This privacy notice page lets you know how we collect and use your personal information by using our website, FenceHouseDental.co.uk, and employing our services at Fence House Dental.
We, Fence House Dental, are the data controllers. We are responsible for the personal information that we collect from you via our website. We will refer to our company as ‘we’, ‘us’, and ‘our’ throughout this document.
You can contact us at any time. Our full contact details are below:
Fence House Dental
info@pmclinic.co.uk
Fence House, 84 Buxton Rd, Macclesfield, Cheshire SK10 1JS
+44 1625 682683
We are obliged to keep the details we have about you accurate. If anything changes in your circumstances, such as, but not limited to, a change in address or phone number, please contact us so we can correct your data.
It’s important that you understand all the ways we collect and use your personal information. Personal data is anything that could be used to identify you.
We need to contact you on a regular basis during the entirety of our relationship. Our rules for holding this data depend on the decisions you make about whether to undergo treatment with us.
We store all contact details in our practice management software, Carestack. This helps us manage our practice. As such, our legal basis for using your data this way is legitimate interest. It would be impossible to manage our practice without some form of practice management software.
We also store some contact details in our customer-relations management software, Leadflo 360. We use this to ensure we follow up with you when we need to. As such, our legal basis for using your data this way is in our legitimate interests. We must ensure that we follow up with all customers thoroughly. We also use a CRM to ensure that our communications with you are highly relevant and timely.
If you do choose to become a patient with us, your contact details become part of your healthcare records, after which the legal bases and our obligations for storing them changes. Please read more below.
We must store sensitive healthcare data to treat you as a patient. Your treatment may depend on sharing some of this data with a laboratory or an auditor. We are legally obliged to hold this data for 10 years. Depending on the complexity of your treatment, we may choose to retain this data for a longer period upon review after the 10-year period. Otherwise, it is destroyed. As such, our legal bases for holding this data are, at first, to fulfil a contract to you and then, afterwards, legal obligation.
We log your IP address along with the pages you visit, information about your web browser (your User Agent e.g. Google Chrome, Safari, Internet Explorer) and whether you faced an error or not. We use this data to diagnose errors and investigate malicious attacks. Our web servers automatically collect this data and store it on the same server. This data is never shared or used for any purposes beyond diagnostics and investigation. This data is destroyed at six-monthly intervals. As such, our legal basis for holding this data is legitimate interest.
If you are a customer, we must keep track of your basic financial information (transactions made with us) by law for six years from the day you no longer use our services. As such, our legal basis for storing this data is a legal obligation.
Basic financial information includes:
Your contact details
Identification
Transactional and financial data
We collect website usage data using Google Analytics and Facebook. We use this information to improve our website’s user experience, identify opportunities for business growth and improve and monitor ongoing marketing campaigns. This data also allows us to run marketing campaigns that are highly relevant to the individual who can then make a better-informed decision whether our services are right for them or not. We retain this data for a maximum of 38 months so we have enough data to make meaningful statistical analyses. As such, our legal basis for collecting, storing and using this data is within our legitimate interests. You may use cookie-blocking software to disable this tracking to no detriment to this website’s function.
We collect, store and process data about phone calls you make to our practice. This is to ensure a consistent and high-quality customer service, to manage marketing activities and improve our business processes. We use call-tracking software to do this. We have configured Univerge Blue Connect to retain data for 90 days maximum – this provides just enough data to meet the intentions stated. As such, our legal basis for processing this data is legitimate interest. You may use the phone number listed on this page to bypass call tracking.
We have a legal obligation to store your preference to receive marketing from us. If, by request or by our own data handling rules and obligations, we erase your data, we will lose your marketing preferences. If you contact us again, you will need to state your marketing preferences again.
We may send you information about special offers, competitions and other deals that are strictly relevant to you as a customer. The period of time in which we do this depends on the treatment you express interest in. At a maximum, this is around 12 months. We will stop and erase your data if you do not respond to our marketing emails. Our legal basis for this is a legitimate interest.
We will never sell or provide your personal data to third parties for marketing purposes. We will only ever market our own business to you, depending on your preferences.
We may use a combination of your contact details, usage data and marketing data to display relevant, targeted content to you from our website or through advertising networks such as Google Ads and Facebook Ads. As such, our legal basis for doing so is legitimate interest.
As stated above, we may hold sensitive data about you in the form of healthcare records. If we don’t collect this data, we will be unable to provide you healthcare services. We will never process this data outside of our duties as a healthcare provider. If, in the event of one-time processing, we will contact you and request explicit consent. This would be an exception rather than a norm.
We take, at a minimum, in a clinical setting:
Dental X-rays
Notes on your current dental health condition
Relevant notes on your dental history
Previous practice details, if relevant
For more information, please email us at info@pmclinic.co.uk.
We do not use your information to make automated decisions or profile you.
As stated previously, we may send you relevant marketing communications on the basis of growing our practice, which is within our legitimate interest. Where we wish to send you general and non-specific marketing communications, we will always do this on the basis of your consent.
The Privacy and Electronic Communications Regulations (PECR) permits us to communicate with you for marketing purposes if:
You are a patient or expressed interest in becoming a patient
You have explicitly opted in to marketing communications
You have not withdrawn that consent
Your consent is still deemed relevant
After 12 months of no contact, we will deem your consent expired.
You may request we stop marketing at any time using the contact details above.
To perform all business functions, we may need to share some of your personal data with third-party data processors:
Fence House Dental
Website management agency
Marketing agency
IT management and support
Carestack (practice management software)
Solicitors, accountants, auditors
Healthcare regulators (CQC, GDC)
HMRC
Government bodies
Dental laboratories (Innovate, Matrix, The Cube)
Leadflo CRM
Google Analytics
Facebook Ads
Google Ads
Dropbox
Gmail
If we sell the business, the acquiring party
Some of our processing requires transfer of your personal information outside of the European Economic Area (EEA).
All processors we use comply with GDPR, EU law adequacy decisions, or the EU-US Privacy Shield.
We will not use a processor outside these protections unless you give explicit consent for a one-time action.
Our systems follow “Privacy by Design” principles to ensure your personal data is protected from loss, access, processing or misuse without authority.
Only necessary staff have access to your information.
If a data breach occurs, we will notify you and the regulator within three days.
We only hold your personal data for as long as necessary.
Where possible, we have specified retention periods.
Sensitive data is held longer due to legal obligations.
Under GDPR, you have the right to:
Request access
Correct your data
Erase data
Restrict processing
Transfer data
Object
Data portability
Withdraw consent
You can contact us using the details at the beginning of this document.
You also have the right to complain to the ICO: www.ico.org.uk
External websites we link to have their own privacy policies.
Please review theirs when visiting them.