Trust & Security
Praxis is built so that even in a worst-case breach, no patient could be identified from our systems. This page sets out, in plain English, exactly how your data, and your patients’, is protected.
Our core guarantee
Praxis stores only a Patient ID, the bare reference number from your Dentally system. We hold no patient names, dates of birth, addresses, phone numbers, emails, NHS numbers, medical alerts or clinical records. A Patient ID means nothing on its own; it can only be linked to a real person inside your own Dentally account. Identifiers are stripped at ingestion, before anything is written to our database.
Technical & organisational measures
Data minimisation by design
An explicit field whitelist drops every patient identifier at the door. What we don’t need never reaches our database.
EU data residency
Your data is stored in the EU (Supabase, Ireland) and the app runs in Vercel’s Dublin region.
Encryption in transit & at rest
Everything moves over TLS and is encrypted at rest. Your Dentally API credentials are additionally encrypted with AES-256-GCM.
Row-Level Security
Isolation is enforced at the database level, each user can only ever read their own rows, even if application code had a bug.
Read-only integration
Praxis only ever reads from Dentally. We never write back to your practice system.
Least-privilege access
The app runs under a restricted database role; elevated access is reserved for background workers and is never used to serve a normal request.
Two-factor authentication
Optional TOTP two-factor login with single-use recovery codes, plus “log me out everywhere”.
Audit logging
Sensitive actions are logged. Security logs are kept for 12 months, then deleted automatically.
Who processes your data (sub-processors)
We use a small set of vetted providers, each under its own data-processing agreement with standard contractual safeguards for any transfer outside the UK/EU. We give notice of changes and you may object on reasonable grounds.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database & encrypted file storage | Ireland (EU) |
| Vercel | Application hosting | Dublin (EU) region |
| GitHub | Scheduled data-import workers | EU/US, under safeguards |
| Anthropic | AI drafting (letters, call prep, voice notes), no training on your data | US, under safeguards |
| Resend | Account & team emails only (never patient data) | US, under safeguards |
| Optional sign-in | US, under safeguards | |
| Upstash | Rate limiting / abuse and brute-force protection (transient request counters keyed by IP or user id, no patient data) | Ireland (EU) |
| AssemblyAI | Speech to text for the voice transcriber. Audio is sent to their EU servers, is not used to train their models, and is not retained by AssemblyAI once transcribed; Praxis itself never stores the audio or the transcript | Ireland (EU) |
| Dentally | Your practice system, the source of practice data | UK |
Our legal footing
Controller and processor. For your own account data, Praxis is the controller. For patient-related data drawn from Dentally, you (the associate/practice) are the controller and Praxis acts only as your processor, under a written Data Processing Agreement (UK GDPR Article 28). Every user accepts the Terms and DPA before use, so the processor relationship is actually in force.
Breach notification. If a personal-data breach affecting your data ever occurs, we notify you without undue delay after becoming aware of it, with enough detail for your own ICO and data-subject obligations.
Retention & deletion. Patient-related data is deleted automatically 30 days after the last connection to a practice ends (sooner on request). Patients deleted in Dentally are removed from Praxis automatically. You can delete your account yourself at any time in Settings.
Operated by.Praxis Health Technologies Ltd, registered in England & Wales (company no. 17294974), registered office 128 City Road, London, EC1V 2NX. Aligned with UK GDPR and the EU GDPR, and registered with the ICO under reference ZC180094. You can verify this on the ICO public register.
Questions, or a security concern?
Our data-protection contact is info@praxisdental.co.uk. For the full detail, read the Privacy Policy, the Data Processing Agreement and our Cookie notice.
Legal terms version 2026-06-23.