Status of This Document
This is a template, not a published policy. It sets out the structure and subject matter a UK GDPR-compliant privacy notice requires, but the identifying details have deliberately been left as placeholders. It must be reviewed by a suitably qualified legal adviser and completed with verified information before it is published or relied upon. No statement in it should be treated as a representation about how any particular organisation actually processes data.
Effective date: ORG PLACEHOLDER — effective date
Last reviewed: ORG PLACEHOLDER — last reviewed date
This policy explains how personal data submitted through or in connection with this website would be collected, used, stored and disclosed, and what rights individuals have in relation to it. It does not apply to any third-party website reached through a link from here; those sites operate their own policies.
Who the Data Controller Is
The data controller is the organisation that determines the purposes and means of processing personal data. Under the UK GDPR it carries primary responsibility for lawful processing and is the party to whom rights requests are directed.
Controller: ORG PLACEHOLDER — registered legal name of the controller
Registered address: ORG PLACEHOLDER — registered address
Registration details: ORG PLACEHOLDER — company or professional registration details
Data protection enquiries: CONTACT PLACEHOLDER — data protection contact point
Where a data protection officer is appointed, whether because it is required or voluntarily, that person's contact details must be added here. Whether an appointment is mandatory depends on the nature and scale of the processing and should be assessed before publication.
Personal Data That May Be Collected
The categories below describe what an enquiry-based dental website typically collects. The final version must reflect only what is actually collected in practice.
Information you provide
- Identifying details such as your name and the contact details you choose to supply.
- The content of your enquiry, including any description of a dental concern, previous treatment or symptoms that you decide to include.
- Any preferences you state, such as access requirements, interpreter needs or a preferred method of reply.
- Correspondence exchanged subsequently, including notes of telephone conversations where these are recorded.
Information collected automatically
- Technical data generated when a page is requested, which may include an IP address, browser and device characteristics, and the pages viewed.
- Any data collected by analytics or similar technologies, if and when such technologies are deployed on this site.
Special category data
Information about physical or dental health is special category personal data and attracts additional protection. This site does not invite health information to be sent unsolicited, and readers are asked on the contact page not to send clinical details or photographs until specifically asked for them. Where such information is nevertheless received, it must be handled under the enhanced conditions described below.
Lawful Bases for Processing
Every processing operation requires a lawful basis under Article 6 of the UK GDPR, and processing of health data additionally requires a condition under Article 9.
- Consent. Where you voluntarily submit an enquiry, consent may be the basis for using your details to respond. Consent must be freely given, specific, informed and unambiguous, and it can be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.
- Legitimate interests. Responding to correspondence, maintaining records of enquiries, securing the website and preventing misuse may rest on legitimate interests, provided a balancing assessment shows those interests are not overridden by the rights and freedoms of the individual. That assessment should be documented.
- Legal obligation. Some retention and disclosure is required by law, including obligations connected with the regulation of dental care and with the keeping of clinical records.
- Contract. Where care is subsequently provided, processing necessary to perform that agreement may be relied upon.
- Health and healthcare conditions for special category data. Clinical information may be processed where it is necessary for the purposes of preventive or occupational medicine, medical diagnosis, or the provision of health or social care or treatment, carried out by or under the responsibility of a professional subject to an obligation of professional secrecy. Explicit consent may apply in other circumstances. The condition relied upon must be identified and recorded, together with the appropriate policy document that UK law requires for certain conditions.
How Information Is Used
Personal data collected through this site would be used to acknowledge and answer enquiries, to arrange and prepare for an assessment where one is requested, to keep an accurate record of what was asked and answered, to meet professional and regulatory record-keeping obligations, to maintain the security of the website, and to improve the accuracy of the information published here.
Personal data is not used for profiling or for automated decision-making producing legal or similarly significant effects, and would not be sold, rented or exchanged. If direct marketing were ever introduced, a separate and specific consent mechanism would be required, with a straightforward means of opting out.
Who Information May Be Shared With
Personal data may be disclosed to service providers acting as processors under written contracts meeting the requirements of Article 28 of the UK GDPR. Typical categories include website hosting, email delivery, practice management or records systems, and professional advisers. Each processor actually used must be listed before publication.
ORG PLACEHOLDER — processors and categories of recipient
Disclosure may also occur where it is required by law, by a court order, or by a regulator exercising statutory powers, or where it is necessary to protect the vital interests of an individual. Beyond these circumstances, information is not shared with third parties.
How Long Information Is Kept
Personal data must be kept no longer than is necessary for the purposes for which it was collected. Different categories attract different periods: general enquiry correspondence is usually held for a short defined period, whereas clinical records are subject to considerably longer statutory and professional retention requirements. A documented retention schedule should govern this, with secure deletion or anonymisation at the end of each period.
ORG PLACEHOLDER — retention periods for each category of data
Your Rights Under the UK GDPR
Individuals have the following rights, some of which apply only in defined circumstances and depend on the lawful basis relied upon.
- The right to be informed about how personal data is collected and used, which this notice is intended to satisfy.
- The right of access to a copy of the personal data held about you, together with supplementary information about the processing.
- The right to rectification of inaccurate personal data and to have incomplete data completed.
- The right to erasure, sometimes called the right to be forgotten, which does not apply where the data must be retained to comply with a legal obligation or for certain healthcare purposes.
- The right to restrict processing in specified circumstances, such as while the accuracy of data is being verified.
- The right to data portability, applying to data provided by you which is processed by automated means on the basis of consent or contract.
- The right to object to processing based on legitimate interests, and an absolute right to object to direct marketing.
- Rights in relation to automated decision-making and profiling, including a right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
- The right to withdraw consent at any time where consent is the lawful basis relied upon.
- The right to complain to the supervisory authority.
Requests are normally answered within one month, extendable by two further months where a request is complex or where several have been made. No fee is charged unless a request is manifestly unfounded or excessive, and identity verification may be required first.
How to exercise these rights: CONTACT PLACEHOLDER — route for rights requests
Cookies and Analytics
No claim should be made about cookies until it has been verified against what the site actually sets. A statement that a site uses no cookies is itself a factual assertion and can be wrong, particularly where hosting or embedded content introduces storage without the publisher realising it.
Before publication, an audit should establish which cookies and similar technologies are set, whether each is strictly necessary or requires consent under the Privacy and Electronic Communications Regulations, what each does, how long it persists and who sets it. Where any non-essential technology is present, a compliant consent mechanism is required, allowing consent to be refused as easily as it is given.
ORG PLACEHOLDER — cookie inventory, purposes and durations
ORG PLACEHOLDER — analytics provider, if any, and its configuration
Security, Transfers, Children and Changes
Security measures
Appropriate technical and organisational measures are required to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage. These typically include access controls, encryption in transit, secure storage, staff training and confidentiality obligations, and a documented procedure for detecting, investigating and reporting personal data breaches within the statutory timescale. Ordinary email is not a secure channel.
International transfers
Personal data should ordinarily be processed within the United Kingdom. Where a processor stores or accesses data outside the UK, the transfer requires a lawful mechanism such as adequacy regulations or the International Data Transfer Agreement, supported by a transfer risk assessment. Any such arrangement must be identified here.
ORG PLACEHOLDER — international transfers and safeguards
Children's data
This website is written for adults and is not directed at children. Enquiries concerning a child should be made by a person with parental responsibility. Where information relating to a child is processed, it requires particular care, and the age at which a child can consent in their own right to online services in the UK should be applied.
Changes to this policy
This policy may be updated to reflect changes in practice, technology or law. The effective date at the top records when the current version took effect. Material changes affecting how personal data is used should be communicated directly to affected individuals rather than left to be noticed.
Complaints to the Supervisory Authority
If you are concerned about how your personal data has been handled, raising it directly with the controller is usually the quickest route to resolution. If you remain dissatisfied, you have the right to complain to the Information Commissioner's Office, the supervisory authority for data protection in the United Kingdom. Making a complaint does not affect any other legal remedy available to you.
ORG PLACEHOLDER — internal complaints route
ORG PLACEHOLDER — verified ICO contact details and registration reference
The wording describing the supervisory authority, and any registration reference quoted, must be checked against current official sources before publication rather than reproduced from another website. This document is a drafting aid only and does not constitute legal advice; the material elsewhere on this site about whitening services and realistic results is likewise educational information rather than dental advice.
