Professional Tooth Whitening Services

Privacy Policy

How personal information relating to Teeth Whitening enquiries would be handled under the UK GDPR and the Data Protection Act 2018.

Status of This Document

This is a template, not a published policy. It sets out the structure and subject matter a UK GDPR-compliant privacy notice requires, but the identifying details have deliberately been left as placeholders. It must be reviewed by a suitably qualified legal adviser and completed with verified information before it is published or relied upon. No statement in it should be treated as a representation about how any particular organisation actually processes data.

Effective date: ORG PLACEHOLDER — effective date

Last reviewed: ORG PLACEHOLDER — last reviewed date

This policy explains how personal data submitted through or in connection with this website would be collected, used, stored and disclosed, and what rights individuals have in relation to it. It does not apply to any third-party website reached through a link from here; those sites operate their own policies.

Who the Data Controller Is

The data controller is the organisation that determines the purposes and means of processing personal data. Under the UK GDPR it carries primary responsibility for lawful processing and is the party to whom rights requests are directed.

Controller: ORG PLACEHOLDER — registered legal name of the controller

Registered address: ORG PLACEHOLDER — registered address

Registration details: ORG PLACEHOLDER — company or professional registration details

Data protection enquiries: CONTACT PLACEHOLDER — data protection contact point

Where a data protection officer is appointed, whether because it is required or voluntarily, that person's contact details must be added here. Whether an appointment is mandatory depends on the nature and scale of the processing and should be assessed before publication.

Personal Data That May Be Collected

The categories below describe what an enquiry-based dental website typically collects. The final version must reflect only what is actually collected in practice.

Information you provide

Information collected automatically

Special category data

Information about physical or dental health is special category personal data and attracts additional protection. This site does not invite health information to be sent unsolicited, and readers are asked on the contact page not to send clinical details or photographs until specifically asked for them. Where such information is nevertheless received, it must be handled under the enhanced conditions described below.

Lawful Bases for Processing

Every processing operation requires a lawful basis under Article 6 of the UK GDPR, and processing of health data additionally requires a condition under Article 9.

How Information Is Used

Personal data collected through this site would be used to acknowledge and answer enquiries, to arrange and prepare for an assessment where one is requested, to keep an accurate record of what was asked and answered, to meet professional and regulatory record-keeping obligations, to maintain the security of the website, and to improve the accuracy of the information published here.

Personal data is not used for profiling or for automated decision-making producing legal or similarly significant effects, and would not be sold, rented or exchanged. If direct marketing were ever introduced, a separate and specific consent mechanism would be required, with a straightforward means of opting out.

Who Information May Be Shared With

Personal data may be disclosed to service providers acting as processors under written contracts meeting the requirements of Article 28 of the UK GDPR. Typical categories include website hosting, email delivery, practice management or records systems, and professional advisers. Each processor actually used must be listed before publication.

ORG PLACEHOLDER — processors and categories of recipient

Disclosure may also occur where it is required by law, by a court order, or by a regulator exercising statutory powers, or where it is necessary to protect the vital interests of an individual. Beyond these circumstances, information is not shared with third parties.

How Long Information Is Kept

Personal data must be kept no longer than is necessary for the purposes for which it was collected. Different categories attract different periods: general enquiry correspondence is usually held for a short defined period, whereas clinical records are subject to considerably longer statutory and professional retention requirements. A documented retention schedule should govern this, with secure deletion or anonymisation at the end of each period.

ORG PLACEHOLDER — retention periods for each category of data

Your Rights Under the UK GDPR

Individuals have the following rights, some of which apply only in defined circumstances and depend on the lawful basis relied upon.

Requests are normally answered within one month, extendable by two further months where a request is complex or where several have been made. No fee is charged unless a request is manifestly unfounded or excessive, and identity verification may be required first.

How to exercise these rights: CONTACT PLACEHOLDER — route for rights requests

Cookies and Analytics

No claim should be made about cookies until it has been verified against what the site actually sets. A statement that a site uses no cookies is itself a factual assertion and can be wrong, particularly where hosting or embedded content introduces storage without the publisher realising it.

Before publication, an audit should establish which cookies and similar technologies are set, whether each is strictly necessary or requires consent under the Privacy and Electronic Communications Regulations, what each does, how long it persists and who sets it. Where any non-essential technology is present, a compliant consent mechanism is required, allowing consent to be refused as easily as it is given.

ORG PLACEHOLDER — cookie inventory, purposes and durations

ORG PLACEHOLDER — analytics provider, if any, and its configuration

Security, Transfers, Children and Changes

Security measures

Appropriate technical and organisational measures are required to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage. These typically include access controls, encryption in transit, secure storage, staff training and confidentiality obligations, and a documented procedure for detecting, investigating and reporting personal data breaches within the statutory timescale. Ordinary email is not a secure channel.

International transfers

Personal data should ordinarily be processed within the United Kingdom. Where a processor stores or accesses data outside the UK, the transfer requires a lawful mechanism such as adequacy regulations or the International Data Transfer Agreement, supported by a transfer risk assessment. Any such arrangement must be identified here.

ORG PLACEHOLDER — international transfers and safeguards

Children's data

This website is written for adults and is not directed at children. Enquiries concerning a child should be made by a person with parental responsibility. Where information relating to a child is processed, it requires particular care, and the age at which a child can consent in their own right to online services in the UK should be applied.

Changes to this policy

This policy may be updated to reflect changes in practice, technology or law. The effective date at the top records when the current version took effect. Material changes affecting how personal data is used should be communicated directly to affected individuals rather than left to be noticed.

Complaints to the Supervisory Authority

If you are concerned about how your personal data has been handled, raising it directly with the controller is usually the quickest route to resolution. If you remain dissatisfied, you have the right to complain to the Information Commissioner's Office, the supervisory authority for data protection in the United Kingdom. Making a complaint does not affect any other legal remedy available to you.

ORG PLACEHOLDER — internal complaints route

ORG PLACEHOLDER — verified ICO contact details and registration reference

The wording describing the supervisory authority, and any registration reference quoted, must be checked against current official sources before publication rather than reproduced from another website. This document is a drafting aid only and does not constitute legal advice; the material elsewhere on this site about whitening services and realistic results is likewise educational information rather than dental advice.