Legal & Compliance Centre

AIAH Health Limited · Company No. 17322326

Special Category Data Policy

How AIAH.Health processes health, biomarker, hormonal and mental wellbeing data under Article 9 UK GDPR.

Last updated: 7 July 2026

The core purpose of AIAH Health Limited is to help women understand their own health. That means we process large volumes of special category data. This Policy is our Appropriate Policy Document (APD) for the purposes of Schedule 1 of the Data Protection Act 2018, where required.

1. Categories of special category data

  • General health information — symptoms, conditions, medications, allergies.
  • Reproductive, sexual, fertility, pregnancy and postnatal information.
  • Hormonal health, menstrual cycle, perimenopause and menopause information.
  • Biomarker and bloodwork results uploaded by you or your clinician.
  • Mental wellbeing indicators — mood, sleep, stress and journal entries.
  • Genetic data (where you choose to upload it).

2. Article 9 conditions relied on

  • Explicit consent (Art. 9(2)(a)) — the primary condition for entries you make in the Service, for research participation, and for enabling AI features.
  • Provision of health or social care (Art. 9(2)(h)) — where we facilitate clinical services with a registered healthcare professional bound by professional secrecy.
  • Public interest in the area of public health (Art. 9(2)(i)) — for pseudonymised health research under governance.
  • Scientific research (Art. 9(2)(j)) — with Article 89 safeguards and an approved protocol.

Where a DPA 2018 Sch. 1 condition is engaged, this Policy serves as the required Appropriate Policy Document.

3. Data minimisation

  • Only fields necessary for the specific feature are collected.
  • New fields are approved by the DPO before launch.
  • Free-text fields include user guidance not to enter identifying data about third parties.

4. Consent management

  • Explicit consent is obtained through clear affirmative action, separately from acceptance of general Terms.
  • Consent statements identify the specific purpose, data categories and any transfers.
  • Withdrawal is as easy as giving consent, and is available in the account settings.
  • We keep an immutable consent log with timestamp, version and the wording accepted.

5. Access controls

  • Least-privilege role-based access to health data; production access requires multi-factor authentication.
  • Just-in-time production access via a documented approval workflow for time-limited investigations.
  • All production access is logged, monitored and reviewed monthly.

6. Security measures

  • Encryption in transit (TLS 1.2+).
  • Encryption at rest (AES-256) on databases, object storage and backups.
  • End-to-end encryption for designated sensitive fields, where technically feasible.
  • Field-level pseudonymisation where identity is not required for the feature.
  • Secure key management with rotation and dual control.

7. Retention

Retention aligns with the Data Retention Policy. Health data is deleted within 30 days of a verified deletion request (subject to backup rotation of up to 35 days) and is not carried into research datasets without a separate lawful basis.

8. Sharing

  • Health data is not sold, and is not shared with advertisers or data brokers.
  • Sharing with clinicians happens only where you explicitly initiate it.
  • Processors handling health data are bound by Article 28 contracts and confidentiality obligations.

9. Governance

The DPO reviews Article 9 processing quarterly, monitors incidents and consent metrics, and reports to the Board. This Policy is reviewed annually or on material change.