Legal & Compliance Centre

AIAH Health Limited · Company No. 17322326

Privacy Policy

How AIAH.Health collects, uses and protects your personal data under UK GDPR and the Data Protection Act 2018.

Last updated: 7 July 2026

AIAH Health Limited (company number 17322326), a company incorporated in England and Wales with registered office at [REGISTERED OFFICE ADDRESS] ("AIAH.Health", "we", "us", "our"), is the data controller for personal data processed through the AIAH.Health website, mobile application, member services, webinars, courses, newsletters, research programmes and related services (together, the "Service"). We are registered with the UK Information Commissioner's Office under registration number [ICO REGISTRATION NUMBER].

1. Scope and about us

This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, how long we keep it, and the rights you have. It applies to visitors, account holders, members, research participants, newsletter subscribers, event attendees, prospective customers and healthcare partners.

Data protection queries: [dpo@aiah.health]. Postal correspondence: Data Protection Officer, AIAH Health Limited, [REGISTERED OFFICE ADDRESS].

2. Personal data we collect

Data you provide

  • Identity and contact data: name, email, date of birth or age band, country of residence.
  • Account and security data: password (hashed), authentication tokens, sign-in history, device identifiers.
  • Membership and payment data: subscription tier, billing address, VAT status, payment method reference (payment card details are handled by our PCI-DSS compliant payment processor, not stored by us).
  • Communications data: correspondence with our support, community and clinical teams, appointment or webinar bookings.
  • User-generated content: journal entries, symptom logs, mood entries, uploaded photographs, community posts.

Special category health data (Article 9 UK GDPR)

  • Menstrual cycle, perimenopause and menopause data.
  • Reproductive, sexual, fertility, pregnancy and postnatal information.
  • Symptoms, mood, sleep, mental wellbeing indicators.
  • Uploaded bloodwork, biomarker and clinical documents.
  • Family and personal medical history you choose to share.
  • Medication, supplement and allergen information.

Data collected automatically

  • Technical data: IP address, browser type and version, operating system, device model, time-zone, language.
  • Usage data: pages viewed, features used, referring URLs, in-app events, aggregated engagement metrics.
  • Cookies and similar technologies (see our Cookie Policy).

Data from third parties

  • Authentication providers (e.g. Google Sign-In) — profile identifier and email.
  • Payment processor (Stripe) — payment status, subscription events, fraud signals.
  • Wearable and lab integrations you explicitly connect.
  • Publicly available professional information for clinicians who apply to join our network.

3. Lawful bases for processing under UK GDPR

We rely on the following lawful bases in Article 6 UK GDPR:

  • Contract (Art. 6(1)(b)) — to create and operate your account, deliver the Service, process membership and take payment.
  • Legitimate interests (Art. 6(1)(f)) — to secure the Service, prevent fraud and abuse, improve product quality, run analytics on aggregated data, and communicate with existing customers about similar services (subject to your right to object).
  • Consent (Art. 6(1)(a)) — for non-essential cookies, marketing communications to prospects, optional research participation, and connecting third-party integrations.
  • Legal obligation (Art. 6(1)(c)) — for tax, accounting, safeguarding and regulatory record-keeping.
  • Vital interests (Art. 6(1)(d)) — in the rare event of an urgent safeguarding risk to you or another person.

For special category health data we additionally rely on one or more Article 9 UK GDPR conditions:

  • Explicit consent (Art. 9(2)(a)) — the primary basis for entries you log in the Service and for research participation.
  • Provision of health or social care (Art. 9(2)(h)) with DPA 2018 Sch. 1 safeguards — where we facilitate clinical services with a registered healthcare professional.
  • Public interest in the area of public health (Art. 9(2)(i)) — for de-identified health research conducted under appropriate governance.
  • Scientific research (Art. 9(2)(j)) — under Article 89 safeguards with an approved protocol.

4. How we use your data

  • Provide, personalise and improve the Service and generate the intelligence, insights and educational content you request.
  • Operate memberships, process payments, issue receipts and manage renewals.
  • Send transactional and safety-related communications you cannot opt out of while an account is active (e.g. security alerts, service changes).
  • Send marketing, editorial and educational newsletters where you have opted in or where the soft opt-in for existing customers applies.
  • Run internal research and product analytics on aggregated or pseudonymised data.
  • Comply with legal obligations, respond to lawful requests and enforce our Terms.
  • Detect, prevent and investigate fraud, abuse and security incidents.

5. Automated decision-making and AI transparency

The Service uses artificial intelligence to organise, summarise and provide educational context for the information you enter — for example, to surface patterns in your symptom entries or to draft narrative explanations of uploaded bloodwork. These outputs are educational and informational only, are not medical advice, and are not a diagnosis.

We do not use solely automated decision-making that produces legal or similarly significant effects on you within the meaning of Article 22 UK GDPR. A human — either you as the user, or one of our clinical or support team — remains in the decision loop for any consequential action (such as booking a clinician, changing your medication or altering your care).

Where AI features process your health data, we rely on your explicit consent, we minimise inputs to what is necessary for the feature, and we retain audit records of prompts and outputs for safety monitoring. You may disable AI features from your account settings.

6. Who we share your data with

  • Service providers acting as our processors under written contracts that meet Article 28 UK GDPR: cloud hosting, database, authentication, email delivery, payment processing, analytics, error tracking, customer support and AI model providers.
  • Clinicians and clinical services you explicitly book or share your data with — as separate controllers or joint controllers, as appropriate.
  • Research collaborators and academic partners — using de-identified or explicit-consent datasets under governance agreements.
  • Regulators, courts, law enforcement and other authorities where legally required.
  • Professional advisers (lawyers, auditors, accountants) under confidentiality obligations.
  • A successor entity in the event of a merger, acquisition, restructuring or asset transfer, subject to equivalent protection.

We do not sell your personal data. We do not share your identifiable health data with advertisers, data brokers or social media platforms for advertising purposes.

7. International transfers

Where personal data is transferred outside the United Kingdom, we rely on: (a) UK adequacy regulations; (b) the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses; or (c) another lawful transfer mechanism. We complete a Transfer Impact Assessment where required and apply supplementary measures such as encryption and pseudonymisation. A copy of the relevant safeguards is available on request from our DPO.

8. Data retention

We keep personal data only for as long as necessary for the purposes for which it was collected. Full periods are set out in our Data Retention Policy; headline periods are:

  • Active account data: for the life of your account, plus 12 months after closure to allow reinstatement.
  • Health entries (journals, cycles, symptoms, bloodwork): retained while your account is active; deleted within 30 days of verified account deletion request, subject to limited backup rotation.
  • Financial and tax records: 6 years after the end of the accounting period (UK statutory).
  • Marketing preferences and suppression list: retained indefinitely to honour opt-outs.
  • Support correspondence: 3 years from case closure.
  • Research data collected with consent: as set out in the specific research consent notice, typically pseudonymised and retained for 10 years.
  • Website analytics: aggregated data retained for up to 26 months.

9. Security

We apply technical and organisational measures appropriate to the risk, including: encryption in transit (TLS 1.2+); encryption at rest (AES-256) for stored health data; end-to-end encryption for designated sensitive fields where feasible; multi-factor authentication for staff and administrative access; role-based access control and least-privilege; secure software development lifecycle, code review and dependency scanning; independent penetration testing; documented incident response; and continuous logging and monitoring. Full detail is set out in our Information Security Policy.

10. Your rights

Subject to the conditions in UK GDPR, you have the right to: be informed; access your data; rectify inaccurate data; erasure ('right to be forgotten'); restrict processing; data portability; object to processing (including direct marketing); and not to be subject to solely automated decision-making. Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of earlier processing.

To exercise any right, contact [dpo@aiah.health]. Our Subject Access Request Procedure explains the process and identity verification steps.

11. Children

The Service is intended for users aged 16 and over. We do not knowingly collect data from children under 16. If you believe a child has provided personal data, please contact us so we can delete it.

12. Cookies

We use cookies and similar technologies as set out in our Cookie Policy. Non-essential cookies are only set with your consent through our cookie banner.

13. Changes to this policy

We may update this Policy from time to time. Material changes will be notified in-app or by email at least 14 days before they take effect where practical. The version and date at the top of this Policy identify the current version.

14. Complaints and contact

If you have a concern about how we handle your personal data, please contact us first at [dpo@aiah.health] so we can try to resolve it. You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at any time: https://ico.org.uk, telephone 0303 123 1113, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.