← Back to VitalReach

Privacy Policy

VitalReach — part of Vital Healthcare
Last updated: 11 September 2026  ·  Version 1.0

This Privacy Policy explains how your personal data — including sensitive health information — is collected, used, shared and protected when you use the VitalReach app and related Vital Healthcare services. VitalReach uses your phone’s camera to estimate health indicators, so we treat your privacy with the same care expected of a clinical tool.

1. Who we are

VitalReach is operated by Pryvate Technologies Ltd (“Vital Healthcare”, “we”, “us”), the data controller responsible for your personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Where VitalReach is provided to you through a clinic, employer or care provider, that organisation may act as a joint or separate controller for some of your data. We will make that clear to you at the point of sign-up.

2. The data we collect

CategoryExamples
Account dataName, email address, date of birth, account identifiers, login credentials managed via our identity provider.
Health & biometric-derived dataThe numerical results of each scan — e.g. heart rate, heart rate variability, respiratory rate, blood pressure estimates, SpO₂, stress index, BMI — together with scan timestamps and quality/confidence scores.
Consent recordsA record of the explicit biometric-processing consent you give before your first scan, and any later changes.
Device & technical dataDevice model, operating system version, app version, crash and diagnostic logs, and limited analytics about how the app is used.
Subscription dataYour plan status and scan allowance. Payment is processed by the Apple App Store or Google Play; we do not receive or store your card details.
What we do not collect: VitalReach analyses your face on the device in real time. No camera photos or video are stored on your phone by VitalReach, and no raw images or video are ever uploaded to our servers. Only the derived numerical results leave your device.

3. How the camera scan works

The scan runs locally on your device using an on-device measurement engine. The camera feed is processed in memory to estimate physiological signals; the imagery itself is not retained or transmitted. Once the scan completes, only the resulting numbers (and their confidence scores) are encrypted and sent to your Vital Healthcare record.

4. Why we use your data and our legal basis

PurposeLegal basis (UK GDPR)
Providing the scan and storing your results in your health recordPerformance of our contract with you (Art. 6(1)(b)); for health data, your explicit consent (Art. 9(2)(a)).
Processing facial signals to estimate your vitals (biometric processing)Your explicit consent (Art. 9(2)(a)), given before your first scan.
Enabling follow-up and care pathways where your results are flaggedExplicit consent, or the provision of health/care where arranged through your provider (Art. 9(2)(h)).
Managing your account, subscription and supportPerformance of our contract (Art. 6(1)(b)).
Keeping the app secure, diagnosing faults and improving reliabilityOur legitimate interests in a safe, working service (Art. 6(1)(f)).
Meeting legal, regulatory and audit obligationsLegal obligation (Art. 6(1)(c)).

You can withdraw consent at any time (see section 8). Withdrawal does not affect processing carried out before you withdrew.

5. Who we share it with

We do not sell your data, and we do not use it for advertising. We share it only:

6. Storage, security and location

Your results are transmitted over encrypted connections and stored encrypted within your medical record, with access controls and audit logging of each scan. Data is hosted on secure servers; where data is transferred outside the UK, we use appropriate safeguards such as UK adequacy regulations or the International Data Transfer Agreement / Standard Contractual Clauses.

7. How long we keep it

We keep your account and health data for as long as your account is active and for any period required by applicable healthcare record-keeping and legal obligations. When data is no longer needed, it is securely deleted or anonymised. Diagnostic logs are kept only for a limited period.

8. Your rights

Under UK data protection law you have the right to:

To exercise any of these, contact [email protected]. You also have the right to complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk, though we’d appreciate the chance to resolve your concern first.

9. Children

VitalReach is not intended for use by anyone under 18 unless access has been specifically arranged and consented to through an appropriate provider or guardian.

10. Changes to this policy

We may update this Privacy Policy from time to time. Where changes are significant we will notify you in the app. The “last updated” date above shows when it was last revised.

11. Contact us

Questions about this policy or your data: [email protected].

Important — legal review required. This document is a working draft prepared to match the VitalReach service. Before you publish it, please have it reviewed by a qualified data-protection adviser, complete the bracketed placeholders (company number, registered address), and confirm the named contact address and any clinic/provider controller arrangements.