Privacy Policy & GDPR Statement

1. Who We Are And How To Contact Us

1.1 Delapre Dental Care, operated by Dr Sabina Nasir, is the data controller responsible for the personal information we hold about you.

1.2 If you have any questions about how we use your personal information, or wish to exercise any of your rights (see Section 10), please contact us at: Delapre Dental Care, 5 Billing Road, Northampton, NN1 5AN. Telephone: 01604 636836.

1.3 Where required by law, we may be obliged to appoint a Data Protection Officer (DPO). Details of any DPO appointed will be added to this policy and displayed at the Practice premises.

2. What Personal Information We Collect

2.1 We collect and process the following categories of personal information:

2.2 We do not collect or process special category data beyond what is necessary for the provision of dental care, the operation of the Voice Agent, and the fulfilment of our legal and regulatory obligations.

3. How We Collect Your Information

3.1 We collect personal information directly from you when you register as a patient, complete medical history forms, attend appointments, contact the Practice by telephone, email, or via our website, or interact with our digital Voice Agent.

3.2 We may also receive information from NHS England, your GP, referring clinicians, dental laboratories, or other healthcare providers involved in your care, where this is necessary for your treatment.

3.3 When you interact with the Voice Agent, your conversation inputs are transmitted in real time to third-party large language model providers for processing (see Section 5 and Section 8). Data is collected automatically through this interaction; you are not required to provide personal information to use the Voice Agent, and our Terms & Conditions expressly prohibit you from doing so.

4. Why We Use Your Information And Our Lawful Basis

4.1 We process your personal information for the following purposes and on the following legal bases under UK GDPR:

4.2 Where our lawful basis is consent, you may withdraw your consent at any time by ceasing to use the Voice Agent. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

5. Who We Share Your Information With

5.1 We share your personal information only where necessary and only with the following recipients or categories of recipients:

5.2 We do not sell your personal information to any third party. We do not share your information for marketing purposes without your explicit consent.

5.3 Third-party large language model providers. The Voice Agent is powered by third-party large language model (LLM) technology. Conversation inputs are transmitted to and processed by these providers in order to generate responses. The LLM providers used by the Voice Agent may change from time to time and may include, but are not limited to, LLMs provided by companies such as Anthropic, Google, and OpenAI.

5.4 The use of the Voice Agent is subject to the terms of service and privacy policies of the third-party LLM providers whose technology powers the Voice Agent. Users are strongly encouraged to review the terms and privacy policies of these providers to understand how their data may be processed. The Practice does not control and cannot guarantee the data handling practices of these independent third-party providers.

5.5 In respect of data processed through the Voice Agent, the Practice acts as a data controller to the extent it determines the purpose and means of processing. The third-party LLM providers are independent controllers in respect of their own processing activities and are responsible for their own compliance with applicable data protection law.

6. How Long We Keep Your Information

We retain patient records in accordance with NHS and professional guidance. Current retention periods are:

6.2 These retention periods reflect our legal obligations under the Limitation Act 1980, NHS guidance, GDC professional standards, and ICO guidance on data minimisation. Records will be securely destroyed at the end of the applicable retention period.

6.3 The Practice cannot control the retention periods applied by third-party LLM providers to data processed through their systems. Users should consult the privacy policies of those providers (listed in Section 5.3) for information about their data retention practices.

7. This Website And Digital Services

7.1 When you visit this website, standard technical information may be collected automatically, including your IP address, browser type, and pages visited. This information is used solely for the purpose of maintaining the security and performance of the website and is not used to identify you personally.

7.2 AI Voice Agent. This website features a digital AI voice assistant ("the Voice Agent") that uses large language model technology to provide general information about the Practice, answer frequently asked questions, and facilitate administrative functions such as appointment booking requests. The Voice Agent is not a secure or confidential communication channel.

7.3 Prohibition on sharing personal information. You must not disclose personal identifiable information, sensitive personal data, or special category data during any interaction with the Voice Agent. This includes your name, address, date of birth, contact details, NHS number, medical or dental history, symptoms, medications, or financial information. Full details of this prohibition are set out in clause 7.9 of our Terms & Conditions. The Practice accepts no liability for personal data voluntarily disclosed to the Voice Agent in breach of this prohibition.

7.4 Accuracy disclaimer. AI and large language model technology can produce information that is inaccurate, incomplete, or out of date — a phenomenon known as "hallucination." Nothing communicated via the Voice Agent constitutes a clinical consultation, diagnosis, or treatment recommendation. No dentist–patient relationship is created by interacting with the Voice Agent. For any clinical concern, please contact the Practice directly and speak with a qualified dental professional.

7.5 Recording and monitoring. All interactions with the Voice Agent may be recorded, transcribed, logged, and monitored for the purposes of quality assurance, service improvement, system diagnostics, and compliance. By using the Voice Agent, you consent to this recording and monitoring in accordance with the Regulation of Investigatory Powers Act 2000, the Telecommunications (Lawful Business Practice) (Interception of Communications) Regulations 2000, and the UK GDPR. Recorded interactions may be reviewed by authorised Practice staff and by authorised personnel of the Practice's technology providers.

7.6 Age restriction. The Voice Agent is intended for use by persons aged 16 or over. Persons under the age of 16 must not use the Voice Agent unless they have the verifiable consent of a parent or person with parental responsibility. Where a parent or guardian uses the Voice Agent on behalf of a child, these provisions apply to that parent or guardian.

7.7 We do not use cookies beyond those strictly necessary for the operation of this website. We do not use tracking, profiling, or advertising cookies.

8. Transferring Your Data Outside The UK

8.1 Clinical patient records and administrative data held by the Practice are not routinely transferred outside the United Kingdom.

8.2 Voice Agent data. Conversation data processed through the Voice Agent is transmitted to third-party large language model providers whose servers may be located outside the United Kingdom, including in the United States and the European Economic Area. By using the Voice Agent, you acknowledge and consent to this international transfer of data.

8.3 Where personal data is transferred outside the United Kingdom, we ensure that appropriate safeguards are in place. For transfers to the United States, we rely on the UK Extension to the EU-US Data Privacy Framework where the recipient provider is certified, or on UK International Data Transfer Agreements (IDTAs) or UK Addenda to Standard Contractual Clauses where applicable. For transfers to the EEA, we rely on the relevant UK adequacy regulations.

8.4 You may request further details of the safeguards applied to any international transfer of your personal data by contacting us at the address in Section 1.

9. Children's Data

9.1 The Practice treats patients of all ages. Clinical records for child patients are processed on the same lawful bases as adult records (see Section 4) and are retained in accordance with the periods set out in Section 6.

9.2 In respect of the Voice Agent, the Practice does not knowingly collect or process data from persons under the age of 16 without parental consent. The Voice Agent is restricted to users aged 16 or over, in accordance with the age of digital consent under UK GDPR Article 8 and the ICO's Age Appropriate Design Code.

9.3 If the Practice becomes aware that a person under 16 has used the Voice Agent without appropriate parental consent, any data collected during that interaction will be deleted as soon as reasonably practicable.

10. Your Rights

10.1 Under UK GDPR, you have the following rights in relation to your personal data:

10.2 To exercise any of these rights, please contact us in writing at the address in Section 1. We will not charge a fee for a Subject Access Request unless it is manifestly unfounded or excessive.

10.3 If you are dissatisfied with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO): Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Telephone: 0303 123 1113. Website: ico.org.uk.

11. Changes To This Privacy Policy

11.1 We review this Privacy Policy regularly. Any material changes will be notified to patients and updated on this website. The date at the top of this document reflects the most recent revision.

11.2 Where material changes are made to the provisions relating to the Voice Agent, third-party data processing, or international data transfers, the Practice will use reasonable endeavours to draw such changes to users' attention via a notice on the website.