Privacy Policy
At The Smile Designers, we are committed to protecting and respecting your privacy. This policy explains how we collect, use, store, and protect your personal information in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and relevant professional obligations under the General Dental Council (GDC) Standards for the Dental Team.
Who We Are
The Smile Designers
92a Arundel Street
Sheffield S1 4RE
Telephone: 0114 281 22 11
Email: reception@thesmiledesigners.co.uk
Data Controller: Dr. Fahad Khan
Data Protection Officer (DPO) / Lead for Data Protection: Dr. Fahad Khan – contact via the above details.
What Information We Collect
Website & Online Enquiry Data
Website & Online Enquiry Data
When you submit an enquiry through our website (including contact forms, smile assessment forms, appointment requests, or marketing landing pages), we collect the personal information you choose to provide. This may include your name, contact details, information about your dental concerns, medical history relevant to your enquiry, and any images you upload.
This information is processed for the purpose of responding to your enquiry, assessing your suitability for treatment, arranging consultations, and providing pre-treatment advice. Online enquiries are securely transmitted and stored on third-party systems used by the practice (see “Third-Party Processors” below).
Our website may also automatically collect technical data such as IP addresses, browser type, device information, and usage analytics for security and performance monitoring. Cookies or similar technologies may be used to improve website functionality and user experience. You can control cookie settings through your browser.
Any data submitted online is treated with the same level of confidentiality and security as information collected within the practice.
Third Party Processors
Third-Party Processors (Practice Management & CRM Systems)
To operate our dental practice safely and efficiently, we use secure third-party systems that process personal data under strict confidentiality and data-processing agreements. These providers act as “data processors” under the UK GDPR, meaning they process information solely on our documented instructions.
Dentally – Practice Management System (PMS)
We use Dentally to manage clinical records, appointments, treatment plans, medical history forms, radiographs, and communications relating to your care. Dentally securely hosts and stores patient data on encrypted servers located within the UK/EU and complies with the UK GDPR, NHS DSP Toolkit requirements, and relevant cybersecurity standards. Only authorised team members have access to your clinical records through unique logins with audit trails.
Boxly CRM – Enquiry Management & Communication System
We use Boxly as our CRM system to manage website enquiries, patient communications, treatment interest tracking, appointment follow-ups, and service-related correspondence. Information submitted through our website or by phone/email may be transferred into Boxly for administrative purposes. Boxly processes this data under contract, does not use it for its own purposes, and stores all information on secure, encrypted servers in compliance with UK GDPR obligations.
General Protections
All third-party processors used by the practice:
are vetted for GDPR compliance and data security measures
operate under written data-processing agreements
cannot access or use your data for their own purposes
implement encryption, access controls, and data-minimisation standards
store data in the UK or EU, or are subject to appropriate safeguards such as Standard Contractual Clauses where applicable
We regularly review our processors to ensure ongoing compliance and security. For the latest information you can contact us directly at reception@thesmiledesigners.co.uk.
We may collect and process the following categories of personal data:
- Personal Identification Data – Name, date of birth, address, telephone number, email address, gender, next of kin/emergency contact.
- Health Records – Medical history, dental records, treatment notes, radiographs, photographs, referral letters, prescriptions.
- Financial Data – Bank account details, payment history, insurance details.
- Communication Records – Emails, letters, text messages, and phone call logs relevant to your care.
- Special Category Data – Information relating to your health, ethnic origin, or other sensitive information where necessary for your treatment.
- Photography and Video – Clinical photographs and videos for treatment planning, training, monitoring progress, medico-legal documentation, and (with consent) marketing or educational purposes, including social media and website use.
- CCTV Footage – Images of visitors, patients, and staff captured by our CCTV system for security and safety purposes.
- Cookies & Website Analytics. Our website may use cookies or similar technologies to improve functionality, analyse usage, and enhance user experience. Cookies may collect anonymised data such as pages visited, time spent on the site, interactions, and approximate location. You can manage or disable cookies via your browser settings. Analytical and technical data is collected solely to ensure website performance, security, and service improvement.
Why We Collect Your Data
We process your personal data for the following purposes:
- To provide safe, effective dental care in line with GDC Standards.
- To manage appointments, recalls, and treatment plans.
- To maintain accurate and complete clinical records.
- To liaise with other healthcare providers where necessary.
- For legal and regulatory compliance (e.g., GDC, CQC, HMRC).
- For legitimate business purposes, such as service quality improvement and staff training.
- With your consent, for marketing communications about our services.
- For Photography/Video – To assist in diagnosis and treatment planning, maintain accurate medical records, provide evidence in case of complaints or claims, and (with explicit written consent) to use images/videos for marketing, website, and social media purposes.
- For CCTV – To maintain the security of our premises, ensure the safety of patients, visitors, and staff, and assist in the prevention and detection of crime.
Lawful Basis for Processing
We will only process your data where we have a lawful basis under UK GDPR:
- Contract – To deliver dental care and treatment.
- Legal Obligation – To meet GDC, CQC, and tax compliance requirements.
- Vital Interests – In a medical emergency.
- Consent – For optional services, marketing communications, and any use of patient-identifiable photographs or video for promotional purposes.
- Legitimate Interests – For business administration, service improvement, and the use of CCTV for security purposes.
Special category (health) data is processed under Article 9(2)(h) – provision of health or social care.
CCTV footage is processed under legitimate interests for the security of premises, staff, and patients. We also process special category data where necessary for the establishment, exercise, or defence of legal claims (UK GDPR Article 9(2)(f)), for example, in the event of complaints or medico-legal matters.
How We Store and Protect Your Data
- Patient records are stored securely on our practice management software and/or in locked filing systems.
- Access is restricted to authorised personnel only.
- Electronic communications are encrypted where possible.
- We maintain strong cybersecurity measures, including antivirus software, secure passwords, and regular backups.
- Paper records are destroyed securely when no longer needed.
- Photography and Video – Clinical images/videos are stored securely within your patient records. Images/videos used for marketing are stored separately and only used in accordance with signed consent.
- CCTV recordings are stored securely on site, retained for no longer than 24 hours, and accessed only by authorised personnel.
Sharing Your Data
We may share your information with:
- Other dental/medical professionals involved in your care.
- Laboratories, referral centres, or imaging services.
- Regulatory bodies such as the GDC or CQC.
- HMRC for financial compliance.
- Our IT support, third party partners, cloud service providers, or auditors (under strict confidentiality agreements).
- CCTV footage may be shared with law enforcement agencies if required for the investigation of a crime or legal matter.
- Photographs/Videos for marketing or social media will only be shared with your explicit, informed written consent.
We will not share your data for marketing purposes without your explicit consent.
We do not transfer patient data outside the UK unless adequate safeguards are in place.
How Long We Keep Your Data
We retain patient records for at least 11 years after the last treatment, or until the patient is 25 years old (whichever is longer), in line with GDC guidance.
CCTV footage is retained for 24 hours unless required for an ongoing investigation.
Marketing photographs/videos will be stored for the duration of their agreed use or until consent is withdrawn.
After the retention period, records and footage will be securely destroyed.
Retention of Administrative & Enquiry Data
• Website and CRM enquiry data (Boxly CRM) is retained for 1-2 years, unless you become a patient, after which it is transferred to Dentally PMS.
• Marketing opt-in data is retained until consent is withdrawn.
• Staff and HR records are retained for 6 years after employment ends.
Your Rights
You have the right to:
- Access your records, photographs, videos, or CCTV footage that identifies you.
- Request correction of inaccurate information.
- Request deletion of your data (where legally permissible).
- Restrict processing in certain circumstances.
- Withdraw consent for the use of your images/videos in marketing at any time.
- Object to processing for direct marketing or CCTV surveillance where applicable.
- Data portability (where applicable).
To exercise your rights, please contact Dr. Fahad Khan using the details above.
Subject Access Requests (SARs)
You can request a copy of your personal information at any time. We will respond within one month. We may request proof of identity before releasing information. If your request is complex, we may extend the period by a further two months, and will notify you if this is necessary. Requests should be submitted to Dr. Fahad Khan at reception@thesmiledesigners.co.uk.
Data Breaches
In the unlikely event of a personal data breach that may affect your rights or freedoms, we will:
Investigate immediately and take corrective action
Notify the Information Commissioner’s Office (ICO) within 72 hours if required
Inform affected patients if there is a likely risk of harm
All breaches are documented internally with details of impact, actions taken, and outcomes.
Complaints
If you have any concerns about how we handle your data, please contact Dr. Fahad Khan.
You also have the right to complain to the Information Commissioner’s Office (ICO):
Website: www.ico.org.uk
Telephone: 0303 123 1113
Updates to This Policy
We may update this policy from time to time to reflect changes in law, regulation, or our practice procedures. The latest version will always be available at reception and on our website.