GDPR / Data Protection Summary

This page provides a plain-English summary of how we handle your personal data under UK GDPR. For full details, please see our Privacy Notice.

What we store

  • Your name, contact details, and address
  • Professional information (GDC number, practice details)
  • Quote and policy information
  • Payment records (via Stripe)
  • Technical logs for security and audit

How long we keep it

Quotes
Incomplete applications
24 months
Policies
Active and expired policies
7 years after expiry
Marketing consent
Email preferences
Until withdrawn

Note: We retain policy data to meet regulatory and legal obligations.

Your rights

✓ Right to access
Request a copy of your data
✓ Right to rectification
Correct inaccurate information
✓ Right to erasure
Request deletion (subject to limits)
✓ Right to portability
Receive your data in a structured format

Making a request (DSAR)

To request access to, deletion of, or export of your personal data, please email:

privacy@dentalindemnitydirect.co.uk

We aim to respond within 30 days. Please include proof of identity with your request.

Important: Some data (e.g., policy records) must be retained for legal and regulatory reasons, even if you request deletion.

Questions or concerns?

If you have any questions about how we handle your data, please contact us at privacy@dentalindemnitydirect.co.uk

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk