Privacy policy
Last updated 24 September 2026
1. Who we are
Elevate Dental OS ("the system") is an internal business system operated by [to be completed: registered company name], a company registered in England and Wales under number [to be completed: company number], registered office [to be completed: registered office address] ("we", "us").
The system is built and used only by us and our own group of dental practices. It is not sold, licensed or offered to any other business or to the public, and we do not market it or accept sign-ups from outside users.
For personal data about our own staff users, and for the Google account data described below, we are the controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Contact us about this policy at [to be completed: contact email].
2. What personal data the system holds
- Staff accounts: name, work email address, role, permissions and a sign-in record, so authorised staff can use the system securely.
- Activity records: an audit log of changes made in the system, and technical logs (for example IP address and browser) kept for security.
- Practice records: appointment, treatment, payment and enquiry records imported from our own practice management, CRM and finance systems. These are processed for our own practices under the privacy notices those practices give their patients; this policy does not replace them.
- Google account data: see section 3.
3. Google user data
When an authorised member of staff connects a Google account, they choose to give the system permission to read specific data. We request only these permissions:
- Google Search Console (read-only): how our own websites appear in Google Search — searches, pages, clicks, impressions and positions, sitemaps and index status.
- Google Analytics (read-only): aggregate visits, engagement and key events (such as enquiry form submissions) for our own websites. We store daily totals only, never individual visitors.
- Google Business Profile: views, calls, direction requests and website clicks for our own practice listings. We only read this data; the system never changes a listing, although Google offers this permission only as a combined read-and-manage permission.
- Google Sheets: reading the spreadsheets staff choose to connect, and writing to the one spreadsheet staff choose for exports.
- Your email address and basic profile: to show which Google account is connected.
How we use it. Only to show our own business reports inside the system to our own authorised staff.
What we do not do. We do not sell Google user data, use it for advertising, share it with third parties (except the service providers in section 5 who host the system for us), let people read it except where needed for security, legal compliance or to operate the system, or use it to develop, improve or train artificial intelligence or machine learning models.
Elevate Dental OS's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Search queries. Google already withholds rare search terms. In addition we discard any search term containing an email address, a phone number or a full postcode before it is stored.
Removing access. Staff can disconnect a Google account in the system at any time, and anyone can remove the system's access from their Google account at myaccount.google.com/permissions. After disconnection we stop collecting data and delete stored sign-in tokens; reports built from data already collected are kept as described in section 6 unless you ask us to delete them.
4. Our lawful basis
We process this data on the basis of our legitimate interests in running and managing our own dental practices (UK GDPR Article 6(1)(f)), and to meet our legal obligations where they apply. Staff account data is also processed to perform our employment and engagement arrangements.
5. Who processes the data for us
The system is hosted by service providers acting on our instructions under written contracts, including our database host (Supabase), our application host (Railway), and our email and error-monitoring providers. Where a provider stores data outside the UK we rely on UK adequacy regulations or the UK International Data Transfer Agreement / Addendum.
6. How long we keep it
- Google Search Console and Analytics reports: up to 16 months of daily history, matching what Google itself keeps, then deleted on a rolling basis.
- Google sign-in tokens: until the account is disconnected, then deleted.
- Staff accounts: for as long as the person needs access, then removed.
- Audit and security logs: as long as needed for security and our legal obligations.
7. Security
Access is limited to named staff accounts with role-based permissions. Google sign-in tokens and other integration credentials are encrypted at rest. Data is transmitted over encrypted connections, and every change is recorded in an audit log.
8. Your rights
Under UK data protection law you can ask to access, correct or delete your personal data, restrict or object to its processing, and ask for a copy to move elsewhere. Contact [to be completed: contact email]. We will reply within one month. If you are unhappy with how we handle your data you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.
9. Cookies
The system uses only the cookies strictly necessary to keep authorised staff signed in. It does not use advertising or analytics cookies, so no cookie consent banner is required.
10. Changes
We will update this page if our practices change, and show the date of the latest version at the top.