Privacy Policy
This Privacy Policy explains how your personal data — including sensitive health information — is collected, used, shared and protected when you use the VitalReach app and related Vital Healthcare services. VitalReach uses your phone’s camera to estimate health indicators, so we treat your privacy with the same care expected of a clinical tool.
1. Who we are
VitalReach is operated by Pryvate Technologies Ltd (“Vital Healthcare”, “we”, “us”), the data controller responsible for your personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
- Registered company: Pryvate Technologies Ltd, Company No. [COMPANY NUMBER]
- Registered address: [REGISTERED ADDRESS]
- Privacy contact / Data Protection Officer: [email protected]
Where VitalReach is provided to you through a clinic, employer or care provider, that organisation may act as a joint or separate controller for some of your data. We will make that clear to you at the point of sign-up.
2. The data we collect
| Category | Examples |
|---|---|
| Account data | Name, email address, date of birth, account identifiers, login credentials managed via our identity provider. |
| Health & biometric-derived data | The numerical results of each scan — e.g. heart rate, heart rate variability, respiratory rate, blood pressure estimates, SpO₂, stress index, BMI — together with scan timestamps and quality/confidence scores. |
| Consent records | A record of the explicit biometric-processing consent you give before your first scan, and any later changes. |
| Device & technical data | Device model, operating system version, app version, crash and diagnostic logs, and limited analytics about how the app is used. |
| Subscription data | Your plan status and scan allowance. Payment is processed by the Apple App Store or Google Play; we do not receive or store your card details. |
3. How the camera scan works
The scan runs locally on your device using an on-device measurement engine. The camera feed is processed in memory to estimate physiological signals; the imagery itself is not retained or transmitted. Once the scan completes, only the resulting numbers (and their confidence scores) are encrypted and sent to your Vital Healthcare record.
4. Why we use your data and our legal basis
| Purpose | Legal basis (UK GDPR) |
|---|---|
| Providing the scan and storing your results in your health record | Performance of our contract with you (Art. 6(1)(b)); for health data, your explicit consent (Art. 9(2)(a)). |
| Processing facial signals to estimate your vitals (biometric processing) | Your explicit consent (Art. 9(2)(a)), given before your first scan. |
| Enabling follow-up and care pathways where your results are flagged | Explicit consent, or the provision of health/care where arranged through your provider (Art. 9(2)(h)). |
| Managing your account, subscription and support | Performance of our contract (Art. 6(1)(b)). |
| Keeping the app secure, diagnosing faults and improving reliability | Our legitimate interests in a safe, working service (Art. 6(1)(f)). |
| Meeting legal, regulatory and audit obligations | Legal obligation (Art. 6(1)(c)). |
You can withdraw consent at any time (see section 8). Withdrawal does not affect processing carried out before you withdrew.
5. Who we share it with
We do not sell your data, and we do not use it for advertising. We share it only:
- With clinicians, your care provider or Vital Healthcare care pathways, where your care is set up that way or a result is flagged for follow-up;
- With service providers (“processors”) who host and operate the platform on our behalf — for example secure cloud hosting, error logging and push-notification delivery — all bound by contract to protect your data and use it only on our instructions;
- With the Apple App Store or Google Play, which process your subscription payment under their own privacy terms;
- Where we are required to by law, regulation, or a valid legal request, or to protect safety.
6. Storage, security and location
Your results are transmitted over encrypted connections and stored encrypted within your medical record, with access controls and audit logging of each scan. Data is hosted on secure servers; where data is transferred outside the UK, we use appropriate safeguards such as UK adequacy regulations or the International Data Transfer Agreement / Standard Contractual Clauses.
7. How long we keep it
We keep your account and health data for as long as your account is active and for any period required by applicable healthcare record-keeping and legal obligations. When data is no longer needed, it is securely deleted or anonymised. Diagnostic logs are kept only for a limited period.
8. Your rights
Under UK data protection law you have the right to:
- access a copy of the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased in certain circumstances;
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw your consent to biometric and health-data processing at any time.
To exercise any of these, contact [email protected]. You also have the right to complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk, though we’d appreciate the chance to resolve your concern first.
9. Children
VitalReach is not intended for use by anyone under 18 unless access has been specifically arranged and consented to through an appropriate provider or guardian.
10. Changes to this policy
We may update this Privacy Policy from time to time. Where changes are significant we will notify you in the app. The “last updated” date above shows when it was last revised.
11. Contact us
Questions about this policy or your data: [email protected].