How OmniHealth handles your personal data · Last updated: [EFFECTIVE DATE]
OmniHealth (“we”, “us”) is a health platform that lets individuals and families record, understand and share their health information, and lets health service providers and third-party developers offer tools and services within it.
The data controller for the personal data described here is [LEGAL ENTITY NAME, company number, registered address]. Our Data Protection Officer is [DPO NAME / ROLE] and can be contacted at [DPO EMAIL].
Service providers as controllers. When a health service provider uses the platform to deliver care to you, that provider is a separate (or joint) controller for the data they collect about you in that capacity. This policy covers our processing; your provider should give you their own privacy information. [Confirm controller / joint-controller arrangements and Art 26 responsibilities.]
A personal health record, not your official medical record. OmniHealth is a personal health record that you own and control — not the official medical record kept by your GP or hospital, and not a medical device. For a plain-language explanation of what that means, see Your health record, explained.
| Category | Examples |
|---|---|
| Account & identity | Name, email, phone number, date of birth, address, country of residence, password (stored only as a secure hash). |
| Health data (special category) | Health-river entries, notes, documents and images you add; medicines; data recorded through monitoring tools; patient records you create or that are shared with you. |
| Provider & developer data | Organisation details, verification information, service definitions, API client and webhook configuration. |
| Payments | Wallet balance and transactions, orders, and country of a transaction. Card details are handled by our payment provider — we do not store them. [Confirm payment provider(s).] |
| Usage & technical | IP address, device/browser information, session data, sign-in attempts (for security), audit logs of significant actions. |
| Communications | In-app notifications, emails we send you, and support correspondence. |
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Provide and operate your account and the platform | Performance of a contract — Art 6(1)(b). |
| Store and process your health information and tools | Your explicit consent — Art 9(2)(a); and, where a provider delivers care, provision of health/social care — Art 9(2)(h). [Confirm chosen Art 9 basis per feature.] |
| Sharing with providers/family you choose | Explicit consent — Art 9(2)(a); contract — Art 6(1)(b). |
| AI clinical-information features | Explicit consent — Art 9(2)(a). Data is de-identified before any external processing (see §5). |
| Payments and wallet | Contract — Art 6(1)(b); legal obligation for financial records — Art 6(1)(c). |
| Security, fraud & abuse prevention (incl. sign-in throttling) | Legitimate interests — Art 6(1)(f). |
| Service messages and, where you opt in, other communications | Contract — Art 6(1)(b); consent — Art 6(1)(a) for optional messages. |
| Meeting legal and regulatory obligations | Legal obligation — Art 6(1)(c). |
Where we rely on consent, you can withdraw it at any time (see §9); withdrawal does not affect processing already carried out. [Confirm how consent is captured and recorded at sign-up and per feature.]
Most of what the platform holds is health data, which the GDPR gives extra protection. We only process it on one of the Article 9 bases above, we apply role- and permission-based access controls so only people you have authorised can see it, and we keep audit records of significant access and changes. Some entries can be marked visible only to verified medical professionals and withheld from other users.
The platform offers an optional AI feature that answers health questions about a patient. Before any data is sent to our AI provider, it is de-identified: name, date of birth and contact details are removed, and a pseudonymous reference is used instead. The AI returns information and reasoning support only — it does not diagnose or make decisions with legal or similarly significant effects about you, and it is used under human oversight. This means it is not “solely automated decision-making” under Art 22. [Confirm this characterisation and whether a DPIA has been completed for the AI feature.]
De-identification substantially reduces, but does not entirely remove, identifiability; the data sent remains pseudonymised personal data, processed under your explicit consent and our processor terms with the AI provider (see §6–7).
We do not sell your data. We share it only as needed to run the service, with:
| Recipient | Purpose |
|---|---|
| Health service providers and family/carers | Only those you explicitly grant access to, at the level you choose. |
| Third-party developers (via our API) | Only data produced by a service you have enabled, and only with the permissions granted; access is consent-gated and logged. Broader access requires a separate administrative grant. |
| OpenAI (AI processing) | De-identified content for the AI feature only. [Confirm processor / DPA in place.] |
| Mailgun (email delivery) | To send account and service emails. [Confirm processor / DPA.] |
| DigitalOcean (hosting & backups) | Infrastructure and backups. [Confirm region and DPA.] |
| Payment provider | To process payments. [Confirm provider / DPA.] |
| Authorities / advisers | Where required by law, or to establish, exercise or defend legal claims. |
Each processor acts under a written data-processing agreement and only on our instructions. [Maintain a Record of Processing Activities and a processor register.]
The platform is hosted in the [UK / hosting region]. Some processors are outside the UK/EEA — in particular our AI provider processes data in the United States. Where we transfer personal data internationally we rely on an appropriate safeguard, such as the UK International Data Transfer Agreement / Addendum or the EU Standard Contractual Clauses, together with a transfer risk assessment. [Confirm the exact mechanism per processor and attach/reference it.]
We keep personal data only as long as needed for the purposes above, then delete or anonymise it. Indicative periods: [account data — while your account is active + X; health records — [retention period, noting any clinical-record retention requirements]; payment records — [statutory period, e.g. 6 years]; security logs — [X months]; login-attempt logs — pruned automatically after a short window]. Health-record retention obligations can extend beyond a deletion request; where they apply we restrict rather than delete (see §9). [Confirm a retention schedule.]
Under the UK/EU GDPR you have the right to: access your data; have it corrected; have it erased (“right to be forgotten”); restrict or object to processing; data portability; and to withdraw consent at any time. You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects (see §5).
To exercise any right, contact us at [PRIVACY CONTACT EMAIL]. We will respond within one month. Some rights are qualified — for example, we may need to retain certain health or financial records to meet legal obligations, in which case we will restrict rather than delete and explain why. [Confirm the identity-verification step and the erasure/restriction workflow, including data held by providers/developers.]
If you are unhappy with how we handle your data you can complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk, or your local supervisory authority. We would appreciate the chance to address your concern first.
No system is perfectly secure, but we work to protect your data and will notify you and the relevant authority of a personal-data breach where required. [Confirm breach-response procedure and 72-hour notification readiness.]
We use a strictly necessary session cookie to keep you signed in and to protect forms against cross-site request forgery. [Confirm whether any non-essential/analytics cookies are used; if so, add a cookie banner and consent mechanism and list them here.]
Families may hold records for children. Where a record concerns a child, it is managed by a parent or guardian with authority to do so. [Confirm the minimum age for a self-managed account and the parental-consent approach, per UK age of digital consent (13) and any clinical considerations.]
We may update this policy; we will change the “last updated” date and, for material changes, tell you in advance. Questions or requests: [PRIVACY CONTACT EMAIL] · Data Protection Officer: [DPO EMAIL].