Legal & Compliance Centre

AIAH Health Limited · Company No. 17322326

Subject Access Request Procedure

How to make a Subject Access Request and how AIAH.Health handles it under UK GDPR.

Last updated: 7 July 2026

AIAH Health Limited is committed to responding promptly and transparently to requests from individuals exercising their rights under UK GDPR. This procedure explains how we handle Subject Access Requests (SARs) and other data subject rights requests.

1. How to make a request

You can make a request by email to [dpo@aiah.health], by post to the Data Protection Officer at our registered office, or via the account settings page in the App. Requests can be made in any format and do not need to reference the UK GDPR.

2. What you can request

  • Access to a copy of the personal data we hold about you.
  • Correction of inaccurate or incomplete data.
  • Erasure of your data ('right to be forgotten').
  • Restriction of processing.
  • Data portability.
  • Objection to processing (including direct marketing).
  • Withdrawal of consent, where processing is based on consent.
  • Not to be subject to a solely automated decision producing legal or similarly significant effects.

3. Identity verification

To protect your data we must verify your identity before disclosing information. We may ask you to confirm details we already hold, or to provide proof of identity where the request cannot be authenticated through your account. We ask only for what is necessary and proportionate.

4. Response timeframe

We respond within one calendar month of receiving your request (or of receiving the information needed to identify you). We may extend by up to two further months for complex or numerous requests; if we do, we tell you within one month and explain why.

5. Fees

Requests are free of charge. We may charge a reasonable fee based on administrative costs, or refuse the request, where it is manifestly unfounded or excessive (in particular if repetitive), and we will explain our decision.

6. Format of response

Where you make the request electronically we provide the information in a common electronic format (usually PDF and/or machine-readable JSON) unless you ask otherwise. Portability responses are provided in a structured, commonly used, machine-readable format.

7. Exemptions

Certain exemptions apply under UK GDPR and the DPA 2018 — for example where disclosure would infringe another person's rights, prejudice ongoing negotiations, breach legal professional privilege, or affect crime prevention. Where an exemption applies we tell you which one and why, unless doing so would defeat the purpose of the exemption.

8. Refusals

If we refuse a request we will explain the reason, inform you of your right to complain to the ICO and your right to seek a judicial remedy.

9. Third-party data

Where responding would disclose data about another individual, we consider whether it is reasonable to disclose without their consent, and redact where appropriate.

10. Record keeping

We keep a record of every request, the response and the reasoning for 6 years.

11. Appeals and complaints

If you are not satisfied with our response, please contact our DPO at [dpo@aiah.health]. You may also complain to the ICO at https://ico.org.uk or 0303 123 1113.