What we hold, and what we never touch.
Written plainly by the founder rather than assembled from a template. It is short because we hold very little.
This notice is a draft. It is being checked by a solicitor before we take a first paying customer, and the processor names below are placeholders to confirm. Please do not treat it as final or as legal advice. If anything here matters to a decision you are making, ask us and we will tell you exactly where it stands.
Who we are
Practice Radar Limited is the data controller for the information described on this page. It is a company registered in England and Wales, company number 17476616, with its registered office at Chester House, Lloyd Drive, Ellesmere Port, CH65 9HQ. Write to us at hello@practiceradar.co.uk about anything on this page.
What we hold
Three kinds of information, and nothing else.
Your business contact details
- Your name, work email address and the name of your practice or agency
- The town or postcode of the market you asked us to map, and your website address
- Account data: your email address, a hashed password, and session records so you stay logged in
- Any message you send us, and a note of what we replied. The message itself is kept as an ordinary business record until you ask us to delete it; the IP address and referring page recorded with it are removed automatically after 12 months
- A mobile number, only if you set up a phone alert yourself. It is used for that and nothing else, it is never used for marketing, and deleting the alert deletes it
- Billing details held by our payment processor, not by us
- If you connect your website, the connector's token for that site, used only to read page titles and descriptions and to apply the changes you approve
Public search data about your market
- Search result positions for terms in your area, the way a patient's search would show them
- Public business listings: names, addresses, categories, opening hours and directory entries
- Public review counts and star ratings for every practice in your market, and the text of those public reviews, including the reviewer name Google shows against them. This is what the Voice of the market page reads to tell you what patients across the town praise and punish. It is the same text anyone can read on Google; we hold a recent sample of it, we never publish it as ours, and we delete it on request. Ask us to remove a market and its review text goes with it.
- Public website measurements such as page speed and technical health
- Reports from your own advertising or analytics accounts, only where you have connected them yourself
A security record of how the service is used
- The IP address an action on an account arrives from, with the time and what happened. That covers signing up, logging in and the contact form, and equally changing a password, creating or revoking a share link or an API token, a billing event, and changes to your settings or connections. This is how we tell a person fumbling their password from somebody guessing at other people’s. Separately from this, the web server keeps an ordinary access log of every request it serves, including the IP address, browser and referring page, the way any web server does; it is used for diagnosing faults and abuse, is rotated as it fills rather than on a fixed clock, and is not linked to accounts or used for anything else
- These entries are kept for 12 months and then deleted automatically. Nothing in them is used for marketing, profiling or advertising, and none of it is shared
What we never hold
We hold no patient records of any kind. We do not connect to practice management systems, we do not receive appointment books, treatment records, clinical notes or patient contact details, and we do not want them. If you send us a file containing patient information by accident, tell us and we will delete it and confirm in writing.
One thing does need saying plainly, because it is the only personal data about members of the public that this product touches. We hold a recent sample of the public Google reviews written about the practices in your market, with the reviewer name Google displays. People sometimes mention their own treatment or health in a review. We did not solicit it, it is already published by Google for anyone to read, we use it only to summarise what patients across a town praise and punish, and we never republish it as our own. If you are a reviewer and would rather we did not hold your review, tell us and we will remove it and keep it out.
Our lawful basis under UK GDPR
- Contract for running your account, building and refreshing your market map, and sending the reports your plan includes
- Legitimate interests for collecting public search data about businesses in your market, which is business information already visible to anyone searching, and for keeping the service secure. We have weighed this against the interests of the practices concerned and consider the impact minimal
- Consent for connecting your advertising or analytics accounts, and for any marketing email. You can withdraw either at any time
- Legal obligation for keeping accounting and tax records
Who processes data for us
Where a service below processes personal data on our behalf, a data processing agreement is in place or being put in place before launch. The public utilities on the list (postcodes.io, PageSpeed, Stadia Maps, the NHS and CQC registers, IndexNow) receive no personal data beyond what the entry says, and offer no agreements to sign; naming them here is the disclosure.
- Google Analytics
- Counts visits to this marketing site in cookieless mode. Receives the page viewed and an approximate region. Stores nothing on your device and cannot recognise you across visits. Not used anywhere inside the dashboard.
- Google Ads
- Only if you arrived from one of our own adverts. Google puts a click reference in the link it sends you with; if you then start a free month, that reference is kept with your signup and we tell Google Ads that the click led to a signup and, later, to a confirmed email. No cookie or pixel is involved, and it tells Google nothing about you that the click did not already carry.
- DataForSEO
- Supplies the public search results and listing data behind your market map. Receives search terms and locations. Receives no personal data about you or your patients. Transfer safeguards to confirm.
- Hosting provider
- Placeholder, to confirm. Runs the server holding the application and its database. A UK region is our intention.
- Mailgun
- Sends account email, the weekly digest and the monthly brief, through its EU region. Receives your name, your email address and the contents of those messages.
- Twilio
- Sends phone alerts by SMS, and only if you set one up. Receives the mobile number you entered and the text of the alert, which names the market and what moved. Receives nothing else about you or your patients. Transfer safeguards to confirm.
- Meta
- Sends phone alerts by WhatsApp, where that is the channel you chose. Receives the same two things Twilio does: the mobile number and the text of the alert. Transfer safeguards to confirm.
- postcodes.io
- Turns the postcode you type on the signup form into a town, so we know which market to build. Receives the postcode and nothing else.
- Google PageSpeed Insights
- Measures the speed and technical health of your website. Receives your website address, and no personal data.
- Stadia Maps
- Supplies the map images your market map, rank grid and CQC map are drawn on, built from OpenStreetMap data. Receives the map area requested, and no personal data.
- NHS Organisation Data Service, NHS Service Search and NHS Business Services Authority
- The NHS's public registers of practices, their opening times, which patients they are accepting and their published NHS contract activity. We look practices up by postcode or NHS code; they receive nothing about you.
- Care Quality Commission
- CQC's public register of inspections, read so the CQC page can show what was reported for each practice. We look practices up by council and location; it receives nothing about you.
- Companies House
- The public register of companies, read to show who owns the dental practices in your area. We look companies up by number; it receives nothing about you.
- IndexNow
- When an approved change goes live on your website, tells Bing and other search engines which page changed. Receives the page address, and no personal data.
- Anthropic
- Writes the parts of the product that are written rather than counted: the monthly brief, the review reply assistant, the Voice of the market read of public review text, the copy audit's rewrites, drafted page briefs and Google Business Profile post drafts. Receives the public review text and the market findings being written about, and the practice's own page copy where the copy audit is used. Receives no patient data. Anthropic does not train on it.
- Stripe
- Takes payments and holds your card details. Receives your email address and which plan you are buying. We never see or store a full card number.
How long we keep it
We keep your account data while you are a customer, and after you leave we keep it so that a returning practice does not start from nothing. We do not yet delete it automatically on a timer: today an account is erased when you ask us to, by writing to the address at the top of this page, and we do that by hand within 30 days. We would rather say that plainly than describe an automatic deletion that does not happen. Market data is kept as history because the history is the point of the product. Accounting records are kept for six years as the law requires.
Ask us to delete your data and we will do it within 30 days, and confirm in writing when it is done. That deletion covers your account, your contact details, your market history and the security record described above.
Your rights
Under UK GDPR you can ask us for a copy of the data we hold about you, ask us to correct it, ask us to delete it, ask for it in a portable format, or object to our processing it. Ask by email and we will answer within one month at the latest. There is no charge.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk, and we would rather you told us first so we can put it right.
Cookies
The pages you can read without an account set no tracking cookie of any kind: no advertising pixel, nothing that can recognise you on a later visit. The one thing they keep in your browser is a note, in its local storage, that you closed the founding-rate banner, so it stays closed; it holds the single value "1", is never sent to us, and you can clear it with your browser's site data. We do count visits, using Google Analytics in its cookieless mode, which records that a page was viewed and roughly which region from, and cannot store an identifier on your machine. The exceptions are all the same cookie: any page carrying a form you can submit without being logged in (the trial signup form, the login page, a set-password or invitation link) sets d4s_csrf, which exists only to prove the form you submit is the form we sent you. It carries no identity, expires after two hours, and is the kind of strictly necessary cookie that needs no consent. Nothing here is used for advertising or shared with anyone, with the one exception under Google Ads above: a click reference from our own adverts, carried in the link rather than in a cookie. The client dashboard at /app sets one cookie once you log in, d4s_session, which is what keeps you signed in; the d4s_csrf cookie above is deleted at that point, because inside the dashboard the same protection is held against your session record on our server rather than on your machine. Accounts that hold more than one market also get d4s_market, which remembers which market you were last looking at and nothing else. All of these are strictly necessary, so none needs a consent banner.
Security
Traffic is encrypted in transit. Passwords are stored as bcrypt hashes and never in readable form. Access to the server is limited to the founder. A backup is taken nightly and kept on the server: copies of the database for thirty days, the market readings for fourteen days, and the rest of the service's files for seven. Since 16 September a copy of each is also pulled down daily to a separate machine, off the server, and kept there for thirty days. Since 23 September 2026 every backup is encrypted before it is stored, in both places, and the key that opens them is not kept on the server, so a copy of the backups on its own cannot be read. The service itself runs without administrator rights on the server. If a breach ever affects your data we will tell you and the Information Commissioner's Office within 72 hours of becoming aware.
Changes to this notice
When this notice changes materially we will email account holders and update the date below. The version you are reading is a draft written by the founder, and it will be reviewed by a solicitor before the first paying customer.
Any of this worth a question.
Ask before you sign up rather than after. The founder answers this inbox personally.