Privacy Policy
Last updated: 21 July 2026
This policy explains how MillMyArch ("we", "us") collects, uses, stores and protects personal data when you use our website and case-submission service, in line with the EU General Data Protection Regulation (GDPR), the UK GDPR and, for users in Poland, the RODO implementing rules.
1. Who we are (Data Controller)
MillMyArch is the data controller responsible for your personal data. You can reach us regarding any privacy matter at [email protected]. Registered/operating location: United Kingdom.
2. The data we collect
Depending on how you use the service, we may collect:
- Account data: name, email address, password (stored only in hashed form), and role.
- Order & contact data: billing and shipping address, phone number, clinic details.
- Case data: patient reference/name as supplied by you, tooth and gum shade, material selection, notes, and uploaded design files (e.g. intra-oral scans, STL/PLY models, images).
- Payment data: processed by our payment provider; we do not store full card details.
- Technical data: strictly necessary cookies and basic security/session information.
3. Special-category (health) data
Uploaded case files and patient references may constitute health / special-category data under Article 9 GDPR. We treat this data to a higher standard: access is restricted to authorised laboratory and manufacturing staff on a need-to-know basis, files are served only through authenticated, access-controlled links, and they are stored on secured cloud infrastructure. You are responsible for ensuring you have the appropriate lawful basis and patient consent to share this data with us for the purpose of manufacturing the device.
4. Lawful basis for processing
- Contract (Art. 6(1)(b)): to create your account, receive your case, manufacture and ship the device, and provide support.
- Legal obligation (Art. 6(1)(c)): to meet accounting, tax and medical-device record-keeping duties.
- Legitimate interests (Art. 6(1)(f)): to secure the service and prevent fraud.
- Consent (Art. 6(1)(a)): for any optional cookies and non-essential communications. For health data, processing is carried out under Art. 9(2)(h)/(a) for the provision of the custom device.
5. Retention
We keep personal and case data only as long as necessary for the purposes above. Records relating to a manufactured custom-made medical device (including material and lot traceability) are retained for the period required by applicable medical-device regulations. Account data is kept while your account is active. When data is no longer required, it is securely deleted or anonymised.
6. Processors we use
We share data only with service providers that process it on our behalf under contract:
- Cloud hosting & application infrastructure (website, database, authentication).
- Encrypted cloud file storage (for your uploaded case files).
- Payment processing (card and checkout handling).
- Transactional email delivery (order and status notifications).
- Shipping / courier partners (delivery of the finished device).
Where data is transferred outside the UK/EEA, we rely on appropriate safeguards such as Standard Contractual Clauses.
7. Your rights
Subject to conditions, you have the right to access, rectify, erase, restrict or object to processing, to data portability, and to withdraw consent at any time. You may also lodge a complaint with your supervisory authority (in the UK, the ICO; in Poland, the UODO). To exercise any right, contact [email protected].
8. Cookies
We set strictly necessary cookies to run the site and keep you signed in. Optional (analytics/marketing) cookies are only set with your consent, which you can change at any time via the “Cookie Settings” link in the footer.
9. Changes to this policy
We may update this policy from time to time. The “Last updated” date above reflects the latest revision.