Toothfully

Data processing agreement

Version 2026-09-28. This agreement forms part of the terms for Verified Reviews between Toothfully (“we”, the processor) and the dental practice (“you”, the controller). A practice accepts it in its portal before sending us patients’ details.

1. What we process and why

You send us patients’ names, email addresses and/or mobile numbers, and appointment dates and times (by typing them in, uploading a spreadsheet, our appointments API or by forwarding appointment emails). We use them only to send each patient an invitation to review their visit, one reminder, and to check reviews come from real visits. We don’t use them for anything else, and never for marketing.

Data subjects: your patients. Types of data: name, contact details, appointment date and time. Because being a patient of a dental practice can reveal information about health, you must not send clinical details, and we treat the data with the care due to health information.

2. Your responsibilities

  • You have a lawful basis to share the data with us, and your privacy notice tells patients that their details are shared with Toothfully to invite them to review.
  • You send only the data listed above, and you invite every patient you see, not a selection.
  • You tell us promptly if a patient objects, so we don’t contact them.

3. Our responsibilities (UK GDPR Article 28)

  • We process the data only on your documented instructions (this agreement and your use of the service), unless the law requires otherwise.
  • Everyone who can access the data is bound by confidentiality.
  • We keep the data secure, with appropriate technical and organisational measures: encrypted connections, access limited to people who need it, and single-use private review links.
  • We use the sub-processors listed on our sub-processors page, under written terms that protect the data in the same way. We’ll tell you about changes to the list, and you can object.
  • We help you respond to requests from patients to access, correct or erase their data, and with data protection impact assessments and consultations where needed.
  • We tell you without undue delay, and within 48 hours, after becoming aware of a personal data breach affecting your data.
  • Where data is transferred outside the UK, we make sure it’s protected by UK adequacy regulations or the ICO’s International Data Transfer Agreement or Addendum.
  • We make available the information you need to show compliance, and allow reasonable audits with notice.

4. How long we keep it

Invitation links expire after 60 days. We remove patients’ names and contact details from invitation records after 90 days, and from our email log after 90 days. When you stop using Verified Reviews, we delete or anonymise the patient details you sent us within 90 days, unless the law requires us to keep them.

5. Reviews

When a patient writes a review, the review itself, and the name they choose to show, are processed by Toothfully as a separate controller under our own privacy notice, because we publish and moderate reviews independently of practices.

6. General

This agreement lasts as long as we process patient data for you. It’s governed by the law of England and Wales.