Privacy

Privacy Policy

How TOOFI LTD collects, uses, stores, and shares personal data when you use our website and platform.

1. Introduction

TOOFI LTD ("we", "us", "our"), Company Number 17118394, registered at 167-169 Great Portland Street, 5th Floor, London, W1W 5PF, is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share your data when you use our website and platform. ICO Registration Number: C1898012.

2. Our Role

3. Data We Collect as Controller

Data Purpose Legal Basis
Name, email, job title of clinic staff Account management, service delivery Contract performance
Billing and payment data Payment processing via Stripe Contract performance
Usage analytics, IP address Service improvement, security Legitimate interests
Cookie data Analytics, site functionality Consent
Email for marketing Product updates, newsletters Consent

4. Patient Data (Processor Role)

When dental practices use Toofi to manage patient records, we process this data solely on behalf of and under the instructions of the practice. This data may include: patient names, contact details, dental records, treatment history, medical history, appointment data. This constitutes health data (special category data under Article 9 UK GDPR). We do not access, use, or share patient data for any purpose other than providing the Service as instructed by the dental practice.

5. Sub-Processors

Sub-Processor Purpose Location DPA
Supabase (AWS eu-west-2) Database hosting London, UK supabase.com/legal/dpa
Stripe Payment processing Ireland/USA (DPF-certified) stripe.com/legal/dpa
Google (Gmail) Email communication USA (DPF-certified) Built into Google Workspace ToS

We will notify customers of changes to sub-processors with 30 days' notice.

6. International Data Transfers

Primary data storage: London, UK (Supabase, AWS eu-west-2). Transfers to USA: covered by UK-US Data Bridge (extension to EU-US Data Privacy Framework) for DPF-certified recipients, or by Standard Contractual Clauses with UK Addendum. Transfers to EU/EEA: covered by UK adequacy decision. Transfers to Canada: covered by adequacy for PIPEDA-regulated organizations.

7. Data Retention

8. Your Rights (UK GDPR)

You have the right to: access your data, rectify inaccurate data, erase your data (subject to legal obligations), restrict processing, data portability, object to processing based on legitimate interests, withdraw consent at any time.

For patient data: patients should contact their dental practice directly. We will assist practices in fulfilling data subject requests.

To exercise your rights: email toofi.app.official@gmail.com.

9. Data Security

We implement: AES-256 encryption at rest, TLS 1.2+ encryption in transit, multi-factor authentication, row-level security for tenant isolation, regular backups with point-in-time recovery, access logging and audit trails.

10. Data Breach Notification

In the event of a personal data breach, we will notify the ICO within 72 hours where required. Where we act as Processor, we will notify the affected dental practice within 48 hours. ICO contact: ico.org.uk, 0303 123 1113.

11. Cookies

We use: strictly necessary cookies (no consent required), analytics cookies (consent required), marketing cookies (consent required). You can manage preferences through our cookie banner. Non-essential cookies are off by default until you consent.

12. Children's Data

We do not knowingly collect data from children under 16. Our Service is designed for use by dental professionals.

13. Changes to This Policy

We will notify you of material changes by email at least 30 days in advance.

14. Contact Us

TOOFI LTD
167-169 Great Portland Street, 5th Floor, London, W1W 5PF
Email: toofi.app.official@gmail.com
ICO Registration: C1898012

15. Right to Complain

You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

Last updated May 27, 2026
Company TOOFI LTD - Company Number 17118394
ICO Registration C1898012