Privacy Policy

Effective date: 31 July 2026

Last reviewed: 31 July 2026

1. Who we are

Dentistry.co.uk is operated by Finlayson Media Communications Limited (“FMC”, “we”, “us” or “our”). FMC is the controller of the personal data described in this notice except where we expressly say that we act as a processor for another organisation.

Our registered address is 1 Hertford House, Farm Close, Shenley, Hertfordshire, WD7 9AB. Our ICO registration number is Z7492221. Our Data Protection Officer is Laurie Glover. You can contact the Data Protection Officer at [email protected] or at the postal address above.

This notice applies to Dentistry.co.uk and its subdomains, Dentistry Account, our media, publications, events, awards, webinars, surveys, competitions and the FMC products and services that link to this notice.

2. When another organisation is the controller

In some services, FMC processes personal data on another organisation’s instructions:

  • for a commissioned webinar, the client named on the registration page is normally the controller of registration and attendance data and FMC acts as its processor;
  • dental practices and other customer organisations are controllers of patient, workforce, compliance and assigned-learning data that they place in Dentistry Consent, Dentistry HR, Dentistry Compliance or a managed Dentistry CPD service; and
  • where Xcelerator Dental provides client-owned marketing services, the relevant client controls the data held in its own account and Xcelerator Dental acts on its instructions.

In those circumstances, the relevant controller’s privacy notice explains its purposes and lawful basis. FMC may still act as an independent controller for limited purposes such as platform security, preventing fraud or misuse, maintaining operational records, administering our own contracts and meeting legal obligations.

3. Personal data we collect

Depending on how you interact with us, we may collect:

  • identity and contact data, including name, postal address, email address and telephone number;
  • professional data, including employer or practice, job title, profession, GDC number, professional interests and areas of practice;
  • account and subscription data, including login identifiers, account status, licence entitlements, purchases, subscriptions and communication preferences;
  • learning data, including course activity, test results, progress and CPD certificates;
  • event, webinar and awards data, including registration, attendance, engagement, networking profile, entries, nominations, judging information, guest details and dietary or accessibility requirements;
  • survey, competition and research data, including responses, preferences, entry information and prize-draw details;
  • sales and support data, including enquiries, meetings, correspondence, deal information, tickets, complaints and call or meeting records;
  • payment and transaction data, including billing details, transaction references and subscription history. Full payment-card details are processed by our payment provider and are not retained by FMC;
  • website and device data, including IP address, browser, device, session, navigation, referral, analytics, advertising and cookie-choice information;
  • editorial and media data, including contributor details, biographies, correspondence, photographs, audio, video and approved published material; and
  • information contained in documents, prompts or communications that authorised staff process using approved business technology, including approved business AI services, where this is necessary for the underlying business purpose.

We do not intentionally ask people to provide special-category data through ordinary account, marketing or enquiry forms. Some activities, such as accessibility arrangements, occupational matters, patient-consent services or customer support, may involve health or other sensitive information. We minimise this information and apply additional access restrictions where it is required.

4. Where the data comes from

We collect personal data:

  • directly from you through forms, accounts, purchases, registrations, surveys, competitions, correspondence and attendance;
  • from your employer, practice, licence owner or another organisation that registers you for or provides access to a service;
  • from clients that commission events, webinars, research, advertising or other services;
  • from payment, account, analytics and communication services used to administer your relationship with us;
  • from professional or public sources where it is reasonable and lawful to use the information for editorial, research or business-to-business activity; and
  • from your use of our websites, emails, products and services.

Where we obtain your data from another source, we use it only for the purposes described in this notice or in a more specific notice presented to you.

5. How and why we use personal data

5.1 Dentistry Account, subscriptions and products

We use account, contact, professional, subscription and interaction data to create and secure your Dentistry Account, authenticate you, administer licences and subscriptions, give you access to products, provide customer service, process payments and maintain business records.

Our lawful bases are performance of a contract or taking steps at your request before a contract, our legitimate interests in operating secure and effective services, and legal obligations relating to finance, taxation and record-keeping.

Dentistry Account and entitlement data is shared between the services you choose to use through our Wayfinder identity and licence platform. Subscription and account information may also be received from Stripe and processed in our CRM and data warehouse for administration, reconciliation and reporting.

5.2 Dentistry CPD

For direct individual Dentistry CPD users, FMC is the controller and uses identity, professional, subscription, course, assessment and certificate data to provide the learning service and maintain professional-development records. CPD certificates are retained indefinitely so that the learner can review them and provide them to the General Dental Council or another professional body where required.

Where a practice or enterprise selects learners and assigns training, it is the controller for that assigned-learning activity and FMC acts as processor. The enterprise administrator may view assigned progress and completion while its licence is active. When the licence ends, the enterprise administrator loses access, but the individual learner retains access to their certificates.

5.3 Sales, meetings, customer support and complaints

We use contact, account, meeting, deal, ticket, correspondence and complaint information to respond to enquiries, arrange requested meetings, discuss proposed contracts, administer customer relationships, resolve issues and establish or defend legal claims.

Our lawful bases are steps requested before a contract, performance of a contract, legal obligations and our legitimate interests in managing customer relationships and resolving service issues. If you ask to communicate with us through WhatsApp Business, we may use it through HubSpot for the requested pre-contractual or customer discussion.

Some product demonstrations and business meetings may be recorded for staff training, quality assurance and accurate follow-up. We tell participants before recording. Participants may keep their camera off and should not disclose identifiable patient information or confidential third-party material. We do not publish recordings or use identifiable participants for promotion without separate permission.

5.4 Publications, editorial and contributors

We use contributor, speaker, interviewee and professional-contact information to commission, edit, verify, publish, archive and promote editorial and media content. Our lawful bases are contract, our legitimate interests in professional publishing and freedom of expression, and consent where it is the appropriate basis for a particular use.

Approved published editorial material forms part of our permanent digital archive and may be retained indefinitely. We consider correction, objection and takedown requests in light of data protection law, freedom of expression, journalism and the public interest.

5.5 Events and networking

We use registration, profile, attendance, networking, communication and logistics data to administer events, issue joining information, operate event apps, support networking and matchmaking, manage speakers and sponsors, check attendance and provide event services.

Our lawful bases are performance of a contract or requested registration, and our legitimate interests in running relevant professional events. Where we request dietary, accessibility or other sensitive information, we ask only for what is needed and use consent or another appropriate condition for that information.

Event and networking providers may include Grip, venues, caterers and authorised event suppliers. Where sponsor or exhibitor access to personal data is offered, this will be explained at the point of registration or collection.

5.6 Webinars

For commissioned webinars, the client named on the registration page is normally the controller of the registration and attendance data. FMC acts as its processor to authenticate users, deliver the webinar and report registration and attendance. FMC acts as an independent controller only for limited security, fraud-prevention, operational-log and legal-compliance purposes.

The registration page explains the controller and the data disclosure. Please read the Dentistry.co.uk Webinar Terms & Conditions and the named client’s privacy notice before registering.

5.7 Awards

We use entry, nomination, judging, professional, payment and guest data to administer awards, verify eligibility, manage judging, communicate with entrants and judges, publish approved finalist and winner information and run awards ceremonies. Our lawful bases are contract and our legitimate interests in operating fair and effective awards programmes. We use consent where it is specifically required, including for some optional promotional uses.

Evessio is used to administer entries and judging. Full entries, scores and feedback are restricted to the awards team and authorised judges. We do not use AI to judge entries or produce judging feedback.

5.8 Surveys, competitions and research

We use contact, response and entry information to invite participation, run surveys, analyse responses, administer competitions or prize draws and contact winners. Most surveys invite the participant to provide an email address at the end if they wish to enter a prize draw. Providing an email address for a prize draw is optional unless the specific survey says otherwise.

Our lawful bases depend on the activity and may be consent, performance of the promotion terms or our legitimate interests in conducting proportionate audience and customer research. SurveyMonkey and authorised research or fulfilment suppliers may process this information for us. A specific survey or competition may provide additional information about its sponsor, recipients or purposes.

5.9 Marketing and communication preferences

We use contact, professional, preference, source, engagement and suppression information to send relevant industry news, clinical articles, publications, webinars, events, awards, product information and selected partner updates.

Depending on the recipient, channel and relationship, we rely on consent, the electronic-mail soft opt-in or our legitimate interests where those bases are permitted by data protection law and the Privacy and Electronic Communications Regulations. Consent choices are unticked by default. You can unsubscribe at any time through the link in an email, reply with the stated stop instruction where available or contact us. We retain suppression information so that we can respect your choice.

We use Wayfinder, Mailchimp and HubSpot to manage relevant preferences and communications. We may also use TextMagic for SMS, Stannp for post and HubSpot for requested WhatsApp Business conversations. We do not sell unrestricted access to our contact database. Where a named partner will receive your identifiable information as a controller, such as for a commissioned webinar or disclosed lead-generation activity, this is explained when you register or submit the information.

5.10 Audience matching and advertising

We use website activity and selected contact identifiers to measure advertising and create relevant audiences. With consent, advertising pixels and cookies may be used as described below. Separately, FMC may upload email-address lists from its controlled data warehouse to Meta to create, exclude or develop related and lookalike audiences for campaigns delivered through FMC-owned Meta business and advertising accounts.

FMC selects the targeting and may run campaigns for FMC services or for media clients using FMC’s Dentistry pages and advertising accounts. Media clients do not receive or access FMC’s underlying contact list or Custom Audience membership. Meta processes the matched identifiers under its applicable business and Custom Audience terms. Upload files are removed from user devices after transfer.

The lawful basis for proportionate customer-list audience matching is FMC’s legitimate interests in advertising relevant services and measuring campaigns. You have the right to object to this use at any time by contacting [email protected].

5.11 Website operation, analytics and cookies

We use necessary cookies and technical information to provide, protect and balance the website and account services you request. With your consent, we use analytics, advertising and similar technologies to understand use, measure campaigns and improve relevance.

Our cookie banner is provided through Cookie-Script. It offers Accept all and Reject all choices for non-essential technologies. Non-essential analytics, advertising and other tracking technologies are blocked before consent and after Reject all. You can revisit your choice at any time through Change cookies settings in the website footer.

The principal technologies currently include:

  • Necessary and preference technologies: the CookieScriptConsent cookie, normally retained for 30 days; account, security, WordPress and Cloudflare cookies where required; dentistry_internal_source for up to two days; and a short-lived pop-up preference;
  • Google Analytics 4: `_ga` and related cookies may remain for up to two years, while GA4 user and event data is configured for a 14-month retention period;
  • Hotjar: returning-visitor information may remain for up to 365 days and session information for around 30 minutes;
  • Google advertising services: click and conversion identifiers are generally retained for up to 90 days, with some advertising-delivery cookies retained for up to 13 months;
  • Meta Pixel: `_fbp` is generally retained for 90 days;
  • LinkedIn Insight Tag: consent, routing and advertising-measurement cookies have periods ranging from 24 hours to six months; and
  • Embedded forms and services: HubSpot, Mailchimp, Calendly, video, webinar and social-media services may set cookies when their features are displayed or used, subject to the available consent controls.

Consent-aware Google services may receive limited consent status and technical signals for aggregate measurement even when advertising storage is refused. Cookie names and periods can change as providers update their services. The banner and this notice describe the principal technologies rather than every short-lived technical cookie.

5.12 Payments and financial records

We use identity, contact, billing, subscription and transaction information to take payments, issue invoices, process refunds, reconcile accounts, prevent fraud and comply with tax and accounting obligations. Our lawful bases are contract, legal obligation and our legitimate interests in secure financial administration.

Stripe processes full payment-card details and fraud checks. FMC receives transaction references and related account information rather than retaining full card details.

5.13 Approved AI and productivity services

Authorised staff may use approved business versions of OpenAI and Anthropic services, together with approved connected business tools, to search, summarise, draft, analyse and support work. Any personal data processed in this way must be necessary for an existing approved business purpose; AI use does not create a new lawful basis.

We require data minimisation, authorised business accounts, role-based access, human review and compliance with our AI at Work Policy. We do not use these tools to make solely automated decisions about individuals that produce legal or similarly significant effects.

6. Who we share personal data with

Depending on the service, recipients may include:

  • the customer, employer, practice, licence owner, webinar client or other organisation that is the controller of the relevant activity;
  • authorised FMC and group-company staff who need the information for their role;
  • website, cloud hosting, identity, CRM, customer-support, communications, analytics, advertising, event, webinar, awards, survey, payment, finance, printing and professional-service providers;
  • speakers, judges, venues, caterers, exhibitors, sponsors and fulfilment providers where necessary and disclosed for the activity;
  • printers Walstead Roche and Buxton Press, which receive name and postal-address mailing files through secure file transfer for magazine fulfilment and delete those files one month after use;
  • regulators, courts, law enforcement, professional advisers, auditors and public authorities where disclosure is required or reasonably necessary; and
  • a purchaser, investor or adviser involved in an actual or proposed corporate transaction, subject to appropriate confidentiality and data-protection safeguards.

Our principal technology providers include Microsoft, AWS, Google Cloud, Stripe, HubSpot, Mailchimp, Meta, Cookie-Script, SurveyMonkey, Grip, Evessio, PandaDoc, Jira/Atlassian, OpenAI and Anthropic. The provider used depends on the service and changes from time to time.

Service providers may use personal data only to provide their contracted service, meet legal obligations and protect their service as allowed by the applicable agreement. A separately identified controller, such as a webinar client, processes the information under its own notice and lawful basis.

7. International transfers

FMC uses UK, European Economic Area and international service providers. This means personal data may be accessed or stored outside the UK, including in the United States and other countries in which a provider or its approved subprocessors operate.

Where UK personal data is subject to a restricted international transfer, we use an applicable UK adequacy regulation or contractual safeguards such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses or other safeguards permitted by UK data protection law. We also assess and manage supplier and transfer risks as appropriate.

You can ask the Data Protection Officer for more information about the safeguard relevant to a particular service and how to obtain a copy.

8. How long we keep personal data

We retain personal data only for as long as needed for the purpose, legal and regulatory obligations, the establishment or defence of claims and the protection of our systems. Key current periods include:

  • Dentistry Account operational data: while the relationship is active; warehouse copies are normally deleted or anonymised two years after the relationship ends, and daily warehouse snapshots after one year;
  • CPD certificates: indefinitely for the individual learner’s professional record;
  • event and networking records: one year after the event;
  • under FMC’s standard webinar arrangement, FMC’s copy of registration, attendance and reporting data, and the named client’s webinar lead data supplied through that arrangement: one year after the webinar, subject to any justified webinar-specific period or legal hold;
  • awards entries, scores and feedback: two years after the relevant awards cycle;
  • identifiable survey responses and prize-draw email addresses: two years;
  • routine closed support tickets: two years; formal complaints and material disputes: six years; spam, test and duplicate tickets: 90 days;
  • financial, tax, invoice and accounting records: at least six years;
  • GA4 user and event data: 14 months; cookie-consent logs: while relied upon and for two years after withdrawal or replacement;
  • postal marketing supplier files: one year; print-fulfilment mailing files held by printers: one month after use;
  • Meta Custom Audiences: one year after the relevant campaign;
  • sales deal and requested WhatsApp conversation records: one year after the deal closes;
  • approved published editorial material: indefinitely as part of the website archive; and
  • marketing suppression records: for as long as needed to respect the objection or withdrawal.

Some records may be retained longer where required by law, professional obligations, dispute handling or a legal hold. Where FMC acts only as processor, the customer controller determines the applicable period through its instructions and service configuration.

9. Profiling and automated decisions

We use engagement, account, professional-interest and website information to segment audiences, measure campaigns and make communications more relevant. This is profiling, but FMC does not use it to make solely automated decisions that have legal or similarly significant effects on you.

You may object to profiling carried out for direct marketing at any time.

10. Security

We use proportionate technical and organisational measures including access controls, authentication, encryption, supplier contracts, staff confidentiality, backups, monitoring and role-based restrictions. No internet or information system is completely secure, but we review risks and controls and require our processors to protect the information they handle for us.

11. Your rights

Depending on the processing and lawful basis, you may have the right to:

  • request access to your personal data and supplementary information;
  • ask us to correct inaccurate or incomplete data;
  • request erasure in applicable circumstances;
  • request restriction of processing;
  • receive certain data in a portable format;
  • object to processing based on legitimate interests;
  • object at any time to direct marketing, including related profiling;
  • withdraw consent at any time where processing relies on consent, without affecting earlier lawful processing; and
  • complain to the Information Commissioner’s Office.

There is normally no fee for exercising a data protection right. We may ask for information needed to verify identity and understand the request. Some rights are subject to exemptions and do not apply in every circumstance.

Your right to object to direct marketing is unconditional. Contact us or use the unsubscribe or stop mechanism in the communication and we will stop that marketing channel, subject to retaining minimum suppression data.

Where another organisation is the controller, we may refer the request to that controller and assist it as required.

12. Complaints

Please contact our Data Protection Officer first so that we can investigate and try to resolve your concern.

You also have the right to complain to the Information Commissioner’s Office:

  • Website: ico.org.uk/make-a-complaint
  • Telephone: 0303 123 1113
  • Address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

13. Changes to this notice

We review this notice at least annually and when a material processing activity, supplier, integration or legal requirement changes. We will update the effective date and provide a more prominent notice where a change would materially affect individuals.

Appendix: Dentistry Club subscription terms retained from the previous page

The following provisions apply where you purchase Dentistry Club Silver or Dentistry Club Gold:

  • subscriptions renew automatically for subsequent billing periods at the agreed charge until cancelled by either party;
  • by providing payment information, you authorise the agreed renewal charge to the same payment method unless you update it;
  • any renewal-price change will be communicated in advance, with an opportunity to cancel before renewal;
  • a renewal reminder will provide the renewal date, amount and cancellation instructions;
  • cancellation must be requested before the renewal date to avoid the next renewal charge;
  • renewal charges are non-refundable unless otherwise stated or required by law;
  • you are responsible for keeping payment details accurate and current; and
  • FMC may suspend or terminate a subscription for breach of the applicable terms or misuse of the service.
Register for webinar

Stay updated with relevant information about this webinar

Share
Add to calendar