For UK dental clinics
Dental patient
confidentiality.
How we handle patient details and run campaigns on your clinic’s behalf.
What your clinic needs to doTL;DR — what your clinic needs to do
- 1. Verify patient permissionCheck the original consent wording and records for email/SMS marketing, any opt-outs, and permission to share and use patient information for this campaign.
- 2. Agree the safeguardsCheck your privacy notice, sign the DPA with Vesora, and confirm access, providers, deletion and opt-out handling before uploading.
- 3. Upload and approveOnce those checks are complete, upload eligible patients’ names, emails and phone numbers. Approve the campaign; Vesora sends it on your behalf.
From your patient list
to an approved campaign.
Your clinic decides who may be contacted and approves the campaign. We manage the sending, while clinical decisions and patient care stay with your team.
- 01
You confirm permission
Check which patients can receive your marketing and whether their details may be shared for this purpose. Agree the data processing terms with us before uploading.
- 02
You upload contact details
Upload eligible patients’ names, email addresses and phone numbers to your Vesora account. Clinical notes, diagnoses, X-rays and treatment plans are not needed for this campaign upload.
- 03
We run your approved campaign
Vesora sends the approved texts and emails on your clinic’s behalf. Messages identify your clinic, include an opt-out, and direct clinical questions back to your team.
What to check
before uploading.
Start with your consent form, consent records and privacy notice. Being an existing patient does not automatically mean someone can receive marketing.
Email and SMS each need valid permission. If relying on a PECR soft opt-in instead of consent, check every condition in the ICO’s guidance.
The original consent wording
Look for a clear, voluntary agreement to marketing from your clinic, specifying email and/or SMS. Consent to treatment or appointment reminders is different.
The consent record
Check when and how each patient agreed, the wording they saw, their channel choices and any later withdrawal. A marketing ‘yes’ flag alone may not show this.
Your privacy information
Check what patients were told about external providers handling contact details for your clinic’s marketing. Resolve unclear or conflicting wording before uploading.
How you select patients
Check whether patient status, attendance or treatment information reveals health data. For marketing using health data, explicit consent should normally cover that use too.
An agreement
we both sign.
Before the first upload, your clinic and Vesora sign a Data Processing Agreement. It records our instructions, confidentiality duties, security measures, providers, retention and deletion, and how we assist with patient rights and incidents.
We can prepare it for your review alongside the service terms. An NDA alone is not a substitute, and the agreement does not create missing marketing permission.
A clear choice
for every patient.
Vesora includes opt-out instructions in marketing texts and an unsubscribe link in every marketing email. The campaign process must respect withdrawals and prevent further marketing in the channels a patient opts out of.
Before sending begins, we agree how preferences are kept up to date, including requests received by your clinic. Adding an unsubscribe link does not replace permission to send the first message.
Agree the safeguards.
Then start the service.
Confirm the upload and storage protections, who can access your data, separation between clinics, and the email, SMS and hosting providers involved. Address any overseas transfers and agree retention periods before sharing patient information.
The agreed use should be limited to your campaigns, with no resale or use for Vesora’s own marketing. Set out deletion or return of data and an incident contact. Vesora must notify your clinic of a personal data breach without undue delay.
Questions
from clinic owners.
Do patients need to consent to Vesora by name?
Not automatically. ICO guidance says processors do not need to be named in the consent request when acting only on the clinic’s behalf. Your privacy information must still explain the processing, and patient-confidentiality requirements still apply. Introducing a processor does not fix missing marketing permission.
Is a marketing opt-in enough to get started?
It is a starting point. Check what the consent covers, whether it remains valid, and whether the intended disclosure and use of patient information are permitted. Before uploading, both parties also need agreed processing terms and appropriate safeguards. If the wording is unclear, ask your privacy lead or dental defence organisation to review it.
Who signs the data processing agreement?
Your clinic and Vesora. Vesora can prepare the agreement for your review; it does not need to originate from your clinic. For campaigns delivered under your instructions, your clinic is the controller and Vesora is the processor. The agreement binds both parties but does not itself create patient consent.
What happens when a patient opts out?
Vesora includes opt-out instructions in marketing texts and an unsubscribe link in marketing emails. The campaign process must record withdrawals and suppress further marketing in the channels the patient opts out of, including after future uploads. Agree how your clinic passes any opt-outs received directly to Vesora before sending begins.