Legal

Legal & Policies

Privacy, terms, cookies, data protection, retention, and security policies for Ortho-Facial Planning Ltd.

Clinical Standards

Ortho-Facial Planning Ltd delivers digital surgical planning in accordance with established clinical and professional standards.

  • Planning is performed by qualified clinicians with expertise in orthognathic surgery.
  • Our workflows align with recognised orthognathic planning practices.
  • Outputs are compatible with hospital imaging systems and clinical workflows.
  • Clinicians involved in planning hold relevant professional registration (e.g. GDC) where applicable.
  • We adhere to recognised surgical planning practices and quality standards.

Privacy Policy

Last updated: 1 May 2026

This Privacy Policy explains how Ortho-Facial Planning Ltd collects, uses, and protects your personal information when you visit our website or use the Ortho-Facial Planning Portal.

1. Who we are

Ortho-Facial Planning Ltd is the data controller for information collected through this website and the portal. We are registered in England and Wales (Company No. 15073037). Our registered address is Bon Marche Business Centre, Unit 116A, 241–251 Ferndale Road, London SW9 8BJ.

You can contact us regarding privacy matters at info@ortho-facialplanning.co.uk or by calling +44 7939 963290.

2. Information we collect

We collect different categories of information depending on how you interact with us:

  • Account information: name, email address, job title, clinic name, and login credentials when you register for the portal.
  • Usage data: pages visited, features used, browser type, device information, and IP address, collected automatically via server logs and analytics tools.
  • Communications: the content of emails or messages you send us, including enquiries and support requests.
  • Payment information: billing details processed securely through our payment provider (Stripe). We do not store card numbers on our own systems.
  • Clinical case data: DICOM imaging files and patient case information uploaded to the portal by clinicians. We process this data strictly as a data processor on behalf of the uploading clinic (see Section 5).

3. How we use your information

We use your information for the following purposes and on the following legal bases:

  • Providing our services — processing cases, managing your account, and delivering completed plans. Lawful basis: performance of a contract.
  • Communications — responding to enquiries and sending service-related notifications. Lawful basis: legitimate interests / contract.
  • Billing and financial administration — processing payments and maintaining financial records. Lawful basis: contract and legal obligation.
  • Improving our platform — analysing usage patterns to enhance features and fix issues. Lawful basis: legitimate interests.
  • Legal and regulatory compliance — complying with applicable law and professional obligations. Lawful basis: legal obligation.

4. Cookies and tracking

We use cookies and similar technologies on this website. Please see our Cookies Policy below for full details.

5. Clinical case data and data processor role

When a clinic uploads patient case data (including DICOM images and associated patient identifiers) to the portal, Ortho-Facial Planning Ltd acts as a data processor on behalf of that clinic, which remains the data controller for that patient's information. We process such data solely to deliver the requested planning service and do not use it for any other purpose. A Data Processing Agreement governs this relationship. If you are a clinician with questions about how your patients' data is handled, please refer to your clinic's own privacy notices.

6. Sharing your information

We do not sell or rent your personal data. We share it only in the following circumstances:

  • Service providers: trusted sub-processors who help us operate the platform (cloud hosting, email delivery, payment processing, error monitoring). Each is bound by a data processing agreement.
  • Legal requirements: where disclosure is required by law, court order, or regulatory authority.
  • Business transfer: in the event of a merger, acquisition, or sale, your data may transfer to the successor entity, subject to equivalent protections.

7. International transfers

We store data on servers located within the United Kingdom. Where any of our sub-processors transfer data outside the UK, we ensure that adequate safeguards are in place (such as the UK International Data Transfer Agreement or equivalent adequacy decisions).

8. Your rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you (Subject Access Request).
  • Rectify any inaccurate or incomplete data.
  • Erase your data where there is no compelling reason to continue processing it.
  • Restrict processing in certain circumstances.
  • Data portability — receive a copy of your data in a machine-readable format.
  • Object to processing based on legitimate interests.
  • Withdraw consent at any time where processing is based on consent.

To exercise any of these rights, contact us at info@ortho-facialplanning.co.uk. We will respond within one calendar month. If you are unhappy with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

9. Retention

We retain personal data only as long as necessary. For specific retention periods, please see our Data Retention Policy below.

10. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email to registered users or by a prominent notice on this page. Continued use of our services after an update constitutes acceptance of the revised policy.


Terms of Service

Last updated: 1 May 2026

These Terms of Service govern your use of the Ortho-Facial Planning website and portal. Please read them carefully. By accessing or using our services, you agree to be bound by these terms.

1. Definitions

  • “Company” means Ortho-Facial Planning Ltd, registered in England and Wales (No. 15073037), Bon Marche Business Centre, Unit 116A, 241–251 Ferndale Road, London SW9 8BJ.
  • “Services” means the digital orthognathic surgical planning services and the online portal provided by the Company.
  • “User” or “you” means any individual or organisation accessing or using the Services.
  • “Client” means a dental or surgical practice or clinic that has entered into a service agreement with the Company.

2. Eligibility and professional use

The Services are intended solely for qualified dental and medical professionals and their authorised staff. By registering, you confirm that you are accessing the Services in a professional clinical capacity and that your use will comply with all applicable professional and legal obligations, including those set by the General Dental Council (GDC) or equivalent regulatory body.

The planning outputs produced by the Company are intended to support — not replace — clinical judgement. The treating clinician retains full responsibility for all clinical decisions made in relation to their patients.

3. Account registration

To use the portal, you must create an account and provide accurate, up-to-date information. You are responsible for maintaining the confidentiality of your login credentials and for all activity that occurs under your account. You must notify us immediately at info@ortho-facialplanning.co.uk if you suspect any unauthorised access.

4. Acceptable use

You agree not to:

  • Use the Services for any unlawful purpose or in breach of any professional duty.
  • Upload content that infringes third-party intellectual property rights or that you do not have authority to share.
  • Attempt to reverse-engineer, decompile, or extract source code from any part of the platform.
  • Share your account credentials with unauthorised individuals or allow concurrent access by multiple users.
  • Use automated scripts, bots, or scrapers to interact with the Services without prior written consent.
  • Introduce malware, viruses, or other malicious code into the platform or its connected systems.

5. Intellectual property

All content, software, workflows, and technology comprising the Services are owned by or licensed to the Company and are protected by intellectual property law. Nothing in these Terms transfers ownership of any intellectual property to you.

You retain ownership of the clinical data and images you upload. By uploading content, you grant the Company a limited licence to process that content solely for the purpose of delivering the Services.

6. Fees and payment

Fees for the Services are as set out in your service agreement or on the relevant pricing page. Fees are due in accordance with the agreed payment schedule. The Company reserves the right to suspend access to the portal in the event of non-payment. All fees are quoted in GBP and are subject to VAT where applicable.

7. Disclaimers

The Services are provided “as is” and “as available”. While we take all reasonable steps to ensure the accuracy and quality of our planning outputs, the Company makes no warranty — express or implied — that the outputs will be error-free or suitable for any particular clinical outcome. The treating clinician is solely responsible for verifying the clinical appropriateness of any plan before use.

8. Limitation of liability

To the fullest extent permitted by law, the Company's aggregate liability for any claim arising from or related to these Terms or the Services shall not exceed the fees paid by the Client in the three months preceding the event giving rise to the claim. The Company shall not be liable for indirect, consequential, special, or punitive damages.

Nothing in these Terms excludes or limits liability for death or personal injury caused by negligence, fraud, or any other liability that cannot be excluded by English law.

9. Termination

Either party may terminate a service agreement by giving notice in accordance with that agreement. The Company may suspend or terminate your access immediately if you breach these Terms, fail to make payment when due, or if required by law or regulatory authority. Upon termination, your access will be revoked and case data will be handled in accordance with our Data Retention Policy.

10. Governing law and disputes

These Terms are governed by the laws of England and Wales. Any disputes arising under or in connection with these Terms shall be subject to the exclusive jurisdiction of the courts of England and Wales. For consumer disputes, statutory rights remain unaffected.

11. Changes to these Terms

We may update these Terms from time to time. We will provide reasonable notice of material changes by email or via the portal. Continued use of the Services after the effective date of any change constitutes acceptance of the updated Terms.


Cookies Policy

Last updated: 9 July 2026

This page sets out how Ortho-Facial Planning Ltd uses cookies and similar technologies on this website and within the portal.

What are cookies?

Cookies are small text files placed on your device by a website. They are widely used to make websites work, to improve user experience, and to provide information to website operators.

Cookies we use

We use the following categories of cookies:

Strictly necessary cookies

These cookies are essential for the website and portal to function and cannot be switched off. They include:

  • Session cookies — maintain your login state while you are using the portal.
  • Security cookies — protect against cross-site request forgery (CSRF) and other threats.
  • Preference cookies — store your theme or UI preference selections.

These cookies do not require your consent as they are technically necessary.

Analytics cookies

With your consent, we may use analytics tools to understand how visitors interact with our website, such as which pages are most visited and how users navigate. This helps us improve the platform. Analytics data is collected in aggregate and is not used to identify individual users. Analytics cookies are off by default until you accept them.

You can accept, reject, or change analytics cookies at any time via the cookie preference centre (the banner on first visit, or "Cookie settings" in the site footer). You can also control cookies through your browser settings.

Third-party cookies

Some pages may embed content from third-party services (for example, payment widgets provided by Stripe). These third parties may set their own cookies, subject to their own privacy and cookie policies. We do not control third-party cookies. Where a third-party technology is not strictly necessary, we only enable it after you have given the relevant consent.

Managing cookies

On your first visit we show a cookie banner with equal options to accept all cookies, reject non-essential cookies, or manage preferences by category. Your choice is stored in your browser so we remember it on later visits. You can reopen the preference centre at any time using "Cookie settings" in the footer.

Most browsers also allow you to control cookies through their settings — you can block or delete cookies at any time. Please note that disabling strictly necessary cookies may affect the functionality of the portal. For more information on managing cookies, visit allaboutcookies.org.


Data Protection & GDPR

Last updated: 1 May 2026

How we process personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018).

Data controller

Ortho-Facial Planning Ltd is registered as a data controller with the Information Commissioner's Office (ICO). Our nominated contact for data protection matters is reachable at info@ortho-facialplanning.co.uk.

Lawful bases for processing

We rely on the following lawful bases under UK GDPR Article 6:

  • Article 6(1)(b) — Contract: processing necessary to perform our services or take steps prior to entering a contract.
  • Article 6(1)(c) — Legal obligation: where processing is required to comply with a legal obligation (e.g. tax and accounting records).
  • Article 6(1)(f) — Legitimate interests: where our legitimate business interests are pursued and are not overridden by your rights and freedoms (e.g. platform security, fraud prevention, service improvement).

Special category data

Clinical case data submitted to the portal may constitute special category health data under UK GDPR Article 9. Where Ortho-Facial Planning Ltd processes such data as a data processor on behalf of a clinic, processing is carried out under Article 9(2)(h) (health or social care purposes) and the applicable Schedule 1 condition under DPA 2018. The clinic, as data controller, is responsible for ensuring patients have been appropriately informed and for obtaining any necessary consents.

Data Processing Agreements

All client clinics processing patient data through the portal are required to enter into a Data Processing Agreement (DPA) with Ortho-Facial Planning Ltd before uploading any patient data. This agreement sets out the obligations of both parties in accordance with UK GDPR Article 28. See the Data Processing Agreement section below, or contact us at info@ortho-facialplanning.co.uk to request a copy.

Sub-processors

We engage the following categories of sub-processors to help deliver our services, each bound by appropriate data processing agreements:

  • Cloud infrastructure and database hosting (UK-based servers)
  • Transactional email delivery
  • Payment processing (Stripe, Inc. — operating under approved transfer mechanisms)
  • Error monitoring and application performance tooling

A full and up-to-date list of sub-processors is available on request at info@ortho-facialplanning.co.uk.

Your rights

Under UK GDPR, you have rights of access, rectification, erasure, restriction, portability, and objection. To exercise any of these rights, submit a written request to info@ortho-facialplanning.co.uk. We will respond within one calendar month (extendable by a further two months for complex requests, with notice). We may ask you to verify your identity before proceeding.

Complaints to the ICO

If you believe we have mishandled your personal data, you have the right to lodge a complaint with the ICO, the UK supervisory authority for data protection:

  • Website: ico.org.uk/make-a-complaint
  • Telephone: 0303 123 1113
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

Data Processing Agreement

Last updated: 8 July 2026 (Version 1.0)

This Data Processing Agreement (“Agreement”) is made between Ortho-Facial Planning Ltd (“the Processor”, “we”, “us”), a company registered in England and Wales (Company No. 15073037, registered address Bon Marche Business Centre, Unit 116A, 241–251 Ferndale Road, London SW9 8BJ), and the Clinic (“the Controller”, “you”), being the dental/surgical practice identified by the account details submitted when accepting this Agreement (together, “the Parties”). It takes effect for each Clinic on the date the Clinic accepts it during account signup on the portal, as recorded in the Clinic's account record.

Background

  • The Processor operates the Ortho-Facial Planning Portal, a digital orthognathic surgical planning service used by dental and surgical clinics.
  • In the course of using the portal, the Clinic will submit personal data relating to its patients (including special category health data) to the Processor so that the Processor can produce digital occlusion models, surgical plans, and related outputs.
  • In relation to that patient data, the Clinic is the data controller and the Processor acts as a data processor, processing personal data only on the Clinic's documented instructions.
  • This Agreement sets out the terms on which the Processor will process that personal data, as required by Article 28 of the UK GDPR.
  • This Agreement does not cover data for which the Processor is itself the controller (clinic account and staff data, billing records), which is governed by our Privacy Policy and Terms of Service.

1. Definitions

Terms not defined here have the meaning given in the UK GDPR / the Data Protection Act 2018.

  • “UK GDPR” means the UK General Data Protection Regulation as defined in the Data Protection Act 2018.
  • “Data Protection Legislation” means the UK GDPR and the Data Protection Act 2018, together with any successor or replacement legislation.
  • “Personal Data”, “Processing”, “Controller”, “Processor”, “Data Subject”, “Personal Data Breach”, and “Special Category Data” have the meanings given in the UK GDPR.
  • “Patient Data” means the Personal Data described in Annex 1, submitted by or on behalf of the Clinic to the portal for the purpose of the planning service.
  • “Sub-processor” means any processor engaged by the Processor to process Patient Data in providing the Services, as listed in Annex 2.
  • “Services” means the digital orthognathic surgical planning services provided through the portal.

2. Subject matter, duration, nature and purpose

Full details of the processing (subject matter, duration, nature, purpose, data categories, and data subjects) are set out in Annex 1, which forms part of this Agreement. In summary: the Processor processes Patient Data for the duration of the Clinic's use of the Services, for the purpose of producing surgical planning outputs on the Clinic's instructions, and deletes it in line with the retention periods in Annex 1 and section 8.

3. Processor obligations

The Processor shall:

3.1 Process only on instructions

Process Patient Data only on the Clinic's documented instructions, including in relation to transfers of Patient Data to a third country, unless required to do otherwise by UK law — in which case the Processor will inform the Clinic of that legal requirement before processing, unless the law prohibits this. Using the portal to submit a case, request a plan, or configure account settings constitutes a documented instruction for the ordinary operation of the Services.

3.2 Confidentiality

Ensure that any person authorised to process Patient Data (employees, contractors, or planning staff) is subject to a duty of confidentiality, whether contractual or statutory.

3.3 Security

Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 UK GDPR. The measures currently in place are described in Annex 1 and in our Security & Compliance policy; in summary this includes encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access control enforced server-side, optional two-factor authentication, server-write-only database rules (clients cannot write case data directly), short-lived signed upload URLs, hashed invite tokens, audit logging, and automated retention deletion.

3.4 Sub-processors

Not engage another processor to process Patient Data without the Clinic's prior general written authorisation. The Clinic gives general authorisation to the Sub-processors listed in Annex 2 as of the effective date. The Processor will:

  • give the Clinic at least 30 days' notice of any intended addition or replacement of a Sub-processor (by email or portal notice), during which the Clinic may object on reasonable data-protection grounds;
  • impose data protection terms on each Sub-processor that are no less protective than this Agreement; and
  • remain fully liable to the Clinic for a Sub-processor's failure to fulfil its data protection obligations.

3.5 Assistance with data subject rights

Taking into account the nature of the processing, assist the Clinic by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Clinic's obligations to respond to requests from patients exercising their rights under Chapter III of the UK GDPR (access, rectification, erasure, restriction, portability, objection). Where the Processor receives such a request directly from a patient, it will forward it to the Clinic without undue delay and will not respond to the patient directly except to acknowledge receipt and confirm it has been forwarded, unless the Clinic instructs otherwise.

3.6 Assistance with security, breach, and DPIA obligations

Taking into account the nature of processing and the information available to the Processor, assist the Clinic in ensuring compliance with its obligations under Articles 32 to 36 UK GDPR (security, breach notification, data protection impact assessments, and prior consultation with the ICO), including by notifying the Clinic without undue delay after becoming aware of a Personal Data Breach affecting Patient Data, and providing the information required for the Clinic's own notification obligations as it becomes available, in accordance with our documented incident response procedure.

3.7 Deletion or return of data

At the Clinic's choice, delete or return all Patient Data to the Clinic after the end of the provision of the relevant Services, and delete existing copies, except to the extent UK law requires the Processor to retain some or all of the Patient Data. In practice, deletion happens automatically per the schedule in Annex 1 unless the Clinic requests earlier deletion or export; on termination of the Clinic's account, the Processor will, on request, make Patient Data available for export for a reasonable period before deletion, as further described in section 8.

3.8 Audit and information

Make available to the Clinic all information reasonably necessary to demonstrate compliance with this Agreement and Article 28 UK GDPR, and allow for and contribute to audits, including inspections, conducted by the Clinic or an auditor mandated by the Clinic, subject to:

  • reasonable prior written notice (at least 15 business days, except where a Personal Data Breach makes shorter notice necessary);
  • audits being conducted during business hours, no more than once in any 12-month period (unless following a Personal Data Breach affecting the Clinic's Patient Data), and in a manner that does not unreasonably disrupt the Processor's business or compromise the confidentiality or security of other clinics' data; and
  • the Clinic bearing its own costs of the audit; the Processor may charge reasonable costs for audits beyond the above frequency.

The Processor may, in place of a physical audit, provide a copy of a relevant independent security certification or assessment report where this reasonably demonstrates compliance.

4. Controller obligations

The Clinic warrants that:

  • it has a lawful basis under Article 6 UK GDPR, and where applicable an Article 9(2) condition and DPA 2018 Schedule 1 condition, for the processing of Patient Data, including any special category health data;
  • its instructions to the Processor comply with Data Protection Legislation and any professional obligations applicable to the Clinic;
  • it has provided its patients with the information required by Articles 13/14 UK GDPR regarding the use of the Processor to support their treatment; and
  • it is responsible for the accuracy of Patient Data it submits and for retaining its own clinical records for the periods required by its professional obligations, independently of the Processor's retention periods (see section 8).

5. International transfers

Patient Data is stored and processed on infrastructure located in the United Kingdom (Google Cloud region europe-west2, London). Where a Sub-processor transfers Patient Data outside the UK (see Annex 2 for current international transfers), the Processor ensures an appropriate transfer mechanism is in place, such as the UK International Data Transfer Addendum or the EU Standard Contractual Clauses as modified for the UK, or an applicable UK adequacy regulation.

6. Liability

Each Party's liability arising out of or in connection with this Agreement shall be subject to any limitations and exclusions of liability set out in the Clinic's service agreement or the Processor's Terms of Service with the Clinic. Nothing in this Agreement limits either Party's liability for matters which cannot be limited or excluded under Data Protection Legislation, including liability to Data Subjects under Article 82 UK GDPR, or for death or personal injury caused by negligence, or fraud.

7. Breach notification

Where the Processor becomes aware of a Personal Data Breach affecting Patient Data, it will notify the Clinic without undue delay, following our documented incident response procedure, and will provide the information required by Article 33(3) UK GDPR as it becomes available, to enable the Clinic to meet its own notification obligations as controller (including, where applicable, to the ICO within 72 hours and to affected patients).

8. Term, termination, and deletion on exit

This Agreement takes effect on the effective date and continues for as long as the Processor processes Patient Data on the Clinic's behalf. It terminates automatically on termination of the Clinic's underlying service agreement with the Processor. On termination:

  • the Clinic should download any planning outputs and case data it requires before the automatic retention deadlines described in Annex 1;
  • on request, the Processor will assist with exporting outstanding Patient Data for a reasonable period (30 days) following termination; and
  • the Processor will then delete all remaining Patient Data and copies, except where UK law requires retention (e.g. limited financial records relating to payments, retained per our Data Retention Policy).

9. General

  • Variation — this Agreement may only be varied in writing (including by the Processor publishing an updated version and giving the Clinic at least 30 days' notice before it takes effect, unless a shorter period is required to address an urgent security or legal issue).
  • Order of precedence — in the event of a conflict between this Agreement and any other agreement between the Parties regarding the processing of Patient Data, this Agreement prevails.
  • Governing law — this Agreement is governed by the laws of England and Wales, and the Parties submit to the exclusive jurisdiction of the courts of England and Wales.
  • Electronic acceptance — this Agreement is validly entered into when an authorised representative of the Clinic accepts it via the checkbox presented during account signup on the portal. The Processor records the acceptance (account, timestamp, and version of this Agreement accepted) as evidence of the Clinic's acceptance. The Clinic warrants that the person accepting on its behalf has authority to do so.
  • Entire agreement — this Agreement is the entire agreement between the Parties regarding the processing of Patient Data, superseding any prior discussions on that subject.

Annex 1 — Details of processing

  • Subject matter: provision of digital orthognathic surgical planning services by the Processor to the Clinic.
  • Duration: for the duration of the Clinic's account with the Processor, and thereafter as set out in section 8.
  • Nature of processing: collection, storage, organisation, structuring, analysis, and production of planning outputs; transmission to authorised Clinic staff; automated deletion at the end of the retention period.
  • Purpose of processing: to produce digital occlusion models, surgical plans, and case reports for named patients, on the Clinic's instructions, to support the Clinic's treatment planning.
  • Categories of data subjects: patients of the Clinic referred for orthognathic surgical planning.
  • Categories of personal data: patient name, date of birth, patient reference, scan date, surgery date, clinical notes; upper/lower jaw STL scans, CBCT/DICOM imaging, treatment plan PDFs, facial soft-tissue scans; produced occlusion models, surgical plans, and case reports. This includes special category health data under Article 9 UK GDPR.
  • Retention / deletion: clinical files on completed cases are deleted 60 days after case completion; abandoned draft cases are deleted after 90 days of inactivity; deletion is available on the Clinic's instruction at any time. Full detail: Data Retention Policy.
  • Security measures: see Security & Compliance and section 3.3 above.

Annex 2 — Authorised sub-processors

  • Google Cloud EMEA (Firebase Authentication, Firestore, Cloud Storage) — authentication, database, and file storage for all Patient Data. Region europe-west2 (London); Google Cloud DPA + UK Addendum where applicable.
  • Vercel Inc. — application hosting; Patient Data in transit through the application. EU/US edge network; Vercel DPA + SCCs / UK Addendum.
  • Stripe Payments UK Ltd — payment processing; payer name, email, case reference, and amount (only where the Clinic instructs direct patient invoicing). Stripe DPA.
  • Resend (Plus Five Five, Inc.) — transactional email delivery; recipient name/email, case reference, notification content. United States; Resend DPA + SCCs / UK Addendum.

The Processor will update this Annex (and give notice under section 3.4) before adding or replacing any sub-processor.

Annex 3 — Acceptance record

For clinics accepting electronically via the portal signup flow, this Agreement is evidenced by the account record maintained by the Processor (acceptance timestamp, version accepted, and accepting user). Clinics requiring a countersigned paper copy (e.g. NHS Trusts or larger clinic groups) can request one at info@ortho-facialplanning.co.uk.


Data Retention Policy

Last updated: 1 May 2026

We retain personal data only for as long as is necessary for the purposes for which it was collected, or as required by law. This policy sets out our retention periods by data category.

Guiding principles

Our retention decisions are based on the following principles:

  • Data is not kept for longer than is necessary for its original purpose.
  • Retention periods account for legal, regulatory, and contractual obligations.
  • Data is securely deleted or anonymised at the end of its retention period.
  • Where we act as a data processor, we follow the data controller's documented instructions regarding retention and deletion.

Retention periods by category

Account and registration data

User account information (name, email, role, clinic) is retained for the duration of the active account relationship, plus 12 months following closure to allow for any outstanding queries or disputes. Accounts inactive for 24 consecutive months may be archived and then deleted.

Clinical case data

DICOM imaging files, planning outputs, and associated case data are subject to automatic deletion as follows:

  • Draft cases — cases that remain in draft status and have not been submitted for planning are automatically purged after 90 days of inactivity. Both the case record and all uploaded files are deleted.
  • Completed cases — once a case is marked as complete, a deletion date is set 60 days from the completion date. Files and case data are automatically purged on or after that date.

Clinics are responsible for downloading and retaining any planning outputs they require before the deletion date. We recommend downloading all deliverables promptly upon case completion. We are not able to recover data after the automatic purge has run.

Clinics should note that separate obligations may apply under NHS records management standards or applicable professional guidelines — including minimum retention periods for clinical records — which are the data controller's responsibility. Our retention window is designed for portal data only and does not substitute for your own records management obligations.

Financial and payment records

Invoices, payment records, and related financial correspondence are retained for 7 years from the end of the relevant financial year, in line with HMRC requirements.

Communication records

Emails and support communications are retained for 3 years from the date of the last communication, after which they are deleted unless required for an ongoing legal matter.

Security and access logs

System access logs, authentication events, and security audit logs are retained for 90 days for operational security purposes, and for up to 12 months where a security incident is under investigation.

Website analytics data

Aggregated analytics data (non-identifiable) may be retained indefinitely. Any IP-address-level or session-level analytics data is anonymised or deleted after 26 months.

Deletion and anonymisation

At the end of the applicable retention period, data is either securely deleted (overwritten in a manner that makes recovery infeasible) or irreversibly anonymised so that it can no longer be attributed to any individual. Deletion requests submitted by individuals or clinics are processed within 30 days.


Security & Compliance

Last updated: 1 May 2026

Protecting the confidentiality, integrity, and availability of clinical and personal data is central to how we operate. This page describes our approach to information security.

Encryption

All data in transit between your browser and our servers is encrypted using TLS 1.2 or higher. Data at rest — including clinical case files and personal data — is encrypted using AES-256 encryption.

Access controls

Access to clinical case data within the portal is strictly role-based. Each user is granted the minimum level of access required for their role:

  • Clinic portal users can only access their own clinic's cases and data.
  • Internal planning staff access only the cases assigned to them for planning work.
  • Administrative access is restricted to named personnel and protected by multi-factor authentication.

UK data residency

Primary data storage and processing occurs on infrastructure located within the United Kingdom. We do not store clinical case data on servers outside the UK without explicit agreement and appropriate transfer safeguards in place.

Security monitoring and incident response

We operate continuous monitoring for suspicious activity, unauthorised access attempts, and anomalous behaviour. In the event of a personal data breach, we follow a documented incident response procedure. Where a breach is likely to result in risk to individuals, we will notify the ICO within 72 hours of becoming aware of it, as required by UK GDPR Article 33. Affected individuals will be notified without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

Staff and contractor obligations

All staff and contractors with access to personal or clinical data are subject to confidentiality obligations. Staff receive data protection and information security training on onboarding and at least annually thereafter.

Vulnerability management

We conduct regular reviews of our technology stack and apply security patches promptly. Responsible disclosure of potential vulnerabilities is welcomed — please contact us at info@ortho-facialplanning.co.uk with details. We commit to acknowledging all security reports within 5 business days.

Regulatory compliance

We maintain compliance with the following:

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018
  • Privacy and Electronic Communications Regulations 2003 (PECR)
  • NHS data security standards where applicable to our clinical clients