Privacy Policy
UK GDPR compliant — Brush Labs Limited
Who we are
Brush Labs Limited is the data controller for personal data processed via the Platform. Dental practices are independent controllers of clinical data.
Data we collect
Identity data
- Name
- Phone number
Booking data
- Appointment details
- Attendance
- Cancellations
Payment data
- Transaction metadata
- Payment tokens (no full card details)
Usage data
- Clicks
- Searches
- Engagement patterns
How we use data
We use data to operate the marketplace, process bookings and payments, prevent fraud, improve platform performance, and optimise ranking and availability.
Legal basis
We rely on contract performance, legitimate interests, and legal obligations.
Data sharing
We share data with dental practices, payment processors (e.g. Stripe Connect), and service providers (hosting, analytics). We do not sell personal data.
Clinical data
We do not access or process clinical records held by dental practices.
Payments
Payments are processed via third-party providers. Brush does not store full card details.
Automated decision-making
We use automated systems for ranking, matching, and allocation. No clinical decisions are automated.
Data retention
- Account data: retained while active
- Booking data: retained per legal/operational requirements
- Anonymised data: retained for analytics
Your rights (GDPR)
You have the right to access, correction, deletion, restriction, portability, and objection.
Security
We use encryption, secure infrastructure, and controlled access.
International transfers
Only via compliant mechanisms (e.g. standard contractual clauses).
Contact
You can contact us regarding data protection at data@trybrush.com.