Privacy

What is kept, and what cannot be deleted.

A record of what you understood is kept for fifteen years, and asking us to delete it does not shorten that. This page says why, and exactly which parts you can ask us to delete.

Who is in charge of it

Your dental practice decides. We store it for them.

Under UK data protection law your practice is the controller (it decides how your data is used) and ConsentIQ is the processor (it holds the data for them). That matters, because it tells you who to ask.

Ask your practice

To get a copy of your record, correct it, limit how it is used, or ask for it to be deleted, write to the practice that treated you. They decide, and we do what they tell us. We will not act on a request sent straight to us, because we cannot check who you are and they can.

What we are

ConsentIQ records what a patient understood before treatment: what was explained, what was answered, what was corrected and what was signed. It is evidence of understanding that supports the consent conversation. It never replaces it, and it makes no claim about the treatment or about anyone’s legal position afterwards.

ConsentIQ has not launched yet. It is not yet a registered company and is not yet on the register of the ICO (the UK data protection regulator), and both are listed openly on the compliance page rather than left to be discovered.

What is collected

Enough to know it was you, and what you understood.

Who you are. Your name, your date of birth, and the practice’s own reference for you. Date of birth is there because age changes how a risk has to be explained and who may lawfully agree to treatment, not to profile anybody.

Your consent visit. Which procedure, which tooth, which clinician, which language, when it started and when it finished, every question you were shown, every answer you gave including the wrong ones, every part that was explained again, how long you spent, anything you refused, and anything the software told the clinician you had not yet understood.

Signatures. Your signature image and typed name, the time, and the same for a witness or a person with parental responsibility where one signed.

Ability to decide (capacity), children and best interests. Where a clinician checked whether you could make this decision, that check and their notes. Where treatment went ahead as a best-interests decision (made for you, in your interest) or in an emergency without the usual steps, the record of that decision.

Contact details, sometimes. If the practice sent you a link to read at home, your email address or mobile number is held with that consent, along with whether the message arrived.

Files. A photograph, X-ray or scanned form the clinician attached because it was part of what you were shown.

Other personal details, which have a space but are empty. The patient record has spaces for an address, a postcode, a telephone number, an NHS number, a guardian’s details and a legal representative’s details. Nothing in the product writes any of them today, and no deletion request reaches them. They are named here because a notice that only lists the fields currently in use is a notice that goes stale the day one is filled in.

Never collected

Clinical notes, medical history, medications, allergies, X-rays from your notes, periodontal (gum) charts, correspondence and financial records. Where ConsentIQ reads from a practice’s software it does not read any of them, so they are not in the database to be sent anywhere. There is no advertising anywhere in this product, no analytics service, no tracking of any kind, and nothing is sold or shared for marketing.

Where it is

Where it is stored is checked by the app itself.

The app will not start if it is set up in a location outside the allowed list.

Application

Runs on Vercel, fixed to London. Every time data is read, the database itself checks the person is allowed to see it.

Files

Private Amazon S3 storage, with no public or shareable link. Every download goes through the app, which first checks the person is allowed, and is logged.

Sent and stored

Encrypted (scrambled) while it is sent. Encrypted while stored, by the storage providers.

How long

Fifteen years, and it cannot be shortened by asking.

For an adult, a record is kept for fifteen years from the day the consent was completed. For a patient who was under sixteen at the time, it is kept until their twenty-fifth birthday or fifteen years from completion, whichever falls later.

A practice can change those two numbers, within limits the software enforces: adult records kept for between eleven and thirty years, and the age for a child between twenty-five and thirty. Eleven years is a minimum, not a default. A practice cannot keep adult records for less, even if it wants to, and every change is written to the activity log (the permanent log of changes).

Once a record is sealed (locked so any change shows), its keep-until date is fixed on the record itself and the database refuses to change it. A practice that later shortens its policy does not shorten the clock on records already sealed.

We keep it because the law requires it. Not your consent, and not our interests. A record of what a patient was told before treatment is exactly the thing a claim made years afterwards turns on, and dental record-keeping obligations are why the period is what it is. UK GDPR (the UK law on personal data) Article 17(3)(b) says the right to erasure (deletion) does not apply where using the data is needed to meet a legal duty. That is the whole reason the clock cannot be shortened on request, and it is the honest answer rather than a convenient one.

Your rights

All of them, and the one that is limited here.

Seeing your data, correcting it, limiting its use, objecting, taking it elsewhere (portability) and complaining all work as normal. Deletion (erasure) is the one that is limited, and here is exactly how.

What a deletion request does remove

  • Your email address, your phone number, and any note the practice wrote about how to send you the link.
  • Who each message was sent to, and any error recorded when a message to you did not arrive.
  • The name of every file attached to your consent. A file name can name a person.
  • The attached files themselves. Every stored version of them is removed, not marked as deleted.
  • The text of any note waiting to be added to the practice's own software. Any such note not yet added is cancelled.
  • The clinical content of the sealed (locked) record, which is replaced with a note saying it was removed (redacted).
  • Once the time we must keep it has passed: appointments and treatments copied from the practice's software, and the links between your ConsentIQ record and that software.

What it does not remove

  • Your name, your date of birth, and the practice's own reference for you.
  • The consent itself: that it happened, its status, its timings, which clinician ran it, and which language it was in.
  • Every answer you gave, including the ones you got wrong.
  • Every signature.
  • The check of whether you could make this decision (capacity), including the clinician's notes.
  • Best-interests decisions (made for you, in your interest), emergency treatment without the usual steps, withdrawals, parts explained again, and notes that something was not understood.
  • The sealed record's tamper check (proof it has not been changed), the tamper check of the record before it, its place in the sequence, when it was sealed, by whom, how, and the date it is kept until.
  • The activity log (the record of who did what), in full.
  • Invoices held by the payment provider for the practice, which tax law requires be kept for six years.

Most of the record is in the second list, and that is on purpose. Twenty-two tables in the database are linked to a patient, a consent or a record. Sixteen of them can never be deleted from: the database itself refuses. The app has no permission to delete a patient, a consent or a record, and the database blocks any attempt, even one made by an administrator.

Removing personal details (redaction) takes out the content and keeps the outline: the tamper check, the record’s place in the sequence, and the fact that a record existed and had details removed, with the reason and the name of the person who asked. If a record were quietly removed, the tamper checks either side of it would prove nothing. That is why the outline stays.

A practice can close its account. Nobody can delete one. Closing an account cancels the subscription, deletes the stored card at the payment provider, removes every user’s access and signs out every tablet. It does not touch a single clinical record, and the activity log records the closure and says so. There is no delete-everything button anywhere in this product and there will not be one.

You can complain to the Information Commissioner’s Office (the UK data protection regulator) at any time, and you do not have to raise it with the practice or with us first.

Cookies

Four cookies, one thing on the tablet, and no banner.

There is no advertising, no analytics, no tracking and no third-party script anywhere in this product, so there is nothing here for a consent banner to ask about.

candour_session

Shows that a member of practice staff is signed in. It holds a random code; the database keeps only a scrambled copy of it.

How long: 12 hours. Not readable by any script on the page.

Why it is needed: Signing in. Without it, staff cannot sign in.

consentiq-acting-practice

Which clinic an owner of a group is currently working in.

How long: 30 days. Not readable by any script on the page.

Why it is needed: Written only when somebody uses the clinic switcher, and it is what makes the screen they asked for show the clinic they asked for.

candour_sso_attempt

A one-time code used when staff sign in with their organisation's own work account. It ties that sign-in to the browser that started it.

How long: Minutes, and deleted the moment it is used, whether or not the sign-in worked.

Why it is needed: Security. Without it, someone could reuse a sign-in from another device.

consentiq-theme

The word light or the word dark. Nothing else.

How long: One year. Readable by the page, because the page has to act on it before anything is drawn.

Why it is needed: It stops each page flashing in the wrong colours for a moment as it loads. See the note below: this is the one exception on this page.

consentiq-queue-… (stored on the device, not a cookie)

Your own answers, held on the tablet you are answering on until they reach the practice's record.

How long: Cleared when the answers have been received.

Why it is needed: So that if the internet drops halfway through, you do not lose what you already answered.

Under the Privacy and Electronic Communications Regulations, storing anything on your device needs your permission unless it is strictly necessary for a service you asked for. Signing in, keeping a sign-in secure, showing an owner the clinic they selected, and holding your own answers on the tablet until they arrive are all in that category. None of them identifies you to anybody else, none is shared, and no page in this product makes a request to a third party.

The one exception, stated. The theme cookie is a choice when you use the toggle. On a first visit, though, a small script reads whether your browser prefers light or dark and writes the cookie before you have chosen anything. Its value is one of two words and it identifies nobody, but it is written before you ask for it, so it does not clearly fit the exemption. The fix is one line: stop that script writing the cookie and let the server keep serving the default until somebody uses the toggle. It is recorded here rather than hidden behind a banner, because a banner asking a patient at a chairside tablet for permission to remember a colour would be pointless.

Who else sees it

The whole list, including the parts that are switched off.

15 outside companies are built into this product. Our list says 4 of them are switched on; the rest are built in but switched off. This column is our own list, last checked by hand on 29 August 2026. It does not read the running deployment (the live system), so it can be out of date. The live answer for email, text messages, file storage and billing is on your practice's settings screens in ConsentIQ.

WhoWhereDeclared in the register
NeonLondon (aws-eu-west-2). This was fixed when the database was set up and cannot be moved.Switched off
VercelSet to run in London (lhr1).Switched on
AnthropicUnited States. Anthropic does not offer processing kept inside the UK.Switched on
Amazon Web Services (S3)London (eu-west-2). If no region is set, ConsentIQ refuses to start rather than picking one.Switched on
ResendProcessed in the EU.Switched off
MessageBird (Bird)Its EU servers (rest-eu.messagebird.com).Switched off
PureSMS (Divergent Cloud)United Kingdom (connect-api.divergent.cloud). Texts come from a UK short number or sender name.Switched off
TwilioUnited States. By default, messages are routed and logged in the US.Switched off
StripeStripe Payments UK Ltd, with processing that includes the United States.Switched off
Independent time stamp service (RFC 3161)Wherever the chosen service is. A setting (TSA_URL) decides it.Switched on
Google sign-in (OpenID Connect)Worldwide, mainly the United States.Switched off
Your practice's own sign-in service (SAML)Wherever the practice runs it.Switched off
DentallyDentally's servers (api.dentally.co), in the practice's own account, or Dentally's test system (api.sandbox.dentally.co) when set to use it.Switched off
CloudflareWorldwide (it answers from the nearest location).Switched off
The Windows app update serverNot decided, and never contacted: no update server is set up, so the app never checks for updates.Switched off

The three that can see anything about a patient are the database, the file store and the AI model that drafts content for a clinician to check. The AI model is sent a procedure, a tooth, a diagnosis, the clinician’s note about it, the risks marked as important for you and an age band. It is never sent your name, your date of birth, your NHS number, your address, your email or your phone number, and their absence is checked by an automated test rather than promised in a document. It runs in the United States, which is the one part of this system that leaves the country, and we list it openly as an unresolved issue.

Email and text-message providers, where a practice turns them on, are sent your first name, the practice name, a one-time link and when it expires. Not your full name, and not what the appointment is for.

The full list, including exactly what each one receives and which are outside the United Kingdom, is kept in PROCESSORS.md in the source code and is shown to every practice inside the console.

Computer decisions

Nothing here decides anything about you.

Your answers are marked against the answer recorded with each question when a clinician approved it. An AI model is not asked whether you understood, and it is not asked anything about you.

An AI model drafts explanations, risk descriptions and questions for a clinician to read, change and approve. Until a clinician has approved it, the database refuses to show it to a patient. Nothing in this product produces a decision about you by automated means, and nothing here decides whether you are treated. Where the software notices that something was not understood, it tells the clinician and the conversation continues.

This page is written to match the software. The parts checked automatically are: how long records are kept, the list of companies that receive data, and the claim that no page contacts an outside company.

Privacy · ConsentIQ