AIAH Health Limited · Company No. 17322326
Internal governance policy setting out how AIAH.Health complies with UK GDPR, the Data Protection Act 2018 and ICO guidance.
Last updated: 7 July 2026
This Policy sets out how AIAH Health Limited (company number 17322326) governs the processing of personal data across its operations. It is owned by the Board and administered by the Data Protection Officer. It applies to all directors, employees, contractors, interns, volunteers and third parties acting on our behalf.
To ensure that AIAH.Health processes personal data — including special category health data — lawfully, fairly and transparently, and that we can demonstrate compliance with the UK GDPR, the Data Protection Act 2018, PECR and ICO guidance.
This Policy applies to all personal data processed by AIAH.Health in any format (digital, paper, verbal), and to every workflow — product, clinical, research, marketing, operations, HR and finance.
We identify a valid Article 6 (and where relevant Article 9) basis before processing and provide clear privacy information at the point of collection.
Personal data is collected for specified, explicit and legitimate purposes and is not further processed in incompatible ways.
We collect only the data we need. Product teams justify each new data field against a specific purpose and reviewer sign-off.
We enable users to review and correct their data and we correct or delete inaccurate data without undue delay.
Retention periods are defined in the Data Retention Policy and enforced by automated deletion or scheduled review.
Data is protected by the controls set out in the Information Security Policy.
Health data is our highest-risk asset. We: (a) identify a valid Article 9 condition; (b) document an Appropriate Policy Document where DPA 2018 Sch. 1 conditions apply; (c) apply defence-in-depth security; and (d) limit access on a least-privilege basis.
AI features are subject to the AI Governance Policy. Every AI feature that processes personal data is reviewed by the DPO before launch, has a DPIA where required, includes explicit user consent where relevant, and cannot be deployed in a way that constitutes solely automated decision-making with legal or similarly significant effects.
A DPIA is required whenever processing is likely to result in a high risk to individuals, and in particular for: new AI features processing health data; large-scale processing of special category data; systematic monitoring; any processing on the ICO's DPIA list. DPIAs are signed off by the DPO before go-live and reviewed on material change.
Requests are handled per our Subject Access Request Procedure and answered within one calendar month, extendable by two further months for complex cases with an explanation to the requester.
All incidents are triaged under our Data Breach Response Plan. Reportable breaches are notified to the ICO within 72 hours and to affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
The DPO performs an annual internal compliance audit and reports findings and remediation to the Board. Independent audit is commissioned where required by customers, regulators or funding conditions.
This Policy is reviewed at least annually and on any material change to the law, our processing activities or ICO guidance.