DD Group Privacy Policy
1. Introduction
This Privacy Notice explains how the DD Group (“DD Group”, “we”, “our” or “us”) collects, uses, shares, stores and otherwise processes personal information in connection with our Group-level activities and when you interact with the DD Group website.
The DD Group comprises a number of companies operating across the dental, aesthetics and related healthcare markets. The particular DD Group company responsible for your personal information will depend on the company, website, product, service or activity with which you interact. Where appropriate, a business-specific or activity-specific privacy notice will identify the relevant data controller and provide additional information about that processing. The DD Group website is operated by DD Products and Services Ltd, which is the data controller responsible for personal information collected directly through this website and for certain central activities carried out on behalf of the DD Group.
This Group Privacy Notice is intended to provide the common framework applying across the DD Group. It should be read together with any specific privacy notice provided to you by a DD Group company. Where a specific notice applies, it supplements this Group Privacy Notice in relation to that activity.
We are committed to protecting your privacy and processing personal information fairly, lawfully and transparently in accordance with applicable data protection legislation, including the UK General Data Protection Regulation (“UK GDPR”) and Data Protection Act 2018 where applicable.
2. Who does this Privacy Notice apply to?
Depending on the circumstances, this Privacy Notice may apply to personal information relating to:
- customers and prospective customers;
- healthcare professionals and other users of our products and services;
- suppliers, manufacturers, brand partners and other business contacts;
- users of the DD Group website;
- individuals who contact or correspond with us;
- job applicants and prospective employees;
- attendees at Group events, exhibitions or training; and
- other individuals whose personal information is processed as part of our Group-level business activities.
3. Different ways we process personal information
DD Group companies may process personal information as controllers in their own right, jointly with another organisation where appropriate, or as processors acting on behalf of another controller. The role we perform depends on the relevant activity.
Where you deal directly with a particular DD Group business—for example, by creating an account, purchasing products or services, attending an event or contacting that business—the relevant Group company will generally act as the data controller for that relationship. Its specific privacy notice may provide further information.
Certain Group functions and systems are operated centrally or shared between DD Group companies. Personal information may therefore be processed across the Group for purposes such as finance, IT support, legal and regulatory compliance, information security, reporting, governance and business management, subject to appropriate access controls and data protection arrangements.
4. Personal Information We Collect and How We Collect It
We collect personal information directly from individuals, automatically when our websites and digital services are used and, where appropriate, from DD Group companies and third parties. The information collected depends on the nature of your relationship with us. Depending on the circumstances, this may include:
- your name and contact details;
- your employer, organisation or place of work;
- billing, delivery and correspondence addresses;
- professional title, role, registration details and speciality;
- account details and communications with us;
- information relating to orders, deliveries, returns and services;
- marketing and communication preferences;
- information provided when attending events or training, completing surveys, entering competitions or promotions, or otherwise interacting with us; and
- other information reasonably required for the relevant business relationship or activity.
Where required by law, regulation or the nature of the products or services provided by a Group company, additional information may be collected or verified. The relevant business-specific privacy notice will provide further detail where appropriate.
Website information
When you visit a DD Group website, we may automatically collect certain technical information, such as your IP address, browser type, device information and website usage data through cookies and similar technologies. Further information will be available in the relevant Cookie Policy.
Recruitment
If you apply for a role with a DD Group company, we may process personal information provided as part of your application and recruitment process. This may include your contact details, CV, employment and education history, qualifications, application and interview information, references and information relating to your right to work.
Where relevant and permitted by law, we may also process information concerning reasonable adjustments, equal opportunities monitoring, health information or criminal convictions. We will only process this information where we have an appropriate lawful basis and, where required, an additional condition for processing special category or criminal offence information.
We use this information to manage the recruitment process, assess your suitability for a role, communicate with you about your application, carry out appropriate pre-employment checks and comply with our legal obligations.
We may share recruitment information where necessary with DD Group companies involved in the recruitment process and with recruitment agencies, background-check providers, professional advisers and other service providers supporting our recruitment activities. We retain recruitment information only for as long as reasonably necessary for the recruitment process and related legal or business purposes.
Information from third parties
We may receive personal information from third parties where they are lawfully permitted to provide it to us. This may include other DD Group companies, business partners, professional or regulatory registers, service providers and organisations with which we have a commercial relationship.
5. How We Use Your Personal Information and the Lawful Basis for Processing
We will only use personal information where we have an appropriate lawful basis under applicable data protection legislation. Depending on the circumstances, we may use personal information to:
- manage our relationship with customers, suppliers, partners and other business contacts;
- administer accounts and support the supply of products and services;
- respond to enquiries and provide customer or business support;
- verify professional or other eligibility where required;
- send service and operational communications;
- manage events, exhibitions and training;
- comply with legal and regulatory obligations;
- operate, administer and improve our businesses, products, services, systems and websites;
- carry out internal reporting, governance, finance, audit and business management activities;
- prevent fraud, manage risk and maintain the security of our systems, premises and information; and
- send marketing communications where permitted by law or with consent where required.
We rely on one or more of the following lawful bases:
- performance of a contract, or taking steps at your request before entering into a contract;
- compliance with a legal obligation;
- our legitimate interests, where these are not overridden by your rights and freedoms. These may include operating and improving our businesses, maintaining business and customer relationships, administering the Group efficiently, protecting our systems and information, preventing fraud, managing risk and complying with applicable law and industry standards; and
- your consent, where required.
Where a DD Group company processes special category personal information, it will also identify an appropriate condition for that processing where required by law. More specific information may be provided in the privacy notice for the relevant activity.
6. Marketing Communications
Where permitted by law, DD Group companies may send information about products, services, events or other matters that may be of interest to you. Where consent is required, it will be obtained before marketing communications are sent.
You can opt out of marketing at any time using the unsubscribe mechanism in our communications, updating your preferences where available or contacting the relevant DD Group company. Opting out of marketing will not prevent us from sending service-related or other non-marketing communications where appropriate.
We may also use secure hashed identifiers with advertising platforms to measure advertising effectiveness and improve the relevance of marketing. Where this occurs, you may object to this processing at any time. Further information may be provided in the privacy notice or cookie information for the relevant website or business.
7. Sharing Your Personal Information
We only share personal information where necessary for the purposes described in this Privacy Notice or a relevant supplementary notice, where required by law or where we otherwise have an appropriate lawful basis. Where organisations process personal information on our behalf, we require them to protect it appropriately and comply with applicable data protection legislation.
DD Group companies
We may share personal information between DD Group companies where necessary for purposes such as customer and supplier administration, finance, IT support, legal and regulatory compliance, information security, internal reporting, governance and business management. Access is limited to those with a legitimate business need.
Service providers
We use third-party providers to support our businesses, which may include providers of website hosting, cloud services, IT support, logistics, payment processing, customer relationship management, marketing, document storage, professional verification, security and fraud prevention services. Where these organisations process personal information on our behalf, they do so under appropriate contractual arrangements.
Manufacturers, suppliers and business partners
Where necessary to supply or support products or services, administer our commercial relationships, verify professional eligibility, provide technical or warranty support, manage product safety or recalls, deliver training or meet regulatory requirements, DD Group companies may share limited personal information with manufacturers, suppliers, brand partners or other business partners. Where those organisations receive personal information as independent controllers, they will process it in accordance with their own privacy information.
Regulators, professional advisers and others
We may disclose personal information where required by law or regulation, in response to lawful requests from regulators or public authorities, to establish, exercise or defend legal claims, in connection with corporate transactions or reorganisations, or to obtain professional advice.
8. International Transfers of Personal Information
The DD Group operates internationally and some DD Group companies, suppliers, service providers and other organisations with whom we share personal information may be located outside the country in which the information was originally collected.
Where personal information is transferred internationally, the relevant DD Group company will ensure that an appropriate transfer mechanism or safeguard is used where required by applicable data protection legislation. For transfers subject to UK data protection law, this may include UK adequacy regulations, the UK International Data Transfer Agreement or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses. For transfers subject to EU data protection law, this may include an adequacy decision or the EU Standard Contractual Clauses.
9. How Long We Keep Your Personal Information
We retain personal information only for as long as necessary for the purposes for which it was collected, including to comply with legal, regulatory, tax, accounting and reporting obligations and to establish or defend legal claims. Different categories of information are retained for different periods depending on the nature of the processing and applicable local requirements. DD Group companies apply the Group’s data retention framework, supplemented where necessary by local or activity-specific requirements.
10. Keeping Your Personal Information Secure
We implement appropriate technical and organisational measures designed to protect personal information against unauthorised or unlawful access, use, alteration, loss, misuse or disclosure. Access to personal information is restricted according to business need and appropriate security requirements.
11. Your Privacy Rights and Complaints
Depending on the data protection laws that apply to you, you may have rights in relation to your personal information, including rights of access, correction, erasure, restriction, objection, data portability and rights relating to consent and automated decision-making. These rights are subject to the conditions and exemptions set out in applicable law.
To exercise your rights, please contact the relevant DD Group company or the DD Group Data Protection Officer using the details below. We may need to verify your identity before responding to a request.
We hope that we can resolve any questions or concerns you may have about the way we process personal information. You may also have the right to complain to the data protection supervisory authority in the country in which you live or work, or where you consider an infringement has occurred. In the UK, the supervisory authority is the Information Commissioner’s Office (ICO).
12. Contact Us
If you have questions about this Privacy Notice, wish to exercise a privacy right or have a concern about how personal information is processed, please contact us at:
Email: marketing@ddgroup.com
Address: 6 Perry Way, Witham, Essex, CM8 3SX, United Kingdom
Alternatively, you can contact the DD Group Data Protection Officer at: GDPR@ddgroup.com
Where your query relates to a particular DD Group company, product or service, you may also use the contact details in the relevant business-specific privacy notice.
We will respond to privacy requests in accordance with applicable data protection legislation.
13. Changes to this Privacy Notice
We may update this Privacy Notice from time to time to reflect changes to the DD Group, our activities, applicable laws or regulatory guidance.
The latest version will be available on the DD Group website and will show the date on which it became effective. Where we make material changes, we will take appropriate steps to notify affected individuals where required by applicable law.
Cookie Policy – https://www.ddgroup.com/help/cookie-policy/
Modern Slavery Act Statement
Modern Slavery Act 2015: DD Group Slavery and Human Trafficking Statement
This statement is published on behalf of DD Group covering DD Products and Services Ltd, Med-fx Ltd and Fox Pharma Limited. References to ‘DD Group’ in this statement refer to Phey Topco Ltd and its subsidiaries.
Introduction on Approach
DD Group is committed to improving our practices to combat the risk of slavery and human trafficking in our business and supply chain.
Organisational structure
We are a supplier of goods and services within the dental and aesthetics industries. DD Group has its head office in the UK, operating primarily in the UK and Europe.
Our supply chains
As a provider of a wide range of clinical products, our supply chains span many international jurisdictions. We recognise that modern slavery risks can vary according to factors including sourcing jurisdiction, product category and the nature of the supplier relationship. We therefore seek to take a proportionate, risk-based approach to supply-chain oversight and are developing our supplier due diligence processes to provide enhanced scrutiny where higher risks are identified.
Relevant Policies
We operate the following policies which set out our approach to the identification of modern slavery risks and steps to be taken to prevent slavery and human trafficking in our operations and supply chains:
- Anti-Slavery and Human Trafficking Policy – reflecting our commitment to acting ethically and with integrity in all our business relationships and to implementing and enforcing effective systems and controls designed to mitigate the risk of slavery and human trafficking occurring. The policy applies to all employees and persons working for us in any capacity. It explains the nature of Anti-Slavery and Human Trafficking, the reason to operate the policy, and to whom the policy applies. It also clearly sets out how to report any concerns about Anti-Slavery or Human Trafficking.
- Whistleblowing policy – The organisation makes clear to employees the actions and behaviour expected of them when representing the organisation. The organisation strives to maintain the highest standards of employee conduct and ethical behaviour. We encourage all our workers and other business partners to report any concerns related to the direct activities, or the supply chains of, the organisation. This includes any circumstances that may give rise to an enhanced risk of slavery or human trafficking. Our whistleblowing procedure is designed to make it easy for workers to make disclosures, without fear of retaliation.
Progress during FY26
During FY26, the Group continued to operate its existing policies and reporting mechanisms relating to modern slavery and ethical conduct. Following changes in the Group’s structure and personnel, we considered our approach to modern slavery compliance and identified opportunities to strengthen and further standardise our supply-chain due diligence and monitoring processes.
No modern slavery concerns were reported through the Group’s reporting channels during FY26. Our focus for FY27 is to build on the existing framework through a proportionate, risk-based programme of supplier due diligence, risk assessment and awareness.
FY27 Priorities
During FY27, our initial priorities will focus on strengthening our approach across our core UK businesses, with a view to developing a proportionate and consistent approach across the wider Group over time, including:
- supplier risk assessment – visibility beyond direct suppliers varies across the Group’s supplier base, and we will look to develop a proportionate methodology for identifying higher-risk suppliers, taking account of factors such as jurisdiction, product/category and nature of supply;
- supplier due diligence – our supplier arrangements include requirements relating to compliance with applicable laws and ethical standards, including modern slavery requirements, although the extent of supporting assurance and monitoring currently varies according to supplier and category. We intend to review and enhance onboarding/periodic due diligence for suppliers identified as presenting greater modern slavery risk;
- contracting and assurance – review standard supplier contractual requirements and procurement documentation relating to modern slavery and ethical sourcing, including appropriate minimum supplier standards;
- training/awareness – provide targeted awareness or guidance for relevant procurement and supply-chain personnel; and
- governance – establish a process for periodic review of identified risks, concerns and actions to support preparation of the annual statement.
As these measures are implemented, we intend to develop proportionate measures to assess their implementation and effectiveness.
This statement is made pursuant to section 54(1) of the Modern Slavery Act 2015 and constitutes our Group’s slavery and human trafficking statement for the financial year ending 30 June 2026 and was approved by the board on 18 September 2026.
Howard TaylorGroup CEO
Ethical business
This statement sets out how we conduct our business operations in an ethical and responsible manner.
Our values are collaboration, integrity, trust and excellence. This statement describes how we reflect those values in how we govern the business, and links to the policies that sit behind it.
Scope
This statement applies to all companies within DD Group. It sets out the standards we expect of our employees, suppliers and partners in how we are governed, and links to the key policies that describe how we operate.
Human rights and modern slavery
We are committed to ensuring that modern slavery plays no part in our business, and we do what we can to see the practice stopped. Our modern slavery statement and policy can be found here.
Anti-corruption and bribery
We take a zero-tolerance approach to bribery in any part of our business. We provide training and clear policy guidance on what we expect of our employees, and we require that our suppliers take no part in bribery of any kind.
Competition
Businesses thrive in a market with free and fair competition. We have a clear policy on how we comply with competition law and ensure we do not restrict competition. Training is compulsory for our employees, and we identify higher-risk areas of the business for specific training and audit.
Data privacy
We understand the concern individuals have about how their personal information is used. We comply with data privacy legislation at all times and our policies and processes are built around the protection of personal data. As a business working closely in health and personal care markets, some of the personal data we handle can be sensitive, and we take particular care with it. Our privacy statement sets out how we deal with personal data and can be found here.
Whistleblowing
We want people to raise concerns, and we want them to feel safe doing so. Anyone working for or with DD Group can report a concern about conduct in our business without fear of reprisal, and every report is taken seriously.