Legal
Privacy Policy
Last updated: [DATE]
This policy explains how NUPHASE Ltd collects, uses, stores and protects your personal information, including health information, when you use our website and service.
This is a working draft pending legal review and does not yet constitute final policy. Items marked To confirm are placeholders awaiting sign-off.
Who we are
NUPHASE is a service operated by [FULL LEGAL ENTITY NAME], a company registered in England & Wales under company number [NUMBER], registered office [ADDRESS]. We are the ‘data controller’ for the personal information described in this policy.
To confirm
Confirm registered entity name, company number and registered office. Add ICO registration number and a Data Protection Officer / contact if appointed.
The information we collect
Information you give us:
- Identity and contact details: name, date of birth, address, email, phone number.
- Account details: login credentials and settings.
- Health information: your questionnaire responses, symptoms, medical history, and the information you share with your clinician.
- Payment information: processed by our payment provider; we do not store full card details.
Information generated through the service:
- Blood test results from our diagnostics partner.
- Clinical records: consultation notes, prescriptions, monitoring and treatment history.
- Correspondence with your clinical team.
Information collected automatically: device, browser and usage data, and cookies (see our Cookie Policy).
How we use your information and our lawful bases
Under UK GDPR we rely on the following lawful bases:
- To provide care and treatment — processing of health data for the provision of healthcare (Article 9(2)(h)), under the responsibility of a regulated health professional.
- To operate your account and take payment — performance of a contract (Article 6(1)(b)).
- To meet legal and regulatory duties — legal obligation (Article 6(1)(c)), including CQC, MHRA and pharmacy record-keeping requirements.
- To improve and secure our service — legitimate interests (Article 6(1)(f)), balanced against your rights.
- For marketing — only with your consent (Article 6(1)(a)), which you can withdraw at any time.
Who we share it with
We share your information only as needed to deliver your care and run the service, including with:
- Our clinical partner(s) and the GMC-registered clinicians responsible for your care.
- Our diagnostics partner for blood testing.
- Our pharmacy partner for dispensing and compounding.
- Our technology, payment and delivery providers acting as our processors.
- Your GP, where you ask us to or where clinically appropriate and agreed with you.
- Regulators and authorities where we are legally required to.
To confirm
Add the named processors / sub-processors list: Medical Hub, Refine Group, Randox, payment provider, hosting, delivery.
Where your information is held
Your information is stored and processed in the United Kingdom, on servers in London. Encrypted backup copies are also held in Ireland so that your records survive the loss of a data centre. Ireland is covered by the UK’s adequacy regulations, which means it is recognised as offering equivalent protection, so no additional safeguard is required.
Some of the providers we rely on process information outside the UK, principally in the United States. Where they do, we put appropriate safeguards in place — either a UK adequacy decision (including the UK Extension to the EU-US Data Privacy Framework) or the ICO’s International Data Transfer Agreement or Addendum. You can ask us for details of the safeguards used for any particular provider.
To confirm
Confirm the final processor list and the safeguard relied on for each before publication — see claude_docs/legal/policy-information-pack.md.
How long we keep it
We keep medical records for the period required by law and professional guidance, and other information only as long as needed for the purposes above.
To confirm
Confirm clinical record retention period: align with GMC / CQC / pharmacy guidance.
Your rights
You have rights to access, correct, erase, restrict and object to processing of your data, to data portability, and to withdraw consent. To exercise them contact [PRIVACY CONTACT]. You can also complain to the Information Commissioner’s Office (ico.org.uk).
To confirm
Add the privacy contact email / address.
How we protect your information
We use appropriate technical and organisational measures to keep your information secure, including encryption, access controls and staff confidentiality obligations.
Changes to this policy
We may update this policy and will post the revised version here with a new ‘last updated’ date.