Data Processing

How OpenDentist processes, stores, and protects patient data throughout the clinical note generation workflow.

Data Protection Impact Assessment (DPIA)

A comprehensive DPIA has been completed and is kept under ongoing review, covering all processing activities including audio capture, speech-to-text transcription, AI-assisted clinical note generation, and encrypted data storage.

The DPIA was approved by the Data Protection Officer and identifies risks and mitigations for processing special category health data using innovative AI technology. All identified risks have been mitigated to Low or Very Low residual risk levels.

Data Flow

1

Audio Capture

Consultation audio captured via lapel microphone, encrypted at source with TLS 1.3

2

Transcription

Speech-to-text conversion via encrypted API call to transcription provider (zero data retention)

3

AI Note Generation

Transcript processed by AI to produce structured clinical notes (zero data retention)

4

Clinician Review

Mandatory review, editing, and approval by the treating clinician before finalisation

5

Record Export

Approved clinical notes available for export to practice management system (PMS)

Note: Audio recordings are automatically deleted as soon as the transcript has been processed. Audio is not permanently retained unless the clinician explicitly elects to keep it in their account settings.

Lawful Basis for Processing

Art 6(1)(e)Public interest — processing necessary for the provision of healthcare
Art 9(2)(h)Healthcare provision — processing of special category health data with appropriate safeguards
The dental practice acts as the Data Controller. OpenDentist acts as a Data Processor under a signed Data Processing Agreement (DPA).

Data Retention

Data TypeRetention Period
Approved clinical notes11 years (adults) / 25 years (children)
Consultation transcripts (default)Same as clinical notes
Consultation transcripts (opt-out)Deleted after 7 days
Audio recordings (default)Deleted once transcript is processed
Audio recordings (clinician-elected)11 years (adults) / 25 years (children)
Audit logs12 months minimum
Billing records6 years

Sub-processors

Sub-processorFunction
AWSCloud hosting, database, and encrypted storage
StripePayment processing and subscription management
CloudflareDDoS protection, WAF, and CDN
AI providersSpeech-to-text transcription and clinical note generation
Full sub-processor list including AI provider details is available on request under NDA. All sub-processors are governed by signed Data Processing Agreements. Contact us.

International Data Transfers

All patient health data is stored within the United Kingdom (AWS eu-west-2, London)
AI processing involves encrypted API calls to providers under UK International Data Transfer Agreements (IDTA) or UK Addendum to EU Standard Contractual Clauses (SCCs)
Zero data retention agreements mean no patient data is stored outside the UK by any AI provider
Full details of international data transfer safeguards are available on request under NDA. Contact us.