Dental Audit — Privacy Policy
Last updated: 2nd July 2026
Digitally Transform Dental IT Consultancy Limited (“we”, “us”, “our”, “the Company”) provides the Dental Audit web application (the “Service”). The Service is hosted and operated on our behalf by Digitally Transform Me Ltd. This Privacy Policy explains what personal data we collect through the Service, how and why we use it, who we share it with, and the rights available to you under UK data protection law.
This policy applies to the account holders and users of Dental Audit — that is, dental practice owners, coordinators, and auditors who use the Service to complete internal compliance self-audits. Dental Audit is a B2B compliance and quality-assurance tool for a practice’s own operations. It is not a patient-facing product and is not used to manage patient appointments, clinical records, or treatment, and this policy does not apply to a practice’s patients.
1. Who we are — data controller
The data controller for personal data processed through Dental Audit is:
- Digitally Transform Dental IT Consultancy Limited, a company registered in England & Wales (company number 11394302), registered office at 255 Poulton Road, Wallasey, Wirral CH44 4BT.
The Service is hosted and technically operated on our behalf by Digitally Transform Me Ltd, acting under our instructions as a processor. Digitally Transform Dental IT Consultancy Limited remains the entity legally responsible for your personal data and is the appropriate contact for any privacy query or complaint.
You can contact us about this policy via Contact Us.
2. Personal data we collect
2.1 Account and profile data
When a practice signs up and when users are invited, we collect:
- Practice name and practice address
- User full name and email address
- A securely hashed password (we never store your password in readable form)
- User role (Owner, Coordinator, or Auditor)
2.2 Audit response data
The Service lets your staff complete structured compliance checklists (for example, Record Keeping, Infection Control, Disability Equality, Radiograph Quality, Urgent Care, and Medical Emergency Preparedness). Most questions are answered with yes/no, multiple-choice, or numeric/date responses that record whether a particular field or process exists in the practice’s own records or procedures (for example, “was date of birth recorded?”). Answering these questions does not require entering any actual patient’s name, date of birth, or other identifying information into Dental Audit.
A small number of audit types include free-text or notes fields. These are intended for general observations about the practice’s processes only. See section 8 (“Important — do not enter patient-identifiable information”) below.
2.3 Billing data
Subscription payments are collected by Direct Debit through our payment processor, GoCardless. We do not collect or store your bank account number, sort code, or card details. We store only the GoCardless mandate ID and subscription ID associated with your account, which we use to identify and manage your subscription.
2.4 What we do not collect
Dental Audit does not currently include any file, photo, document, or attachment upload feature — for example, no scanned patient records or X-ray images can be uploaded to or stored in the Service. We also do not currently use any analytics or tracking tools (such as Google Analytics, PostHog, or Mixpanel) within the Service.
2.5 Technical data
As with any web application, our hosting infrastructure automatically processes limited technical data necessary to operate the Service securely and reliably — for example, IP addresses used for rate-limiting sign-up and other sensitive actions to protect against abuse, and standard server logs. This data is used for security and service-operation purposes only.
3. How we use your personal data
We use the personal data described above to:
- Create and administer your practice’s account and individual user accounts
- Provide, maintain, and secure the Service, including enforcing that each user can only access their own practice location’s data
- Enable the audit, scoring, template-building, and PDF export features you use the Service for
- Send account-related communications: sign-up verification, user invitations, password reset emails, and access-change notifications
- Manage billing and subscriptions, including identifying your GoCardless mandate and subscription
- Apply rate limiting and other security controls to protect the Service and other practices’ data
- Comply with our legal obligations and enforce our Terms and Conditions
4. Legal basis for processing
Under UK GDPR, we rely on the following legal bases:
- Performance of a contract — to create your account, provide the Service you have subscribed to, and manage billing.
- Legitimate interests — to secure the Service (e.g. rate limiting, fraud and abuse prevention), to maintain and improve the platform, and to communicate necessary operational and account-related messages, balanced against your rights and interests.
- Legal obligation — where we must retain or disclose data to comply with the law.
We do not rely on consent as the general basis for processing account, audit response, or billing data, because this data is necessary to provide the Service you have subscribed to.
5. Who we share your data with
We share personal data only with trusted service providers (sub-processors) who help us operate the Service, and only to the extent necessary for them to perform their function. We do not sell personal data or share it with third parties for their own marketing purposes.
Our current sub-processors are:
- Supabase — provides our primary database (Postgres) and user authentication. All account, profile, and audit response data is stored with Supabase. (UK region)
- Vercel — provides application hosting and compute for the Service. Our deployment region is configured to London, UK.
- GoCardless — processes recurring Direct Debit subscription payments (UK Direct Debit / Bacs). GoCardless receives and holds your bank account details directly; we never receive or store your raw bank account number or sort code.
- Resend — sends transactional emails on our behalf, including sign-up verification, invitations, password resets, and access-change notifications.
We may also disclose personal data where required by law, to protect our legal rights, or in connection with a merger, acquisition, or sale of assets, in which case we will take reasonable steps to ensure your data continues to be protected.
6. International data transfers
Our infrastructure is configured to store and process data in the UK/EU region where possible (Vercel hosting is configured to London, UK). Where any of our sub-processors process data outside the UK, we ensure an appropriate safeguard is in place, such as the UK’s International Data Transfer Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism recognised under UK GDPR.
7. Data retention
We retain your account and audit data for as long as your subscription is active, and afterwards as follows:
- If you cancel your subscription, your practice retains full access to the Service until the end of your current paid billing period.
- After that grace period ends, premium data is archived: all audits are removed except the two most recent free-tier audits of each audit type, which remain accessible.
- Deleted audit sessions are first moved to a recoverable “recycle bin” before permanent deletion which can be actioned by the owner.
We may retain limited data for longer where necessary to comply with a legal obligation, resolve disputes, or enforce our agreements.
8. Important — do not enter patient-identifiable information
Dental Audit is designed so that you do not need to enter any patient’s personal data into the Service. Audit questions ask only whether your practice’s own records contain certain fields or whether a process was followed — not for the underlying patient details themselves.
A small number of free-text or notes fields exist across certain audit types. You must not enter any real patient-identifiable information (such as a patient’s name, date of birth, address, or clinical details) into any free-text field within the Service. If you choose to enter such information against this instruction, you do so at your own risk and remain responsible, as the data controller for your own patients’ data, for that data and for complying with your own obligations under data protection law. See also our Terms and Conditions, which set out this restriction as a condition of use.
9. How we keep your data secure
We apply the following technical and organisational measures:
- Multi-tenant database security: our database enforces Row-Level Security so that every practice’s data is scoped to that practice location, and a user can only read or write data belonging to their own location. This access control is enforced at the database level, not only within the application.
- Passwords are managed by Supabase Auth using industry-standard hashing; we never store or have access to your plaintext password.
- Invitation links and password-reset links are single-use and time-limited (invitation links expire after 7 days).
- IP-based rate limiting is applied to sign-up and other sensitive actions to reduce the risk of automated abuse.
No method of transmission or storage is completely secure, but we work to protect your personal data using appropriate measures in line with the nature of the data we hold.
10. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Have inaccurate personal data corrected
- Request erasure of your personal data, subject to our legal and contractual obligations
- Restrict or object to certain processing
- Request a copy of your data in a portable format
- Withdraw consent at any time, where processing is based on consent
To exercise any of these rights, please contact us at privacy@dentalaudit.co.uk. Note that some data (such as audit records) may need to be retained by your practice’s Owner or Coordinator for compliance purposes independent of this Service; individual user requests relating to that data should generally be directed to your practice in the first instance.
If you are unhappy with how we have handled your personal data, you have the right to complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk or by calling 0303 123 1113. We would, however, welcome the opportunity to address your concerns directly first.
11. Cookies and similar technologies
The Service uses only strictly necessary cookies or equivalent local storage required to keep you signed in and to operate core functionality (such as authentication session tokens managed by Supabase Auth). We do not currently use analytics, advertising, or tracking cookies. If this changes in the future, we will update this policy and, where required, seek your consent.
12. Children
The Service is intended for use by adult professional staff of dental practices in a business context. It is not directed at, and we do not knowingly collect personal data from, children.
13. Changes to this policy
We may update this Privacy Policy from time to time, for example to reflect changes in the Service or in the law. Where changes are material, we will take reasonable steps to notify practice Owners (such as by email or an in-app notice) before the changes take effect. The “Last updated” date at the top of this policy shows when it was last revised.
14. Contact us
Digitally Transform Dental IT Consultancy Limited
Registered office: 255 Poulton Road, Wallasey, Wirral, CH44 4BT
Company number: 11394302
Service hosted and operated on our behalf by Digitally Transform Me Ltd.
