1. Who is responsible
For website enquiries, contact details, applications and DBX ONE's own administration, DBX ONE generally acts as controller. When processing supplier documents or configured stock data on a client's documented instructions, DBX ONE generally acts as processor and the client remains controller. Privacy questions can be sent to [email protected].
2. Information processed
- Names, work contact details and organisation information.
- Supplier invoices, credit notes, purchase references and business correspondence.
- Account/tax-code names, supplier lists, coded examples and optional setup documents where needed for the agreed workflow.
- Generated management outputs, exception decisions, draft import files, reports and audit records.
- Where STOCKROOM is used: stock-item names, pack sizes, rooms or cupboard labels, configured replenishment levels, delivery confirmations, stock-round records and supplier discrepancies.
3. Purpose
Information is used to receive and validate submissions; prepare supplier-document and stock workflows; identify exceptions; generate agreed management or operational outputs; provide support; secure the service; administer contracts and billing; and meet legal obligations.
4. Information DBX ONE does not need
Patient records, clinical information, passwords, bank-login credentials, payroll employee records, personal tax returns and pension files are outside the normal INSIGHTS and STOCKROOM scope. Clients should remove unrelated personal information where practical and submit only what is needed.
5. AI and model training — current workflow
For the current AI-assisted supplier-document workflow, original supplier files may be uploaded to DBX ONE's individual ChatGPT consumer account. This is not ChatGPT Business, Enterprise or the OpenAI API. DBX ONE keeps “Improve the model for everyone” switched off, and OpenAI states that new consumer conversations are not used to train its models when that control is off.
A separate conversation is used for each client, public shared links are not created, material is not reused for other clients and DBX ONE does not submit thumbs-up/down feedback on conversations containing client material. Ordinary chats remain in the consumer account until deleted. When DBX ONE's retention process requires deletion, the corresponding conversation is deleted and any relevant file retained separately in ChatGPT Library is also removed where applicable. OpenAI states that deleted chats are scheduled for permanent deletion within 30 days, subject to stated legal/security exceptions.
The organisation expressly authorises this consumer-service workflow by accepting the Terms and DPA during submission. A future API, Business or Enterprise workflow will be disclosed before live processing rather than silently substituted.
6. Sharing and service providers
DBX ONE may use Cloudflare for website/hosting/storage infrastructure, Zoho Mail / Zoho EU for business email, Stripe for payment processing and OpenAI's consumer ChatGPT service for the separately disclosed current AI-assisted workflow. DBX ONE does not sell client information. The detailed provider position is set out on the Confidentiality page and in the DPA.
7. International processing
Service providers may process information outside the United Kingdom under their applicable terms and safeguards. In particular, the controller acknowledges that the disclosed consumer ChatGPT workflow may involve processing outside the UK under OpenAI's consumer terms and privacy policy.
8. Retention
Free-trial material is normally retained for up to 90 days after delivery while the practice decides whether to continue, unless earlier deletion is requested or another legal requirement applies. Active-client records may be retained for service delivery, comparisons, corrections and audit trail until the service ends or deletion is agreed. ChatGPT conversations and any corresponding separately retained Library files follow the same client lifecycle before OpenAI's own deletion cycle applies.
9. Security
DBX ONE uses access controls, HTTPS, private storage, protected delivery routes, purpose limitation and incident handling appropriate to the service. No system can be guaranteed absolutely secure.
10. Your rights
Depending on the circumstances and lawful basis, individuals may have rights to request access, correction, deletion, restriction, portability or objection. Requests can be sent to [email protected]. Where DBX ONE acts only as processor, the request may need to be referred to the client controller.
11. Complaints
Please contact DBX ONE first so the issue can be reviewed. Individuals also have the right to complain to the Information Commissioner's Office, the UK data-protection regulator.
12. Internal sign-off by practices
Before submitting supplier files, practices may wish to run the service past their DPO, information-governance lead, finance/procurement lead, practice partners or Caldicott Guardian equivalent where relevant, and record the processing in their own records if personal data is involved.
13. Changes to this notice
This notice will be updated if DBX ONE changes its live storage, email, payment or AI-processing environment. The current version will be published here.