Data Processing
How OpenDentist processes, stores, and protects patient data throughout the clinical note generation workflow.
Data Protection Impact Assessment (DPIA)
A comprehensive DPIA has been completed and is kept under ongoing review, covering all processing activities including audio capture, speech-to-text transcription, AI-assisted clinical note generation, and encrypted data storage.
The DPIA was approved by the Data Protection Officer and identifies risks and mitigations for processing special category health data using innovative AI technology. All identified risks have been mitigated to Low or Very Low residual risk levels.
Data Flow
Audio Capture
Consultation audio captured via lapel microphone, encrypted at source with TLS 1.3
Transcription
Speech-to-text conversion via encrypted API call to transcription provider (zero data retention)
AI Note Generation
Transcript processed by AI to produce structured clinical notes (zero data retention)
Clinician Review
Mandatory review, editing, and approval by the treating clinician before finalisation
Record Export
Approved clinical notes available for export to practice management system (PMS)
Lawful Basis for Processing
Data Retention
| Data Type | Retention Period |
|---|---|
| Approved clinical notes | 11 years (adults) / 25 years (children) |
| Consultation transcripts (default) | Same as clinical notes |
| Consultation transcripts (opt-out) | Deleted after 7 days |
| Audio recordings (default) | Deleted once transcript is processed |
| Audio recordings (clinician-elected) | 11 years (adults) / 25 years (children) |
| Audit logs | 12 months minimum |
| Billing records | 6 years |
Sub-processors
| Sub-processor | Function |
|---|---|
| AWS | Cloud hosting, database, and encrypted storage |
| Stripe | Payment processing and subscription management |
| Cloudflare | DDoS protection, WAF, and CDN |
| AI providers | Speech-to-text transcription and clinical note generation |
OpenDentist Notes