Legal & Compliance Centre

AIAH Health Limited · Company No. 17322326

Data Protection Policy

Internal governance policy setting out how AIAH.Health complies with UK GDPR, the Data Protection Act 2018 and ICO guidance.

Last updated: 7 July 2026

This Policy sets out how AIAH Health Limited (company number 17322326) governs the processing of personal data across its operations. It is owned by the Board and administered by the Data Protection Officer. It applies to all directors, employees, contractors, interns, volunteers and third parties acting on our behalf.

1. Purpose

To ensure that AIAH.Health processes personal data — including special category health data — lawfully, fairly and transparently, and that we can demonstrate compliance with the UK GDPR, the Data Protection Act 2018, PECR and ICO guidance.

2. Scope

This Policy applies to all personal data processed by AIAH.Health in any format (digital, paper, verbal), and to every workflow — product, clinical, research, marketing, operations, HR and finance.

3. Roles and responsibilities

  • The Board has ultimate accountability for data protection and approves this Policy.
  • The Data Protection Officer (DPO) oversees compliance, advises on DPIAs, is the primary contact for data subjects and the ICO, and reports independently to the Board.
  • Department leads own compliance within their functions and maintain their sections of the Record of Processing Activities (RoPA).
  • All personnel must complete mandatory data protection training and follow this Policy and its associated procedures.

4. Accountability principle

  • Maintain a Record of Processing Activities (RoPA) under Article 30.
  • Keep evidence of lawful bases, consents, Legitimate Interests Assessments and Article 9 conditions.
  • Complete Data Protection Impact Assessments (DPIAs) for high-risk processing.
  • Operate a documented policy framework, review annually and version-control changes.
  • Log security incidents and personal data breaches with root-cause analysis.

5. Data protection principles

5.1 Lawfulness, fairness and transparency

We identify a valid Article 6 (and where relevant Article 9) basis before processing and provide clear privacy information at the point of collection.

5.2 Purpose limitation

Personal data is collected for specified, explicit and legitimate purposes and is not further processed in incompatible ways.

5.3 Data minimisation

We collect only the data we need. Product teams justify each new data field against a specific purpose and reviewer sign-off.

5.4 Accuracy

We enable users to review and correct their data and we correct or delete inaccurate data without undue delay.

5.5 Storage limitation

Retention periods are defined in the Data Retention Policy and enforced by automated deletion or scheduled review.

5.6 Integrity and confidentiality

Data is protected by the controls set out in the Information Security Policy.

6. Special category health data

Health data is our highest-risk asset. We: (a) identify a valid Article 9 condition; (b) document an Appropriate Policy Document where DPA 2018 Sch. 1 conditions apply; (c) apply defence-in-depth security; and (d) limit access on a least-privilege basis.

7. AI governance

AI features are subject to the AI Governance Policy. Every AI feature that processes personal data is reviewed by the DPO before launch, has a DPIA where required, includes explicit user consent where relevant, and cannot be deployed in a way that constitutes solely automated decision-making with legal or similarly significant effects.

8. Third parties and processors

  • Every processor is vetted for security, legal presence and data protection maturity.
  • A written contract meeting Article 28 UK GDPR is in place before any personal data is shared.
  • Sub-processors are approved in advance and listed on our public sub-processor page.
  • International transfers are only made with a lawful transfer mechanism in place.

9. Data Protection Impact Assessments (DPIAs)

A DPIA is required whenever processing is likely to result in a high risk to individuals, and in particular for: new AI features processing health data; large-scale processing of special category data; systematic monitoring; any processing on the ICO's DPIA list. DPIAs are signed off by the DPO before go-live and reviewed on material change.

10. Individual rights

Requests are handled per our Subject Access Request Procedure and answered within one calendar month, extendable by two further months for complex cases with an explanation to the requester.

11. Breach management

All incidents are triaged under our Data Breach Response Plan. Reportable breaches are notified to the ICO within 72 hours and to affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

12. Training and awareness

  • All personnel complete data protection training on induction and annually thereafter.
  • Engineering, clinical and marketing teams receive additional role-specific training.
  • Training completion is tracked and reported to the Board.

13. Audit and monitoring

The DPO performs an annual internal compliance audit and reports findings and remediation to the Board. Independent audit is commissioned where required by customers, regulators or funding conditions.

14. Policy review

This Policy is reviewed at least annually and on any material change to the law, our processing activities or ICO guidance.