Privacy Notice
Last updated: 4 September 2026
This notice explains what personal information Dental Treatment Abroad collects when you use our website and enquiry form, why we use it, who we share it with and the rights you have over it. We have tried to keep it clear and jargon-free, because we know that sharing health information is a personal thing and you deserve to understand exactly what happens to it.
Dental Treatment Abroad is a UK-based patient-coordination and referral service. We are online only, with no premises, phone line or call centre; you can reach us by email during our business hours. We introduce and coordinate patients who are interested in dental treatment in Romania with one vetted partner dental clinic in Bucharest. We do not provide dental treatment ourselves and we do not form a dentist-patient relationship with you. Any clinical assessment, treatment and treatment contract is strictly between you and the clinic.
Who we are (the data controller)
Dental Treatment Abroad (“we”, “us”, “our”) is the controller of the personal data described in this notice. That means we decide what information is collected and how it is used, and we are responsible for looking after it.
You can contact us about anything in this notice, including to exercise your rights or to withdraw your consent, by email:
- Email: hello@dentaltreatmentabroad.co.uk
- Website: dentaltreatmentabroad.co.uk
- Business hours: Monday to Friday, 09:00 to 18:00 UK time
The personal data we collect
We only collect what we need to respond to your enquiry and to coordinate a treatment quote for you. When you complete our enquiry form, this may include:
- Contact details: your full name, email address and (optional) phone number.
- Enquiry details: the treatment you are interested in (for example implants, veneers, crowns, All-on-4 or full-mouth treatment) and any optional free-text message you choose to add.
- Dental and health information you choose to share: for example your dental history, symptoms or X-rays. This is entirely optional, but if you provide it, it helps the clinic prepare a more accurate quote and recommendation.
About your health information. Information about your health, including dental and medical details and any X-rays, is treated as “special category data” under UK data protection law (UK GDPR Article 9). The law gives it extra protection, and so do we. We only collect it if you choose to share it, and we only use it for the purpose you gave it to us for.
We do not knowingly collect information from anyone under 18. Our service is intended for adults arranging their own dental treatment.
Why we use your data and our lawful bases
The law requires us to have a valid “lawful basis” for using your personal data. Here is what we do and the basis we rely on:
| What we do | Why | Lawful basis |
|---|---|---|
| Respond to your enquiry and correspond with you using your contact details | So we can reply to you and coordinate your quote | Consent and/or our legitimate interests in responding to an enquiry you have initiated (UK GDPR Art. 6(1)(a) and/or 6(1)(f)) |
| Share your details with our partner clinic to prepare a treatment quote and recommendation | So the clinic can assess your enquiry and give you a quote | Consent (UK GDPR Art. 6(1)(a)) |
| Use any dental/health information you provide, and share it with the partner clinic | So the clinic can prepare an accurate quote and recommendation | Your explicit consent for special-category (health) data (UK GDPR Art. 9(2)(a)), alongside our Article 6 basis above |
The consent you give. When you submit the form, you tick an unbundled, opt-in box (it is switched off by default) that says:
“I consent to Dental Treatment Abroad sharing the dental and contact details I enter here with one partner clinic in Bucharest, Romania so it can prepare a treatment quote and recommendation, and to Dental Treatment Abroad using these details to reply to me.”
You do not have to consent, and you can change your mind at any time (see Your rights below). Getting a quote is free and there is no obligation to proceed.
Who we share your data with
We share your data with only one external recipient in connection with your enquiry: our single vetted partner dental clinic in Bucharest, Romania. We pass on the details you have entered so the clinic can prepare a treatment quote and recommendation, and we relay the clinic’s response back to you.
The partner clinic is an independent, Romanian-registered dental practice (registered with the Romanian College of Dental Surgeons). The clinic states that it complies with EU Medical Device Regulation (MDR) 2017/745. That is the clinic’s own statement about its own compliance and not a guarantee given by Dental Treatment Abroad. The clinic is a separate controller of the data once it receives it for the purpose of assessing and treating you, and its own privacy terms will apply to the treatment relationship between you and the clinic.
We also use a small number of trusted service providers (“processors”) to run our website and service. They only act on our instructions and only handle your data to provide their service to us:
- Website hosting: our website is hosted by Hostinger, under its data-processing terms.
- Enquiry storage: your enquiry is stored in the website’s WordPress database, hosted by Hostinger under the same terms, within the site’s private admin area.
- Email delivery: enquiry emails are delivered to our inbox through Hostinger’s mail service.
- Consent management and website measurement: Complianz records your cookie choices. If you grant Statistics consent, Google Analytics, PostHog and the standalone Microsoft Clarity project process limited website-use measurement for us. Clarity provides masked heatmaps and session playback. If you grant Marketing consent, Meta Pixel and Microsoft UET process campaign and interaction measurement. Clarity is disabled inside the UET tag. Google Ads conversion measurement remains inactive until verified Dental Treatment Abroad identifiers are configured.
Website analytics and consent
Google Analytics, PostHog and the standalone Microsoft Clarity project do not load unless you grant Statistics consent through the cookie banner. You can refuse or withdraw that consent without affecting the website or your ability to send an enquiry.
Google Analytics measures aggregate page use, consented contact interactions and the website’s verified enquiry-success event. PostHog receives only six allowlisted event names: page_view, cta_click, form_start, generate_lead, form_error and whatsapp_click, with broad categorical labels such as page group and CTA type. PostHog autocapture, session replay and IP capture are disabled. Standard analytics is memory-only; the optional 30-day internal-analysis identifier requires a separate choice.
We do not send names, email addresses, phone numbers, form answers, treatment choices, free-text messages, X-rays or other health information in our custom events to Google Analytics, PostHog, Google Ads, Meta or Microsoft. The site masks the whole page and every form field before the standalone Clarity project loads, and our custom events contain only an allowlisted event name without values or full URLs. Clarity is disabled inside Microsoft UET. The enquiry form’s separate health-data consent is not consent for analytics.
We never sell your data. We do not, and will not, sell your personal data or share it for anyone else’s marketing. Apart from the partner clinic and the service providers listed above, we do not share your data with any other organisation unless we are required to do so by law.
Sending your data to Romania (international transfer)
To prepare your quote, your data is sent from the UK to the partner clinic in Romania. Romania is in the EU/EEA. The UK treats the EEA as providing an adequate level of data protection, so no additional transfer safeguards are required for this transfer.
PostHog is configured to use its EU service. Google may process consented analytics data outside the UK. Where that happens, Google relies on the transfer safeguards described in its data-processing terms. No enquiry content or health information is included in these analytics events.
How long we keep your data
We keep your data only for as long as we need it for the purposes described above, and then we securely delete it.
- If you enquire but do not proceed: we keep your enquiry (including any health information) for 12 months from your last contact, so we can deal with any follow-up, after which it is deleted.
- If you proceed to treatment via the partner clinic: we keep a record of the coordination for up to 6 years, to cover any legal, insurance or complaint matters, after which it is deleted.
- If you withdraw your consent: we stop using your data and delete it from our active systems, unless we are legally required to keep a limited record.
Your rights
Under UK data protection law you have the following rights over your personal data:
- The right to be informed: this notice is part of how we do that.
- The right of access: you can ask for a copy of the data we hold about you.
- The right to rectification: you can ask us to correct data that is wrong or incomplete.
- The right to erasure: you can ask us to delete your data (“the right to be forgotten”).
- The right to restrict processing: you can ask us to pause how we use your data.
- The right to object: you can object to us using your data where we rely on legitimate interests.
- The right to data portability: you can ask for the data you gave us in a portable format.
- The right to withdraw consent at any time: where we rely on your consent (including your explicit consent for health information), you can withdraw it whenever you like. Simply email hello@dentaltreatmentabroad.co.uk. Withdrawing consent does not affect anything we lawfully did before you withdrew it, and it will not affect any separate relationship you have with the clinic.
To exercise any of these rights, email us at hello@dentaltreatmentabroad.co.uk. We will respond within one month. Using these rights is normally free, although we may charge a reasonable fee or decline a request if it is clearly unfounded or excessive, as the law allows.
Complaining to the regulator. If you are unhappy with how we have handled your data, we would like the chance to put it right, so please contact us first. You also have the right to complain to the UK’s data protection regulator, the Information Commissioner’s Office (ICO), at any time. You can find out how at ico.org.uk.
How we keep your data secure
We take the security of your information seriously, especially your health information. Enquiries are stored privately within our website’s WordPress admin area and are emailed to our inbox; access is limited to those who need it to run the service. In practice, our measures include serving the whole website over an encrypted HTTPS/TLS connection with HTTP Strict Transport Security enforced, running a web application firewall and malware scanning on the site, applying browser security headers, restricting and protecting administrator access, and keeping the software and its components updated. On a normal visit the site sets no cookies until you interact with the cookie notice.
No method of transmission or storage is ever completely secure, but we work to protect your data and to keep our measures under review.
Cookies
Our website uses strictly necessary cookies for WordPress, page caching and consent choices. If you grant Statistics consent, Google Analytics may set analytics cookies, PostHog may send limited events using page memory, with a 30-day browser identifier only after separate internal-analysis consent, and the standalone Microsoft Clarity project may provide masked heatmaps and session playback. If you grant Marketing consent, Microsoft UET may measure page visits and a server-verified enquiry-success conversion, while Meta Pixel may measure PageView and server-verified Lead events. Clarity is disabled inside the UET tag. Google Ads conversion measurement is not currently active. A fresh Reject requests none of these non-essential loaders. We do not send form content, contact details, treatment information or health information in our custom events to these providers. Google enhanced conversions, user-provided data collection and ad personalisation are disabled. Meta automatic matching and automatic event detection are also disabled. For full details and controls, please see our Cookie Policy.
Changes to this notice
We may update this notice from time to time, for example if our service or the law changes. When we do, we will change the “Last updated” date at the top. Where changes are significant, we will take reasonable steps to make them clear.
Governing law
This notice, and any matter relating to how we handle your data, is governed by the law of England and Wales.
Optional PostHog internal analysis
Updated 15 September 2026. Statistics consent alone does not enable this option. If you separately select internal journey analysis and save your choice, we use a random browser identifier on this website to count repeat activity, broad interactions and a form start followed by an observed successful submission within 24 hours. This is internal website analysis, not advertising targeting or evidence of a booking. Refusing it does not affect your enquiry.
The local-storage entries seo_control_ph_journey_choice_v1 and seo_control_ph_journey_id_v1 expire 30 days after your explicit choice. Normal visits do not extend them. Each website has its own identifier; we do not match you across our websites or devices. Linked events use only broad home, contact, legal or other-content categories and fixed interaction/form labels, without names, contact details, exact URLs, treatment choices, message contents or files. PostHog EU Cloud processes these events in Frankfurt. Replay, automatic capture, person profiles and advertising exports are disabled.
We analyse a rolling period of up to 12 months. Browser expiry or withdrawal stops future linkage and clears the local identifier; it does not delete earlier server events. PostHog documents one year of event storage on Free plans and seven years on paid plans, with deletion enforcement rolling out separately. Our project settings do not expose their event-retention or enforcement values, so we cannot promise automatic deletion at one year. See PostHog event retention.
To withdraw, reopen Cookie settings or Manage cookies, untick internal journey analysis and save; rejecting Statistics also withdraws it. To request access or deletion, use the privacy contact shown in this policy and mention PostHog internal analysis. We will assess the request and coordinate with PostHog where needed; we may be unable to locate anonymous events once their random browser identifier is no longer available. Withdrawal is not a completed server-erasure request. Do not send dental records or other health information for an analytics request.
ChatGPT Ads conversion measurement
Updated 7 September 2026. With your Marketing consent, this website can send OpenAI the fact that a WhatsApp or email button was clicked. A click does not mean a message was sent or an enquiry was received. Measurement is separate from the information you choose to send us.
Our server sends only the generic click-event name, a random event identifier, the event time, this website’s home address and, when available after consent, the OpenAI ad-click reference. We do not send form contents, names, email addresses, phone numbers, uploaded files, health information, treatment-page addresses, page titles, referrers or your browser IP address or user agent. The OpenAI browser SDK and automatic customer-data matching are not used. Each event is opted out of future user-level personalisation.
If an OpenAI ad-click reference is available after consent, the first-party pfa_cg_oppref cookie can retain it for up to 30 days for attribution. It is removed when Marketing consent is withdrawn. We retain aggregate delivery counters and the latest delivery time/status, plus short-lived local duplicate-prevention and abuse-control records; no enquiry or customer record is attached. OpenAI processes received conversion events under its applicable privacy terms, including any international processing described there.
Use the website’s cookie controls to decline or withdraw Marketing consent. The website, email, WhatsApp links and enquiry form still work. No pre-consent clicks are replayed. See OpenAI’s privacy policy for its data handling and rights information.