No patient recordsDBX ONE is for supplier and stock workflows, not clinical records.
Private cloud storageOperational data and submitted files use controlled cloud services.
Two AI routesSTOCKROOM API automation and the current INSIGHTS manual route are disclosed separately.
You can askContact DBX ONE about access, correction or deletion.
1. Who is responsible
For website enquiries, account administration, marketing contacts and DBX ONE's own business records, DBX ONE generally acts as controller. When DBX ONE processes supplier documents, stock records or related operational information for a client practice on its instructions, DBX ONE generally acts as processor and the practice remains controller.
2. Information we may process
- Names, work email addresses, organisation details and user-account information.
- Supplier invoices, credit notes, supplier emails, purchase references, product descriptions and delivery information.
- STOCKROOM products, rooms, targets, physical counts, expiry lots, replenishment transactions, shopping items and activity history.
- INSIGHTS submissions, supplier-review outputs, evidence references, exceptions and report-access records.
- Support messages, security events, audit records and technical logs.
- Billing/contact information where a paid service is used. Payment-card and bank-mandate details are handled on Stripe-hosted routes where Stripe is used.
3. Why we use it
We use information to provide the requested service; authenticate users; receive and process supplier documents; maintain stock and delivery workflows; generate reports and review outputs; provide support; prevent abuse; troubleshoot incidents; administer trials and contracts; bill clients; and comply with legal obligations.
4. Legal bases when DBX ONE is controller
Depending on the context, DBX ONE relies on taking steps at an organisation's request or performing a contract, legitimate interests in operating and securing the service, and legal obligations. Consent is used only where consent is the appropriate legal basis. Where DBX ONE acts as processor, the client is responsible for establishing its own lawful basis for the processing.
5. Current STOCKROOM processing route
STOCKROOM account, configuration and stock records are stored in Cloudflare infrastructure, including D1. Supplier invoice files may be stored privately in Cloudflare R2 and processed asynchronously through Cloudflare Queues. Automated invoice extraction can use Cloudflare AI services first and, under the configured fallback rules, the OpenAI API. Operational/support email may be sent through Resend and delivered to DBX ONE's Zoho mailbox. If a user chooses app notifications, STOCKROOM stores the browser/device push subscription needed to deliver those alerts. The notification is then delivered through the push service used by that browser or operating system.
OpenAI states that API inputs and outputs are not used to train its models by default unless an organisation explicitly opts in. OpenAI may retain API abuse-monitoring data for a limited period under its current platform data controls.
6. Current INSIGHTS trial route
INSIGHTS trial files submitted through this website are stored privately in Cloudflare R2 and made available through controlled internal/private access. The current manual AI-assisted INSIGHTS workflow may use DBX ONE's individual ChatGPT consumer account with model-improvement switched off. This consumer route is not described as the OpenAI API or as covered by an OpenAI business DPA. The submission form requires the authorised representative to read that disclosure before sending files.
7. Service providers
| Provider | What it is used for |
|---|
| Cloudflare | DNS/CDN, Pages/Workers, D1 database, R2 object storage, Queues, Turnstile and configured AI/infrastructure services. |
| OpenAI | STOCKROOM API fallback where configured; current INSIGHTS manual AI assistance may use an individual ChatGPT consumer account as separately disclosed. |
| Resend | Transactional and support email delivery. |
| Browser / operating-system push service | Delivery of app notifications where a user explicitly enables them on a supported device or browser. |
| Zoho | DBX ONE business email and support correspondence. |
| Stripe | Hosted payment collection, subscriptions or invoices where a paid INSIGHTS route uses Stripe. |
8. International processing
Some providers may process data outside the UK. DBX ONE relies on the contractual and transfer safeguards provided by the relevant service provider where required. The client should review the provider information and DPA if its own governance requires additional assessment.
9. Retention
Account and operational STOCKROOM data is normally kept while the organisation remains active and for only as long afterwards as needed for deletion, support, legal or security purposes. Free INSIGHTS trial material may be kept during the trial and decision period, normally up to 90 days after delivery unless deleted earlier or the practice continues. Security/audit/provider logs may have separate limited retention periods.
10. Deletion and correction
Authorised users can correct some account and stock data directly. A practice can ask DBX ONE to correct or delete information. STOCKROOM also provides an owner-admin practice termination process intended to delete organisation-scoped service data. Deletion from third-party provider logs or backups follows the provider's own documented retention process.
11. Security
DBX ONE uses HTTPS, authenticated access, role controls, CSRF protections, private cloud storage, audit records and other technical measures appropriate to the service. No internet service is risk-free, so suspected incidents should be reported promptly.
12. Your rights and contact
Individuals may have rights under UK data-protection law, including access, correction, erasure, restriction, objection and complaint rights depending on the circumstances. Contact [email protected]. You can also complain to the UK Information Commissioner's Office if you believe your data has been handled unlawfully.