Omni Health
DRAFT for legal review. Every [bracketed] item is a placeholder to confirm before publishing. This describes how the platform processes personal data today and is written to align with the UK GDPR / EU GDPR — but it is not legal advice and must be reviewed and approved.

Privacy Policy

How OmniHealth handles your personal data · Last updated: [EFFECTIVE DATE]

1. Who we are

OmniHealth (“we”, “us”) is a health platform that lets individuals and families record, understand and share their health information, and lets health service providers and third-party developers offer tools and services within it.

The data controller for the personal data described here is [LEGAL ENTITY NAME, company number, registered address]. Our Data Protection Officer is [DPO NAME / ROLE] and can be contacted at [DPO EMAIL].

Service providers as controllers. When a health service provider uses the platform to deliver care to you, that provider is a separate (or joint) controller for the data they collect about you in that capacity. This policy covers our processing; your provider should give you their own privacy information. [Confirm controller / joint-controller arrangements and Art 26 responsibilities.]

A personal health record, not your official medical record. OmniHealth is a personal health record that you own and control — not the official medical record kept by your GP or hospital, and not a medical device. For a plain-language explanation of what that means, see Your health record, explained.

2. What personal data we collect

CategoryExamples
Account & identityName, email, phone number, date of birth, address, country of residence, password (stored only as a secure hash).
Health data (special category)Health-river entries, notes, documents and images you add; medicines; data recorded through monitoring tools; patient records you create or that are shared with you.
Provider & developer dataOrganisation details, verification information, service definitions, API client and webhook configuration.
PaymentsWallet balance and transactions, orders, and country of a transaction. Card details are handled by our payment provider — we do not store them. [Confirm payment provider(s).]
Usage & technicalIP address, device/browser information, session data, sign-in attempts (for security), audit logs of significant actions.
CommunicationsIn-app notifications, emails we send you, and support correspondence.

3. Why we process your data, and our legal bases

PurposeLegal basis (UK/EU GDPR)
Provide and operate your account and the platformPerformance of a contract — Art 6(1)(b).
Store and process your health information and toolsYour explicit consent — Art 9(2)(a); and, where a provider delivers care, provision of health/social care — Art 9(2)(h). [Confirm chosen Art 9 basis per feature.]
Sharing with providers/family you chooseExplicit consent — Art 9(2)(a); contract — Art 6(1)(b).
AI clinical-information featuresExplicit consent — Art 9(2)(a). Data is de-identified before any external processing (see §5).
Payments and walletContract — Art 6(1)(b); legal obligation for financial records — Art 6(1)(c).
Security, fraud & abuse prevention (incl. sign-in throttling)Legitimate interests — Art 6(1)(f).
Service messages and, where you opt in, other communicationsContract — Art 6(1)(b); consent — Art 6(1)(a) for optional messages.
Meeting legal and regulatory obligationsLegal obligation — Art 6(1)(c).

Where we rely on consent, you can withdraw it at any time (see §9); withdrawal does not affect processing already carried out. [Confirm how consent is captured and recorded at sign-up and per feature.]

4. Health data (special category data)

Most of what the platform holds is health data, which the GDPR gives extra protection. We only process it on one of the Article 9 bases above, we apply role- and permission-based access controls so only people you have authorised can see it, and we keep audit records of significant access and changes. Some entries can be marked visible only to verified medical professionals and withheld from other users.

5. AI features and de-identification

The platform offers an optional AI feature that answers health questions about a patient. Before any data is sent to our AI provider, it is de-identified: name, date of birth and contact details are removed, and a pseudonymous reference is used instead. The AI returns information and reasoning support only — it does not diagnose or make decisions with legal or similarly significant effects about you, and it is used under human oversight. This means it is not “solely automated decision-making” under Art 22. [Confirm this characterisation and whether a DPIA has been completed for the AI feature.]

De-identification substantially reduces, but does not entirely remove, identifiability; the data sent remains pseudonymised personal data, processed under your explicit consent and our processor terms with the AI provider (see §6–7).

6. Who we share your data with

We do not sell your data. We share it only as needed to run the service, with:

RecipientPurpose
Health service providers and family/carersOnly those you explicitly grant access to, at the level you choose.
Third-party developers (via our API)Only data produced by a service you have enabled, and only with the permissions granted; access is consent-gated and logged. Broader access requires a separate administrative grant.
OpenAI (AI processing)De-identified content for the AI feature only. [Confirm processor / DPA in place.]
Mailgun (email delivery)To send account and service emails. [Confirm processor / DPA.]
DigitalOcean (hosting & backups)Infrastructure and backups. [Confirm region and DPA.]
Payment providerTo process payments. [Confirm provider / DPA.]
Authorities / advisersWhere required by law, or to establish, exercise or defend legal claims.

Each processor acts under a written data-processing agreement and only on our instructions. [Maintain a Record of Processing Activities and a processor register.]

7. International transfers

The platform is hosted in the [UK / hosting region]. Some processors are outside the UK/EEA — in particular our AI provider processes data in the United States. Where we transfer personal data internationally we rely on an appropriate safeguard, such as the UK International Data Transfer Agreement / Addendum or the EU Standard Contractual Clauses, together with a transfer risk assessment. [Confirm the exact mechanism per processor and attach/reference it.]

8. How long we keep your data

We keep personal data only as long as needed for the purposes above, then delete or anonymise it. Indicative periods: [account data — while your account is active + X; health records — [retention period, noting any clinical-record retention requirements]; payment records — [statutory period, e.g. 6 years]; security logs — [X months]; login-attempt logs — pruned automatically after a short window]. Health-record retention obligations can extend beyond a deletion request; where they apply we restrict rather than delete (see §9). [Confirm a retention schedule.]

9. Your rights

Under the UK/EU GDPR you have the right to: access your data; have it corrected; have it erased (“right to be forgotten”); restrict or object to processing; data portability; and to withdraw consent at any time. You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects (see §5).

To exercise any right, contact us at [PRIVACY CONTACT EMAIL]. We will respond within one month. Some rights are qualified — for example, we may need to retain certain health or financial records to meet legal obligations, in which case we will restrict rather than delete and explain why. [Confirm the identity-verification step and the erasure/restriction workflow, including data held by providers/developers.]

If you are unhappy with how we handle your data you can complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk, or your local supervisory authority. We would appreciate the chance to address your concern first.

10. How we protect your data

  • Encryption in transit (HTTPS/TLS) for all connections.
  • Passwords stored only as strong one-way hashes; sign-in attempts are rate-limited and abusive sources blocked.
  • Role- and permission-based access controls, with audit logging of significant actions.
  • De-identification before external AI processing.
  • Regular backups. [Confirm encryption at rest and backup handling; a more secure distributed storage model is planned.]

No system is perfectly secure, but we work to protect your data and will notify you and the relevant authority of a personal-data breach where required. [Confirm breach-response procedure and 72-hour notification readiness.]

11. Cookies & similar technologies

We use a strictly necessary session cookie to keep you signed in and to protect forms against cross-site request forgery. [Confirm whether any non-essential/analytics cookies are used; if so, add a cookie banner and consent mechanism and list them here.]

12. Children

Families may hold records for children. Where a record concerns a child, it is managed by a parent or guardian with authority to do so. [Confirm the minimum age for a self-managed account and the parental-consent approach, per UK age of digital consent (13) and any clinical considerations.]

13. Changes & contact

We may update this policy; we will change the “last updated” date and, for material changes, tell you in advance. Questions or requests: [PRIVACY CONTACT EMAIL] · Data Protection Officer: [DPO EMAIL].

×