Deltaly Trust Centre
Last updated: 13 July 2026
Trust through transparency
At Deltaly, protecting personal information is a fundamental design principle.
We build software for dental practices to improve workflows and administer patient memberships. We believe software should only process the information it genuinely needs.
Wherever reasonably practicable, patient-identifiable clinical information remains within the dental practice and is processed locally within the user’s browser rather than being transmitted to Deltaly.
This page explains how we approach privacy, security and data protection.
Privacy by Design
Privacy considerations are built into every stage of Deltaly’s development.
When designing new features we aim to:
- process information locally wherever reasonably practicable;
- minimise the personal information transmitted to Deltaly;
- avoid creating unnecessary copies of clinical records;
- collect only the information required to provide the requested service;
- regularly review whether existing processing remains necessary.
Where server-side processing of identifiable patient information is required, Deltaly documents the operational need and completes a Data Protection Impact Assessment (DPIA) before introducing the feature.
Clinical Information
The Deltaly Chrome extension works alongside Dentally.
The extension can access information already available to authorised users within their authenticated Dentally session in order to provide workflow enhancements requested by the user.
Examples include:
- formatting patient information;
- highlighting changes in medical histories;
- improving the presentation of clinical information;
- simplifying administrative workflows.
Patient-identifiable clinical information accessed by the extension is processed locally within the browser wherever reasonably practicable.
Deltaly does not maintain a separate copy of a practice’s clinical records as part of the normal operation of the Chrome extension.
Membership Services
Practices may choose to use Deltaly to administer patient memberships.
Unlike the Chrome extension, this service requires Deltaly to process a limited amount of patient information in order to operate the membership.
Depending on the services used, this may include:
- patient name;
- email address;
- membership plan;
- payment status;
- subscription identifiers;
- linked family memberships.
This information is used only to administer memberships, process recurring payments and provide membership self-service.
Clinical records remain within the dental practice wherever reasonably practicable.
Payment card details and Direct Debit mandates are processed securely by Stripe and are not stored by Deltaly.
How we protect information
We apply a range of technical and organisational measures designed to protect personal information.
These include:
- encrypted connections using HTTPS/TLS;
- passwordless authentication using one-time verification codes where appropriate;
- risk-based authentication for higher-risk actions;
- least-privilege administrative access;
- secure hosting;
- automated server security updates;
- regular software maintenance;
- activity logging for security and troubleshooting;
- encrypted payment processing through Stripe;
- regular backups provided by our hosting provider.
Security measures are reviewed and updated as Deltaly evolves.
Data Protection
Different organisations are responsible for different aspects of your information.
Dental practices remain responsible for the personal information they process when providing dental care.
Deltaly is responsible for operating the Deltaly platform, including user accounts, authentication, membership administration and platform security.
Depending on the service provided, Deltaly may act either as a data controller or as a data processor on behalf of the dental practice.
Further information is available in our Privacy Notice.
Third-Party Services
Deltaly uses carefully selected service providers to operate the platform.
These currently include:
- Stripe (payment processing)
- Guru (website hosting and email)
- Google Analytics (website analytics)
- Google reCAPTCHA (spam and abuse prevention)
Where third-party providers process personal information on our behalf, appropriate contractual safeguards are put in place.
What Deltaly does not do
As part of our Privacy by Design approach, Deltaly does not:
- sell personal information;
- use patient information for advertising;
- use patient information to train artificial intelligence models;
- store payment card or Direct Debit details;
- create unnecessary copies of a practice’s clinical records.
Transparency
We believe people should understand how their information is used.
Our public documentation includes:
- Privacy Notice
- Cookie Policy
- Website Terms of Use
- Deltaly Platform Terms
- Membership Terms and Conditions
- Subprocessor Register
Contact
If you have any questions about privacy, security or data protection, please contact us.