Trust & Compliance

Security & Compliance

OakStone is built for the one thing a dental group cannot get wrong: patient data. Our core design decision is to hold as little of it as physically possible. This is the detail your practice manager or DPO will want — a companion to our Data & Compliance overview.

Last updated: 14 September 2026 · OakStone Digital Ltd (company no. 17102271)

The core principle: we don't hold your clinical records

Your patients' clinical records — notes, x-rays, treatment history — never leave your practice management system. Our own database stores only aggregate metrics, pseudonymised delivery events (hashed identifiers that cannot be reversed without a per-client secret held separately), redacted workflow logs and per-client configuration.

If OakStone's database were ever fully exposed, an attacker would find aggregate statistics and hashed identifiers — not a single patient's clinical record, and no readable list of who your patients are. The sensitive material stays where it already is: inside your PMS.

Security controls

Hosting & residency

Stored data is hosted in the UK (London region) on managed PostgreSQL. Separate development, staging and production environments — not one database with a flag.

Encryption

TLS 1.2+ in transit on every connection; AES-256 at rest. Secrets live in an encrypted credential store; the database holds only opaque references, never secret values.

Client isolation

Enforced at the database layer with Postgres row-level security and client-scoped keys — one client can never read another's data, even in the event of an application bug.

Access & keys

Production access is least-privilege and MFA-protected on every administrative account. Per-client hashing salts are stored only in secrets management, never logged, and are rotatable.

Retry & idempotency

Every external action checks before it runs and follows a defined retry ladder, so a transient failure never double-sends or double-books.

Fail-closed sending

A circuit breaker, suppression list and volume governor sit in front of every message. If any safety check can't be confirmed, the message is held, not sent.

Sub-processors

A small number of vetted providers deliver the service. We give 30 days' notice before adding or replacing any of them, and you may object on reasonable data-protection grounds. Providers configured to receive no patient data (our observability tools) are not listed.

ProviderFunctionData it seesLocation
SupabaseDatabase & authAggregates + pseudonymised eventsHosted UK (AWS London)
360dialogWhatsApp delivery (primary)Phone number, message content, statusGermany (EEA)
Meta / WhatsAppWhatsApp transmissionPhone number, message content, metadataIreland (EEA) / US
TwilioSMS fallbackPhone number, SMS content, statusIreland / US
AnthropicAI message wordingFirst name + appointment label only — no phone numbers, no clinical dataUS
n8nWorkflow orchestrationTransient payloads; errors pruned after 7 daysGermany (EEA) or self-hosted
Retell AI / ElevenLabsVoice (only if you enable it)Phone number + call audio / spoken textUS

Transfers outside the UK rely on UK adequacy (EEA providers) or approved mechanisms (UK Addendum / IDTA) with a documented transfer-risk assessment for US providers. AI providers are configured for no model-training on your data. The definitive, version-controlled list forms Annex 3 of our DPA.

Data retention

DataKept for
Message content (sent & received)Deleted within 90 days
Pseudonymised delivery eventsTerm of agreement + 60 days, then anonymised
Patient contact records synced from PMSDeleted within 30 days of ineligibility
Opt-out (suppression) listKept indefinitely as hashed identifiers
Voice recordings (if enabled)30 days
Database backups35-day rolling window

Governance & go-live gates

We'd rather show our rigour than claim maturity we don't have. We treat the following as conditions precedent to processing any real patient data — they must be in force before go-live, not promised afterwards:

Signed DPA

An Article 28 UK GDPR data-processing agreement, executed before any real data flows.

Cyber insurance in force

Cyber and professional-indemnity cover, with a breach-response panel, active from the go-live date.

Named DPO

An outsourced Data Protection Officer named in your DPA before real patient data is processed.

Supporting this: a completed Data Protection Impact Assessment, a documented DPO necessity assessment, a per-client kill-switch held by your practice manager, a monthly verified ledger with a line-item dispute window, and a yearly right for you to audit us at no charge. OakStone is registered with the ICO.

Request the security pack

For due diligence we provide, on request and at no charge: the full Data Processing Agreement, the DPIA, our sub-processor due-diligence records, and answers to your security questionnaire.

Email hello@oakstone-digital.com

This page is a plain-English summary for prospective and current clients. Where it differs from the executed Data Processing Agreement and Master Services Agreement, those documents govern. It is not legal advice.