Legal
Privacy Policy
Last updated 4 August 2026
This policy explains how Kaizo Ltd handles personal data. Where we process patient data for a dental practice, we do so as their processor - see section 1.
1. Who we are and what this policy covers
Kaizo Ltd (“Kaizo”, “we”, “us”) provides software for dental practices in the United Kingdom. This policy explains how we handle personal data for which we are the data controller: the people who visit our website, enquire about or use Kaizo, and the staff of the dental practices we work with.
Kaizo also processes patient data (including health data) on behalf of dental practices. For that data the dental practice is the controller and Kaizo is its processor: we act only on the practice's documented instructions under a written data processing agreement, and we do not use patient data for our own purposes. If you are a patient, your rights are exercised through your dental practice; ask them for their own privacy notice.
2. The information we collect (as controller)
- Account and contact details: name, work email, phone number, job role and the practice you belong to.
- Business details: practice name, address and the settings you configure in Kaizo.
- Usage and technical data: pages used, actions taken, device and browser information, IP address, and security logs.
- Communications: messages you send us (support, demos, email) and our replies.
- Billing details: the information needed to invoice a practice (billing contact, plan). Card details are handled by our payment processor and are not stored by Kaizo.
3. Messages sent to practices on Instagram and Facebook
When someone messages a dental practice through the practice's Instagram or Facebook account, Meta sends Kaizo the information needed to show that conversation to the practice: the message content, the sender's name and platform ID, the sender's profile picture, and message timestamps.
We use this information for one purpose: so that practice staff can read and reply to enquiries in Kaizo. Kaizo processes it on the practice's behalf, as its processor. We never use it for advertising, and we never sell it.
To have this data deleted, see our data deletion page: you can remove Kaizo from your Facebook or Instagram settings, or email privacy@kaizosystems.com.
4. Health and other special-category data
Patient records, clinical notes and consultation audio are special-category (health) data. Kaizo only ever processes these as a processor for a dental practice, under our data processing agreement with that practice. We do not sell this data, and we do not use it to train third parties' AI models for their own purposes.
5. Why we use your information and our lawful bases
- To provide and secure the service, and to administer accounts (performance of our contract with your practice).
- To respond to enquiries and provide support (our legitimate interests in running and improving Kaizo).
- To send service and security notices (legitimate interests / contract). Marketing emails, if any, are sent only where permitted and you can opt out at any time.
- To meet legal and regulatory obligations (legal obligation).
6. Who we share it with
We share personal data with the service providers (“subprocessors”) that help us run Kaizo, each under a written data processing agreement. This includes hosting (Amazon Web Services, in the UK region), messaging, email delivery and AI processing providers.
Our current subprocessors, what each one does and the data each one touches are listed on our subprocessors page. We may also disclose information where required by law, or to protect our rights, users or the public.
7. International transfers
We aim to keep patient data at rest in the United Kingdom (Amazon Web Services, London region). Some of our providers are based in the United States. Where personal data is transferred outside the UK, we rely on a UK International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses) and appropriate safeguards.
8. How long we keep it
We keep personal data only for as long as we need it for the purposes above, or as required by law or our contracts. Account data is kept for the life of the account and a reasonable period afterwards. Patient data retention is set by each dental practice (the controller); on request, and on the end of our contract, we return or delete it.
9. How we protect it
- Encryption in transit and at rest, including envelope encryption for sensitive fields and encrypted, backed-up databases.
- Multi-factor authentication, role-based access controls and per-practice data isolation.
- A tamper-evident audit trail of sensitive actions, and human review gates before the AI takes patient-facing actions.
10. Your rights
Under UK data protection law you have the right to access your personal data, to have it corrected or erased, to restrict or object to processing, to data portability, and to withdraw consent where we rely on it. To exercise these rights for data we control, email privacy@kaizosystems.com. If you are a patient, please contact your dental practice, which is the controller of your records.
You also have the right to complain to the UK Information Commissioner's Office at ico.org.uk, though we would welcome the chance to resolve your concern first.
11. Cookies
Kaizo uses only the cookies needed to sign you in and keep the service secure. See our Cookie Policy for details.
12. Children
Kaizo is a business tool used by dental practices and is not directed at children. Any patient information about a child is provided and controlled by the dental practice, not by us.
13. Changes to this policy
We may update this policy from time to time. We will change the “last updated” date above and, for material changes affecting our customers, give notice through the service or by email.
14. Contact us
For any privacy question, or to reach our data protection contact, email privacy@kaizosystems.com or write to Kaizo Ltd (company number 17266896), registered office 83 Langley Way, Watford, WD17 3FA, United Kingdom.