GDPR & Data Protection

Last updated: 5 May 2026

At B4MIND Brand Consulting and Digital Marketing Ltd (operating as "CareDental"), data protection is central to how we build and operate our platform. This page explains our approach to the UK GDPR and EU GDPR and the commitments we make to clinics ("Customers") and the individuals whose data we process.

1. Our role

CareDental processes personal data in two capacities:

  • Processor — for patient and lead data that clinics manage through the platform. The clinic is the controller; CareDental processes this data only on the clinic's documented instructions.
  • Controller — for clinic user accounts and website visitors (see our Privacy Policy).

This page focuses on our commitments as a processor to our Customers.

2. Data Processing Agreement (DPA)

We can put a Data Processing Agreement in place with Customers as part of our contract; contact us to arrange one. Our DPA sets out:

  • The subject matter, duration, nature, and purpose of processing
  • The types of personal data and categories of data subjects
  • Our obligation to process data only on documented instructions
  • Confidentiality commitments from personnel
  • Security measures (UK GDPR Art. 32)
  • Sub-processor terms and prior notice of changes
  • Assistance with data subject requests and breach notification
  • Deletion or return of data on termination
  • Audit and information rights

To arrange a DPA, contact info@caredental.ai.

3. Lawful basis and consent (important for clinics)

Because CareDental enables outbound WhatsApp messaging — including follow-up to leads who may not have initiated contact — clinics are responsible for ensuring a valid lawful basis and, where required, valid consent before adding leads or enabling AI follow-up. Our platform supports this by:

  • Defaulting AI follow-up to off for manually and bulk-added leads
  • Requiring an explicit consent record before AI follow-up can be enabled
  • Including an opt-out mechanism in outbound messaging

These features support, but do not replace, the clinic's own compliance obligations as controller.

4. Special category (health) data

Information about dental treatment may constitute health data, a special category under GDPR. Clinics, as controllers, are responsible for ensuring an appropriate Article 9 condition for processing such data. CareDental processes it only as processor, under appropriate safeguards.

5. Sub-processors

We use vetted sub-processors to deliver the Service (including database, hosting, AI, messaging, and email providers — see our Privacy Policy for the current list). We:

  • Impose data-protection obligations on each sub-processor by contract
  • Maintain a current list available to Customers on request
  • Provide prior notice of intended changes, allowing Customers to object

6. International transfers

Where personal data is transferred outside the UK/EEA, we rely on appropriate safeguards (UK IDTA, the UK Addendum to the EU SCCs, or an adequacy decision).

7. Security measures

Our technical and organisational measures include: encryption of sensitive credentials and tokens; encrypted transport (TLS); strict tenant isolation in our multi-tenant architecture; role-based access controls; least-privilege access; and secure authentication. We continually review and improve these measures.

8. Data subject rights

We assist Customers in responding to requests from individuals exercising their rights (access, rectification, erasure, restriction, objection, portability). Where an individual contacts us directly about data we process on a clinic's behalf, we will refer the request to the relevant clinic or act on its instructions.

9. Data breach notification

We maintain procedures to detect, investigate, and respond to personal data breaches, and will notify affected Customers without undue delay in accordance with our DPA and applicable law.

10. Data retention and deletion

Patient/lead data is retained and deleted in accordance with the relevant clinic's instructions. On termination, we make Customer Data available for export and then delete it, subject to any legal retention requirements.

11. Your supervisory authority

Individuals in the UK may contact the Information Commissioner's Office (ICO) at ico.org.uk. We are registered with the ICO under registration number ZB863194.

12. Contact

For data-protection enquiries, our DPA, or sub-processor information:

B4MIND Brand Consulting and Digital Marketing Ltd (operating as CareDental)

66 Paul Street, London, England, EC2A 4NA

General enquiries and data protection enquiries: info@caredental.ai