01Who We Are
Denpath ("we", "us") operates denpath.co.uk, a practice management platform used by dental practices. Contact us at hello@denpath.co.uk.
For patient data entered by a dental practice, the practice is the data controller and we act as its data processor under a Data Processing Agreement — the practice decides what data is collected and why, and is who to contact about it directly. For account holders and waitlist signups, we are the controller ourselves.
02What We Collect
We collect the following personal data:
- Waitlist signups: email address, practice name
- Account holders: name, email address, and the practices they belong to
- Patient data: name, email, phone, date of birth, and dental treatment plans and clinical findings entered by dental practices — special category health data under Article 9 UK GDPR
- Technical data: authentication cookies, session tokens, and the IP address recorded against sign-up and legal-document acceptances
- Billing data: for practices with an active subscription, billing contact details — card details themselves are held by Stripe, not by us
We deliberately avoid collecting more than we need — for example, we do not ask for NHS numbers or free-text medical history beyond the clinical findings a dentist records.
03How We Use Your Data
- Provide and maintain the practice management service
- Facilitate treatment plan communication between practices and patients
- Manage user accounts, authentication, and role-based access within a practice
- Send service-related communications (verification, invites, treatment plan links, billing)
- Maintain security and an audit trail of administrative actions
- Comply with legal obligations
Legal bases for processing under UK GDPR: performance of contract (service delivery), legitimate interests (service improvement, security), consent (waitlist, marketing), and legal obligation (regulatory compliance). Where we process patient health data as a practice's processor, the practice determines the lawful basis and, where relevant, the Article 9 condition that applies.
04Data Storage and Security
Data is stored on servers located in the United Kingdom, via our infrastructure providers listed in Section 8. We use encryption in transit (TLS) and at rest, role-based access control enforced on every request, per-practice data isolation, hashed credentials, and an audit log of administrative actions. We do not transfer personal data outside the UK without an appropriate transfer mechanism in place. Security is an ongoing programme; we review and improve these measures over time.
05Data Retention
Account data is retained while your account is active and deleted upon request, except where we must keep billing records for legal reasons.
Patient data is controlled directly by the practice, as data controller. A practice can correct or delete a patient record from within the Service at any time — deleting a record removes it, and the exams and treatment plans linked to it, immediately and permanently. We hold no separate recovery copy beyond routine database backups, which age out on their own schedule. It is the practice's responsibility, not ours, to retain patient records for as long as professional dental record-keeping requirements demand before choosing to delete them.
06Your Rights
Under UK GDPR you have the right to:
- Access your personal data
- Rectify inaccurate data
- Request erasure of your data
- Restrict or object to processing
- Data portability
- Lodge a complaint with the ICO (ico.org.uk)
For your account data, contact hello@denpath.co.uk to exercise any of these rights. For patient treatment data, these rights are normally exercised through the dental practice that holds your records, since they are the data controller — if you contact us directly about patient data, we will forward your request to the relevant practice.
07Cookies
We use strictly necessary cookies for authentication, session management, and remembering which practice you have selected. These are essential for the service to function and cannot be disabled. We do not use advertising or analytics cookies, so no cookie consent banner is shown.
08Sub-processors
We share data with the following infrastructure providers, each under a data processing agreement, solely to provide the Service:
- Neon — database hosting
- Vercel — application hosting
- Resend — transactional email delivery
- Stripe — subscription billing (practice billing contacts and payment data only; never patient data)
We do not sell personal data. The full sub-processor terms for practices are set out in our Data Processing Agreement.
09Children's Data
Dental patients may be under 18. Where a practice enters data for a child patient, the practice is responsible for any parental or guardian consent their own processing requires — we do not collect this data directly from children ourselves.
10Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email or in-app notice, and signed-in users are asked to review and accept the updated policy before continuing to use the Service.
11Contact
For privacy-related enquiries, including breach reports: hello@denpath.co.uk