GDPR Compliance Statement

Last updated: June 2026

Azina Health Ltd is a UK-based healthcare platform. We are committed to protecting personal data in line with the UK General Data Protection Regulation (UK GDPR), the EU GDPR where it applies, and the Data Protection Act 2018. This statement summarises how we meet our obligations when you use our website, apps, and clinical services.

GDPR principles we follow

We apply the seven core principles set out in Article 5 GDPR:

  • Lawfulness, fairness, and transparency in how we collect and use data

  • Purpose limitation — we process data only for specified, explicit purposes

  • Data minimisation — we collect only what is necessary for our services

  • Accuracy — we take steps to keep personal data up to date

  • Storage limitation — we retain data only as long as needed

  • Integrity and confidentiality through appropriate security safeguards

  • Accountability — we document our processing and demonstrate compliance

Lawful bases for processing

We process personal data only where we have a valid legal basis under Articles 6 and 9 GDPR:

  • Contract

    Processing needed to provide appointments, prescriptions, shop orders, and platform features you request.

  • Legal obligation

    Processing required to meet healthcare, tax, or regulatory duties applicable in the UK.

  • Legitimate interests

    Improving platform security, preventing fraud, and supporting care delivery, balanced against your rights.

  • Consent

    Where required for marketing communications or optional features — you may withdraw consent at any time.

  • Vital interests & health care

    In limited cases, processing special category health data to deliver safe clinical care and related services.

Your data protection rights

Under UK GDPR and EU GDPR, you may have the following rights in relation to your personal data:

  • Right of access

    Request a copy of the personal data we hold about you and how we use it.

  • Right to rectification

    Ask us to correct inaccurate personal data or complete incomplete records.

  • Right to erasure

    Request deletion of your data where there is no compelling reason for us to keep processing it.

  • Right to restrict processing

    Ask us to limit how we use your data in certain circumstances.

  • Right to data portability

    Receive your data in a structured, commonly used format where technically feasible.

  • Right to object

    Object to processing based on legitimate interests or for direct marketing.

  • Rights related to automated decision-making

    Not be subject to decisions based solely on automated processing where the law applies.

  • Right to withdraw consent

    Withdraw consent at any time where processing is based on consent, without affecting prior lawful processing.

To exercise any of these rights, contact us at privacy@azinahealth.com. We respond within one month, as required by law. You may also lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.

Governance, transfers & accountability

  • Privacy notices and transparent information about how data is used

  • Data Processing Agreements with clinics, practitioners, and subprocessors

  • Records of processing activities and regular privacy impact assessments where appropriate

  • Staff training and access controls aligned to role and need-to-know

  • Procedures for breach detection, reporting, and notification within statutory timeframes

  • International transfer safeguards (e.g. UK IDTA / EU SCCs) when data leaves the UK or EEA

For full details on categories of data, retention periods, and subprocessors, see our Privacy Policy and Data Processing Agreement.

Security & technical measures

Article 32 GDPR requires appropriate technical and organisational measures. We protect personal and health-related data using:

Encryption in transit and at rest

Role-based access controls

Continuous monitoring

Audit trails and logging