This Privacy Policy explains how Smile Success ("we", "us", "our") collects, uses, and protects personal data when you visit our website, contact us, or attend our practice. We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
Smile Success is a private dental practice operated at:
For the purposes of UK GDPR, Smile Success is the data controller for the personal data we collect through this website and our practice.
When you submit our enquiry form, call us, message us via WhatsApp, or attend a consultation, we may collect:
When you browse this website, our service providers may automatically collect:
| Purpose | Lawful basis under UK GDPR |
|---|---|
| To respond to your enquiry and book a consultation | Article 6(1)(b) — performance of a contract / pre-contractual steps |
| To provide dental treatment and keep clinical records | Article 6(1)(b) and Article 9(2)(h) — provision of healthcare |
| To send appointment reminders and treatment-related communications | Article 6(1)(b) — performance of a contract |
| Website analytics and performance measurement | Article 6(1)(a) — your consent (via cookie banner) |
| Marketing measurement (Google Ads, Meta) | Article 6(1)(a) — your consent (via cookie banner) |
| Legal, regulatory, and accounting obligations | Article 6(1)(c) — legal obligation |
| Defence of legal claims | Article 6(1)(f) — legitimate interests |
We share your data only with trusted service providers who help us run our practice and website. Each provider acts as a data processor on our behalf and is contractually required to protect your data.
| Recipient | Purpose | Country |
|---|---|---|
| Netlify, Inc. | Website hosting and form submission processing | United States (see Section 5) |
| Zapier, Inc. | Lead-routing automation between systems | United States (see Section 5) |
| Google LLC (Google Workspace, Sheets, Gmail, Ads, Analytics, Tag Manager) | Lead storage, internal notifications, advertising measurement | United States (see Section 5) |
| Meta Platforms, Inc. (Pixel) | Advertising measurement — not currently active. Will only be enabled in future after a Cookie Policy update and fresh consent prompt. | United States (see Section 5) |
| Meta Platforms, Inc. (WhatsApp) | Communications service when you choose to message us via WhatsApp, including any photos, X-rays, or clinical details you choose to send | United States (see Section 5) |
| Tabeo Ltd | Patient finance applications (only if you apply) | United Kingdom |
| Our clinical software providers | Clinical records and appointments (when you become a patient) | United Kingdom / EEA |
| HMRC, regulators, and lawful authorities | Where required by law | United Kingdom |
We do not sell your personal data, and we do not share it with third parties for their own marketing purposes.
Some of the providers above are based in the United States. Where personal data is transferred outside the UK, we rely on appropriate safeguards as required under UK GDPR, which may include:
You can request a copy of the relevant safeguards by contacting us at reception@smile-success.co.uk.
| Data type | Retention period |
|---|---|
| Website enquiry forms (non-patient) | 2 years from last contact, then deleted |
| Clinical records (adult patients) | 11 years from end of treatment, per NHS / GDC guidance |
| Clinical records (patients under 18) | Until 25th birthday, or 11 years from treatment end — whichever is later |
| Financial / accounting records | 6 years (HMRC requirement) |
| Cookies and analytics | See our Cookie Policy |
You have the following rights in relation to your personal data:
To exercise any of these rights, contact us at reception@smile-success.co.uk or write to the practice address above. We will respond within one month.
We take appropriate technical and organisational measures to protect your data, including TLS encryption in transit, access controls, password protection, and staff training. While no system is perfectly secure, we work hard to safeguard your information.
This website is intended for adults. We do not knowingly collect personal data from anyone under 16 through our website. If you believe a minor has submitted data through our forms, please contact us so we can delete it.
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the latest version. Material changes will be notified on the website.
For any privacy-related question or to exercise your rights: