Skip to main content

    Legal · Privacy Notice

    Privacy Notice

    This notice explains how Circlemount Dental Technology Ltd ("dentorb", "we", "us") handles personal data when you visit our website, contact us, join the waitlist, or use the dentorb platform on behalf of a dental practice.

    v1.0Effective 27 April 2026Reviewed 27 April 2026
    Table of contents▾

    1. Who we are

    Circlemount Dental Technology Ltd is a company registered in England & Wales (Company No. 17188772). Our registered office is The Squires, 5 Walsall Street, Wednesbury, West Midlands, England, WS10 9BZ. We are registered with the UK Information Commissioner's Office (ICO No. TBC).

    For any privacy question, contact our Data Protection lead at marcus@dentorb.ai.

    2. Scope of this notice

    This notice covers personal data we process as a controller — primarily for marketing, sales, support, and account administration.

    When the dentorb platform processes patient data on behalf of a dental practice, the practice is the data controller and dentorb is the data processor. Those activities are governed by our Data Processing Agreement.

    • Controller activities: website, waitlist, sales, billing, support tickets, recruitment.
    • Processor activities: patient records, comms and clinical data inside the platform — see DPA.

    3. Personal data we collect

    • Identity and contact data — name, role, practice name, email, phone.
    • Account data — login identifiers, authentication factors, audit metadata.
    • Usage data — pages visited, features used, device and browser data, IP address.
    • Communications data — messages you send us by email, web form, or chat.
    • Marketing preferences — consent state and channel preferences.

    4. Lawful bases

    We rely on the following UK GDPR lawful bases:

    • Contract — to provide the service you've signed up for or to take steps before contract.
    • Legitimate interests — to run, secure and improve the service, prevent fraud, and conduct B2B marketing to dental practice decision-makers.
    • Consent — for non-essential cookies, marketing emails to individuals, and any optional features.
    • Legal obligation — for tax, accounting, regulatory and law-enforcement responses.

    5. How we use personal data

    • Provide and operate the platform and our website.
    • Authenticate users and protect accounts.
    • Respond to enquiries, sales conversations, and support requests.
    • Send service notifications (always) and marketing emails (where permitted).
    • Measure product usage and website performance in aggregate.
    • Detect, investigate and prevent abuse, fraud and security incidents.
    • Meet legal, regulatory and accounting obligations.

    6. Who we share data with

    We share personal data only with vetted sub-processors who help us run the service, and with professional advisers, regulators, or law enforcement where legally required. A current sub-processor list is published and version-controlled.

    • Cloud infrastructure and database hosting (UK / EU regions).
    • Email delivery for transactional and waitlist communications.
    • Analytics and product telemetry (privacy-respecting, aggregated).
    • Professional advisers (legal, accounting) under confidentiality.

    7. International transfers

    Patient data is stored in the UK with EU redundancy. Where a sub-processor is located outside the UK / EEA, we rely on UK adequacy regulations or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, plus supplementary measures where required.

    8. Retention

    • Marketing leads and waitlist entries: up to 24 months from last interaction, then deleted or anonymised.
    • Customer account records: for the duration of the contract, plus 7 years for tax / accounting.
    • Support tickets: 24 months from closure.
    • Server logs and security telemetry: 12 months.
    • Patient data inside the platform: per the practice's instructions and the DPA.

    9. Your rights

    Under UK GDPR you have the right to access, rectify, erase, restrict, port and object to processing of your personal data, and to withdraw consent at any time where processing is based on consent.

    To exercise any right, email marcus@dentorb.ai. We will respond within one month. You can also complain to the ICO (ico.org.uk) — though we'd appreciate the chance to resolve the matter first.

    10. Security

    We protect personal data with encryption in transit (TLS 1.3) and at rest (AES-256), role-based access, MFA for staff, audit logging, and continuous monitoring. See our Security Overview for full detail.

    11. Children

    The dentorb platform is sold to dental practices, not to consumers. Patient records inside the platform may relate to children — those records are processed on behalf of the practice under the DPA. Our marketing site is not directed at children.

    12. Changes to this notice

    We may update this notice. Material changes will be highlighted on this page and, where appropriate, communicated by email. The version and effective date are shown at the top.

    Questions about this document?

    Email marcus@dentorb.ai.

    Circlemount Dental Technology Ltd · Company No. 17188772 · Registered in England & Wales
    Incorporated 29 April 2026 · Registered office: The Squires, 5 Walsall Street, Wednesbury, West Midlands, England, WS10 9BZ

    © 2026 Circlemount Dental Technology Ltd · Company No. 17188772 · Registered in England & Wales