This policy explains how AI-assisted features work in Lumina, what they process, where that processing happens, what is retained and for how long, and what the Customer is responsible for. It sits alongside the Lumina Data Processing Agreement (DPA), which governs Lumina's processing of Customer Data. Where this policy and the DPA describe the same subject, the DPA governs.
1 Overview of AI Features
Lumina provides the following AI-assisted capabilities:
- AI charting, which maps a clinician's narration to Lumina's charting options for the clinician to review and chart.
- Live dictation, which converts a clinician's speech to text for clinical entry.
- Scribe, which drafts structured examination notes from recorded findings.
- Booking assistant, a staff-facing diary assistant for booking, moving and cancelling appointments.
- Form builder, which builds and edits practice forms from a description.
- Lumina Intelligence, an administrative assistant that answers questions about the organisation.
AI features are optional. The Customer can enable or disable all AI functionality, or individual AI capabilities, at organisation level through the Service, and can change those settings at any time.
AI features are available subject to the usage limits of the Customer's subscription tier.
Lumina expects to add AI-assisted capabilities over time. New capabilities are built within the governance framework described in this policy, and this policy is updated when the material facts change.
2 How AI Processes Data
When a user invokes an AI feature, Lumina sends a deliberately constructed, feature-specific request to the model. It is not a general extract of Customer Data. Relevant context, which for clinical features includes clinical content, is included where the requested functionality requires it.
Lumina applies feature-specific data minimisation, pseudonymisation and payload controls designed to reduce identifiable Personal Data where it is not required for the functionality. These controls differ by feature. For example, the Scribe payload consists of structured examination findings and a pseudonymous internal patient identifier rather than the patient's name or date of birth, and in the booking assistant, selected entities are replaced with pseudonymous placeholders before model processing, with the mapping remaining within Lumina.
Certain AI-assisted clinical features necessarily process clinical information, because that information is what the feature exists to work on. Lumina does not claim that requests contain no Personal Data. Authorised users can also enter Personal Data into free-text fields, and the Customer should address this in staff training and acceptable-use guidance.
Data is encrypted in transit and at rest using appropriate managed and Lumina-controlled key-management arrangements.
3 Where AI Processing Happens, and Who Can Access It
Lumina's application services and data stores run in the United Kingdom, in the AWS London region.
AI model invocation is routed through Amazon Bedrock using approved European geographic inference profiles. These keep inference within a fixed set of AWS regions in the United Kingdom and the European Economic Area. Verified in August 2026, the possible inference locations are: London (United Kingdom), Dublin (Ireland), Paris (France), Frankfurt (Germany), Stockholm (Sweden), Milan (Italy) and Zaragoza (Spain). Lumina's controls restrict AI inference to those approved profiles. Global inference profiles, which can route worldwide, are not authorised for Lumina's production AI processing.
Where an inference request is served in an EEA region rather than London, the traffic remains on the AWS network, encrypted in transit, and does not traverse the public internet. Processing is confined to the United Kingdom and the EEA. EEA member states are covered by UK adequacy regulations, so no additional Article 46 transfer safeguard is required for the AI inference described here.
Speech transcription for live dictation is served in the AWS London region only. Dictation audio does not leave the United Kingdom.
For the foundation models Lumina currently approves for production use, under AWS's published commitments for Amazon Bedrock and Lumina's configuration as verified in August 2026:
- no request or response is durably retained at the model layer;
- AWS service operators cannot access model input or output content;
- the provider of the underlying model does not receive, and cannot access, requests, responses or Bedrock logs;
- Lumina has not enabled the optional mode that shares inference data with model providers, and the models Lumina uses do not require it;
- model invocation logging is not enabled in any environment, so prompt and completion content is not captured in Lumina's logging or storage; and
- Customer Data is not used to train, fine-tune or improve any model, by Lumina, by AWS or by the model provider.
Lumina reviews the processing location, retention characteristics, provider-access arrangements and applicable data-protection requirements of a foundation model before approving it for production use. The position above describes the models and configuration currently approved. It is not a statement about every model AWS may offer. Where a change to these arrangements would give a model provider access to Personal Data, Lumina will treat that provider as a new sub-processor and follow the DPA's sub-processor change process before the processing begins.
4 Retention
Retention differs by layer. It is not a single figure.
Model layer. For the currently approved production models, no request or response is durably retained, as set out in section 3.
Transient AI content. AI charting input exists for the lifetime of the request only, typically seconds, and is not written to any data store or log. Dictation audio is streamed rather than stored. There is deliberately no archive of this content.
Application AI histories. Where an AI-assisted feature provides a user-facing conversation or session history, Lumina retains that application data for the documented period for that feature and then deletes it automatically. The current periods are: booking assistant conversations, 7 days; form builder conversations, 7 days; Lumina Intelligence conversations, 90 days by default; Lumina Intelligence attachments, 30 days.
Clinical records and clinical drafts. AI-assisted output that a clinician accepts into a patient record becomes part of the clinical record and follows the normal clinical-record lifecycle and the Customer's retention obligations. AI involvement in drafting does not shorten clinical-record retention. Unaccepted Scribe drafts are retained within the patient record pending clinical review. They follow the practice's normal clinical-record lifecycle and can be reviewed, accepted, superseded or deleted by an authorised clinician. They do not expire automatically. They are not visible to patients, and they are not treated as temporary AI conversation history.
Governance and audit metadata. Lumina retains audit and governance information sufficient to establish relevant activity, including the user, the timestamp, the feature used, usage volumes, the action taken and the outcome. This metadata does not include the verbatim content of transient AI inputs.
Because transient AI content is deliberately never retained, Lumina cannot later reproduce the exact text sent to a model in those flows. This is an intentional data-minimisation trade-off rather than an oversight. What can be established after the fact is the audit metadata and, where applicable, the accepted output in the clinical record.
5 What AI Features Are For, and What They Are Not
AI features are assistive. They produce drafts, suggestions and summaries for a qualified person to review.
- AI-generated output is not a substitute for professional clinical judgement.
- AI features are not intended to diagnose conditions, recommend treatments or provide clinical advice, and Lumina does not present them as doing so.
- AI-generated clinical output is a draft and does not form part of a patient's clinical record until a clinician reviews and accepts it.
- Lumina does not rely on the AI capabilities described in this policy to make a decision about an individual based solely on automated processing that produces legal or similarly significant effects.
6 Customer Responsibilities
- All AI-generated output must be reviewed, verified and approved by a suitably qualified person before it is relied on, and by a qualified dental professional where the output is clinical.
- The Customer is responsible for the accuracy and clinical appropriateness of any AI-generated content incorporated into patient records.
- The Customer must ensure its staff understand that AI outputs are assistive tools rather than clinical recommendations.
- The Customer should implement internal policies governing the review and approval of AI-generated content, including the timely review of outstanding clinical drafts.
- The Customer should decide which AI capabilities are available to its staff, using the organisation-level controls in the Service.
- The Customer should train staff to use the designed workflows, including entity selection rather than typed names, so that the minimisation controls in section 2 apply.
- The Customer is responsible for informing patients about the use of AI-assisted tools where required by applicable law or professional guidance.
7 Limitations and Disclaimers
- AI-generated content may contain inaccuracies, omissions or inappropriate suggestions. Even well-constrained models produce confident errors.
- Lumina does not warrant the accuracy, completeness, reliability or fitness for purpose of any AI-generated output.
- Lumina accepts no liability for any clinical decision, action or omission based wholly or partly on AI-generated content.
- Model capabilities and availability change over time. Lumina may modify, suspend or discontinue AI features with reasonable notice.
- AI usage is subject to a daily usage allowance, measured in usage units, which resets at 00:00 UK time and varies by subscription tier. Usage beyond the included daily allowance may require Extra Usage to be switched on, billed pay as you go. Where an organisation has enabled Extra Usage and a feature is consuming chargeable usage beyond its included allowance, the interface says so at the point of use.
8 Transparency and Audit
AI usage is recorded as part of Lumina's audit trail. Records include the user who initiated the request, the timestamp, the feature used and metadata about the request.
Consistent with section 4, transient AI content is not retained and is therefore not available in audit records. What the audit trail establishes is who used which feature, when, and with what outcome.
Audit records are available to the Customer's administrators for compliance and internal review purposes.
9 Compliance Position
Lumina's AI features are designed in alignment with emerging UK guidance on AI in healthcare, including principles published by the Information Commissioner's Office and the NHS AI Lab. Lumina is committed to transparency, fairness and accountability in its use of AI, and monitors developments in UK AI regulation, updating this policy and its practices as the regulatory landscape develops.
AI data processing falls within the scope of the DPA between Lumina and the Customer. The Customer remains the Data Controller for any Personal Data included in AI requests or outputs, and Lumina processes such data as a Data Processor in accordance with the Customer's instructions.
Lumina maintains a DPIA Support and Technical Assurance Pack, which sets out per-feature detail to support a Customer's own Data Protection Impact Assessment. It is available on request.
10 Contact
Questions about AI features: operations@luminadental.co.uk
Data protection queries: privacy@luminadental.co.uk
Security concerns: security@luminadental.co.uk
This AI Usage Policy was last updated in August 2026. Previous versions are available upon request.