Privacy
What is kept, and what cannot be deleted.
A record of what you understood is kept for fifteen years, and asking us to delete it does not shorten that. This page says why, and exactly which parts you can ask us to delete.
Who is in charge of it
Your dental practice decides. We store it for them.
Under UK data protection law your practice is the controller (it decides how your data is used) and ConsentIQ is the processor (it holds the data for them). That matters, because it tells you who to ask.
Ask your practice
To get a copy of your record, correct it, limit how it is used, or ask for it to be deleted, write to the practice that treated you. They decide, and we do what they tell us. We will not act on a request sent straight to us, because we cannot check who you are and they can.
What we are
ConsentIQ records what a patient understood before treatment: what was explained, what was answered, what was corrected and what was signed. It is evidence of understanding that supports the consent conversation. It never replaces it, and it makes no claim about the treatment or about anyone’s legal position afterwards.
ConsentIQ has not launched yet. It is not yet a registered company and is not yet on the register of the ICO (the UK data protection regulator), and both are listed openly on the compliance page rather than left to be discovered.
What is collected
Enough to know it was you, and what you understood.
Who you are. Your name, your date of birth, and the practice’s own reference for you. Date of birth is there because age changes how a risk has to be explained and who may lawfully agree to treatment, not to profile anybody.
Your consent visit. Which procedure, which tooth, which clinician, which language, when it started and when it finished, every question you were shown, every answer you gave including the wrong ones, every part that was explained again, how long you spent, anything you refused, and anything the software told the clinician you had not yet understood.
Signatures. Your signature image and typed name, the time, and the same for a witness or a person with parental responsibility where one signed.
Ability to decide (capacity), children and best interests. Where a clinician checked whether you could make this decision, that check and their notes. Where treatment went ahead as a best-interests decision (made for you, in your interest) or in an emergency without the usual steps, the record of that decision.
Contact details, sometimes. If the practice sent you a link to read at home, your email address or mobile number is held with that consent, along with whether the message arrived.
Files. A photograph, X-ray or scanned form the clinician attached because it was part of what you were shown.
Other personal details, which have a space but are empty. The patient record has spaces for an address, a postcode, a telephone number, an NHS number, a guardian’s details and a legal representative’s details. Nothing in the product writes any of them today, and no deletion request reaches them. They are named here because a notice that only lists the fields currently in use is a notice that goes stale the day one is filled in.
Never collected
Clinical notes, medical history, medications, allergies, X-rays from your notes, periodontal (gum) charts, correspondence and financial records. Where ConsentIQ reads from a practice’s software it does not read any of them, so they are not in the database to be sent anywhere. There is no advertising anywhere in this product, no analytics service, no tracking of any kind, and nothing is sold or shared for marketing.
Where it is
Where it is stored is checked by the app itself.
The app will not start if it is set up in a location outside the allowed list.
Application
Runs on Vercel, fixed to London. Every time data is read, the database itself checks the person is allowed to see it.
Files
Private Amazon S3 storage, with no public or shareable link. Every download goes through the app, which first checks the person is allowed, and is logged.
Sent and stored
Encrypted (scrambled) while it is sent. Encrypted while stored, by the storage providers.
How long
Fifteen years, and it cannot be shortened by asking.
For an adult, a record is kept for fifteen years from the day the consent was completed. For a patient who was under sixteen at the time, it is kept until their twenty-fifth birthday or fifteen years from completion, whichever falls later.
A practice can change those two numbers, within limits the software enforces: adult records kept for between eleven and thirty years, and the age for a child between twenty-five and thirty. Eleven years is a minimum, not a default. A practice cannot keep adult records for less, even if it wants to, and every change is written to the activity log (the permanent log of changes).
Once a record is sealed (locked so any change shows), its keep-until date is fixed on the record itself and the database refuses to change it. A practice that later shortens its policy does not shorten the clock on records already sealed.
We keep it because the law requires it. Not your consent, and not our interests. A record of what a patient was told before treatment is exactly the thing a claim made years afterwards turns on, and dental record-keeping obligations are why the period is what it is. UK GDPR (the UK law on personal data) Article 17(3)(b) says the right to erasure (deletion) does not apply where using the data is needed to meet a legal duty. That is the whole reason the clock cannot be shortened on request, and it is the honest answer rather than a convenient one.
Your rights
All of them, and the one that is limited here.
Seeing your data, correcting it, limiting its use, objecting, taking it elsewhere (portability) and complaining all work as normal. Deletion (erasure) is the one that is limited, and here is exactly how.
What a deletion request does remove
- Your email address, your phone number, and any note the practice wrote about how to send you the link.
- Who each message was sent to, and any error recorded when a message to you did not arrive.
- The name of every file attached to your consent. A file name can name a person.
- The attached files themselves. Every stored version of them is removed, not marked as deleted.
- The text of any note waiting to be added to the practice's own software. Any such note not yet added is cancelled.
- The clinical content of the sealed (locked) record, which is replaced with a note saying it was removed (redacted).
- Once the time we must keep it has passed: appointments and treatments copied from the practice's software, and the links between your ConsentIQ record and that software.
What it does not remove
- Your name, your date of birth, and the practice's own reference for you.
- The consent itself: that it happened, its status, its timings, which clinician ran it, and which language it was in.
- Every answer you gave, including the ones you got wrong.
- Every signature.
- The check of whether you could make this decision (capacity), including the clinician's notes.
- Best-interests decisions (made for you, in your interest), emergency treatment without the usual steps, withdrawals, parts explained again, and notes that something was not understood.
- The sealed record's tamper check (proof it has not been changed), the tamper check of the record before it, its place in the sequence, when it was sealed, by whom, how, and the date it is kept until.
- The activity log (the record of who did what), in full.
- Invoices held by the payment provider for the practice, which tax law requires be kept for six years.
Most of the record is in the second list, and that is on purpose. Twenty-two tables in the database are linked to a patient, a consent or a record. Sixteen of them can never be deleted from: the database itself refuses. The app has no permission to delete a patient, a consent or a record, and the database blocks any attempt, even one made by an administrator.
Removing personal details (redaction) takes out the content and keeps the outline: the tamper check, the record’s place in the sequence, and the fact that a record existed and had details removed, with the reason and the name of the person who asked. If a record were quietly removed, the tamper checks either side of it would prove nothing. That is why the outline stays.
A practice can close its account. Nobody can delete one. Closing an account cancels the subscription, deletes the stored card at the payment provider, removes every user’s access and signs out every tablet. It does not touch a single clinical record, and the activity log records the closure and says so. There is no delete-everything button anywhere in this product and there will not be one.
You can complain to the Information Commissioner’s Office (the UK data protection regulator) at any time, and you do not have to raise it with the practice or with us first.
Who else sees it
The whole list, including the parts that are switched off.
15 outside companies are built into this product. Our list says 4 of them are switched on; the rest are built in but switched off. This column is our own list, last checked by hand on 29 August 2026. It does not read the running deployment (the live system), so it can be out of date. The live answer for email, text messages, file storage and billing is on your practice's settings screens in ConsentIQ.
| Who | Where | Declared in the register |
|---|---|---|
| Neon | London (aws-eu-west-2). This was fixed when the database was set up and cannot be moved. | Switched off |
| Vercel | Set to run in London (lhr1). | Switched on |
| Anthropic | United States. Anthropic does not offer processing kept inside the UK. | Switched on |
| Amazon Web Services (S3) | London (eu-west-2). If no region is set, ConsentIQ refuses to start rather than picking one. | Switched on |
| Resend | Processed in the EU. | Switched off |
| MessageBird (Bird) | Its EU servers (rest-eu.messagebird.com). | Switched off |
| PureSMS (Divergent Cloud) | United Kingdom (connect-api.divergent.cloud). Texts come from a UK short number or sender name. | Switched off |
| Twilio | United States. By default, messages are routed and logged in the US. | Switched off |
| Stripe | Stripe Payments UK Ltd, with processing that includes the United States. | Switched off |
| Independent time stamp service (RFC 3161) | Wherever the chosen service is. A setting (TSA_URL) decides it. | Switched on |
| Google sign-in (OpenID Connect) | Worldwide, mainly the United States. | Switched off |
| Your practice's own sign-in service (SAML) | Wherever the practice runs it. | Switched off |
| Dentally | Dentally's servers (api.dentally.co), in the practice's own account, or Dentally's test system (api.sandbox.dentally.co) when set to use it. | Switched off |
| Cloudflare | Worldwide (it answers from the nearest location). | Switched off |
| The Windows app update server | Not decided, and never contacted: no update server is set up, so the app never checks for updates. | Switched off |
The three that can see anything about a patient are the database, the file store and the AI model that drafts content for a clinician to check. The AI model is sent a procedure, a tooth, a diagnosis, the clinician’s note about it, the risks marked as important for you and an age band. It is never sent your name, your date of birth, your NHS number, your address, your email or your phone number, and their absence is checked by an automated test rather than promised in a document. It runs in the United States, which is the one part of this system that leaves the country, and we list it openly as an unresolved issue.
Email and text-message providers, where a practice turns them on, are sent your first name, the practice name, a one-time link and when it expires. Not your full name, and not what the appointment is for.
The full list, including exactly what each one receives and which are outside the United Kingdom, is kept in PROCESSORS.md in the source code and is shown to every practice inside the console.
Computer decisions
Nothing here decides anything about you.
Your answers are marked against the answer recorded with each question when a clinician approved it. An AI model is not asked whether you understood, and it is not asked anything about you.
An AI model drafts explanations, risk descriptions and questions for a clinician to read, change and approve. Until a clinician has approved it, the database refuses to show it to a patient. Nothing in this product produces a decision about you by automated means, and nothing here decides whether you are treated. Where the software notices that something was not understood, it tells the clinician and the conversation continues.
This page is written to match the software. The parts checked automatically are: how long records are kept, the list of companies that receive data, and the claim that no page contacts an outside company.