Privacy Policy
Last updated: 23 June 2026
Version 3.0 - UK GDPR | DPA 2018 | Data (Use and Access) Act 2026 | PECR
1. Who We Are and How to Contact Us
KodedNest Ltd ("we", "our", "us") operates NetworkDental ("the Platform"), a technology marketplace facilitating direct connections between dental practices and dental nurses in the United Kingdom.
- Company name: KodedNest Ltd
- Company number: 16563013 (incorporated in England and Wales)
- Registered office: 128 City Road, London, United Kingdom, EC1V 2NX
- Website: networkdental.uk
- Data protection contact: kodednest@gmail.com
KodedNest Ltd is the data controllerof your personal information. We are registered with the Information Commissioner's Office (ICO). You can verify our ICO registration at ico.org.uk.
To exercise your data protection rights or raise a concern, contact us at kodednest@gmail.com. We will respond within one calendar month as required by Article 12 UK GDPR.
2. The Data We Collect
We collect different categories of personal data depending on whether you are a dental nurse or a dental practice.
2.1 All Users
- Email address - collected at registration or newsletter sign-up.
- User type - whether you are a dental nurse or a dental practice.
- Technical and usage data - IP address (anonymised where possible), browser type, device type, pages visited, session duration, and referral source, collected automatically via Vercel Analytics.
- Cookie data - as described in Section 10 below.
- Communications data - correspondence you send to us by email or through the Platform.
2.2 Dental Nurses (Additional Data)
- Full name and contact details - name, phone number, email address.
- GDC registration number - to verify professional registration status with the General Dental Council.
- Professional qualifications - copies of certificates evidencing dental nursing qualifications and additional training.
- Proof of identity - a copy of your passport, driving licence, or other government-issued identity document.
- Proof of address - a recent utility bill, bank statement, or equivalent document.
- DBS (Disclosure and Barring Service) certificate information - the certificate number, date of issue, and level of disclosure. See the callout box below regarding the special legal treatment of this data.
- Professional indemnity insurance details - provider name, policy number, and expiry date.
- Work area and location preferences - geographic areas in which you are available and willing to work.
- Availability information - general availability for locum shifts.
- Payment and banking details - your bank account details (sort code and account number, or equivalent) for receiving payment, processed through and stored by Stripe. KodedNest Ltd does not store full bank account details on its own systems.
2.3 Dental Practices (Additional Data)
- Practice name and registered address.
- CQC registration details (or equivalent devolved registration) - to verify regulatory status.
- Contact name, role, and telephone number - the individual managing the account.
- Billing information - payment card details, processed and stored by Stripe. KodedNest Ltd does not store full card details on its own systems.
- Vacancy details - information you provide when posting a vacancy, including shift dates, location, rate of pay, and required skills.
Criminal Convictions Data - DBS Certificates
DBS certificate information constitutes data relating to criminal convictions and offences within the meaning of Article 10 of the UK GDPR. This is a distinct and higher-protection category from ordinary personal data. We process it only under specific statutory conditions set out in Section 4.3 below, and we maintain a written Appropriate Policy Document (APD) as required by Schedule 1, Part 4 of the Data Protection Act 2018. Enhanced security controls apply to all DBS data.
3. How We Collect Your Data
- Directly from you - when you complete our registration or subscription forms, upload documents, post vacancies, or contact us.
- Automatically - through cookies and Vercel Analytics when you visit networkdental.uk.
- From publicly available sources - we cross-reference GDC registration numbers against the publicly searchable GDC online register to verify active registration status.
- From our service providers - Mailchimp (email delivery status), Stripe (payment confirmation and bank verification data), and Vercel (aggregated analytics).
4. Why We Use Your Data (Lawful Bases)
4.1 Standard Personal Data - Lawful Bases under Article 6 UK GDPR
| Processing Activity | Lawful Basis | Statutory Reference |
|---|---|---|
| Account creation and management | Performance of contract | Art. 6(1)(b) |
| GDC number, qualifications, identity, and address verification | Performance of contract; Legitimate interests (platform integrity) | Art. 6(1)(b) and (f) |
| Facilitating connections between nurses and practices | Performance of contract | Art. 6(1)(b) |
| Processing payments (practices and nurses) | Performance of contract | Art. 6(1)(b) |
| Service communications (e.g., account and booking notifications) | Performance of contract; Legitimate interests | Art. 6(1)(b) and (f) |
| Marketing emails to individuals | Consent (UK GDPR and PECR) | Art. 6(1)(a); PECR reg. 22 |
| Platform analytics and improvement | Legitimate interests | Art. 6(1)(f) |
| Fraud detection and misuse prevention | Legitimate interests; Legal obligation | Art. 6(1)(f) and (c) |
| Retaining financial records | Legal obligation (Companies Act 2006; Taxes Management Act 1970) | Art. 6(1)(c) |
Where we rely on legitimate interests (Article 6(1)(f)), we have conducted a legitimate interests assessment (LIA) confirming that the processing is necessary for the interest pursued and that our interests do not override your rights and freedoms. You may request a summary of this LIA by contacting us.
4.2 Marketing Emails - PECR Notice
Where you are an individual (not a corporate subscriber), we will only send you marketing emails with your prior consent, obtained in accordance with regulation 22 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR). You may withdraw consent at any time by clicking the unsubscribe link in any marketing email or by contacting us. Withdrawal of consent does not affect the lawfulness of prior marketing.
4.3 Criminal Convictions Data - DBS Certificates (Article 10 UK GDPR)
DBS certificate information is processed under Article 10 of the UK GDPR and section 10(5) of the Data Protection Act 2018 (DPA 2018). Processing this data requires both a lawful basis under Article 6 and a condition from Schedule 1 of the DPA 2018. We maintain a written Appropriate Policy Document (APD) as required by Schedule 1, Part 4, paragraph 25 of the DPA 2018.
Our processing of DBS certificate information is founded on:
- Article 6(1)(b) UK GDPR - Performance of contract: Processing is necessary to provide the verification service that Dental Nurses request when joining the Platform, which is the Platform's core contractual purpose.
- DPA 2018 Schedule 1, Part 1, paragraph 1 - Employment purposes: Processing is necessary in connection with assessing the suitability of individuals for work-like engagements in patient-facing healthcare settings, which engages obligations arising in connection with employment and social protection law (including GDC standards and CQC requirements applicable to practices).
- DPA 2018 Schedule 1, Part 2, paragraph 10 - Preventing or detecting unlawful acts: Processing is necessary to prevent unsuitable individuals from accessing patient-facing dental settings, and this purpose would be prejudiced if prior consent were required in all cases where DBS information raises safeguarding concerns.
We do not make solely automated decisions based on DBS information. Any concern arising from disclosed information is reviewed by a member of our team before any action is taken.
We do not retain copies of DBS certificates beyond the period necessary for verification. DBS data is held for a maximum of 6 months from submission, in accordance with the DBS Code of Practice and ICO guidance, then securely deleted. See Section 8 for the full retention table.
5. Sharing Your Data
We do not sell your personal data to any third party. We share personal data only in the following circumstances:
- With dental practices or dental nurses (via the Platform): When a Dental Nurse expresses interest in a vacancy, or a Practice views a nurse profile, limited Profile Data (such as name, GDC number, qualifications summary, and location) is shared with the relevant other party. By using the Platform to find or fill vacancies, you consent to this disclosure as an inherent feature of the service. You will be able to control what profile information is publicly visible through your account settings.
- With data processors acting on our instructions:
- Mailchimp (Intuit Inc., USA) - email delivery and marketing list management.
- Stripe Payments Europe, Ltd (Ireland/USA) - payment processing, bank account verification, and payment disbursement.
- Vercel, Inc. (USA) - website hosting, infrastructure, and privacy-preserving analytics.
- With regulators, law enforcement, or courts: Where required by law, court order, or regulatory authority, including the ICO, GDC, CQC, or HMRC.
- In a business transfer or restructuring: If KodedNest Ltd is subject to an acquisition, merger, or sale of assets, your personal data may be transferred to the acquiring entity as part of that transaction. We will give you reasonable advance notice and, where required, seek your consent.
- To protect safety: Where we reasonably believe disclosure is necessary to protect the vital interests of any person or to prevent serious harm to patients or the public.
6. International Data Transfers
We aim to keep your personal data within the UK where possible. However, certain service providers operate outside the UK:
| Processor | Country | Safeguard |
|---|---|---|
| Mailchimp (Intuit Inc.) | United States | UK IDTA (International Data Transfer Agreement) or UK Addendum to EU SCCs |
| Stripe Payments Europe, Ltd | Ireland (EEA) / United States | ICO adequacy decision (EEA); UK IDTA or UK Addendum to EU SCCs (US) |
| Vercel, Inc. | United States | UK IDTA or UK Addendum to EU SCCs |
You may request a copy of the relevant transfer mechanism documentation by contacting us at kodednest@gmail.com.
7. Automated Decision-Making and Profiling
We do not make decisions about you that are based solely on automated processing - including profiling - that produce significant legal or similarly significant effects on you. Any use of automated tools (for example, to flag documents for review) is subject to human oversight before any consequential decision is made.
8. How Long We Keep Your Data
| Data Category | Retention Period | Basis |
|---|---|---|
| Email address and account data | Duration of account + 6 years after closure | Limitation Act 1980 (contractual claims) |
| GDC number and professional qualifications | Duration of account + 3 years after closure | Platform integrity and regulatory accountability |
| Proof of identity and proof of address | Duration of account + 12 months after closure | Anti-money laundering and fraud prevention |
| DBS certificate information | 6 months from date of submission, then securely deleted | DBS Code of Practice; ICO criminal offence data guidance; APD |
| Financial and billing records | 7 years from the financial year end in which the transaction occurred | Companies Act 2006 s.386; Taxes Management Act 1970 s.34 |
| Nurse payment / bank details (Stripe) | As required by Stripe; deleted from Platform on account closure | Stripe data retention terms; statutory accounting obligations |
| Analytics and technical data | 26 months (aggregated; no persistent personal identifiers) | Legitimate interests (platform improvement) |
| Marketing consent records | Until consent is withdrawn + 3 years | ICO direct marketing guidance; PECR |
We may retain data beyond these periods where required to do so by law, by court order, or where necessary to establish, exercise, or defend legal claims.
9. Your Rights Under UK Data Protection Law
Under the UK GDPR and DPA 2018 (as amended by the Data (Use and Access) Act 2026), you have the following rights. These rights are not absolute and are subject to exemptions in certain circumstances.
- Right of access (Article 15) - to request a copy of the personal data we hold about you (a Subject Access Request or SAR). We will respond within one calendar month.
- Right to rectification (Article 16) - to have inaccurate personal data corrected without undue delay.
- Right to erasure (Article 17) - to request deletion of your personal data where, for example, it is no longer necessary for the purpose for which it was collected, or you withdraw consent. This right is subject to our legal retention obligations.
- Right to restriction of processing (Article 18) - to request that we restrict processing of your data in specified circumstances (e.g., where you contest its accuracy).
- Right to data portability (Article 20) - to receive personal data you provided to us in a structured, commonly used, machine-readable format, and to transmit it to another controller, where technically feasible. This right applies where processing is based on contract or consent.
- Right to object (Article 21) - to object to processing based on legitimate interests (Article 6(1)(f)) or to direct marketing at any time. Where you object to legitimate interests processing, we will cease unless we can demonstrate compelling legitimate grounds.
- Rights regarding automated decision-making (Article 22) - not to be subject to a decision based solely on automated processing that produces significant legal or similar effects. As noted in Section 7, we do not carry out such processing.
- Right to withdraw consent (Article 7(3)) - where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
To exercise any of these rights, contact us at kodednest@gmail.com. We may ask you to verify your identity before acting on your request. There is no charge unless your request is manifestly unfounded or excessive.
You have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Telephone: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, SK9 5AF
10. Cookies and PECR
We use cookies in accordance with the Privacy and Electronic Communications Regulations 2003 (PECR) and the UK GDPR. Strictly necessary cookies do not require your consent. We obtain consent before setting any non-essential cookies.
| Cookie | Type | Purpose | Basis |
|---|---|---|---|
| dental_network_form_submitted | Strictly necessary | Prevents duplicate form submissions. Session + 30 days. | Strictly necessary (PECR reg. 6(4)) |
| theme | Strictly necessary | Stores light/dark display preference. Session. | Strictly necessary (PECR reg. 6(4)) |
| Vercel Analytics | Analytics (privacy-preserving) | Aggregated page view data. No persistent user identifiers. No cross-site tracking. | Legitimate interests (Art. 6(1)(f)) |
We do not use advertising, retargeting, behavioural profiling, or third-party social media cookies. Manage cookies through your browser settings. See allaboutcookies.org for guidance.
11. Security and Data Breach Notification
We implement appropriate technical and organisational measures (TOMs) to protect personal data, including:
- HTTPS/TLS encryption for all data in transit.
- Role-based access controls limiting internal access to personal data on a need-to-know basis.
- Enhanced access and encryption controls for criminal convictions data (DBS information).
- Regular review and testing of security measures.
- Supplier due diligence for all data processors.
In the event of a personal data breach likely to result in a risk to the rights and freedoms of data subjects, we will notify the ICO within 72 hours of becoming aware of it (Article 33 UK GDPR). Where the breach is likely to result in a high risk to individuals, we will notify affected data subjects without undue delay (Article 34 UK GDPR).
12. Children
The Platform is directed at registered dental professionals and healthcare practice staff. We do not knowingly collect personal data from children under 18. If you believe we have inadvertently collected data from a child, please contact us and we will delete it promptly.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices, our Services, or applicable law. When we make material changes, we will post the updated policy with a revised "last updated" date and, where appropriate, notify you by email at least 14 days before changes take effect. Continued use of the Platform after changes take effect constitutes acceptance of the revised policy. Where required by law, we will seek your fresh consent.
14. Compliance with the Data (Use and Access) Act 2026
This Privacy Policy has been reviewed in light of the Data (Use and Access) Act 2026, which received Royal Assent on 19 June 2026. That Act amends the DPA 2018, introduces new provisions governing data intermediary services and data sharing, and strengthens the ICO's enforcement powers. We are committed to ongoing compliance with the Act as further implementing regulations and ICO guidance are published.
If you have a complaint about our data handling that you do not believe we have adequately addressed, you are entitled to escalate it to the ICO at ico.org.uk/make-a-complaint.