Privacy & Data

Privacy & Cookie
Policy

How BioHealthcare Group collects, uses, protects, and shares your personal data - and how we use cookies across our digital platforms.

01

Who We Are

Part 1 of 2
Privacy Policy

BioHealthcare Group Ltd is the data controller for personal information collected through our websites and services. We are a UK-registered company operating across the UK, USA, EU, UAE, and India.

Data Controller

BioHealthcare Group Ltd - registered in England & Wales.
Data Protection Officer: privacy@biohealthcare.group

02

Data We Collect

CategoryExamplesSource
Identity DataName, date of birth, titleYou directly
Contact DataEmail, phone, postal addressYou directly
Financial DataPayment details, billing addressYou / payment processor
Technical DataIP address, browser, device ID, cookiesAutomatically
Usage DataPages visited, time on site, links clickedAutomatically
Communications DataEnquiry forms, emails, support requestsYou directly
Marketing PreferencesOpt-ins, consents, preferencesYou directly
Health & Biometric Data ★Biomarkers, diagnostics, monitoring dataYou / clinical partners (consent)
★ Special Category

Health and biometric data is processed only with your explicit consent. See the Health Data section below.

03

How We Use Your Data

  • Respond to enquiries and deliver requested services
  • Provide, manage, and improve our platforms
  • Process payments and manage transactions
  • Send marketing communications (where consented)
  • Maintain platform security and prevent fraud
  • Comply with legal and regulatory obligations
  • Conduct analytics and business intelligence
  • Facilitate investment and partnership discussions
  • Deliver healthcare intelligence to members and partners (with consent)
05

Sharing Your Data

We Never Sell Your Data

BioHealthcare Group does not sell, rent, or trade personal data to third parties for commercial purposes.

  • Service Providers - vendors bound by data processing agreements (hosting, payments, analytics, email delivery)
  • Group Companies - within BioHealthcare Group for integrated service delivery
  • Clinical & Research Partners - under strict confidentiality agreements, with your consent
  • Professional Advisers - lawyers, accountants, auditors under confidentiality
  • Regulatory & Legal Authorities - where required by law
  • Business Transfers - in connection with mergers or acquisitions
06

International Data Transfers

Your data may be processed in the UK, USA, EU, UAE, and India. All international transfers are protected by:

  • Adequacy decisions from the UK Secretary of State or European Commission
  • UK International Data Transfer Agreements (IDTAs) or EU Standard Contractual Clauses (SCCs)
  • UAE PDPL-compliant contractual safeguards
  • India DPDPA-compliant transfer mechanisms
07

How Long We Keep Your Data

Data TypeRetention Period
Identity & Contact Data6 years after last interaction
Financial & Transaction Data7 years (legal obligation)
Marketing PreferencesUntil consent withdrawn + 2 years
Website Analytics26 months
Health & Biometric DataProgramme duration + 10 years
Security Logs12 months
Legal Correspondence7 years after matter closes
08

Your Rights

You have the following rights over your personal data. To exercise any right, contact privacy@biohealthcare.group. We respond within 30 days.

RightDescription
AccessRequest a copy of all personal data we hold about you
RectificationRequest correction of inaccurate or incomplete data
ErasureRequest deletion where there is no compelling reason to continue processing
RestrictionRequest restriction of processing in certain circumstances
PortabilityReceive your data in a portable, machine-readable format
ObjectObject to processing based on legitimate interests or for direct marketing
Withdraw ConsentWithdraw consent at any time without affecting prior lawful processing
Supervisory Authorities

UK: ICO (0303 123 1113)  |  EU: your local supervisory authority  |  UAE: UAE Data Office  |  India: Data Protection Board (once established)

09

Cookies & Tracking Technologies

Part 2 of 2
Cookie Policy

We use cookies and similar technologies (pixels, local storage) to enhance your experience and measure performance. You can manage preferences via our Cookie Preference Centre.

Cookie TypePurposeBasis
Strictly NecessaryCore website function - cannot be disabledLegal obligation
PerformanceAnalytics (Google Analytics, internal tools)Consent
FunctionalPreferences, language, personalisationConsent
MarketingAdvertising delivery and campaign trackingConsent

Manage preferences: Cookie Preference Centre (banner on first visit) or browser settings. US residents may use Global Privacy Control (GPC) to opt out of data sharing for advertising.

Third-Party Cookie Providers

Google Analytics, Google Ads, LinkedIn Insight Tag, Meta Pixel, Hotjar, HubSpot, YouTube, Cloudflare. Each subject to their own privacy policies.

10

Health & Biometric Data

  • Only collected with your explicit, specific, freely given consent
  • Stored on encrypted, access-controlled systems with full audit logging
  • Accessible only to clinical professionals and authorised personnel on a need-to-know basis
  • Never used for insurance profiling, employment decisions, or discriminatory purposes
  • Never shared with third parties for commercial purposes
  • Subject to Data Protection Impact Assessments (DPIAs)
  • Separate consent notices provided before any health data collection
Medical Disclaimer

Collection of health data does not constitute medical advice, diagnosis, or treatment. See our Medical & Regulatory Notice.

11

Children's Privacy

Our services are not directed at children under 18. We do not knowingly collect data from under-18s without verifiable parental consent. Contact privacy@biohealthcare.group if you believe we hold a child's data inadvertently.

12

Data Security

  • Encryption in transit (TLS/SSL) and at rest (AES-256)
  • Role-based access controls and multi-factor authentication
  • Regular penetration testing and vulnerability assessments
  • Staff data protection training
  • Documented incident response and breach notification procedures
Breach Notification

In the event of a personal data breach, we notify the relevant supervisory authority within 72 hours and affected individuals without undue delay.

13

Policy Updates

We update this policy periodically. Material changes are flagged on our homepage and notified to registered users by email. The effective date at the top of this page is always current.

14

Contact Us

Data Protection Officer

BioHealthcare Group Ltd
Email: privacy@biohealthcare.group
ICO registration: ico.org.uk

Questions about Privacy or Cookies?

Contact our Data Protection Officer for any questions about your personal data or cookie preferences.