Deltaly Trust Centre
Last updated: 2 September 2026
Trust through transparency
At Deltaly, protecting personal information is a fundamental design principle.
We build software for dental practices to improve workflows and administer patient memberships. We believe software should only process the information it genuinely needs.
Wherever reasonably practicable, patient-identifiable clinical information remains within the dental practice and is processed locally within the user’s browser rather than being transmitted to Deltaly.
This page explains how we approach privacy, security and data protection.
Privacy by Design
Privacy considerations are built into every stage of Deltaly’s development.
When designing new features we aim to:
- process information locally wherever reasonably practicable
- minimise the personal information transmitted to Deltaly
- avoid creating unnecessary copies of clinical records
- collect only the information required to provide the requested service
- regularly review whether existing processing remains necessary
Where server-side processing of patient information is required, Deltaly documents the need and assesses the associated privacy and data-protection risks, including through a DPIA where required.
Clinical Information
The Deltaly Chrome extension works alongside Dentally.
The extension can access information already available to authorised users within their authenticated Dentally session in order to provide workflow enhancements requested by the user.
Examples include:
- formatting patient information
- highlighting changes in medical histories
- improving the presentation of clinical information
- simplifying administrative workflows
Patient-identifiable clinical information accessed by the extension is processed locally within the browser wherever reasonably practicable.
Deltaly does not maintain a separate copy of a practice’s clinical records as part of the normal operation of the Chrome extension.
Clinical Safety
Deltaly applies clinical risk management processes to functionality that supports clinical workflows. These include hazard identification and assessment, documented safety controls, verification testing, release/change assessment and processes for reporting and responding to suspected defects or unexpected behaviour.
Clinical features are designed to support, rather than replace, professional judgement and the underlying Dentally clinical record. Where Deltaly assists with clinical documentation or prescribing workflows, outputs remain available for review and editing by the clinician before completion or issue.
Deltaly has reviewed the applicability of the NHS England clinical safety standards and considers DCB0129 likely to apply where Deltaly is used to support publicly commissioned direct patient care in England. Deltaly does not currently claim formal DCB0129 conformity and is undertaking structured work towards conformity.
Deltaly provides clinical safety and deployment-support documentation to help practices consider risks and controls relevant to their own deployment and use of Deltaly.
Membership Services
Practices may choose to use Deltaly to administer patient memberships.
Membership requires Deltaly to process a limited amount of patient information in order to provide the service.
Depending on the services used, this may include:
- patient name
- email address
- recommended plan
- relevant recall information
- membership plan
- payment status
- subscription identifiers
- linked family memberships
This information is used only to administer memberships, process recurring payments and provide membership self-service.
Deltaly does not need to hold a copy of the patient’s wider clinical record to provide Membership.
Payment card details and Direct Debit mandates are processed securely by Stripe and are not stored by Deltaly.
How we protect information
We apply a range of technical and organisational measures designed to protect personal information.
These include:
- encrypted connections using HTTPS/TLS
- passwordless authentication using one-time verification codes where appropriate
- UK-based secure hosting
- regular software maintenance and security updates
- automated server security updates
- regular software maintenance
- activity logging for security and troubleshooting
- encrypted payment processing through Stripe
- regular backups provided by our hosting provider
Security measures are reviewed and updated as Deltaly evolves.
Data Protection
Different organisations are responsible for different aspects of your information.
Dental practices remain responsible for the personal information they process when providing dental care.
Deltaly is responsible for operating the Deltaly platform, including user accounts, authentication, membership administration , Hub and platform security.
Depending on the processing activity, Deltaly may act as a data processor on behalf of the dental practice or as a data controller for limited processing undertaken for its own purposes, such as account administration, licensing, support and platform security.
Further information is available in our Privacy Notice.
Third-Party Services
Deltaly uses carefully selected service providers to operate the platform.
These currently include:
- Stripe (payment processing)
- Guru (website hosting and email)
- Google Analytics (website analytics)
- Google reCAPTCHA (spam and abuse prevention)
Where third-party providers process personal information on our behalf, appropriate contractual safeguards are put in place.
What Deltaly does not do
As part of our Privacy by Design approach, Deltaly does not:
- sell personal information
- use patient information for advertising
- use patient information to train artificial intelligence models
- store payment card or Direct Debit details
- create unnecessary copies of a practice’s clinical records
Transparency
We believe people should understand how their information is used.
Our public documentation includes:
- Privacy Notice
- Cookie Policy
- Website Terms of Use
- Deltaly Platform Terms
- Membership Terms and Conditions
- Subprocessor Register
Contact
If you have any questions about privacy, security or data protection, please contact us.