Privacy Policy
Last updated: July 20, 2026
1. Introduction
This Privacy Policy explains how SimplyRoots Limited ("we", "us", or "our"), trading as SmadiDesk, collects, uses, stores, and protects your personal data when you use our AI voice receptionist service for dental practices.
We are committed to protecting your privacy and handling your data in a transparent and lawful manner in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Data Controller
The data controller responsible for your personal data is:
SimplyRoots Limited
Company no. 10404398 (England and Wales)
Registered office: 14 Hill Top, London, NW11 6EE
United Kingdom
Email: [email protected]
Where SmadiDesk processes personal data on behalf of a dental practice (for example, caller information during voice calls or information imported from practice website pages and uploaded materials), the dental practice acts as the data controller and SmadiDesk acts as the data processor. Our responsibilities are governed by a Data Processing Agreement between SmadiDesk and each practice. You can review the current DPA on our Data Processing Addendum page.
3. Data We Collect
We may collect and process the following categories of data:
3.1 Practice Account and Configuration Data
- Practice name, address, and contact details
- Account holder name and email address
- Billing information (processed by our payment provider; we do not store full card details)
- Practice opening hours, services, and pricing
- Staff and practitioner details provided to us directly or contained in imported practice materials
- Information imported from publicly accessible pages of a practice website provided during onboarding or later settings
- Information contained in documents or files uploaded by the practice for onboarding, configuration, or knowledge import
- This may include staff or practitioner names, biographies, qualifications, roles, contact details, opening hours, services, pricing, policies, FAQs, and similar practice information, and may include other personal data contained in those materials
3.2 Caller Data (Voice Interactions)
- Caller phone number
- Voice call recordings and transcriptions
- Information disclosed during calls (name, reason for calling, appointment requests)
- Call duration, timestamps, and call disposition
- Emergency indicators detected by AI (e.g., dental trauma, severe pain)
3.3 Technical Data
- IP address and browser information
- Device type and operating system
- Pages visited and usage patterns on our platform
- Cookies and similar tracking technologies
3.4 Public Live Voice Demo Data
If you choose to start the public live voice demo, ElevenLabs processes your voice audio into a live transcription and generates response audio. Its language-model provider processes the conversation text. Limited session metadata is also processed to run the demo. The demo is not intended for medical, patient, contact, or other personal details.
SmadiDesk does not save public-demo audio or transcripts in its application storage. Provider processing and deletion are described separately in section 8.
4. How We Use Your Data
We process personal data for the following purposes:
- Service delivery: Providing the AI voice receptionist service, including handling calls and capturing enquiries for dental practices
- Onboarding, configuration, and knowledge import: Importing information from publicly accessible practice website pages and uploaded practice materials to configure the service and answer practice-specific questions
- AI processing: Processing customer-call audio and conversation data to deliver the subscribed service
- Public-demo delivery: Sending live demo voice audio and transcription to ElevenLabs, and conversation text to its language-model provider, to run the requested conversation
- Emergency detection: Identifying urgent call scenarios and flagging them for attention
- Lead capture: Recording caller details and appointment requests for practice follow-up
- Integration: Sharing authorised data with connected practice systems
- Billing and payments: Managing subscriptions and payments
- Service improvement: Analysing aggregated, anonymised usage data to improve our AI and platform
- Communication: Sending service emails such as account and billing notices
- Legal compliance: Meeting our legal and regulatory obligations
5. Legal Basis for Processing
We process your personal data based on the following legal grounds under the UK GDPR:
- Contract performance (Article 6(1)(b)): Processing necessary to deliver the SmadiDesk service to subscribing dental practices
- Legitimate interests (Article 6(1)(f)): Processing caller data to provide receptionist services on behalf of the dental practice; service improvement and fraud prevention
- Legal obligation (Article 6(1)(c)): Where we are required to retain data for tax, accounting, or legal purposes
- Consent (Article 6(1)(a)): Where applicable, such as for optional marketing communications
6. Third-Party Data Processors
We share personal data with the following third-party service providers who process data on our behalf:
| Provider | Purpose | Data Processed |
|---|---|---|
| Retell AI | Customer-call voice service delivery | Customer-call audio, recordings, transcripts, and metadata |
| Deepgram | Speech processing | Call audio or transcript data |
| OpenAI | Language processing | Transcript and conversation data |
| ElevenLabs | Public-demo voice and transcription processing; voice synthesis | Public-demo voice audio, live transcript and conversation data, and generated response content |
| Twilio | Telephony services | Phone numbers and call metadata |
| Supabase | Application data storage and authentication | Account and service data |
| Stripe | Billing services | Billing and payment data |
| Dentally | Customer-authorised practice management integration | Appointment and patient data |
| Resend | Transactional email services | Contact details and email content |
| Vercel | Application hosting | Technical logs and usage data |
All third-party processors are bound by data processing agreements and are required to handle your data securely and in accordance with applicable data protection laws.
7. International Data Transfers
Some of our third-party processors are based outside the UK. Where personal data is transferred internationally, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner's Office
- Adequacy decisions by the UK government where applicable
- Binding corporate rules or other approved transfer mechanisms
8. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected:
- Account data: Cancelling a subscription, a late or failed payment, or service suspension does not automatically delete account data. To request account closure or exercise a data protection right, contact us at [email protected]. We will verify the request, assess what action applies, and respond under applicable law. Where deletion or return applies, we delete, return, or anonymise the relevant data, subject to the limited retention and backup treatment described below.
- Customer-call recordings: Scheduled for deletion once they are more than 90 days old
- Customer-call transcriptions and lead data: Handled as account data. Subscription cancellation does not automatically delete them; a closure, return, or erasure request is assessed as described above
- Public live voice demo: SmadiDesk application storage does not save demo audio or transcripts. The required ElevenLabs demo-agent configuration disables saved audio recordings and sets audio, transcript, and PII to 0-day scheduled deletion for new conversations. A separate provider readback must confirm those settings before the public demo is enabled. This is not ElevenLabs Enterprise Zero Retention Mode; ElevenLabs documents that deleted non-ZRM data may remain in backups for up to 30 days and that related debugging or moderation logs may be retained.
- Billing records: Some company-accounting and VAT records may need to be retained after the service ends to meet applicable record-keeping obligations. Applicable periods are commonly six years, but the period and start point depend on the record and circumstances; no single period applies to all billing or account data
- Technical logs: Retention depends on the log source and service provider. We assess those periods against security, reliability, fraud prevention, and applicable legal obligations rather than applying one blanket maximum to every log
Other data is retained only where applicable law requires it or for a documented, narrowly scoped legal hold. Data kept for those reasons is protected and restricted to that purpose, then deleted or anonymised when the requirement ends. Residual backup or service-provider copies may not be capable of immediate deletion and may remain subject to provider recovery or retention processes. We do not treat those copies as deleted until deletion or expiry is verified.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Encryption of data in transit (TLS/SSL) and at rest
- Row-level security in our database ensuring strict data isolation between practices
- Regular security assessments and monitoring
- Access controls limiting data access to authorised personnel only
- Secure authentication with password hashing and session management
10. Your Rights
Under the UK GDPR, you have the following rights regarding your personal data:
- Right of access: Request a copy of the personal data we hold about you
- Right to rectification: Request correction of inaccurate or incomplete data
- Right to erasure: Request deletion of your personal data where there is no compelling reason for continued processing
- Right to restrict processing: Request that we limit how we use your data
- Right to data portability: Request the personal data you provided to us in a structured, commonly used, machine-readable format where the legal conditions for portability apply
- Right to object: Object to processing based on legitimate interests
- Rights related to automated decision-making: Our AI processes calls automatically but does not make decisions with significant legal effects on callers
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month.
Note for callers: If you have called a dental practice that uses SmadiDesk and wish to exercise your data rights, please contact the dental practice directly as they are the data controller for your call data.
11. Cookies
Our website uses cookies and similar technologies. For full details on what cookies we use and how to manage them, please see our Cookie Policy.
12. Children's Privacy
SmadiDesk is a business-to-business service. Account creation, onboarding, and administration of the service are intended for dental practice staff and other authorised adult users, not children.
Where the service processes caller or patient data, including data relating to children, it does so on behalf of dental practices acting as data controllers, with SmadiDesk acting as data processor where applicable. Questions or requests about that data should usually be directed to the relevant dental practice.
13. Business Contacts and Marketing
So that we can tell dental practices about our service, we keep basic business contact information about UK dental practices and, where publicly listed, the people who run them: practice name and address, publicly listed phone number and email address, practice website, company registration details, and the published name and role of the practice owner or practice manager. We collect this from public sources: the NHS Find-a-Dentist directory, the Care Quality Commission register, Companies House, the General Dental Council public register, and practices' own websites. We do not collect patient information, and we do not buy marketing lists.
We use this information to contact practices about our service by post, telephone, or (for corporate subscribers) email. Our legal basis is our legitimate interest in marketing a relevant business service to the businesses it serves (UK GDPR Article 6(1)(f)). We have carried out and keep under review a legitimate interests assessment; you can request a summary via the contact details below. Our telephone marketing is screened against the TPS and CTPS registers.
If a practice shows no interest, we delete its record within 12 months of collection. If you ask us to stop contacting you, we keep the minimum needed (your contact point and the date) on a suppression list solely so that we never contact you again.
You can object to marketing at any time — tell us by any channel (or use the unsubscribe link in any email) and we will stop immediately; this right is absolute. You also have the rights described in Section 10, and we will respond to any request within one month. We share this information only with the service providers that host our systems and send our communications, under contracts that protect it. We never sell or share our contact lists for others' marketing.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes via email or through our platform. The "Last updated" date at the top of this page indicates when this policy was last revised.
15. Complaints
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Website: ico.org.uk
Telephone: 0303 123 1113
We would appreciate the opportunity to address your concerns before you contact the ICO. Please reach out to us first at [email protected].
16. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
SimplyRoots Limited
Company no. 10404398 (England and Wales)
Registered office: 14 Hill Top, London, NW11 6EE
United Kingdom
Email: [email protected]
