Legal

Privacy Policy

Last updated 9 July 2026

Denbot is a lead-capture and messaging platform for dental practices, operated by North & Main Ltd ("Denbot", "we", "us"). This policy explains what personal data we handle, why, and the rights you have. For data we process on behalf of a dental practice (for example, patient enquiries captured through a practice's website), the practice is the data controller and we act as its processor — see our Data Processing Agreement.

Who we are

Denbot is a trading name of North & Main Ltd, a company registered in England & Wales. We are the controller for personal data about our website visitors and our practice customers. For questions about this policy or your data, contact us at privacy@denbot.co.uk.

The data we collect

How we use data

Legal bases

We rely on contract (to deliver the service you or your practice sign up for), legitimate interests (to run and improve our business and keep the service secure), consent (for non-essential cookies and marketing), and legal obligation (for tax and compliance) as the lawful bases for processing under the UK GDPR.

Cookies

Cookies are small files stored on your device. We use them to keep the site working and to understand how it is used.

You can accept or decline non-essential cookies when you first visit, and you can change your choice at any time by clearing cookies in your browser settings. Blocking essential cookies may stop parts of the site from working.

Sharing & sub-processors

We do not sell your personal data. We share it only with trusted service providers who help us run Denbot — such as cloud hosting, database, email delivery, and payment providers — under contracts that require them to protect it. We may also disclose data where required by law.

International transfers

Some of our providers may process data outside the UK. Where they do, we rely on appropriate safeguards such as UK adequacy regulations or the International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses.

Retention

We keep personal data only as long as needed for the purposes above, to meet legal obligations, or to resolve disputes. Patient enquiry data is retained according to the instructions of the practice that controls it.

Security

We use encryption in transit, access controls, and tenant isolation so that each practice's data is kept separate. No system is perfectly secure, but we work to protect your data and to notify the relevant parties promptly if a breach occurs.

Your rights

Under the UK GDPR you have the right to access, correct, delete, restrict, or object to our use of your personal data, and to data portability. To exercise these rights, email privacy@denbot.co.uk. If your data was submitted to a specific dental practice, we will pass your request to that practice as the controller. You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk).

Changes

We may update this policy from time to time. Material changes will be reflected by the "last updated" date above.

Contact

North & Main Ltd — privacy@denbot.co.uk