Compliance

What is done, and what is not finished yet.

Four things done, five not. Both lists are below.

Where your data is kept

The app runs on servers in London.

The app

Runs on Vercel (our hosting company), fixed to its London servers (lhr1).

Encryption

Scrambled so outsiders cannot read it: while it travels over the internet (TLS), and while our hosting company stores it.

Controller and processor

The practice is the controller (in charge of how patient data is used). ConsentIQ is the processor (handles the data for you). ConsentIQ creates your Article 30 record (the list of data uses the law asks you to keep).

What we never read

Eight things ConsentIQ could take from your practice software and does not.

  • Clinical notes
  • Medical history
  • Medications
  • Allergies
  • X-rays (radiographs)
  • Gum charts (perio charts)
  • Correspondence
  • Financial records

What it reads instead: who the patient is, the appointment, the treatment, the tooth and the diagnosis. The import is built so it cannot take anything else. It is not just a promise.

How patients are matched

A patient is matched by the patient number in your practice software, and never by name.

A record attached to the wrong patient is worse than no record.

The record

Records can only be added to. The database makes sure of it.

How records are linked

  1. 890f45295d34…Earlier record
  2. linked to 890f45295d34…
    0c13c74aa4f4…Earlier record
  3. linked to 0c13c74aa4f4…
    414c7a883171…Latest record

Each record carries a tamper check made from the record before it. If anyone changes an old record, every link after it breaks. So it is tamper-evident, which is not the same as tamper-proof: a change always shows, but it is not impossible.

If you turn on the AI features

What leaves your practice, and what we keep a note of.

What is sent

The clinician's own description, the tooth and the plain-English diagnosis. For the assistant, only what the person asking can already see.

What we keep

Every question sent to the AI and every reply. Only your practice can see them, and we keep them as long as your other records.

What it may never do

Anything the AI writes stays marked unchecked until a clinician approves it. This is built into the database, not just a tick box.

What is done and not done

Four things done, five things not.

  • In the product

    Each practice kept apart in the database

    Built into the database itself, not just the app. A search that forgets to pick a practice finds nothing.

  • In the product

    A history log that can only be added to

    Consents, answers, signatures and withdrawals cannot be edited afterwards, even by the app.

  • In the product

    How long records are kept, and removing details

    Fifteen years by default, or until a child patient turns 25. If someone asks for their data to be erased, we remove the personal details (redact) and keep the outline of the record.

  • In the product

    Article 30 record (the list of how you use data)

    Made from your current settings. The account owner or a practice manager can download it.

  • Not done yet

    Company registration

    Not yet set up as a company, so there is no legal body to sign a data processing agreement with.

  • Not done yet

    ICO registration (UK data regulator)

    Not yet registered as a data processor (a company that handles data for others).

  • Not done yet

    Data Protection Impact Assessment

    A written check of privacy risks. Not written yet. The law requires one, because we handle a lot of health data by computer.

  • Not done yet

    Data processing agreement (the contract for handling your data)

    ConsentIQ shows a draft. It stays a draft until a solicitor has agreed the wording.

  • Not done yet

    A clinician's check of the treatment content

    No explanation, risk or question has been checked by a registered clinician yet. ConsentIQ will not show unchecked content to a patient.

Free for UK dental practices

See a record for yourself.

  • In-chair consent
  • Email the link
  • Text the link
Compliance · ConsentIQ