Last updated: 14 September 2026
Document version: 2026-09-14
Dentist Gold Card is operated by TDDUK LIMITED, company number 16466466 (“Dentist Gold Card”, “we”, “us” or “our”).
Our registered address is:
International House
Turner Way
Wakefield
England
WF2 8EF
TDDUK LIMITED is the controller of personal information used to operate the Dentist Gold Card service.
For privacy enquiries, requests or complaints, contact hello@dentistgoldcard.co.uk.
This policy explains how we collect, use, share and protect personal information when you use our membership, benefits, enquiry, referral and rewards services, or interact with us as a practice, partner or supplier.
Dentist Gold Card is intended for people aged 18 and over.
Dentist Gold Card is separate from your dental practice. We do not provide dental treatment or make clinical decisions.
Your dental practice is responsible for its clinical records, treatment advice and patient care. It provides its own privacy notice explaining how it uses information for those purposes.
We use relevant information to manage memberships, respond to enquiries, introduce people to participating practices, assist with bookings, check member discounts and administer referral rewards.
Authorised Gold Card booking staff and relevant practice staff may access the information needed to handle your enquiry or referral. This is different from access by the individual who referred you, whose reporting is limited as explained below.
Practices must have a lawful basis for sharing information with us. We must also have a lawful basis for receiving and using it.
Depending on how you use the service, we collect:
We use postal addresses to send Gold Card materials when requested and to help identify nearby participating dental practices.
We do not collect or store your payment-card details or bank-account details within the Gold Card system. Where payment is required, our payment provider may collect payment information directly.
We do not request full clinical records, dental photographs or medical histories to operate the service. However, treatment interests, appointment outcomes and information you provide in an enquiry or conversation may reveal information about your health. We protect that information accordingly.
We receive information:
When a practice provides information about you, this may include appointment details, outcomes, transaction amounts and discounts relevant to the Gold Card service.
Where we obtain information indirectly, we provide appropriate privacy information within the applicable legal timeframe, unless an exception applies.
We use personal information for the following purposes:
| Purpose | Lawful basis |
|---|---|
| Creating and managing your membership and providing requested benefits | Performance of our contract with you, or steps you request before entering into a contract |
| Responding to enquiries and arranging requested introductions or bookings | Contract where applicable; otherwise our legitimate interests in responding to requests and administering the service |
| Sending requested Gold Card materials and identifying nearby practices | Contract where applicable; otherwise our legitimate interests in fulfilling your request |
| Checking discounts, administering referrals and calculating rewards | Contract where applicable; otherwise our legitimate interests in operating an accurate and fair benefits and rewards service |
| Reviewing appointment outcomes and resolving service issues | Our legitimate interests in managing referrals, checking benefits and improving the service |
| Sending necessary account, enquiry, booking and reward messages | The basis applicable to the underlying service, usually contract or legitimate interests |
| Managing practice, partner and supplier relationships | Our legitimate interests in managing those relationships, and contract where the individual is a party |
| Maintaining security, preventing fraud and investigating misuse | Our legitimate interests in protecting users and the service |
| Sending optional electronic marketing | Consent |
| Meeting applicable accounting, tax and other legal requirements | Legal obligation |
Where we rely on legitimate interests, we assess whether the processing is necessary and balance our interests against your rights and reasonable expectations.
You can object to processing based on legitimate interests. You can object to direct marketing at any time.
Where information is necessary to provide a requested service, we explain this at collection. If you do not provide it, we may be unable to complete that part of your request. Marketing consent is optional.
Information revealing your dental or physical health is special-category personal information.
For the enquiry, referral, appointment-outcome and related reward-administration activities described in this policy, we obtain your explicit consent to process relevant health information, in addition to the ordinary lawful basis applicable to the activity.
We explain the information needed, why it is needed and the participating practice involved before asking for that consent. Where information is supplied by a practice, the consent arrangements must cover the relevant sharing and use by Gold Card.
Health-information consent is separate from optional marketing consent. Acknowledging this privacy policy does not, by itself, give explicit consent.
You can withdraw consent by emailing hello@dentistgoldcard.co.uk. Withdrawal does not affect processing that was lawful before withdrawal. It may prevent us from continuing the part of a referral or service that requires that information.
If we need to retain limited information after withdrawal for a legal claim or another legally permitted reason, we must have an applicable lawful basis and special-category condition.
When you use a referral link, we record the referral source to administer the programme and assess reward eligibility.
Authorised Gold Card staff and relevant participating practice staff may use necessary contact, enquiry, appointment, outcome, discount and transaction information to support the referral and administer benefits.
Individual referrers receive aggregated reward information towards their total “Referral Reward” payment.
We do not provide individual referrers with another person’s identity, contact details, treatment interests, enquiry details, appointment status, attendance, outcomes, treatment costs, spending or clinical information through referral reporting.
Commercial or referral partners acting solely in that capacity do not receive those details either. Access by practice or booking staff depends on their authorised operational role, not their participation in the reward programme.
We use locally hosted artificial intelligence tools within the UK-hosted Gold Card environment to assist staff in reviewing appointment outcomes and identifying referrals that may qualify for reward processing.
The AI flags information for staff review. It does not automatically approve, refuse or trigger referral payments. Staff assess the relevant information before taking action.
Where sensitive information is not needed in identifiable form, we replace identifying details with tokens before AI processing. Tokenised information remains protected as personal information where it can be linked back to someone.
Personal and medical information processed by these AI tools remains within the Gold Card environment. We do not send it to external cloud AI services, retain it in external AI systems or use it to train AI models.
The lawful bases and health-information consent arrangements described above also apply to this use. The AI does not make clinical decisions.
We share information only where relevant and necessary with:
Our communications and payment providers include:
Providers receive only the information relevant to their services. Where they act as our processors, they must process information under appropriate contractual arrangements. Some providers and participating practices may act as independent controllers for particular activities and provide their own privacy information.
Our core Gold Card records and locally hosted AI are held within our UK-hosted environment.
Communications, payment and other service providers may process information separately from our core system. Their processing locations and access arrangements may involve countries outside the UK.
Where a restricted international transfer occurs, we use an applicable lawful transfer mechanism, such as UK adequacy regulations or appropriate contractual safeguards, together with any additional measures required.
You can contact hello@dentistgoldcard.co.uk for information about relevant international processing and how to obtain a copy of applicable safeguards.
When you submit an enquiry or use the service, we may contact you to respond, arrange a requested introduction, manage a booking, confirm account activity or provide relevant reward and service updates.
You do not need to agree to marketing to receive necessary communications about a service you requested.
Optional marketing is separate. Where we seek your consent, we explain the sender, communication channels and type of marketing covered. Refusing or withdrawing marketing consent does not prevent you from submitting an enquiry or retaining your membership.
A referral or recommendation from someone else does not give us your marketing consent. A practice’s marketing consent does not automatically authorise marketing by Gold Card.
You can withdraw marketing consent using the instructions in a message or by emailing hello@dentistgoldcard.co.uk. We may retain a limited suppression record to respect your choice.
We may record calls relating to enquiries, bookings and support to maintain an accurate record, resolve issues and support service quality.
We notify you when a call is being recorded. Where a recording contains health information, the health-information arrangements described in this policy apply.
Call recordings are retained for three months from the date of the call, then deleted, unless a specific legal requirement or dispute requires a relevant recording to be preserved for longer.
Our website uses cookies or similar technologies for functions such as account access, security and remembering settings. Other technologies may support usage measurement and service improvement.
We obtain consent before using technologies that require it. Where a legal exception applies, we meet its applicable conditions.
Information supplied alongside our cookie choices explains the technologies used, their purposes and duration, and how to change your choices. You can also use browser controls, although blocking essential technologies may affect website functions.
We retain information only for as long as necessary for the relevant purpose.
Our general retention periods are:
| Record type | Retention period |
|---|---|
| Membership and account records | While the account remains active, then up to two years after closure |
| Enquiries that do not result in an active membership | Up to two years after the enquiry is closed |
| Operational referral, appointment, outcome and discount records | Up to two years after the relevant referral or matter is completed |
| General support correspondence | Up to two years after the matter is resolved |
| Call recordings | Three months from the call |
| Practice, partner and supplier contact records | During the relationship, then up to two years after it ends |
Records forming part of our required accounting and tax records are retained for the applicable statutory period, generally six years from the end of the relevant company financial year. This does not mean all associated health information is retained for that period.
We keep limited consent and unsubscribe records where necessary to demonstrate and respect your choices. Relevant information may also be retained for longer where necessary for a specific legal obligation, dispute or claim.
We delete or anonymise information when it is no longer needed. Retained exceptions are limited to the information required for their purpose.
We use appropriate technical and organisational measures to protect personal and medical information against unauthorised access, loss, misuse or disclosure.
Access is restricted to authorised personnel who need the information for their work. We apply appropriate access controls and confidentiality requirements and assess providers handling information on our behalf.
We minimise the information used and shared, including tokenising sensitive information for AI processing where appropriate. No system can guarantee absolute security.
Depending on the circumstances, you have rights to:
Contact hello@dentistgoldcard.co.uk to exercise your rights. We may need proportionate information to verify your identity.
We normally respond to rights requests within one month, subject to applicable legal extensions or permitted adjustments. If we cannot fulfil a request in full, we explain why.
You can also raise a privacy complaint at the same email address. We acknowledge complaints within 30 days, investigate appropriately and communicate the outcome without undue delay.
You have the right to complain to the Information Commissioner’s Office (ICO):
Website: https://ico.org.uk/make-a-complaint/
Telephone: 0303 123 1113
We may update this policy to reflect changes to the service, our processing or legal requirements.
The current version and its update date will appear on our website. Where a change materially affects how we use your information, we provide appropriate notice and obtain fresh consent where required.