Data protection & compliance

Last updated 30 September 2026

This page summarises how Praxis is governed, for practice owners, information governance leads and clinical safety officers. Praxis was named PraxisPay until 19 September 2026; PraxisPay is now the name of its associate pay area. Supporting documents are available to customer practices on request from info@praxisdental.co.uk.

The legal entity

Praxis is operated by Praxis Health Technologies Ltd, England & Wales company no. 17294974, registered office 128 City Road, London, EC1V 2NX. The company is registered with the Information Commissioner's Office, registration ZC180094.

Data processing agreement

Each customer practice accepts a UK GDPR Article 28 data processing agreement with us, in Praxis, before live data is processed. It names the practice as controller and Praxis Health Technologies Ltd as processor, defines exactly what patient data Praxis handles (patient names and treatment references from billing records, the appointment diary by patient reference number for follow-up lists, consultation transcripts for 30 days, and never contact details, dates of birth or the clinical record), lists sub-processors, and sets out breach notification, audit and deletion terms. A clinician who creates their own account, rather than being added by a practice, uses Praxis under the terms of service and privacy policy directly; their own area holds their pay records, expenses and CPD, and patient follow-up lists identified by practice management system reference number, with appointment dates and times, practitioner and reason as booked, and the notes and tags they or the practice team type in.

Clinical safety (DCB0129)

Praxis's clinical area drafts clinical notes and patient letters from a clinician's dictation for the clinician to check, and supports recalls and follow-ups; its pay area is financial administration. No clinical decision is made by Praxis, and it is not the practice's clinical record. We maintain a clinical risk management file under DCB0129 covering both areas - a clinical risk management plan, a hazard log scored on the NHS England 5x5 matrix, and a clinical safety case report - so a deploying practice can complete its own DCB0160 assessment from our documentation.

The named Clinical Safety Officer is Dr Syed Ali (GDC 289983), who meets the competence DCB0129 describes for the role, evidenced by current GDC registration and completed clinical risk management training (NHS Digital Clinical Safety programme and a CPD-accredited Clinical Safety Officer practitioner course, 2026).

Where data lives

All data is hosted in the European Union: database and encrypted document storage with Supabase, application hosting with Vercel. Data in transit is protected by TLS. Scanned invoices and other uploaded documents live in a private storage bucket that is never publicly readable. Practice management system keys, consultation transcripts and meeting transcripts and minutes are encrypted at rest (AES-256-GCM) with a key held only in the server configuration, and a key is never shown back in Praxis once saved. Access to data is role-based within the application, and every material action is recorded in an audit log.

Sub-processors

  • Supabase - database and document storage (EU), and the live relay that carries transcript text from a clinician's phone to their computer during a recording, without storing it
  • Vercel - application hosting (EU region)
  • Anthropic - AI invoice reading, aggregate insights, the Praxis Assistant, drafting clinical notes and patient letters from a clinician's transcript, and drafting meeting minutes; it receives transcripts, never recordings; for a patient letter it can also read a treatment plan the clinician uploads and the patient's appointment history, read live from the practice management system; it drafts recall call briefs from a patient's follow-up facts, and reads uploaded pay statements and CPD certificates; and, when a clinician asks, it reviews one of their own consultation transcripts for coaching (DPA clause 2.7(d)); no model training on customer data
  • AssemblyAI - speech to text for live transcription in the voice transcriber in the clinical area (EU); audio is not retained by them once transcribed; we never store the audio, and store the transcript encrypted for 30 days
  • Groq - speech to text for recordings transcribed at the end of a consultation and for recorded practice meetings (US, DPA with SCCs and the UK addendum); the recording is sent once when the clinician stops; Groq does not retain the audio after transcription and does not use it to train models; we never store the audio, and store a consultation transcript for 30 days, or a meeting's transcript with its minutes until deleted, encrypted in both cases
  • Deepgram - backup speech to text for recordings transcribed at the end of a consultation, used only when Groq is temporarily unavailable (EU region, DPA with SCCs and the UK addendum); every request opts out of Deepgram's model improvement programme, so the audio is not used to train models and is kept only for as long as it takes to transcribe; not used for meetings; we never store the audio, and store the transcript for 30 days
  • Resend - email delivery, where enabled: sign-in, registration and sign-up links (including to an address that has not yet finished creating an account), and notices to staff and clinicians; a request to review an item charged to a clinician names the supplier, treatment and patient as shown on the invoice

Practices are told in Praxis, on their next sign-in, when a sub-processor is added or replaced; the change applies from that day, and the practice can object at any time (DPA clause 5.2).

AI apps a user connects are not sub-processors. A user can connect Claude, ChatGPT or another AI app to their own Praxis account (DPA clause 2.8). It is limited to what that user can already see and never returns patient data, except as below. If the user allows it, it can make a limited set of the changes that user could make themselves, each confirmed by them in the AI app before it happens and recorded as made through an AI app; it can never finalise, submit or send back a pay statement. The AI app acts for the user under the user's own agreement with its provider. A clinician may also allow their own AI app to read their own patient follow-up list and their own kept consultation transcripts linked to a patient (DPA clause 2.8). It is off unless the clinician ticks it when connecting, is never offered to practice staff, is read-only, and is a disclosure the clinician makes to a provider they chose; PHT does not treat that provider as a sub-processor.

Sign-in providers are not sub-processors. Where a practice enables staff sign-in with a Google or a Microsoft work account, the member of staff authenticates directly with that provider against their own account. No practice or patient data is sent, and the provider processes nothing on our instructions - it confirms who has signed in. Google's APIs Terms of Service provide for a controller-to-controller relationship rather than a processor one; with a Microsoft work account the provider is already the practice's own supplier for that account. Listed here so the position is disclosed rather than assumed.

What Praxis never holds

No patient contact details, no dates of birth, no NHS numbers, no medical histories, no stored clinical notes or letters, no radiographs, and never a recording. The clinical text Praxis stores is: consultation transcripts, encrypted and deleted 30 days after the recording started; a consultation review a clinician asks for, encrypted, visible only to them and deleted with its transcript, whose scores, which contain no patient information, are kept for the clinician; a meeting's transcript and minutes, encrypted, which may mention a patient; each mirrored appointment's reason as booked in the practice management system; the follow-up notes, tags, action requests and lead labels the team types, which are free text and may contain a name; and recall call briefs drafted from those. The billing patient data surface is limited to what billing records already contain: a name, a treatment description, a tooth reference and an amount. On the follow-up lists, in a clinician's own area and on a practice team's shared list, it is a practice management system reference number, registration and recall dates, an amount outstanding, and each appointment's date and time, practitioner, status, reason as booked and any cancellation reason, with the free text the team types. A clinician or practice team member can show names beside those numbers while the page is open; they are fetched live from the practice management system (or taken from names the practice already holds from billing records), held on screen only and discarded when the page is left, never stored.

Incidents and breaches

Suspected security incidents are reported to info@praxisdental.co.uk and handled under our breach response procedure: containment, assessment, notification of the controller practice without undue delay, and ICO notification where required by law.