Smileline

Privacy Policy

How Smileline Technologies Ltd collects and uses personal data — and the different role we play for the patient data practices store in the platform.

Version 2026-09-02 · Last updated 2 September 2026

This policy explains how Smileline Technologies Ltd, company number 17408336 ("Smileline", "we") handles personal data in connection with the smileline.io website and the Smileline platform (the "Service"). We process personal data in two distinct roles, and it matters which one applies:

  • As a controller — for the data of the people we deal with directly: visitors to this website, and the staff of practices who hold Smileline accounts.
  • As a processor — for the patient data that dental practices store in the Service. The practice is the controller of its patients' data; we process it only on the practice's instructions, under our Data Processing Agreement. If you are a patient of a practice that uses Smileline, contact the practice directly about your data — this policy's sections 1–6 do not govern that data.

1. Data we collect as a controller

  • Account data — name, email address, password hash, role, avatar, language, and the practice you belong to.
  • Billing data — subscription state and invoicing details. Card details are collected and held by Stripe, not by us.
  • Usage and security data — sign-in timestamps, IP address, browser user agent, product interactions, error diagnostics, masked session replays and an audit trail of actions taken in the platform. Session replay masks form inputs and rendered text and does not record request or response bodies.
  • Agreement records — when you accept our Terms, this policy or the DPA, we record who accepted, the document version, the time and the capacity in which it was accepted, as minimised evidence of the agreement. We do not attach an IP address or browser user agent to the acceptance.
  • Contact data — messages you send to our sales or support addresses.

2. Why we process it (lawful bases)

  • Performance of a contract — providing the Service, authentication, billing, support.
  • Legitimate interests — securing the platform, keeping audit trails, preventing abuse, improving the product.
  • Legal obligation — accounting records, and evidencing consent and contract acceptance.

We do not sell personal data, and we do not use it for advertising.

3. Cookies and storage on your device

The public website sets no analytics or advertising cookies. The platform sets one strictly necessary cookie: a session cookie that keeps you signed in. It is kept for 30 days from your last visit and is removed when you sign out.

Signed-in product analytics and masked session replay store an identifier in your browser's local storage rather than in a cookie. We describe it here rather than treating it as exempt: the law on storing information on your device covers local storage the same way it covers cookies, and it is used for our own product analytics rather than to deliver the Service. It runs only for signed-in practice staff — never for patients, and never on the public website. Session replay masks text and form inputs, and does not record request or response bodies. If you would rather not be included, write to privacy@smileline.io and we will exclude your account.

The website tracking script that practices install on their own websites is a separate thing, described in the Data Processing Agreement. It stores a visitor identifier on the visitor's device, and for practices in the UK and the EU it waits for the visitor's consent before doing so. It also honours the Global Privacy Control signal wherever it is sent.

4. Who we share data with

We use a small number of service providers to run Smileline. Those that process personal data on our behalf are listed in the Data Processing Agreement (sub-processors) — principally Cloudflare (hosting), our managed database provider, Stripe (payments), Resend (transactional email) and Telnyx, which carries calls for practices using our calling features: outbound calls for the Power Dialer, and — for practices on SmileLine Voice — inbound and outbound calls, voicemail and call recordings where the practice switches recording on. Where a practice enables SmileLine Voice, stored call recordings and voicemail messages also go through post-call transcription by an automatic speech-recognition model running on our hosting provider's (Cloudflare's) infrastructure; transcripts are kept no longer than the recording they came from. If you try the public phone demo on smileline.io, we keep the number you entered for seven days and, when you book a slot on that call from a mobile, may send it one text with a link to a recap of the demo booking. Calls on SmileLine Voice are offered on an unlimited fair-use basis: we monitor aggregate calling volumes to detect fraud and resale, and we may contact a practice whose usage is far outside normal practice patterns. Where a practice enables the AI add-on we also use two AI providers for different features: OpenAI for inbox assistance and search embeddings, and xAI for the answering model behind the patient-facing chat widget. Where a practice switches on the AI receptionist, a call it answers is carried live by LiveKit Cloud (in the EU for UK and EU practices, in the US for US practices), the caller's speech is recognised and the assistant's replies are spoken by Cartesia, and the assistant's language model and the written summary produced after the call come from OpenAI under zero-data-retention terms. The transcript of such a call comes from that live session; recordings, where the practice switches them on, are transcribed afterwards on Cloudflare as described above. The assistant always introduces itself as the practice's AI assistant, and you can ask for a person at any time. We use PostHog in an EU-hosted project for authenticated product analytics, masked session replay and error diagnostics. Where a practice owner or manager opens the Zapier builder under Settings → Integrations, we pass their name and email address to Zapier so it can sign them in; Zapier then processes it under its own privacy policy. We may also disclose data where required by law. We do not share personal data with anyone else.

5. Where your data is hosted, and international transfers

Every practice is pinned to a service region by the legal country it chose at sign-up, and that choice does not change afterwards. Practices in the United Kingdom and the European Union are served from our EU region, with the primary database hosted in Germany. Practices in the United States are served from our US region, with their data hosted in the United States. A practice's own records stay in its region.

Some of the providers listed in section 4 process personal data outside that region — the AI providers and parts of our telephony and email delivery operate in the United States. For personal data originating in the UK, those transfers rely on UK adequacy regulations or on standard contractual clauses with the UK International Data Transfer Addendum. For personal data originating in the EU, they rely on an adequacy decision or on the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914). You can ask us for a copy of the safeguards that apply to a particular transfer by writing to privacy@smileline.io.

6. Retention

  • Account data is kept while the account exists and deleted or anonymised within 90 days of account deletion.
  • Billing records are kept for 6 years to meet accounting obligations.
  • Agreement-acceptance records are kept for the life of the practice's account and for 6 years after, as evidence of the contract.
  • Practices can set retention periods for message content, patient-bearing activity and audit detail, and call recordings. Shorter periods are applied progressively to existing detail. Structural records needed to preserve security, accountability and operational integrity may remain after that detail is redacted or deleted. See the DPA.

7. Automated decision-making

We do not make decisions about you that produce legal effects or similarly significantly affect you on an automated basis alone. The platform does automate work for practices — routing enquiries, scoring and prioritising leads, sending scheduled messages and placing AI voice calls — but a person at the practice decides on treatment, on booking and on anything else that affects a patient. Where the AI assistant or the AI voice agent handles an enquiry, the practice's team remains reachable and takes over on request.

8. Whether you have to give us data

For account holders, the account data in section 1 is required to enter into and perform our contract with the practice: without it we cannot create an account or provide the Service. Everything else you give us is optional. If you are a patient of a practice that uses Smileline, the practice decides what it records about you — ask the practice.

9. Your rights

Under the UK GDPR and the EU GDPR you can ask us for access to, correction, deletion, restriction or portability of the personal data we hold about you as a controller, and you can object to processing based on legitimate interests. Where we rely on your consent for anything, you can withdraw it at any time; withdrawing it does not affect the lawfulness of what we did before you withdrew.

Write to privacy@smileline.io — we acknowledge promptly and respond within one month. If you are not satisfied with our response, say so in reply and a different person will review it; we will tell you the outcome of that review in writing.

You can also complain to a supervisory authority. In the UK that is the Information Commissioner's Office (ico.org.uk). In the EU it is the supervisory authority of the country where you live or work, or where the problem happened — you do not have to come to us first, though we would appreciate the chance to put things right.

10. Security

All traffic is encrypted in transit (TLS); data is encrypted at rest; access to production systems is restricted, credential-based and logged. Channel-connection credentials stored for a practice are individually encrypted. See the DPA for the security measures we commit to contractually.

11. Changes and contact

Each revision of this policy carries a version date, shown at the top of the page; material changes are re-presented in the app for acceptance. Questions: privacy@smileline.io · Smileline Technologies Ltd · Company 17408336 · 1 Lyric Square, London, England, W6 0NB.