Privacy policy
Last updated 30 September 2026
Who we are
Praxis is a platform for dental practices and dental clinicians, operated by Praxis Health Technologies Ltd ("we"), a company registered in England & Wales, company number 17294974, registered office 128 City Road, London, EC1V 2NX. We are registered with the Information Commissioner's Office under registration ZC180094. Contact: info@praxisdental.co.uk.
Praxis has two sides. Its associate pay area, PraxisPay, is used by dental practice staff - practice owners, managers, reception teams and associate dentists - to produce pay statements. Its clinician area is used by dentists, hygienists and therapists, who may have been added by a practice or may have created an account themselves, to keep their own pay records, expenses, CPD and patient follow-up lists across the practices they work at. It is not a public service and holds no accounts for members of the public. Praxis was named PraxisPay until 19 September 2026; nothing about what is held or who it is shared with changed with the name.
Two roles: controller and processor
For staff account data - your name, work email address, role, GDC registration number (clinicians only), password hash and sign-in activity, and anything you send us through Support or post on the Suggestions board (a suggestion is shown to other Praxis users without your name) - the dental practice that added you to Praxis decides who has an account and why; we process this data to run the service for them. If you created your own account, we hold your account data to provide the service to you, and you can ask us to close the account at any time.
For patient-related data (below), the dental practice is the data controller and Praxis Health Technologies Ltd is the data processor, acting only on the practice's written instructions under a data processing agreement. If you are a patient of a practice that uses Praxis, your rights are exercised through the practice - they control the data; we hold it for them. We will assist the practice with any request.
For a clinician's own records - the pay statements they import or receive, their expenses, CPD records and follow-up lists - the clinician decides what is kept; we process it only to provide the service to them. Where a clinician receives a pay statement from a practice that uses Praxis, that statement is the practice's record and is held under the practice's agreement with us; the clinician sees their own copy.
What patient data Praxis holds - and what it never holds
Praxis's pay area is a financial administration tool. To divide laboratory and treatment costs correctly between a practice and its dentists, it processes, at the practice's instruction:
- patient names as they appear on laboratory invoices and payment records;
- treatment descriptions as billed (e.g. "zirconia crown"), including tooth references;
- amounts charged and paid, and the practice management system's patient reference number;
- scanned laboratory and supplier invoices, which may show a patient's name and treatment;
- dental plan statements the practice uploads (e.g. Denplan, PracticePlan, Lloyd & White): the subscribed patient's name as printed (a title, an initial and a surname), the provider's own patient reference, their plan fee code and the monthly amount paid to the practice.
Patient follow-up lists. In a clinician's own area, and on a practice team's shared follow-up list, Praxis reads the appointment diary from the practice management system and holds, for each patient: the practice management system's patient reference number, their registration and recall dates, the amount of treatment outstanding, and each appointment's date and time, practitioner, status and reason as booked (for example "Implant Crown Fit"), with any cancellation reason. It also holds what the practice team or the clinician types in: a follow-up status, tags, notes and action requests, and the label and note of a potential lead. Those are free text, so they can contain a patient's name or what the patient said, and they are kept as written. When someone asks for help preparing a recall call, the short brief that is drafted is kept with that patient's follow-up record. Praxis reads no patient name or contact details into these lists. A clinician or a member of the practice team can choose to see names beside those reference numbers while the page is open: they are fetched at that moment from the practice management system (or, at a practice on Praxis, taken from the names it already holds from billing records), shown on screen only, and discarded the moment they leave the page or switch away from it; Praxis does not store them. Searching for a patient by name sends the words typed to the practice management system at that moment; they are not stored. Praxis never holds patient contact details (address, phone, email), dates of birth, NHS numbers, medical histories or radiographs, and it is not the practice's clinical record.
Clinical notes, letters and transcripts. In the clinical area a clinician can dictate, or record a consultation, and have clinical notes and a patient letter drafted for them to check and copy into the practice's own clinical system. When drafting a letter, a clinician can also add a treatment plan or referral document, or have Praxis read the patient's appointment history from the practice management system at that moment; neither is stored. The recording is held only in the clinician's own browser until it is sent for transcription (or streamed as they speak), and it is never stored by Praxis; neither are the drafted notes or letters. The transcript is stored encrypted when the recording finishes, with the patient's own name replaced where Praxis can link it to the patient booked at the time; only that clinician can read it, and it is deleted automatically 30 days after the recording started (or sooner, if they delete it). A transcript can contain anything said in the consultation, including information about the patient's health. A clinician can also ask Praxis to review one of their own stored consultation transcripts for coaching on their consultation and case-acceptance skills (how they found out what the patient wanted, explained findings, presented options and costs, answered concerns and agreed next steps). The transcript is read for this by Anthropic, as for notes. The written review is stored encrypted, visible only to that clinician, and deleted with the transcript; the scores alone, which contain nothing about the patient, are kept so the clinician can see how they change over time. The review never assesses clinical care and is never shared with the practice.
Meeting minutes. A practice's managers can record an internal meeting and have minutes drafted from it. The recording is never stored. The meeting's transcript and minutes are stored encrypted for the practice, visible to its managers according to their role, until the person who recorded it or an administrator deletes them.
An example of what that means in practice. Denplan's monthly statement includes a date of birth for every patient on it. Praxis's reader is written to skip that column: the date of birth is not stored, not displayed and not needed to divide the income, so it is discarded when the file is read rather than kept because it happened to be supplied.
Lawful basis
The practice, as controller, relies on its legitimate interests and legal obligations in administering contracts with its dentists and keeping accounting records. To the extent a treatment description linked to a named patient is health data, the practice's basis is Article 9(2)(h) UK GDPR (management of health care systems and services), and we act strictly as its processor. Our basis for staff account data is the performance of our contract with the practice and our legitimate interest in securing the service.
Where data lives and who touches it
Praxis runs on infrastructure in the European Union: the database and encrypted document storage are hosted by Supabase and the application by Vercel, both in EU regions. Data in transit is encrypted (TLS) and invoice scans and other uploaded documents are held in a private bucket that is never publicly accessible. Practice management system keys (the practice's and a clinician's own), consultation transcripts and a meeting's transcript and minutes are also encrypted at rest with a key held only in the application's server configuration, and a key is never shown back in Praxis once saved.
Our sub-processors:
- Supabase - database and document storage (EU), and the live relay that carries transcript text from a clinician's phone to their computer during a recording; the relay passes the text on and does not store it.
- Vercel - application hosting (EU region).
- Anthropic - AI reading of scanned invoices (which may show a patient name and treatment), aggregate financial summaries, and the Praxis Assistant: when you ask the assistant a question, the question and the records you are already entitled to see - which can include patient names, treatment descriptions, clinician names and pay figures - are sent to Anthropic to compose the answer. Assistant conversations are kept for 90 days after their last message, then deleted. Anthropic also drafts clinical notes and patient letters from a clinician's transcript, and minutes from a recorded meeting's transcript: it receives the transcript, never the recording. For a patient letter it can also receive a treatment plan or referral document the clinician uploads, and the patient's appointment history read at that moment from the practice management system (dates, appointment types and status, and for the clinician's own appointments the reason, treatment description and notes as booked). To draft a brief for a recall call it receives the patient's reference number, the date and reason of their last appointment, their recall date, the list's tags and the practice team's note. It also reads the pay statements a clinician or a practice manager uploads, and the CPD certificates a clinician uploads, so the figures and course details can be checked before they are saved. When a clinician asks, it also reviews one of their own consultation transcripts for coaching (see above). Anthropic does not train models on any of this data.
- AssemblyAI - speech to text for live transcription in the voice transcriber in the clinical area. When a clinician chooses to transcribe live, the audio is streamed to AssemblyAI's servers in the EU as they speak and the words come back as text. The audio is not used to train their models and is not kept by them once it has been transcribed. Praxis never stores the audio, and stores the transcript for 30 days (see above). Only a clinician can start a recording, and only for their own dictation.
- Groq - speech to text for recordings transcribed at the end of a consultation, which is the voice transcriber's standard setting, and for recorded practice meetings. The recording stays on the clinician's own device until they press Stop; it is then sent once to Groq, who do not retain the audio after transcription and do not use it to train models, and the words come back as text. Praxis does not keep the recording: it is deleted from the device once it has been transcribed. The transcript is kept for 30 days (see above); a meeting's transcript is kept with its minutes. A recording that has not been sent (for example because the page was closed mid-consultation) stays on the clinician's own device, and nowhere else, until they send or discard it, and is removed from the device after 7 days if they do neither. Groq processes in the United States under a data processing agreement with standard contractual clauses and the UK addendum.
- Deepgram - backup speech to text for recordings transcribed at the end of a consultation, used only when Groq is temporarily unavailable. The recording is sent once, in the same way, to Deepgram's EU region. Every request opts out of Deepgram's model improvement programme, so the audio is not used to train their models and is kept only for as long as it takes to transcribe. Praxis does not keep the recording, and keeps the transcript for 30 days. It is not used for meetings. Deepgram processes under a data processing agreement with standard contractual clauses and the UK addendum.
- Resend - email delivery, where email is enabled: sign-in and registration links, sign-up links (including to an address that has not yet finished creating an account), and notices to practice staff and clinicians. A request to review a laboratory or other item charged to a clinician names the supplier, the treatment and the patient as shown on the invoice, and the clinician's share.
Each is bound by a data processing agreement with appropriate safeguards. The practice's own practice management system (e.g. Dentally) is not a sub-processor of ours - Praxis reads from it on the practice's own credentials, at the practice's instruction, or on a clinician's own credentials, which they add with their practice's permission.
AI apps you connect yourself. You can connect an AI app of your own choosing, such as Claude or ChatGPT, to your Praxis account, so you can ask it about your pay, your finances, your CPD or your practice's pay figures in your own chat. It answers only with what you can already see in Praxis, and never sends patient data: no patient names, patient references, teeth or treatment notes. If you are a clinician, you can choose, separately and only by ticking a box that is off by default, to let the AI app also read your own patient follow-up list (patients shown by their Dentally number, never by name, except anything your practice team typed into a note or tag, which is sent as written) and your own kept consultation transcripts that are linked to a patient, so it can draft a follow-up letter for you to check. A transcript can contain a patient's name and anything said in the appointment, so this sends patient information to the AI app's provider under your own agreement with them. Only turn it on with a plan that is suitable for patient information and does not train on your chats, and only if your practice allows it. Praxis does not send or keep the letters your AI app writes. If you allow it when you connect, it can also make some of the changes you could make yourself, such as approving an invoice or logging a CPD activity; every change is shown to you in the AI app first and happens only when you confirm it there, and Praxis records that it was made through an AI app. The AI app is not a sub-processor of ours: it acts for you, under your own agreement with its provider, and that agreement decides whether your conversations are used to train its models - which you can change in that app's settings or by your choice of plan. What you ask it to record in Praxis (a cost, a CPD activity, a statement) is kept like anything you enter yourself. You can disconnect it at any time from your settings in Praxis, and it is disconnected automatically if your account is frozen or you sign out everywhere.
Signing in with a work account. Where your practice has it enabled, you can sign in with a Google or a Microsoft work account instead of a password. Those providers are not sub-processors of ours, and they are listed separately here rather than above so the position is not misdescribed: you authenticate directly with the provider against your own account, nothing about the practice or its patients is sent to them, and they process nothing on our instructions. All Praxis receives is confirmation of who has signed in, plus an identifier so it recognises you next time. Google's own developer terms provide for a controller-to-controller relationship rather than a processor one, and where a Microsoft work account is used the provider is already your practice's own supplier for that account. Google sign-in is available today; Microsoft is built but not yet switched on.
Cookies
Praxis sets strictly necessary cookies only, and no analytics, advertising or tracking cookies of any kind:
- a signed session cookie that keeps you signed in (30 days, ended sooner by signing out or after 90 minutes without activity);
- if you add a second account to switch between, a cookie holding the signed-in accounts (30 days), and a five-minute marker while you add it;
- while you are between your password and your two-factor code, a five-minute cookie; and, if you tick "remember this device", a signed cookie that lets that browser skip the code for 30 days;
- when an administrator uses the read-only "Role Viewer", a two-hour cookie; and, for Praxis's own developers, a cookie remembering which client they are working in;
- short-lived cookies that protect a sign-in or sign-up with Google or Microsoft, a connection to Xero or OneDrive, and the return to an AI app you are connecting;
- cookies that remember your light or dark theme, whether you have hidden your figures, and which practice panels you left open (one year each).
Some screens also keep small settings in your browser's own storage (for example the order of your CPD list, which AI app you use, or a dismissed tip), and a recording that has not yet been sent stays on your device as described above. None of it is sent anywhere or used to track you.
Retention
Finalised pay statements and the records that support them are the practice's accounting records; we retain them for as long as the practice instructs, in line with UK accounting record requirements. Account and audit records are kept while the service is in use. On termination of our agreement with the practice, data is returned to the practice and then deleted, as the data processing agreement provides. A consultation transcript is deleted 30 days after the recording started; a meeting's transcript and minutes are kept until they are deleted in Praxis. A clinician's own records are kept while their account is open; when they ask us to close it, their records are deleted, except that a statement issued to them by a practice remains in that practice's records.
Your rights
You have the rights UK GDPR gives you, including access, rectification and erasure. Staff can raise these with us directly at info@praxisdental.co.uk. Patients should contact their dental practice, which controls the data; we support the practice in responding. You may also complain to the ICO (ico.org.uk).
Changes
If Praxis changes what it stores or who it shares data with, this page is updated at the same time, and everybody using Praxis is told about the change when they next sign in. The change applies from the day it is notified.