This Privacy Policy covers the Closed Alpha service provided by Health Data Avatar. It explains what information we gather, how we use it, and your legal rights regarding your data.
Effective Date: 2025-08-07
Health Data Avatar (“HDA”, “we”, “our”, “us”) is committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR).This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our services.
“Our Service” refers to the Health Data Avatar App, allowing you to upload, process, and interact with your personal files and medical data.
The "Waiting List" refers to users proactively subscribing for early access to the Health Data Avatar App.
"Marketing Updates" refers to users proactively subscribing for news, features, and other promotional content.
Health Data Avatar Ltd is registered with Companies House in the UK, with company number 16236443
Data Controller: Health Data Avatar
Data Protection Officer: Hex Miller-Bakewell
Email: hex@healthdataavatar.com
We collect the following types of personal data:
Collected only with your explicit consent:
Collected only with your explicit consent:
We process your personal data under the following legal bases:
You can unsubscribe from marketing emails at any time by using the link provided in each email.
For example, if a user opts-in to analytics tracking then we may track the on-boarding process to determine whether people leave before completing it.
Retained until you unsubscribe, or a maximum of 12 months after the public launch of the service, whichever is sooner.
Retained until you unsubscribe.
Retained for up to 12 months, so we can determine how usage of our services changes over time.
Retained for up to 31 days,
Your data is stored on servers located within the European Union (EU) or European Economic Area (EEA).
We apply appropriate technical and organizational measures, including:
We use Microsoft Azure services to store and process your service data.For Marketing Updates and Waiting List data we also use Microsoft Azure, Google Cloud and Amazon AWS.The Microsoft, Google, and AWS services we use are all certified under key international standards (e.g. ISO/IEC 27001, 27017, 27018) and provides contractual assurances as a data processor under the GDPR.
We rely on third-party service providers (subprocessors) to help deliver and maintain our services.
Each subprocessors is contractually obligated to comply with GDPR and provide appropriate safeguards for personal data.
Our primary subprocessors include:
We ensure all subprocessors process data only under our instructions and with sufficient technical and organizational safeguards in place.
We do not use cookies or trackers for analytics or advertising.
However, we use your browser's local storage to store session data for authentication and data cacheing (e.g. keeping you logged in even when you close your browser).This data is not shared with third parties or used for profiling or tracking.
This usage is considered essential to the operation of the service and does not require consent under the ePrivacy Directive.
We do not use your personal data for automated decision-making,including profiling.
You must be at least 16 years old to consent to the processing of your personal data.If you are under 16, consent must be provided by someone with parental responsibility.
You have the following rights regarding your personal data:
You can exercise these rights directly from within the app itself, or by contacting the Data Protection Officer (whose details are at the top of this document).
As we process sensitive health data, we have completed a Data Protection Impact Assessment (DPIA).Any data breaches affecting your data will be reported within 72 hours of discovery.
You can withdraw your consent at any time by:
Withdrawal of consent does not affect the lawfulness of processing prior to withdrawal.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO):
Information Commissioner’s OfficeWycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
If you are an EU resident, you also have the right to lodge a complaint with your local data protection authority.A list of national data protection authorities in the EU is available here:https://edpb.europa.eu/about-edpb/board/members_en
We may update this Privacy Policy from time to time.When we make material changes, we will update the effective date and provide a prominent notice via our service.
If you have any questions or concerns about this Privacy Policy, please contact the Data Protection Officer.
This Privacy Policy covers the Closed Alpha service provided by Health Data Avatar. It explains what information we gather, how we use it, and your legal rights regarding your data.
Effective Date: 2025-08-07
Health Data Avatar (“HDA”, “we”, “our”, “us”) is committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR).This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our services.
“Our Service” refers to the Health Data Avatar App, allowing you to upload, process, and interact with your personal files and medical data.
The "Waiting List" refers to users proactively subscribing for early access to the Health Data Avatar App.
"Marketing Updates" refers to users proactively subscribing for news, features, and other promotional content.
Health Data Avatar Ltd is registered with Companies House in the UK, with company number 16236443
Data Controller: Health Data Avatar
Data Protection Officer: Hex Miller-Bakewell
Email: hex@healthdataavatar.com
We collect the following types of personal data:
Collected only with your explicit consent:
Collected only with your explicit consent:
We process your personal data under the following legal bases:
You can unsubscribe from marketing emails at any time by using the link provided in each email.
For example, if a user opts-in to analytics tracking then we may track the on-boarding process to determine whether people leave before completing it.
Retained until you unsubscribe, or a maximum of 12 months after the public launch of the service, whichever is sooner.
Retained until you unsubscribe.
Retained for up to 12 months, so we can determine how usage of our services changes over time.
Retained for up to 31 days,
Your data is stored on servers located within the European Union (EU) or European Economic Area (EEA).
We apply appropriate technical and organizational measures, including:
We use Microsoft Azure services to store and process your service data.For Marketing Updates and Waiting List data we also use Microsoft Azure, Google Cloud and Amazon AWS.The Microsoft, Google, and AWS services we use are all certified under key international standards (e.g. ISO/IEC 27001, 27017, 27018) and provides contractual assurances as a data processor under the GDPR.
We rely on third-party service providers (subprocessors) to help deliver and maintain our services.
Each subprocessors is contractually obligated to comply with GDPR and provide appropriate safeguards for personal data.
Our primary subprocessors include:
We ensure all subprocessors process data only under our instructions and with sufficient technical and organizational safeguards in place.
We do not use cookies or trackers for analytics or advertising.
However, we use your browser's local storage to store session data for authentication and data cacheing (e.g. keeping you logged in even when you close your browser).This data is not shared with third parties or used for profiling or tracking.
This usage is considered essential to the operation of the service and does not require consent under the ePrivacy Directive.
We do not use your personal data for automated decision-making,including profiling.
You must be at least 16 years old to consent to the processing of your personal data.If you are under 16, consent must be provided by someone with parental responsibility.
You have the following rights regarding your personal data:
You can exercise these rights directly from within the app itself, or by contacting the Data Protection Officer (whose details are at the top of this document).
As we process sensitive health data, we have completed a Data Protection Impact Assessment (DPIA).Any data breaches affecting your data will be reported within 72 hours of discovery.
You can withdraw your consent at any time by:
Withdrawal of consent does not affect the lawfulness of processing prior to withdrawal.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO):
Information Commissioner’s OfficeWycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
If you are an EU resident, you also have the right to lodge a complaint with your local data protection authority.A list of national data protection authorities in the EU is available here:https://edpb.europa.eu/about-edpb/board/members_en
We may update this Privacy Policy from time to time.When we make material changes, we will update the effective date and provide a prominent notice via our service.
If you have any questions or concerns about this Privacy Policy, please contact the Data Protection Officer.
This Privacy Policy covers the Closed Alpha service provided by Health Data Avatar. It explains what information we gather, how we use it, and your legal rights regarding your data.
Effective Date: 2025-08-07
Health Data Avatar (“HDA”, “we”, “our”, “us”) is committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR).This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our services.
“Our Service” refers to the Health Data Avatar App, allowing you to upload, process, and interact with your personal files and medical data.
The "Waiting List" refers to users proactively subscribing for early access to the Health Data Avatar App.
"Marketing Updates" refers to users proactively subscribing for news, features, and other promotional content.
Health Data Avatar Ltd is registered with Companies House in the UK, with company number 16236443
Data Controller: Health Data Avatar
Data Protection Officer: Hex Miller-Bakewell
Email: hex@healthdataavatar.com
We collect the following types of personal data:
Collected only with your explicit consent:
Collected only with your explicit consent:
We process your personal data under the following legal bases:
You can unsubscribe from marketing emails at any time by using the link provided in each email.
For example, if a user opts-in to analytics tracking then we may track the on-boarding process to determine whether people leave before completing it.
Retained until you unsubscribe, or a maximum of 12 months after the public launch of the service, whichever is sooner.
Retained until you unsubscribe.
Retained for up to 12 months, so we can determine how usage of our services changes over time.
Retained for up to 31 days,
Your data is stored on servers located within the European Union (EU) or European Economic Area (EEA).
We apply appropriate technical and organizational measures, including:
We use Microsoft Azure services to store and process your service data.For Marketing Updates and Waiting List data we also use Microsoft Azure, Google Cloud and Amazon AWS.The Microsoft, Google, and AWS services we use are all certified under key international standards (e.g. ISO/IEC 27001, 27017, 27018) and provides contractual assurances as a data processor under the GDPR.
We rely on third-party service providers (subprocessors) to help deliver and maintain our services.
Each subprocessors is contractually obligated to comply with GDPR and provide appropriate safeguards for personal data.
Our primary subprocessors include:
We ensure all subprocessors process data only under our instructions and with sufficient technical and organizational safeguards in place.
We do not use cookies or trackers for analytics or advertising.
However, we use your browser's local storage to store session data for authentication and data cacheing (e.g. keeping you logged in even when you close your browser).This data is not shared with third parties or used for profiling or tracking.
This usage is considered essential to the operation of the service and does not require consent under the ePrivacy Directive.
We do not use your personal data for automated decision-making,including profiling.
You must be at least 16 years old to consent to the processing of your personal data.If you are under 16, consent must be provided by someone with parental responsibility.
You have the following rights regarding your personal data:
You can exercise these rights directly from within the app itself, or by contacting the Data Protection Officer (whose details are at the top of this document).
As we process sensitive health data, we have completed a Data Protection Impact Assessment (DPIA).Any data breaches affecting your data will be reported within 72 hours of discovery.
You can withdraw your consent at any time by:
Withdrawal of consent does not affect the lawfulness of processing prior to withdrawal.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO):
Information Commissioner’s OfficeWycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
If you are an EU resident, you also have the right to lodge a complaint with your local data protection authority.A list of national data protection authorities in the EU is available here:https://edpb.europa.eu/about-edpb/board/members_en
We may update this Privacy Policy from time to time.When we make material changes, we will update the effective date and provide a prominent notice via our service.
If you have any questions or concerns about this Privacy Policy, please contact the Data Protection Officer.