Privacy Policy
How we collect, use and protect personal data — including the health data your practice trusts us with.
Last updated 30 June 2026
On this page
1. Introduction
This Privacy Policy explains how Maxillo Ltd("Maxillo", "we", "us") collects, uses, shares and protects personal data when you visit maxillo.co.uk, use the Maxillo application at app.maxillo.co.uk, or otherwise interact with us.
We are committed to processing personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Where we serve practices or individuals in the EEA, we also act consistently with the EU GDPR.
2. Controller and processor
Data protection law distinguishes between the data controller (who decides why and how data is processed) and the data processor(who processes data on the controller's instructions). Maxillo acts in both roles depending on the data:
- Maxillo as controller — for the data of practice owners, staff and website visitors: account details, billing information, support enquiries and site usage.
- Maxillo as processor — for patient dataentered into the platform. The dental practice is the controller of its patients' data; Maxillo processes it only to provide the service, under a Data Processing Agreement (DPA) and on the practice's documented instructions.
3. Data we collect
- Account data — name, work email, role and authentication details.
- Practice data — practice name, address, surgeries and configuration.
- Billing data — subscription tier, number of surgeries and invoices (card details are handled by our payment processor, not stored by us).
- Patient data — see section 4.
- Usage and technical data — pages viewed, actions taken, device and browser information, and IP address.
- Communications — messages you send us and demo or sales enquiries.
4. Patient data
Patient records may include special category health data, which receives heightened protection under UK GDPR. For this data the practice is the controller and Maxillo is the processor.
- All patient data is stored and processed in the United Kingdom and is not transferred outside the region.
- It is encrypted in transit and at rest, and logically isolated per practice.
- Every action taken on a record is logged in an auditable trail.
- AI-assisted outputs are reviewed and signed by a clinician — AI assists; clinicians decide.
5. Lawful bases for processing
We rely on the following lawful bases under UK GDPR:
- Contract — to provide and administer the service to your practice.
- Legitimate interests — to secure, maintain and improve the platform, where not overridden by your rights.
- Consent — for non-essential cookies and optional analytics.
- Legal obligation — to comply with our legal and regulatory duties.
Processing of patient data is carried out for the practice under a DPA; the practice is responsible for its own lawful basis and, where applicable, the patient relationship.
7. Third-party services and sub-processors
We use a small number of vetted providers to deliver the service. Each is bound by appropriate data-protection terms and, where they process data on our behalf, acts as a sub-processor:
- Hosting & database — UK-region infrastructure for the application and patient data.
- Application hosting / CDN — to serve the website and app.
- Payments — to process subscription billing securely.
- Email & communications — to send transactional and account messages.
A current list of sub-processors is available on request. We do not sell personal data.
8. Data retention
We keep personal data only for as long as necessary for the purpose it was collected, then delete or anonymise it:
- Account & practice data — for the life of the subscription and a limited period afterwards.
- Patient data — retained on the practice's instructions; returned or deleted on termination per the DPA.
- Billing records — kept as required by UK tax and accounting law.
- Usage logs — retained for a limited period for security and diagnostics.
9. Security
We protect data with encryption in transit and at rest, role-based access controls, single sign-on, network isolation between practices, and a full audit trail. No system can be guaranteed perfectly secure, but we follow practices appropriate to healthcare data and review them regularly. See our Security page for more.
10. Your rights
Under UK GDPR you have the right to:
- access a copy of your personal data;
- have inaccurate data corrected;
- have your data erased, where applicable;
- restrict or object to certain processing;
- data portability; and
- withdraw consent at any time.
For patient data, requests are directed to the practice (the controller) and we will assist them. To exercise your rights, contact us using the details below. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
11. International transfers
Patient data is kept in the UK. Limited operational data may be processed by providers outside the UK only where an appropriate safeguard is in place (such as UK adequacy regulations or the International Data Transfer Agreement).
12. Changes and contact
We may update this policy from time to time; the "last updated" date above reflects the latest version. Material changes will be communicated to account holders.
For privacy questions or to exercise your rights, contact us at contact@maxillo.co.uk. Maxillo Ltd is registered in England & Wales.
Questions about this policy? We're happy to help.
Contact us