This privacy notice sets out how 21D Clinical Limited uses and protects any information that you give when becoming a patient of the company. 21D is committed to complying with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the GDC standards, and other relevant data protection and healthcare regulations. The person responsible for Data Protection is Jonathan Garbett.ย 
What type of information do we hold?
- Personal details such as your address, date of birth, phone number and email address. 
- This is for the provision of dental health care, providing treatment plans, estimates and recalls.
- Details of your NHS number and entitlement to healthcare treatment and exemption status if applicable.
- Personal details of family members or emergency contact details.
- Medical history including your GPโs name and address. 
- Past and present dental history including x-rays and photographs
- Information about the treatment we have proposed and provided along with its price. 
- Notes of conversations or incidents that might occur for which a record needs to be kept. 
- Records of permission or consent for treatment. 
- Correspondence to other healthcare professions such as referrals.
- Financial information relating to your treatment. 
- Details of any complaints made.
Why do we need to keep this information?
โWe need to keep records of personal information regarding our patients in order to provide safe and appropriate dental care and treatment. It is also used to maintain accurate treatment records.
Our legal basis forprocessing data is: 
- Consent 
- Legitimate interest - Processing is necessary for the performance of our care for patients and for defence of legal claims. 
- Data relating to your health care records is classed as special category data. Our legal basis for processing this is that it falls under Legal claims or judicial acts and Health and Social Care (Article 9 UK GDPR (f,h)).
What do we do with your information?
โWe do not sell, rent, or trade your personal information, we will only share your information if it is done securely, and it is necessary for us to do so. Your personal information may be securely shared with other healthcare professionals who need to be involved in your care (for example if we refer you to a specialist, need laboratory work undertaken or need to consult with your doctor). We may also share your personal information securely to third parties where we are required by law or regulation to do so. This may include: 
- The General Dental Council 
- The CQC/HIW/HIS/RQIA 
- Dental payment plans or insurers 
- Other companies within the 21D Group
External Data Processorsand Third Parties
โWe sometimes use external organisations (known as data processors) to help us manage our operations and deliver services. These processors act only on our written instructions and are contractually required to comply with the UK GDPR, the Data Protection Act 2018, and our own confidentiality and security standards. External data processors may include:
- Software and IT service providers who supply and support our practice management systems, secure communications, and data backup. 
- Financial and accounting service providers who manage billing, payment processing, and bookkeeping. 
- Legal advisers and insurers who assist with compliance, legal advice, and indemnity matters. 
- External consultants or maintenance providers who have controlled access to our systems as part of their contracted services. 
All such processors are required to: 
- Process personal data only under our documented instructions.
- Maintain appropriate technical and organisational security measures. 
- Ensure the confidentiality of all patient information. 
- Notify us promptly of any data breach or incident. 
- Return or securely delete personal data when their services end.
We regularly review all our third-party processors to ensure ongoing compliance and data security.
How do we store your information? 
Your information is stored securely on protected computer systems. Computer information is backed up regularly and may be securely stored away from our premises. We use reputable UK-based or UK-approved hosting providers, and where data may be stored or accessed outside the UK, appropriate safeguards (such as UK-approved Standard Contractual Clauses) are in place.
Retention periods 
- We are required to retain your dental records, X-rays and study models while you are a patient of this company and after you cease to be a patient for a minimum of 11 years. 
- There ย are several other documents that we may collect that have a variety of retention dates, and we have a retention schedule listing all documents and the time frames for disposal. Retention periods are regularly reviewed and updated to meet professional, legal, and regulatory guidance.
Your rights under UKdata protection law (UK GDPR and Data Protection Act 2018) 
โAccess - You have a right to access the information that we hold about you and to receive a copy. You can make a request by e-mailing CASE@21d.co.uk. 
โRectification - You have a right to correct any information that you believe is inaccurate or incomplete. Please contact us to request a change in information. 
โErasure - You have a right to request that we delete your personal information, although you should be aware that, for legal reasons, we may be unable to erase certain information (for example, information about your dental treatment). Please contact us to make this request. 
Restriction - You have the right to request us to restrict the processing of your personal information for example, sending you reminders for appointments or information about our service. Please contact us to make this request. 
โPortability - You have a right to data portability; this could include supplying your information to another dentist. Please contact us to make this request.
Concerns
โIf you have any concerns about how we use your information and you do not feel able to discuss it with your dentistor anyone in your appointments or support group, you can contact our Data Protection Officer via email at jonathan@21d.co.uk. If you wish to make a complaint about our data handling, you can contact the ICO at www.ico.org.uk or telephone 0303 123 1113.ย This notice is reviewed regularly and updated to reflect any legislative or regulatory changes, including those introduced under the Data (Use and Access) Act 2025.
