Please note: this page is a working draft pending legal review. It describes how OwlDesk intends to operate and will be finalised with our solicitors before contracts are signed.
Data processing
Last updated September 2026
Roles
Your clinic is the data controller for patient enquiries. OwlDesk is a data processor and acts only on your documented instructions. We do not use patient data for our own purposes, we do not sell it and we do not use it to market to patients.
Before you go live we provide a signed data processing agreement covering the requirements of Article 28 of the UK GDPR.
The data flow, step by step
- A patient submits the enquiry form on your website.
- The enquiry passes to OwlDesk. It typically contains the patient’s name, email address, treatment interest, sometimes a phone number, and any free text they wrote.
- OwlDesk drafts one reply in your practice’s agreed style, referencing the treatment they asked about.
- The reply is sent from your own email address, so the patient sees your practice.
- The patient replies directly to you. From that point the conversation is in your inbox and no longer passes through our systems.
Categories of data
Contact details and the content of the enquiry. Patients sometimes volunteer health-related information in free text, for example describing a dental concern. We treat all enquiry content as potentially special category data and apply the same protections to all of it. We never ask for health information and our replies do not request clinical detail.
Sub-processors
We use a small, stable set of providers. The current list, with each provider’s role and hosting location, is supplied with the data processing agreement and kept up to date. It covers cloud hosting and database services, an automation platform used to draft replies, an email sending provider and an error monitoring service. We give you notice before adding or replacing a sub-processor, and you may object.
Location and transfers
Data is processed in the UK or EEA wherever possible. Where a provider processes data elsewhere, we rely on UK adequacy regulations or the UK International Data Transfer Addendum to the EU standard contractual clauses.
Retention and deletion
Enquiry records are retained for a short period so we can investigate delivery problems and audit what was sent, then deleted. Demo submissions made on this website are deleted within 30 days. On the end of your contract we delete or return all patient data within 30 days, apart from anything we must keep by law.
Security measures
- Encryption in transit and at rest.
- Access limited to named personnel who need it, with multi-factor authentication.
- Segregated environments and logged access.
- Breach notification to you without undue delay and within 24 hours of us becoming aware.
Helping you meet your obligations
We assist with data subject requests, help you keep your record of processing accurate and support your responses to the GDC, the CQC or the ICO where our processing is relevant. Email hello@owldesk.co.uk.