Privacy Policy
Last updated: 14 May 2026
Station House DC Limited (trading as Tower Dental) is the data controller for personal information you provide to us. In this policy, "we", "us" and "our" mean Station House DC Limited. This covers information you give us through the website at https://towerdental.uk, by telephone (01253 353759), by email, via WhatsApp, or in person at the practice. This privacy policy explains how we collect, use, store and protect your personal data. We do this under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Who we are
Tower Dental, 302a Devonshire Road, Blackpool, Lancashire FY2 0TW. Telephone 01253 353759. Email info@towerdental.uk. We are regulated by the Care Quality Commission (CQC). All clinicians are registered with the General Dental Council (GDC).
What personal data we collect
We collect the following categories of personal data:
- Identification and contact details: name, date of birth, home address, email address, telephone number
- Medical and dental history: medications, allergies, relevant medical conditions, dental treatment history, x-rays, clinical photographs
- Financial information: payment card details (a secure third-party processor handles these — we do not store card numbers), bank details for plan payments, finance agreement details where applicable
- Correspondence: emails, WhatsApp messages, phone call records (practice notes only — we do not record calls)
- Website data: only basic, aggregated and de-personalised page-view information collected by our cookieless analytics provider (Plausible). No personal data, IP address tracking, fingerprinting or cross-site profiling.
Lawful basis for processing
We process your personal data under the following UK GDPR lawful bases:
- Consent (Article 6(1)(a)) — for marketing communications, non-essential cookies
- Contract (Article 6(1)(b)) — to provide the dental treatment you have booked
- Legal obligation (Article 6(1)(c)) — for clinical record keeping as required by the GDC, CQC and NHS Business Services Authority
- Legitimate interest (Article 6(1)(f)) — for patient recall reminders, practice administration, fraud prevention
- Health/care data — processed under Article 9(2)(h) UK GDPR (provision of health care, including diagnosis, treatment, and management of health/social care systems)
- Vital interests (Article 9(2)(c)) — in a dental emergency where you cannot give consent (for example, you arrive unconscious or in severe distress), we may process your health data to protect your vital interests until you can give explicit consent
Who we share data with
We share personal data with:
- Dentally (Henry Schein One UK Ltd) — our patient management system. Holds clinical notes, treatment plans, appointment history, payment records, radiographs and clinical photography. Cloud-hosted in the UK/EU. Processed under an Article 28 data processing agreement.
- Specialist dentists and dental laboratories when referring you for treatment
- Your GP or other healthcare professionals where clinically relevant and with your consent
- Stripe (payment processing — PCI DSS compliant)
- Denplan / Practice Plan (membership administration)
- Plausible Analytics (cookieless website analytics — no personal data, no IP tracking, no cross-site profiling)
- Our secure cloud backup provider for patient records
- Our indemnity insurer in the event of a claim
- Regulatory bodies (GDC, CQC) where legally required
We do not sell personal data to third parties under any circumstances.
How long we keep data
We keep dental records for at least 11 years after the last appointment (or until age 25 for paediatric patients). NHS record keeping guidelines require this, even for private patients. We keep financial records for 7 years for tax purposes. We keep marketing consent records while consent is active. Website analytics are aggregated and contain no personal data, so no individual-level retention period applies.
Third-Party Services Used by This Website
Tower Dental's website uses the third-party services below to operate. Each has its own privacy policy, linked below. We share only the minimum data each service needs to work.
- Stripe (stripe.com) — processes the £40 consultation payment. We never see or store card numbers. Privacy: stripe.com/gb/privacy
- Plausible Analytics (plausible.io) — cookieless, privacy-friendly traffic measurement. No cookies are set. No personal data, IP addresses, device fingerprints, browser fingerprints or cross-site profiles are processed. Aggregated stats only. EU-hosted. Privacy: plausible.io/data-policy
- Web3Forms / FormSubmit — relays your enquiry form submissions to our practice email. Privacy: web3forms.com/privacy
- Zapier (zapier.com) — relays form submissions to our internal practice management system. Privacy: zapier.com/privacy
- Netlify (netlify.com) — the hosting provider serving this website. Privacy: netlify.com/privacy
All the processors above are GDPR-compliant. They process data under appropriate Article 28 contracts or Standard Contractual Clauses.
Your rights
Under UK GDPR, you have the right to:
- Access your personal data (subject access request)
- Have inaccurate data corrected (rectification)
- Request deletion of data we no longer need (erasure — subject to clinical record retention requirements)
- Restrict processing in certain circumstances
- Data portability
- Object to processing based on legitimate interests or for direct marketing
- Withdraw consent at any time
- Not be subject to automated decision-making
To exercise any of these rights, email info@towerdental.uk or write to Tower Dental, 302a Devonshire Road, Blackpool FY2 0TW. We will respond within one calendar month.
Cookies
This website uses essential cookies. These are needed for basic functionality — for example, to remember a form session while you submit an enquiry. Website analytics are provided by Plausible Analytics, which is cookieless and sets no cookies. We do not use Google Analytics or Google advertising cookies. Our website analytics is provided by Plausible Analytics, which sets no cookies and processes no personal data. So no analytics consent is required under PECR. See our Cookie Policy for full details, or change your Cookie settings.
International transfers of data
Your patient records and clinical data are stored on UK/EU servers (Dentally, Denplan, our backup provider). But some of the supporting services we use process limited data outside the UK:
- Zapier (USA), Netlify (USA) — website hosting and form relay. Same UK IDTA / UK Addendum safeguards apply.
- Stripe (USA/EU) — payment processing under PCI DSS and UK IDTA / UK Addendum.
- Plausible (Germany, EU) — covered by UK adequacy regulations recognising the EU's GDPR framework.
We have reviewed each transfer. We are satisfied that appropriate safeguards are in place. You can ask for a copy of the relevant transfer mechanism by emailing info@towerdental.uk.
Data Protection Officer
We are a small dental practice serving a local community. We do not process personal data on a scale that legally requires the appointment of a Data Protection Officer under UK GDPR Article 37. Responsibility for data protection sits directly with our practice principal, Dr Sarah Metias (CQC Registered Manager), supported by our practice manager. Please send any data-protection question or request to info@towerdental.uk, marked "Data Protection Request". These are escalated directly to the principal.
Complaints
If you are unhappy with how we handle your personal data, please contact us first at info@towerdental.uk. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk or 0303 123 1113.
Changes to this policy
We may update this privacy policy from time to time. The "Last updated" date at the top of this page shows when we last revised it.
How to Contact Our Data Controller
You may have questions about how Tower Dental handles your personal data. You may also wish to exercise any of your UK GDPR rights. You can reach our data controller in several ways. By telephone on 01253 353759 during opening hours (Monday to Friday 8:30am to 5:30pm, Saturday: Closed). By email at info@towerdental.uk — subject line "Data Protection Request" helps us route your enquiry quickly. By post to Data Controller, Tower Dental, 302a Devonshire Road, Blackpool, Lancashire, FY2 0TW. In person at the practice during opening hours. We may ask you to follow up in writing, so we have a clear record of your request.
Data Breach Response
In the unlikely event of a data breach affecting your personal information, Tower Dental will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. UK GDPR Article 33 requires this. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay. We maintain detailed incident response procedures. All clinical staff receive annual data protection training.
Your Right to Complain
If you are unhappy with how Tower Dental has handled your personal data, we would encourage you to raise it with us first. We will do everything we can to resolve your concern. You also have the right at any time to complain directly to the Information Commissioner's Office. The ICO is the UK's independent data protection regulator. You can reach the ICO at ico.org.uk, on 0303 123 1113, or by post to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
Your rights under the UK GDPR
You have the right to access the personal data we hold about you. You have the right to rectification of inaccurate data. You have the right to erasure in certain circumstances. You have the right to restrict or object to processing. You have the right to data portability. You will never be charged for exercising these rights. To exercise any of them, contact the practice using the details on this page. If you are unhappy with how we handle your data, you can complain to the Information Commissioner's Office at ico.org.uk.