Compliance
What is done, and what is not finished yet.
Four things done, five not. Both lists are below.
Where your data is kept
The app runs on servers in London.
The app
Runs on Vercel (our hosting company), fixed to its London servers (lhr1).
Encryption
Scrambled so outsiders cannot read it: while it travels over the internet (TLS), and while our hosting company stores it.
Controller and processor
The practice is the controller (in charge of how patient data is used). ConsentIQ is the processor (handles the data for you). ConsentIQ creates your Article 30 record (the list of data uses the law asks you to keep).
What we never read
Eight things ConsentIQ could take from your practice software and does not.
- Clinical notes
- Medical history
- Medications
- Allergies
- X-rays (radiographs)
- Gum charts (perio charts)
- Correspondence
- Financial records
What it reads instead: who the patient is, the appointment, the treatment, the tooth and the diagnosis. The import is built so it cannot take anything else. It is not just a promise.
How patients are matched
A patient is matched by the patient number in your practice software, and never by name.
A record attached to the wrong patient is worse than no record.
The record
Records can only be added to. The database makes sure of it.
How records are linked
- 890f45295d34…Earlier record
- linked to 890f45295d34…0c13c74aa4f4…Earlier record
- linked to 0c13c74aa4f4…414c7a883171…Latest record
Each record carries a tamper check made from the record before it. If anyone changes an old record, every link after it breaks. So it is tamper-evident, which is not the same as tamper-proof: a change always shows, but it is not impossible.
If you turn on the AI features
What leaves your practice, and what we keep a note of.
What is sent
The clinician's own description, the tooth and the plain-English diagnosis. For the assistant, only what the person asking can already see.
What we keep
Every question sent to the AI and every reply. Only your practice can see them, and we keep them as long as your other records.
What it may never do
Anything the AI writes stays marked unchecked until a clinician approves it. This is built into the database, not just a tick box.
What is done and not done
Four things done, five things not.
In the product
Each practice kept apart in the database
Built into the database itself, not just the app. A search that forgets to pick a practice finds nothing.
In the product
A history log that can only be added to
Consents, answers, signatures and withdrawals cannot be edited afterwards, even by the app.
In the product
How long records are kept, and removing details
Fifteen years by default, or until a child patient turns 25. If someone asks for their data to be erased, we remove the personal details (redact) and keep the outline of the record.
In the product
Article 30 record (the list of how you use data)
Made from your current settings. The account owner or a practice manager can download it.
Not done yet
Company registration
Not yet set up as a company, so there is no legal body to sign a data processing agreement with.
Not done yet
ICO registration (UK data regulator)
Not yet registered as a data processor (a company that handles data for others).
Not done yet
Data Protection Impact Assessment
A written check of privacy risks. Not written yet. The law requires one, because we handle a lot of health data by computer.
Not done yet
Data processing agreement (the contract for handling your data)
ConsentIQ shows a draft. It stays a draft until a solicitor has agreed the wording.
Not done yet
A clinician's check of the treatment content
No explanation, risk or question has been checked by a registered clinician yet. ConsentIQ will not show unchecked content to a patient.
Free for UK dental practices
See a record for yourself.
- In-chair consent
- Email the link
- Text the link