This policy explains how Smileline Ltd ("Smileline", "we") handles personal data in connection with the smileline.io website and the Smileline platform (the "Service"). We process personal data in two distinct roles, and it matters which one applies:
- As a controller — for the data of the people we deal with directly: visitors to this website, and the staff of practices who hold Smileline accounts.
- As a processor — for the patient data that dental practices store in the Service. The practice is the controller of its patients' data; we process it only on the practice's instructions, under our Data Processing Agreement. If you are a patient of a practice that uses Smileline, contact the practice directly about your data — this policy's sections 1–6 do not govern that data.
1. Data we collect as a controller
- Account data — name, email address, password hash, role, avatar, language, and the practice you belong to.
- Billing data — subscription state and invoicing details. Card details are collected and held by Stripe, not by us.
- Usage and security data — sign-in timestamps, IP address, browser user agent, session records and an audit trail of actions taken in the platform.
- Agreement records — when you accept our Terms, this policy or the DPA, we record who accepted, the document version, the time, IP address and browser, as evidence of the agreement.
- Contact data — messages you send to our sales or support addresses.
2. Why we process it (lawful bases)
- Performance of a contract — providing the Service, authentication, billing, support.
- Legitimate interests — securing the platform, keeping audit trails, preventing abuse, improving the product.
- Legal obligation — accounting records, and evidencing consent and contract acceptance.
We do not sell personal data, and we do not use it for advertising.
3. Cookies
The platform uses strictly necessary cookies only: a session cookie to keep you signed in. This website sets no analytics or advertising cookies.
4. Who we share data with
We use a small number of service providers to run Smileline. Those that process personal data on our behalf are listed in the Data Processing Agreement (sub-processors) — principally Cloudflare (hosting), our managed database provider, Stripe (payments), Resend (transactional email) and, where a practice enables the AI assistant, OpenAI. We may also disclose data where required by law. We do not share personal data with anyone else.
5. International transfers
We host data in the UK/EU where the provider allows it. Where a provider processes data outside the UK, transfers are protected by UK adequacy regulations or the appropriate standard contractual clauses with the UK addendum.
6. Retention
- Account data is kept while the account exists and deleted or anonymised within 90 days of account deletion.
- Billing records are kept for 6 years to meet accounting obligations.
- Agreement-acceptance records are kept for the life of the practice's account and for 6 years after, as evidence of the contract.
- Practice Data retention is controlled by the practice — see the DPA.
7. Your rights
Under UK GDPR you can ask us for access to, correction, deletion, restriction or portability of the personal data we hold about you as a controller, and you can object to processing based on legitimate interests. Write to privacy@smileline.io — we respond within one month. You can also complain to the Information Commissioner's Office (ico.org.uk), though we'd appreciate the chance to resolve any concern first.
8. Security
All traffic is encrypted in transit (TLS); data is encrypted at rest; access to production systems is restricted, credential-based and logged. Channel-connection credentials stored for a practice are individually encrypted. See the DPA for the security measures we commit to contractually.
9. Changes and contact
Each revision of this policy carries a version date, shown at the top of the page; material changes are re-presented in the app for acceptance. Questions: privacy@smileline.io · Smileline Ltd, Hammersmith, London.