Legal document

Privacy Policy

How Desklly collects, uses, stores, and protects personal data on behalf of dental practices and their patients, in line with UK GDPR and the Data Protection Act 2018.

Version 1.0Last updated 7 July 2026Governing law England & Wales

1. Who we are

Desklly ("we", "us", "our") provides AI receptionist services to UK dental practices. For the personal data described in this policy, Desklly acts as a data processor on behalf of the dental practice (the data controller). Desklly Ltd is registered in England and Wales and is registered with the Information Commissioner's Office (ICO).

2. What personal data we process

On behalf of practices, we process: caller name, phone number, date of birth, address, appointment details, reason for contact, insurance/plan membership, clinician preference, call audio recordings, call transcripts, and any additional information a patient volunteers during a call. We do not solicit special category health data, but where a patient discloses symptoms or clinical information during a call, this is processed as necessary for the provision of dental care.

3. Legal basis

The practice (as controller) relies on: (a) contract — to provide dental care requested by the patient; (b) legitimate interests — to operate and improve the practice; (c) legal obligation — to keep records required by NHS, CQC, and dental regulators; and (d) explicit consent for optional marketing communications and, where applicable, for the processing of special category (health) data under Article 9(2)(h) UK GDPR.

4. How we use the data

We use personal data solely to: answer calls, book/reschedule/cancel appointments, answer patient questions, take messages, route calls to the correct person, send appointment confirmations and reminders, and provide reporting to the practice. We do not use patient data to train third-party foundation models. Anonymised, aggregated call data may be used to improve Desklly's own service quality.

5. Sharing and sub-processors

We share personal data only with vetted sub-processors under written contract and appropriate safeguards. Current sub-processors are listed in our Sub-processor List. We do not sell personal data. We do not share data with advertisers.

6. International transfers

Personal data is stored in the UK or EEA by default. Where any sub-processor transfers data outside the UK/EEA, transfers are protected by the UK International Data Transfer Agreement, the EU Standard Contractual Clauses with the UK Addendum, or an adequacy decision.

7. Retention

Call recordings and transcripts are retained for the period configured by the practice (default 90 days), or as required by the practice's own retention policy for dental records. Full details are in our Data Retention Policy.

8. Your rights

Patients have the right to access, rectify, erase, restrict, object to, and port their personal data, and to withdraw consent at any time. Requests should be directed to the dental practice as the data controller in the first instance. Desklly will support the practice in responding to any request without undue delay.

9. Security

Desklly operates under an Information Security Policy aligned with the NHS Data Security and Protection Toolkit (DSPT), Cyber Essentials, and ISO/IEC 27001 principles. All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access is role-based, logged, and reviewed.

10. Complaints

Complaints about how personal data is handled can be raised with the dental practice, with Desklly's Data Protection Officer (info@desklly.ai), or with the ICO (ico.org.uk / 0303 123 1113).

11. Contact

Data Protection Officer, Desklly Ltd — info@desklly.ai.