This Privacy Policy explains how 3D Tooth Lab (“DesignMyArch”, “we”, “us”) collects, uses, stores and protects personal data when you use our website and services. We are the “controller” of your personal data for the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Registered company: 3D Tooth Lab, company number [COMPANY NUMBER], registered office 18 Tesla Court, Unit 8, PE2 6FL, Peterborough. ICO registration number: [ICO REGISTRATION NUMBER]. Contact for data protection matters: [email protected].
1. The data we collect
Account & contact data
- Name, email address, telephone number and password.
- Your role (dentist or designer) and, for dentists, practice name.
- Where you sign in with Google, basic profile information provided by Google (name and email).
Case & clinical data
To provide our design services you may upload case files (for example intra-oral scans, CT/CBCT data, STL files, photographs and clinical notes). Some of this information may relate to identifiable patients and may constitute health data — a special category of personal data under Article 9 UK GDPR, which we handle to a higher standard (see sections 3 and 6).
Order, payment & technical data
- Order details and correspondence. Card payments are processed by our payment provider, Stripe — we do not store full card numbers.
- Technical data such as IP address, device/browser information and, with your consent, analytics data (see our Cookie Policy).
2. How we use your data and our lawful bases
- To provide our services and process orders — performance of a contract with you.
- To manage your account and provide support — performance of a contract and our legitimate interests.
- To send service communications (e.g. password resets, order updates) — performance of a contract / legitimate interests.
- For analytics — only with your consent.
- To comply with legal obligations (e.g. accounting, tax, medical device record-keeping) — legal obligation.
Where you upload patient/clinical information, our processing of special-category (health) data is carried out for the provision of your services and, as applicable, relies on an Article 9 condition such as the provision of health or social care/treatment, or your explicit consent. [CONFIRM ARTICLE 9 CONDITION WITH LEGAL ADVISER.] You are responsible, as the treating clinician/controller of your patients’ data, for having a lawful basis to share that data with us; we act on your instructions in respect of that data.
3. Sharing your data
We share personal data only where necessary, with:
- Our hosting and cloud storage providers (for secure file storage).
- Our payment provider (Stripe) to process payments.
- Our design team members who need access to fulfil your case.
- Professional advisers, and regulators or authorities where required by law.
We put appropriate contracts (including data processing terms) in place with our processors. [LIST KEY PROCESSORS AND LOCATIONS.]
4. International transfers
Where personal data is transferred outside the UK, we rely on an adequacy decision or appropriate safeguards such as the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses. [CONFIRM TRANSFER MECHANISM FOR EACH PROCESSOR.]
5. How long we keep your data
We keep personal data only for as long as necessary for the purposes set out above and to meet legal, accounting and regulatory requirements. Case files are retained for [RETENTION PERIOD] and then securely deleted or anonymised. [CONFIRM RETENTION PERIODS, INCLUDING ANY MEDICAL DEVICE RECORD-KEEPING OBLIGATIONS.]
6. How we protect your data
We use appropriate technical and organisational measures to protect personal data, which include encryption of data in transit (TLS), access controls and role-based permissions, restricted staff access on a need-to-know basis, and secure, access-controlled cloud storage. [CONFIRM AND DOCUMENT THE ACTUAL CONTROLS IN PLACE — e.g. encryption at rest, backup, logging, staff training — so that any security statements made on the site are accurate and substantiated.]
7. Your rights
Under UK GDPR you have the right to:
- access a copy of your personal data;
- have inaccurate data corrected;
- have your data erased in certain circumstances;
- restrict or object to processing;
- data portability;
- withdraw consent at any time (where processing is based on consent).
To exercise your rights, contact us at [email protected]. You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk.
8. Changes to this policy
We may update this policy from time to time. The “last updated” date at the top shows when it was last revised.