Legal
Privacy Policy
Last updated: [DATE]
This policy explains how NUPHASE Ltd collects, uses, stores and protects your personal information, including health information, when you use our website and service.
This is a working draft pending legal review. Items marked To confirm are placeholders awaiting sign-off and do not yet constitute final policy.
Who we are
NUPHASE is a service operated by [FULL LEGAL ENTITY NAME], a company registered in England & Wales under company number [NUMBER], registered office [ADDRESS]. We are the ‘data controller’ for the personal information described in this policy.
To confirm
Confirm registered entity name, company number and registered office. Add ICO registration number and a Data Protection Officer / contact if appointed.
The information we collect
Information you give us:
- Identity and contact details: name, date of birth, address, email, phone number.
- Account details: login credentials and settings.
- Health information: your questionnaire responses, symptoms, medical history, and the information you share with your clinician.
- Payment information: processed by our payment provider; we do not store full card details.
Information generated through the service:
- Blood test results from our diagnostics partner.
- Clinical records: consultation notes, prescriptions, monitoring and treatment history.
- Correspondence with your clinical team.
Information collected automatically: device, browser and usage data, and cookies (see our Cookie Policy).
How we use your information and our lawful bases
Under UK GDPR we rely on the following lawful bases:
- To provide care and treatment — processing of health data for the provision of healthcare (Article 9(2)(h)), under the responsibility of a regulated health professional.
- To operate your account and take payment — performance of a contract (Article 6(1)(b)).
- To meet legal and regulatory duties — legal obligation (Article 6(1)(c)), including CQC, MHRA and pharmacy record-keeping requirements.
- To improve and secure our service — legitimate interests (Article 6(1)(f)), balanced against your rights.
- For marketing — only with your consent (Article 6(1)(a)), which you can withdraw at any time.
Who we share it with
We share your information only as needed to deliver your care and run the service, including with:
- Our clinical partner(s) and the GMC-registered clinicians responsible for your care.
- Our diagnostics partner for blood testing.
- Our pharmacy partner for dispensing and compounding.
- Our technology, payment and delivery providers acting as our processors.
- Your GP, where you ask us to or where clinically appropriate and agreed with you.
- Regulators and authorities where we are legally required to.
To confirm
Add the named processors / sub-processors list: Medical Hub, Refine Group, Randox, payment provider, hosting, delivery.
International transfers
If any provider processes data outside the UK, we put appropriate safeguards in place (such as an adequacy decision or International Data Transfer Agreement).
To confirm
Confirm whether any data leaves the UK and the safeguard used.
How long we keep it
We keep medical records for the period required by law and professional guidance, and other information only as long as needed for the purposes above.
To confirm
Confirm clinical record retention period: align with GMC / CQC / pharmacy guidance.
Your rights
You have rights to access, correct, erase, restrict and object to processing of your data, to data portability, and to withdraw consent. To exercise them contact [PRIVACY CONTACT]. You can also complain to the Information Commissioner’s Office (ico.org.uk).
To confirm
Add the privacy contact email / address.
How we protect your information
We use appropriate technical and organisational measures to keep your information secure, including encryption, access controls and staff confidentiality obligations.
Changes to this policy
We may update this policy and will post the revised version here with a new ‘last updated’ date.