Privacy Policy
Last updated: 31 July 2026
This Privacy Policy explains how Dental Scotland("we", "us", "our") collects, uses, and protects your personal data when you use the Dental Scotland Gold Card loyalty and referral programme (the "Programme"). We are committed to protecting your privacy in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are (Data Controller)
Dental Scotland is the data controller for personal data processed through the Programme. If you have any questions, contact us at hello@dentalscotland.com.
2. What data we collect
- Identity data: your name.
- Contact data: WhatsApp/mobile number (wa_id) and email address.
- Programme data: your member code, referral links, referrals made, stored discounts earned and redeemed, and visit/treatment values recorded by the practice.
- Communications: messages exchanged with our WhatsApp assistant.
- Consent records: the exact wording shown to you, your YES/NO (or STOP/START) decision, timestamp, channel (WhatsApp or web), and related WhatsApp message id where applicable.
We do not collect clinical/health records through the Programme. Your dental records are held separately by your dental practice.
3. How we use your data and our lawful basis
- Contract — to operate membership: create your Gold Card, track referrals, apply stored discounts, and send transactional WhatsApp messages needed to run the Programme (e.g. card link, referral credit notices). This is separate from marketing.
- Consent (membership) — you explicitly agree to join the Programme. We store the exact consent wording, time, and your WhatsApp id / phone.
- Consent (marketing) — optional. Only if you reply YES (or START later) do we send promotional / reminder-style Gold Card updates or Meta marketing templates. Reply STOP to withdraw. We store a separate consent record for this.
- Legitimate interests — to prevent fraud/abuse of the referral scheme and to improve the Programme.
4. WhatsApp messaging & Meta rules
Messages are delivered via the WhatsApp Business Platform (Meta). Meta processes delivery under its own terms and privacy policy.
- Free-form replies generally require an open customer-care window (typically 24 hours after your last message). Our onboarding session also expires after 24 hours — if you abandon signup, you must rescan the QR to start again. We do not send a recovery template in v1.
- Marketing templates may only be sent if you have granted marketing consent and Meta has approved the template. Without marketing consent we will not send marketing templates.
- This Programme shares a WhatsApp Business number with other practice systems (e.g. treatment proposals). Gold Card onboarding only starts when you send a message containing REF-GOLD-… (prefilled by our QR). Ordinary replies such as "Hi" or "Thanks" to practice messages do not enrol you.
5. Sharing your data
We share data only with: (a) your chosen dental practice to operate the Programme; (b) service providers who help us run the Programme (hosting, database, WhatsApp delivery via Meta, payment processing via Stripe); and (c) authorities where required by law. We never sell your data.
6. Payments
Card payments are processed securely by Stripe and/or WhatsApp payments. We do not store your full card details on our systems.
7. Data retention
We keep your Programme data for as long as you remain a member and for up to 24 months afterwards, unless a longer period is required by law. Consent records are retained to demonstrate compliance. Abandoned WhatsApp onboarding sessions are deleted after 24 hours. You may request deletion at any time.
8. Your rights
Under UK GDPR you have the right to:
- Access a copy of your personal data;
- Rectify inaccurate data;
- Erase your data ("right to be forgotten");
- Restrict or object to processing;
- Data portability;
- Withdraw marketing consent at any time (reply STOP or email us).
To exercise any right, email hello@dentalscotland.com. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
9. Data security & storage
Data is stored on secure servers within the UK/EEA where possible and protected with encryption in transit. Access is restricted to authorised staff and processors. Inbound WhatsApp events are processed idempotently (duplicate Meta message ids are ignored) to avoid duplicate accounts.
10. Changes to this policy
We may update this policy from time to time. The latest version will always be available on this page.
