Last Updated: 21/07/2025
Under the UK General Data Protection Regulation (UK GDPR), we must have a valid reason to use your personal information. At Smile Stories, we collect and process your data based on the following legal grounds:
At Smile Stories, we use WhatsApp to communicate with patients for appointment confirmations, reminders, general enquiries, and, where appropriate, to share treatment updates, images or post-treatment advice.
Messages sent to us via WhatsApp are securely managed using a third-party platform (respond.io) that allows our team to respond efficiently and in line with our data protection responsibilities. This system does not affect how you use WhatsApp, but it ensures that your messages are handled securely and consistently on our side.
Please note that WhatsApp is a third-party messaging service with its own privacy and security practices, which we do not control. While it uses end-to-end encryption, it is not specifically designed for sharing sensitive medical information.
By contacting us through WhatsApp, you are providing implied consent for us to respond via this platform, including in cases where medical or sensitive information may be shared as part of your enquiry or treatment communication. We use WhatsApp primarily to handle enquiries, manage appointments, and provide relevant updates related to your care.
We also use WhatsApp internally between team members, where necessary, to coordinate patient care, appointment logistics and treatment discussions. All staff are trained in confidentiality and data protection, and any information shared in this way is used appropriately for clinical or administrative purposes.
In addition to WhatsApp, we may contact you by email, SMS (text message), telephone or through our website contact forms. These methods are used to ensure convenience, continuity of care and timely responses to your needs.
If you would prefer not to use WhatsApp for any communication, including messages involving medical or sensitive information, you can inform us at any time by emailing management@smilestories.co, and we will use an alternative contact method such as email or telephone.
Your communication preferences are important to us, and we will do our best to respect your choice.
At Smile Stories, we use a number of trusted third-party services to help us deliver, manage, and improve our services. Some of these services may process personal data outside the United Kingdom (UK) and the European Economic Area (EEA), including in the United States and other countries.
These services include, but are not limited to:
We also work with clinical tools such as:
Whenever your personal data is processed outside the UK or EEA, we take reasonable steps to select service providers that follow strong data protection standards. These providers may be based in countries recognised for having adequate data protection laws or may use legal agreements that aim to safeguard your information to UK standards.
If you would like more details about where your data is stored or how it is safeguarded, you can contact us at management@smilestories.co.
At Smile Stories, we take the security of your personal information seriously and have measures in place to help protect your data from being accidentally lost, accessed without permission, altered, or shared inappropriately.
These measures include:
While all members of our team have access to patient information in order to carry out their roles, we work hard to ensure that all data is handled sensitively, confidentially, and in line with legal and ethical standards.
Please be aware that while we do everything reasonably possible to protect your information, no system can ever be 100% secure. We cannot guarantee the absolute security of information transmitted online, such as through email, messaging apps, or web forms, so we advise caution when sharing sensitive information through these channels.
Our website uses cookies and similar tracking technologies to help us understand how visitors use our site, improve your browsing experience, and provide relevant advertising.
Cookies are small text files stored on your device when you visit a website. Some cookies are essential for the website to function properly, while others help us improve our website or deliver more relevant content and advertising.
We use cookies for the following purposes:
When you visit our website, you will see a cookie banner that allows you to:
You can change or withdraw your consent at any time by clicking on the Cookie Preferences button at the bottom of our website or by adjusting your browser settings.
If you have any questions about this privacy policy, how we handle your personal data, or if you would like to exercise any of your data protection rights (such as accessing your data, correcting it, withdrawing consent, requesting deletion of your data, or restricting how we use your data), you can contact our Practice Manager:
Practice Manager
Smile Stories
Email: management@smilestories.co
We will do our best to respond to your request as promptly as possible and always within the timeframes required by law.
If you are not satisfied with how we handle your personal data or feel we have not resolved your concern, you also have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s independent authority for data protection.
ICO Contact Details:
Website: www.ico.org.uk
Helpline: 0303 123 1113
While we do everything reasonably possible to keep your personal information secure, if we ever experience a personal data breach that puts your privacy at risk, we will take it seriously.
If required by law, we will:
If you become aware of any security incident involving your data in connection with Smile Stories, please contact our Practice Manager immediately at management@smilestories.co.
Thank you for trusting Smile Stories with your personal information.
Please follow this link for our complaints policy.