Denturaa policies
Last updated: September 2026. This policy document reflects Denturaa’s clinical and operational standards across all UK clinic locations in accordance with UK GDPR, ICO, and ASA healthcare regulations.
This Privacy Policy explains how Denturaa Dental Systems and its affiliated clinic practices (operating in Birmingham, London, Manchester, Bristol, Nottingham, and Leeds) collect, hold, process, and protect your personal and healthcare information.
Depending on where you attend your consultation, the legal entity operating the local dental practice acts as the Data Controller (or joint controller) for your clinical records and in-person patient care. Denturaa acts as the controller for general website operations, direct appointment requests, and brand communications.
For any data protection inquiries, Subject Access Requests (DSAR), or to contact our Data Compliance Lead, please email contact@denturaa.com or write to our registered clinical compliance office.
Denturaa and its operating dental clinics comply with the Data Protection (Charges and Information) Regulations 2018 and are registered with the UK Information Commissioner's Office (ICO), the statutory supervisory authority for data protection in the United Kingdom.
You have the unconditional statutory right to lodge a complaint at any time with the ICO if you believe your personal data has been handled unlawfully or your data protection rights have been infringed. We encourage patients to contact our compliance team first so we can promptly address any concern.
Under the UK General Data Protection Regulation (UK GDPR), we must have a valid lawful basis to process your personal data. We rely on the following legal grounds:
Personal data concerning health (including dental records, clinical photographs, oral impressions, edentulous status, medical histories, and treatment notes) constitutes 'Special Category Data' under UK GDPR Article 9.
We process health data strictly under UK GDPR Article 9(2)(h), which permits processing necessary for the provision of healthcare, medical diagnosis, dental treatment, or the management of healthcare systems.
All clinical data is handled by or under the direct supervision of registered dental professionals (Clinical Dental Technicians and Dental Surgeons) who are legally and ethically bound by statutory Standards for the Dental Team (Principle 4: Maintain and protect patients' information).
Security Notice: Please never submit sensitive diagnostic details, medical histories, or private dental photographs through general website inquiry fields or Google Calendar notes. Clinical histories are recorded securely in person during your clinical consultation.
To provide safe and responsive dental consultation services, we may collect the following categories of information:
Our online consultation scheduling utilizes Google Calendar (Google Workspace). When you select an appointment slot, your booking is scheduled directly through Google's appointment scheduling infrastructure (https://calendar.app.google/9xSETLeBFFvqsvAYA).
Google operates as a data processor on our behalf, bound by strict Data Processing Agreements (DPAs) incorporating UK International Data Transfer Addendums and Standard Contractual Clauses (SCCs) to ensure equivalent protection for data transferred outside the UK.
In-clinic records, dental charts, and patient files are maintained inside dedicated dental practice management systems compliant with statutory healthcare governance rules, featuring encrypted databases, audit logging, and multi-factor authentication.
In accordance with our Booking Policy, we expressly advise that Denturaa operates alongside third-party clinical sites, rented surgeries, and partner dental companies. Clinical consultations and denture procedures may be carried out by independent professionals who are not directly employed by Denturaa.
To schedule your appointment, verify medical suitability, and provide custom dental prosthetics, your personal and health information is shared with and received by:
In strict adherence to Advertising Standards Authority (ASA) CAP Code guidelines and PECR rules, Denturaa ensures total transparency across all marketing and promotional communications.
We strictly enforce a policy prohibiting the upload, sharing, or targeting of special-category clinical health data or dental diagnoses with advertising platforms (such as Google Ads, Meta, or third-party ad networks).
Any marketing conversion tracking requires your explicit, prior consent via our Cookie Settings banner. You may opt out of promotional messages at any time by clicking the unsubscribe link or contacting us directly.
We retain personal and clinical information only for as long as necessary to fulfill the purposes for which it was collected, and to comply with statutory healthcare retention requirements:
Under the UK GDPR and the Data Protection Act 2018, you possess key rights regarding your personal information:
In compliance with healthcare governance and NHS Information Governance principles, we maintain robust organizational and technical safeguards.
All electronic communications and website transactions are encrypted using Transport Layer Security (TLS 1.3). Digital clinical records are backed up offsite in encrypted UK-based data centers, and physical records are stored in secure, locked clinical filing environments accessible only by authorized dental staff.
To exercise any of your data protection rights, request a copy of your records, or discuss our compliance policies, please contact:
Data Compliance Lead: contact@denturaa.com Denturaa Dental Systems — Clinical Operations Network Clinics: Birmingham, London, Manchester, Bristol, Nottingham, Leeds