Privacy Policy

Last updated: 26 June 2026.

Who we are

Praxis is an analytics and finances tool for UK associate dentists, operated by Praxis Health Technologies Ltd, a company registered in England & Wales (“Praxis”, “we”, “us”) under company number 17294974, with its registered office at 128 City Road, London, EC1V 2NX, United Kingdom. Founded by Dr Syed Ali. You can contact us at info@praxisdental.co.uk. This policy explains what data we handle and how. It is written to align with UK GDPR and the EU GDPR. Praxis is currently in private beta.

Praxis Health Technologies Ltd is registered with the ICO (Information Commissioner’s Office) under reference ZC180094 (verifiable on the ICO public register).

Our two roles: controller and processor

For your own account (your name, email, GDC number, and the income and expenses you record), Praxis is the data controller.

For patient-related data drawn from your practice’s Dentally system, the practice/associate is the controller and Praxis acts only as a data processor, on your documented instructions and under a Data Processing Agreement.

What we process

Your account: full name, email, GDC number, a securely hashed password (or your Google sign-in), and subscription details.

Your finances: the income and expense entries you create, your associate split percentages, the monthly pay statements you import (and the gross, net and deductions read from them), and any receipts you upload.

Your practice connection: your Dentally API credentials, stored encrypted (AES-256-GCM).

No patient personal data is stored on our side, only Patient IDs. The only patient information Praxis holds is the Patient ID, the internal reference number from your Dentally system. We do not hold patient names, dates of birth, phone numbers, email addresses or postal addresses. A Patient ID is a bare number that means nothing on its own, it can be linked back to an actual person only inside your own Dentally account, which you and your authorised staff already have access to. Nobody at Praxis, and nobody who ever saw our database, could identify a single patient from it. Alongside the Patient ID we hold non-identifying activity data: appointment history (dates, types, attendance, cancellations and their reasons and durations), payment totals attributed to you, recall dates, and, where your Dentally connection allows it, completed-treatment types and the fees charged (to power the per-treatment £/hour analysis), again keyed only to the Patient ID. We also store what your team creates in Praxis (follow-up statuses, notes and their change history, potential-leads entries, and any patient letters you choose to save and can delete), always keyed to the Patient ID, never to a name.

What we deliberately do not store: patient names, contact details, date of birth, address, and NHS numbers, National Insurance numbers, medical alerts, ethnicity, clinical notes and clinical records. For treatments we keep only the treatment type and its fee, never the clinical detail (teeth, surfaces, diagnoses or notes). All of this is stripped out before anything is written to our database, we keep an explicit whitelist of the fields Praxis needs, and everything else is discarded at the door.

AI features: when you generate a patient letter or a “prep my call” summary, the relevant appointment history is sent to our AI provider (Anthropic) to draft the text, no patient name is sent (letters use a placeholder you complete). When you import a pay statement, the text read from that document is also sent to Anthropic to extract the figures. Anthropic never uses this data to train its models and deletes API inputs and outputs automatically after a short period. Voice notes are transcribed in real time; Praxis does not store the audio or the transcript, only anonymous usage counts for billing.

Why we process it (lawful basis)

Your account and billing data is processed to provide the service you’ve signed up for (contract, Article 6(1)(b)). Patient-related data is processed on behalf of you, the associate, for the management of health and care services (Article 9(2)(h) with the corresponding UK DPA 2018 condition), under our processor agreement with you. We do not use your data for advertising and we never sell it.

Where your data lives, and security

Your data is stored in the EU (Supabase, Ireland) and the application runs in Vercel’s Dublin region. Our data-import workers run on GitHub’s cloud infrastructure. Everything is encrypted in transit (TLS) and at rest. We apply database-level Row Level Security so each user can only ever access their own data, we encrypt your Dentally credentials, and we keep an audit trail of sensitive actions. Praxis is read-only from Dentally, we never write back to your practice system.

Who else is involved (sub-processors)

We use a small number of vetted providers, each under its own data-processing agreement with standard contractual safeguards for any transfer outside the UK/EU:

Supabase (database & file storage, Ireland) · Vercel (application hosting, Dublin region) · GitHub (data-import workers) · Anthropic (AI drafting for letters, call prep and voice notes, no training on your data, short automatic deletion) · Resend (account and team emails only, patient data is never emailed) · Google (optional sign-in) · Upstash (rate limiting / abuse and brute-force protection; holds only transient request counters keyed by IP address or user id, no patient data, Ireland) · AssemblyAI (speech to text for our voice transcriber; audio is sent to their servers in Ireland, is not used to train their models, and is not retained by AssemblyAI once transcribed, and Praxis itself never stores the audio or the transcript), plus your practice’s Dentally account as the source of practice data.

How long we keep it

Account and financial records are kept while your account is active; deleting your account (Settings) removes your data. Patient-related data is kept while a practice connection is active and is deleted automatically 30 days after the last connection to that practice ends (sooner on request, just email us). Patients deleted in your practice’s Dentally system are removed from Praxis automatically too. Saved letters can be deleted by your team at any time. Security audit logs are kept for 12 months and sync logs for 6 months, then deleted automatically.

Your rights

You can access, correct, export, or delete your account data, and object to or restrict certain processing. You can delete your account yourself at any time in Settings, or email us at info@praxisdental.co.uk. You also have the right to complain to the Information Commissioner’s Office. Patients exercise their rights through the practice (via Dentally), which holds the system of record; if a patient request reaches us as your processor, we will assist you in answering it.

Cookies

We use essential cookies only: one to keep you signed in, and one to remember the “hide my figures” privacy preference. We do not use advertising or third-party tracking cookies, and we don’t run analytics trackers.

Changes & contact

We’ll update this policy as the product evolves and note the date above. Questions? Email info@praxisdental.co.uk.