Privacy Notice
How we use, share and protect your personal information
Version: 1.1
Effective date: September 2026
Last reviewed: September 2026
1. About this notice
This Privacy Notice (“Notice”) explains how Added Health Ltd (“Added Health”, “we”, “us”, “our”), collects, uses, shares and protects your personal information when you become a member of our service. It is written to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
We also ask you to complete a separate Member Consent Form, and Consent to Contacting Healthcare Providers (together, the “Consent Forms”) covering specific kinds of information sharing and use. This Privacy Notice sits alongside the Consent Forms: the Consent Forms record your consent, while this Notice explains how, and why we process your personal data, as well as which third parties we share your personal data with. If anything in this Notice is unclear, or you would like a version in another format, please contact us at data@addedhealth.com.
2. Who we are and how to contact us
Added Health is the data controller for the personal information described in this Notice. That means we are responsible for collecting and processing your personal data, how it is used and for keeping it safe.
Our contact details
Company: Added Health Ltd (company number 13063427)
Registered address: Belsyre Court, Woodstock Road, Oxford, England, OX2 6HJ, United Kingdom
General data enquiries: data@addedhealth.com
ICO registration number: ZA899695
Data Protection Officer
Our Data Protection Officer (DPO) is responsible for overseeing how we handle personal information and is your point of contact for any data protection question.
Name: Navene Grange
Email: data@addedhealth.com
3. How Your Data is Used - The short version
The below is a very brief summary as to how we use and process your personal data. This summary is not a substitute for reading this Notice in full:
We collect your personal and health information so our clinicians, care coordinators and administrative staff can look after you and so that we can provide you with the services you have requested from us.
We share information internally so the team can work together on your behalf, and we may contact you with service-related messages such as appointment reminders and results.
With your consent, we record, transcribe and securely store your NARIQ™conversations along with your care team conversations so that we can provide you with the services you have requested from us.
With your consent, we may share relevant de-identified information with external specialists or our Clinical Advisory Board for advice, second opinions or onward care.
With your consent, we may use de-identified information to improve our clinical software, including NARIQ™, the AI agent that helps us build a fuller picture of your health.
You have certain rights under the data protection legislation, these are discussed in more detail below, but should you wish to exercise your rights, please email us at data@addedhealth.com.
Added Health is not an emergency or out-of-hours service. In an emergency, call 999 (or your local equivalent). For urgent out-of-hours concerns, contact NHS 111.
4. What personal data we collect
Most of the information we hold comes directly from you when you become a member of Added Health, when you call, write, email or meet with us, and during your ongoing care. We may also collect some of your personal data from other healthcare professionals where you provide your explicit consent for us to do so (for example, your GP, a specialist, or a laboratory), or personal data may be generated by our clinicians and our AI agent NARIQ™ as part of your record.
The categories of personal data we collect are set out below. Much of this information is “special category data” under UK GDPR because it concerns your health.
The “get to know you” model. Added Health’s approach is to build a holistic picture of you and what matters to you, by combining the categories of information above with cutting-edge AI, overseen by expert clinicians. This helps us provide continuity of care, identify opportunities for preventative care, and give your clinicians richer background information during consultations. It also allows us to evaluate the usefulness of GP consultations over time.
Signing in with Apple or Google. If you choose "Sign in with Apple" or "Sign in with Google", we receive a limited set of details from that provider to create and secure your account, your name and email address and a unique identifier that lets you sign in again. We use these only to authenticate you, and we never receive your Apple or Google password. If you delete your Added Health account, we revoke our access to your Apple sign-in at the same time; you can also remove Added Health yourself under Settings → [your name] → Sign in with Apple on your device.
Children. Added Health is intended for adults enrolled with their healthcare provider. It is not directed at, and we do not knowingly collect personal data from, anyone under 18. If you believe someone under this age has given us their data, contact us at data@addedhealth.com and we will delete it.
5. How we use your personal data, and our lawful basis
Under UK GDPR, we must have a lawful basis to use your personal data and an additional condition for where we process your health data – this is because data relating to your health is considered “special category data” and additional safeguards are put in place to protect such sensitive data.
We have the following lawful bases for processing your personal data: (i) for the purpose of delivering our contracted services to you; (ii) in accordance with our legal obligations; (iii) with your explicit consent; (iv) for our legitimate interests as a company; obtaining feedback or other information to improve our services.
Where we process your special category data, including your personal data concerning your health, we rely on your explicit consent. You provide us with this consent when you complete our Consent Forms, or otherwise during your ongoing care. You have the right to withdraw your consent at any time, however, please note this will affect the services which we can provide to you. The table below set out the lawful bases on which we rely when processing your personal data.
Automated decision-making and NARIQ™
NARIQ™ is an AI agent we use to help build a full picture of your health, surface relevant information for clinicians, and support the “get to know you” model. We also use NARIQ™ as an audio and transcription tool. We will ask you if you consent to us using NARIQ™ in our Member Consent Form before we use it as part of our services. NARIQ™ supports clinical decision-making; it does not replace it. Any recommendations produced by NARIQ™ is critically interrogated and assessed by our designated healthcare professionals. For the avoidance of doubt, we do not make decisions that have a legal or similarly significant effect on you based solely on automated processing by NARIQ™ or any other AI tool.
Advice or recommendations produced by NARIQ™ are personalised, but are not a substitute for speaking to one of our designated healthcare providers, your GP, or another healthcare professional as appropriate. We accept no liability for the recommendations, outcomes or advice produced by NARIQ™, or your reliance on them without taking further advice or support.
6. Who we share your personal data with
We only share your information where we have a lawful basis to do so, and (where required) where you have given consent in the Consent Forms. The main recipients are:
Within Added Health
Clinicians, care coordinators and administrative staff involved in your care, so that the team can work together on your behalf.
External clinical professionals (with your consent)
Specialists in the UK and abroad to whom we refer you or seek advice from on your behalf where we rely on your explicit consent to share your personal data.
Qualified members of the Added Health Clinical Advisory Board, for advice or second opinions (as set out in section 7 below).
• Your NHS GP and other healthcare providers, where this supports your care
Only information relevant to the specific clinical question will be shared.
Service providers (processors) acting on our instructions
Technology providers that host our clinical records, payment systems, communications, scheduling and analytics tools, including the providers of our AI tooling, such as Sage and NARIQ™.
Professional advisers such as auditors, lawyers and insurers.
All processors are contractually bound to use your information only on our instructions, to keep it secure, and to comply with UK GDPR.
Authorities and others
Regulators (such as the CQC, the ICO and professional bodies) and law enforcement where we are legally required to disclose information
Safeguarding authorities where we believe there is a risk to you or another person.
The police or other security organisations involved in investigating crimes and courts and/or tribunals.
We will never share your information with third parties for their own marketing purposes.
7. Where your personal data is stored
Your records are stored in secure, access-controlled clinical systems. Our primary clinical record is hosted on Amazon Web Services (AWS) in the UK region, on infrastructure that operates to internationally recognised security standards.
Information may also be processed within secure environments operated by our other technology providers — for example, communications, scheduling and AI services. Wherever your data is stored, we apply the technical and organisational measures described in Section 11.
Data residency
We operate the following data residency rules:
Personal data and personally identifiable information (PII): stored and processed within the United Kingdom and the European Economic Area only. We do not transfer identifiable member data outside the UK / EEA.
De-identified case studies: may be shared with collaborators to support clinical research, education and the continued development of our service. We may also share de-identified case studies with our Clinical Advisory Board for advice, second opinions or to support your onward care. . Before any such sharing, information is de-identified so that it cannot reasonably be used to identify you (no name, specific date of birth, address or other identifying detail), and is therefore no longer personal data under UK GDPR. Where we use specialists based outside the UK and the EEA to support our activities, we only share anonymised records, that do not contain personal data.
8. Our data processors
We use a small number of carefully selected third-party suppliers ("data processors") who help us deliver the service. These typically include providers of:
Cloud hosting and infrastructure (Amazon Web Services, EU region).
Communications, scheduling and member-portal tools.
AI services that support the NARIQ™ agent and the clinical tooling used to support your care.
Professional services such as auditors, lawyers and insurers (acting as separate controllers where appropriate).
Video consultation services that carry your GP video calls. This processing takes place within the EU.
Every processor we use is contractually bound by a written data processing agreement that meets the requirements of data protection legislation. A current list of our key processors and the categories of data each handles is available on request — please email data@addedhealth.com
9. How long we keep your personal data
We keep your personal data only for as long as we need it for the purposes described in this Notice, or for as long as we are required to by law and professional clinical record-keeping standards.
Clinical records are retained in line with applicable UK clinical record retention guidance (for adult records, typically a minimum of 8 years after the end of treatment; longer for certain categories such as records relating to children or maternity care).
Service and contact records (for example, appointment history and correspondence) are retained for as long as you are a member and for a reasonable period afterwards in line with our retention schedule.
Where you withdraw a consent, we stop the relevant processing but may keep a minimum record to evidence the change.
Our full retention schedule is available on request. Please contact us at data@addedhealth.com
10. Your rights
Under UK GDPR you have a number of rights in relation to your personal data. These are summarised below.
Clinical records are retained in line with applicable UK clinical record retention guidance (for adult records, typically a minimum of 8 years after the end of treatment; longer for certain categories such as records relating to children or maternity care).
Service and contact records (for example, appointment history and correspondence) are retained for as long as you are a member and for a reasonable period afterwards in line with our retention schedule.
Where you withdraw a consent, we stop the relevant processing but may keep a minimum record to evidence the change.
Our full retention schedule is available on request. Please contact us at data@addedhealth.com
How to exercise your rights
To exercise any of these rights — including to access, correct, delete or restrict the use of your information, or to withdraw a consent — please email data@addedhealth.com. We will normally respond within one calendar month. There is no charge for most requests, however, we may ask you to verify your identity so that we can be sure we are dealing with the right person.
11. How we keep your personal data secure
We take the security of your information seriously and apply technical and organisational measures appropriate to the sensitivity of the data, including:
Access controls and role-based permissions, so that staff only see information they need for your care.
Encryption of data in transit and at rest in our clinical systems.
Audit logging of access to clinical records.
Staff training in data protection, confidentiality and information security.
Contracts with all suppliers that require them to apply equivalent security standards.
Incident response procedures, including notifying the ICO and affected members where required.
12. Marketing
We will never use your information for marketing without your consent. Where you do give permission, you can withdraw it at any time by emailing data@addedhealth.com or by using the unsubscribe link in any marketing message.
13. Cookies and our website
Our website and member portal may use cookies and similar technologies to make the service work, remember your preferences and understand how the service is being used. Full details are set out in our separate Cookie Policy.
14. Changes to this notice
We may update this Notice from time to time. When we make material changes we will let you know — for example, by email or through the member portal — and update the version and “last reviewed” dates at the top of this document. The current version is always available on our website.
15. Complaints
If you have a concern or a complaint about how we have used your personal data, we would like the chance to put it right. Please contact us in the first instance at data@addedhealth.com.
We aim to respond as soon as practicable, but within 30 days of receiving your complaint. We will take appropriate steps to responding to your concern or complaint without undue delay, which may include asking you for further information about the subject matter of the complaint. Where appropriate, we will keep you informed about the progress of our handling of the complaint, and we will inform you of our outcome without undue delay.
If you remain dissatisfied with our response, you also have the right to complain to the UK Information Commissioner’s Office (ICO):
Website: ico.org.uk
Helpline: 0303 123 1113
Audit logging of access to clinical records.
Address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Details of how to complain to the ICO can be found on its website at: https://ico.org.uk/make-a-complaint/
— End of Privacy Notice —





