Privacy Policy
Last updated: May 2026
AlBarakate LTD, publisher of DentalChase, is committed to protecting the privacy of its platform users and the individuals whose data is processed in that context. This policy describes what data is collected, why, and how it is used, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who is the data controller?
When using DentalChase, two distinct roles apply under the UK GDPR:
- The dental practice (client) is the data controller for patient data it imports into the platform.
- AlBarakate LTD acts as a data processor under Article 28 of the UK GDPR: we process this data solely on the practice's instructions, to deliver the automated follow-up service.
For data relating to platform users (dentists, receptionists), AlBarakate LTD is the data controller.
2. Data collected and purposes
a) Platform user data
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Name, professional email | Account creation and management | Contract (Art. 6.1.b) | Duration of contract + 3 years |
| GDC registration number (optional) | Verification of dental professional status for paid subscription | Legal obligation / Contract (Art. 6.1.b) | Duration of contract + 3 years |
| Companies House number (optional) | Identification of the practice's legal structure | Legitimate interest (Art. 6.1.f) | Duration of contract + 3 years |
| Payment data | Billing and subscription management | Contract (Art. 6.1.b) | 6 years (Companies Act 2006) |
| Connection logs | Security and debugging | Legitimate interest (Art. 6.1.f) | 90 days |
b) Patient data (processed on behalf of the practice)
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Patient name | Personalisation of follow-up messages | Contract (Art. 6.1.b) | Duration of practice contract + 1 year |
| Patient email and phone number | Sending follow-up messages (email/SMS) | Contract (Art. 6.1.b) | Duration of practice contract + 1 year |
| Quote amount and treatment description | AI message generation | Contract (Art. 6.1.b) | Duration of practice contract + 1 year |
| Quote status | Conversion tracking | Legitimate interest (Art. 6.1.f) | Duration of practice contract + 1 year |
Note: dental quote data may constitute indirect health data under UK GDPR. DentalChase implements enhanced security measures for their processing.
SMS: each follow-up SMS includes a "STOP to unsubscribe" opt-out instruction, allowing patients to withdraw consent at any time, in compliance with the Privacy and Electronic Communications Regulations 2003 (PECR).
3. Sub-processors and international transfers
DentalChase uses the following technical sub-processors, all bound by contractual obligations compliant with the UK GDPR:
| Provider | Role | Country | Safeguards |
|---|---|---|---|
| Resend | Sending follow-up emails | United States | DPA + UK IDTA |
| OpenAI | AI message generation (no patient data transmitted) | United States | DPA + UK IDTA |
| Railway | API and database hosting | Netherlands (EU) | DPA + UK IDTA |
| Vercel | Web interface hosting | United States | DPA + UK IDTA |
| Stripe | Payment processing | United States / Ireland | DPA + UK IDTA |
IDTA = UK International Data Transfer Agreement (issued by the ICO under the Data Protection Act 2018)
4. Your rights
Under the UK GDPR and Data Protection Act 2018, you have the following rights regarding your personal data:
- Right of access — obtain a copy of your data
- Right to rectification — correct inaccurate data
- Right to erasure — request deletion of your data. Users with the Administrator role can delete their entire account and associated data directly from Settings → Danger zone. Billing records (Stripe invoices) are retained for 6 years in accordance with Companies Act 2006 accounting obligations, even after account deletion.
- Right to data portability — receive your data in a structured format
- Right to object — object to certain processing activities
- Right to restriction — restrict processing in certain circumstances
To exercise these rights, contact us at contact@dentalchase.co.uk. We will respond within one month.
If you believe that the processing of your data does not comply with applicable law, you have the right to lodge a complaint with the ICO — Information Commissioner's Office — ico.org.uk.
5. Security
DentalChase implements appropriate technical and organisational measures to protect your data: encryption in transit (TLS/HTTPS), HTTP security headers (Helmet), rate limiting, role-based access control (ADMIN / DENTIST / RECEPTIONIST), passwords hashed with bcrypt or passwordless login via single-use magic link, and short-lived authentication tokens. In the event of a data breach presenting a risk to your rights and freedoms, we will notify the ICO within 72 hours as required by the UK GDPR.
6. Cookies
DentalChase does not use any third-party tracking or analytics cookies. An authentication token is stored in your browser's localStorage to maintain your session. This storage is strictly necessary for the service to function and does not require prior consent under PECR.
7. Contact
For any questions regarding the protection of your data: contact@dentalchase.co.uk