Effective Date: 9 July 2026 Version: v1.1
This Privacy Notice explains how Implants Local Ltd trading as Dentalreel (company number 16197776, ICO registration ZB960243, registered office Ayton Firs Hall, Great Ayton, Middlesbrough, England, TS9 6JB) handles personal data when you visit our website or use the Dentalreel platform.
This notice covers personal data we collect about you, the user of dentalreel.com: dental practice owners or staff, agency partners, and prospective customers. Personal data of patients who interact with the Dentalreel widget on a dental practice's website is governed by the Data Processing Agreement and is the responsibility of the dental practice as data controller.
This notice is intentionally short. The full picture for practice subscribers is in the Terms of Service and the Data Processing Agreement.
What we collect
When you create an account (dental practice or agency):
- Email address. Used to identify your account and to send verification, billing, and product emails.
- Password. Stored in hashed form only — we never see the plaintext.
- Practice or agency name, postcode, role. Self-declared during sign-up; used to personalise the dashboard and route support.
- Account status, generation count, generation limit. Internal counters that gate feature access.
When you verify your email:
- A one-time magic-link token, valid for one hour, sent via email and consumed on click.
When you visit the site (any visitor):
- IP address. For rate-limiting (registration, brand-extraction and demo endpoints) we compute SHA-256 of the IP plus a server-side salt and store only the hash. Separately, we retain the raw IP address in two narrow places: (1) the consent audit log created when a patient ticks the consent box before an AI simulation, kept as evidence of that consent; and (2) widget load telemetry recording which websites our embed runs on, kept for security and abuse detection.
- Browser session cookies (
dr-session,dr-refresh-soon). Both first-party. The first carries an authenticated session as a signed JWT (HttpOnly, Secure, SameSite=Lax, 1-hour sliding TTL); the second is a short-lived hint that triggers a background session refresh. - Standard server logs (request path, status, latency, user-agent) for security and operations.
When you try the smile-simulator demo (/try):
- Your selfie or uploaded photo. Processed by our AI provider solely to generate your demo smile preview (image and short video). All demo images — your photo and the generated previews — are automatically deleted within 60 minutes of generation.
- The demo form details — your name, practice name, role, and work email — so we can follow up about Dentalreel.
- A hashed IP address to rate-limit the free demo, and a consent audit record — the time you ticked the consent box, the exact consent wording shown (as a hash), your IP address and browser user-agent — retained as evidence that consent was given.
- An operations copy via Telegram. So our team sees demo results promptly, your before/after preview and form details are sent to our private operations channel on Telegram. That message is automatically deleted within roughly 60–120 minutes by an hourly job; your contact details (not images) are retained so we can follow up.
When you use the smile simulator (bot protection):
- Cloudflare Turnstile signals. To stop automated abuse of the AI simulator, an invisible Cloudflare Turnstile check runs when a simulation is generated. Cloudflare processes a minimal set of client-side signals — your IP address, browser/device characteristics (e.g. User-Agent and TLS fingerprint), and the widget's site identifier — solely to tell human users from bots. Cloudflare cannot directly identify you from these signals, does not use them to profile or target you, and Turnstile sets only a strictly-necessary security cookie. This processing is governed by Cloudflare's Turnstile Privacy Addendum.
Analytics and advertising cookies (consent-only). With your consent — the "Accept all" choice on our cookie banner — we use Google Analytics 4 and the Meta Pixel on our marketing pages to measure how visitors find and use dentalreel.com and to improve our advertising. This includes our own advertising landing pages on dentalreel.com (simulator pages you reach from one of our adverts), where the Meta Pixel records that a simulation was started and that an enquiry was submitted — never your photo, your simulation images, or the content of your enquiry. Choose "Essential only" and none of these tools load, and the simulator and enquiry form work exactly the same. These tools never run inside practice websites.
Why we use it
All personal data is processed on one of these lawful bases under UK GDPR:
| Purpose | Lawful basis |
|---|---|
| Operate your account, deliver the service you subscribed to | Contract performance (Art 6(1)(b)) |
| Send transactional emails (verification, billing, security) | Contract performance |
| Bill you, prevent fraud, keep tax records | Legal obligation, legitimate interest |
| Rate-limit endpoints, detect abuse | Legitimate interest (network and information security) |
| Block bots on the smile simulator via Cloudflare Turnstile | Legitimate interest (network and information security) |
| Generate your demo smile preview from your selfie (/try) | Consent (Art 6(1)(a)) — withdraw any time |
| Send your demo result and form details to our operations team via Telegram, and follow up with you about Dentalreel | Consent (Art 6(1)(a)) |
| Measure marketing-site usage and advertising (GA4, Meta Pixel) | Consent (Art 6(1)(a)) via the cookie banner |
| Improve the product using anonymised aggregate data | Legitimate interest |
We do not sell personal data. We do not share personal data for third-party advertising.
How long we keep it
| Data | Retention |
|---|---|
| Active account data | While your account is active |
| Account data after cancellation | 30 days on production, deleted within a further 14 days; backups rotated out within 90 days |
| Magic-link tokens | Expire 1 hour after issue; not stored server-side |
| IP hash counters (Upstash) | TTL set by the relevant rate-limit window (typically 1 hour or 24 hours) |
| Server logs | 30 days in hot storage, then aggregated |
| Demo selfies and generated previews (/try) | Deleted automatically within 60 minutes of generation |
| Telegram operations copy of a demo result | Deleted automatically within ~60–120 minutes (hourly job) |
| Demo contact details (name, practice, role, work email) | Until you ask us to delete them (email dpo@dentalreel.com) |
| Tax and accounting records | 6 years (HMRC requirement) |
| Anonymised aggregate analytics | Indefinitely |
Patient-data retention on the widget itself is governed by the DPA, clause 11.
Who we share it with
We use a small set of sub-processors to deliver the service. The full list (with location of processing and transfer safeguards) is on our sub-processors page. The current list includes AWS, Supabase, Stripe, Resend, Google Cloud (Gemini / Vertex AI), Vercel, Upstash, and Cloudflare. For the smile-simulator demo on /try, Telegram (Telegram Messenger Inc.) carries the short-lived operations copy of demo results described above.
Where personal data leaves the United Kingdom, we rely on UK adequacy regulations or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.
We will give at least 30 days' notice before adding or replacing a sub-processor.
Your rights
Under the UK GDPR and the Data Protection Act 2018, you have the right to:
- Access the personal data we hold about you (Article 15)
- Correct inaccurate data (Article 16)
- Erase your data, subject to legal retention requirements (Article 17)
- Restrict processing (Article 18)
- Port your data to another provider (Article 20)
- Object to processing on legitimate-interest grounds (Article 21)
- Withdraw consent at any time where processing relies on consent
- Not be subject to a decision based solely on automated processing (Article 22) — Dentalreel does not make decisions of legal or similarly significant effect about you on a fully automated basis
To exercise any of these rights, email dpo@dentalreel.com. We respond within one month.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or 0303 123 1113 if you believe we have mishandled your data.
Security
We protect personal data with the technical and organisational measures described in clause 8 of the DPA — encrypted transit (TLS 1.2+), encrypted at-rest (AES-256), least-privilege role-based access controls on a small number of named administrative accounts, tenant-scoped row-level security in the database, signed and expiring session tokens, regular security patching, and incident response procedures.
If we become aware of a personal data breach that affects you, we will notify you without undue delay (in any event within 72 hours of becoming aware) and, where the breach is high-risk to your rights and freedoms, advise you of the steps you can take.
Contact
- Data protection: dpo@dentalreel.com
- Support: support@dentalreel.com
- Legal: legal@dentalreel.com
- Post: Ayton Firs Hall, Great Ayton, Middlesbrough, England, TS9 6JB
Document version: v1.1 Last updated: 9 July 2026