Children
BookMyDentist is not directed at children under 16. Children's appointments must be booked by a parent or legal guardian. We do not knowingly collect data from children under 16 without parental consent.
13.International Transfers
Your data is primarily stored in the UK (Supabase, London region). Some of our sub-processors may process data outside the UK. Where this occurs, we ensure appropriate safeguards are in place through Standard Contractual Clauses or UK adequacy decisions.
14.Changes to This Policy
We may update this policy from time to time. We will notify you of any material changes by email. Continued use of the platform after notification constitutes acceptance of the updated policy.
15.Complaints
If you have a concern about how we handle your data, please contact us first at hello@bookmydentist.co.uk so we can try to resolve it.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.