GDPR Compliance Statement
Last updated: June 2026
Azina Health Ltd is a UK-based healthcare platform. We are committed to protecting personal data in line with the UK General Data Protection Regulation (UK GDPR), the EU GDPR where it applies, and the Data Protection Act 2018. This statement summarises how we meet our obligations when you use our website, apps, and clinical services.
GDPR principles we follow
We apply the seven core principles set out in Article 5 GDPR:
Lawfulness, fairness, and transparency in how we collect and use data
Purpose limitation — we process data only for specified, explicit purposes
Data minimisation — we collect only what is necessary for our services
Accuracy — we take steps to keep personal data up to date
Storage limitation — we retain data only as long as needed
Integrity and confidentiality through appropriate security safeguards
Accountability — we document our processing and demonstrate compliance
Lawful bases for processing
We process personal data only where we have a valid legal basis under Articles 6 and 9 GDPR:
Contract
Processing needed to provide appointments, prescriptions, shop orders, and platform features you request.
Legal obligation
Processing required to meet healthcare, tax, or regulatory duties applicable in the UK.
Legitimate interests
Improving platform security, preventing fraud, and supporting care delivery, balanced against your rights.
Consent
Where required for marketing communications or optional features — you may withdraw consent at any time.
Vital interests & health care
In limited cases, processing special category health data to deliver safe clinical care and related services.
Your data protection rights
Under UK GDPR and EU GDPR, you may have the following rights in relation to your personal data:
Right of access
Request a copy of the personal data we hold about you and how we use it.
Right to rectification
Ask us to correct inaccurate personal data or complete incomplete records.
Right to erasure
Request deletion of your data where there is no compelling reason for us to keep processing it.
Right to restrict processing
Ask us to limit how we use your data in certain circumstances.
Right to data portability
Receive your data in a structured, commonly used format where technically feasible.
Right to object
Object to processing based on legitimate interests or for direct marketing.
Rights related to automated decision-making
Not be subject to decisions based solely on automated processing where the law applies.
Right to withdraw consent
Withdraw consent at any time where processing is based on consent, without affecting prior lawful processing.
To exercise any of these rights, contact us at privacy@azinahealth.com. We respond within one month, as required by law. You may also lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.
Governance, transfers & accountability
Privacy notices and transparent information about how data is used
Data Processing Agreements with clinics, practitioners, and subprocessors
Records of processing activities and regular privacy impact assessments where appropriate
Staff training and access controls aligned to role and need-to-know
Procedures for breach detection, reporting, and notification within statutory timeframes
International transfer safeguards (e.g. UK IDTA / EU SCCs) when data leaves the UK or EEA
For full details on categories of data, retention periods, and subprocessors, see our Privacy Policy and Data Processing Agreement.
Security & technical measures
Article 32 GDPR requires appropriate technical and organisational measures. We protect personal and health-related data using:
Encryption in transit and at rest
Role-based access controls
Continuous monitoring
Audit trails and logging