Privacy Statement (UK)

Last updated: 22nd December 2024.

In this privacy statement, we explain what we do with the data we obtain about you via https://www.wearewell.org.uk. We recommend you carefully read this statement. In our processing, we comply with the requirements of privacy legislation. 

That means, among other things, that:

  • we clearly state the purposes for which we process personal data. We do this by means of this privacy statement;
  • we aim to limit our collection of personal data to only the personal data required for legitimate purposes;
  • we first request your explicit consent to process your personal data in cases requiring your consent;
  • we take appropriate security measures to protect your personal data and also require this from parties that process personal data on our behalf;
  • we respect your right to access your personal data or have it corrected or deleted, at your request.

If you have any questions or want to know exactly what data we keep of you, please contact us.

  1. WHO IS THE DATA CONTROLLER?

Organization name: SW Healthcare Services Ltd

Organization business address: 38 Kenilworth Close, Redditch, Worcestershire, B97 5JX

United Kingdom

Website: https://www.wearewell.org.uk

Email: team@wearewell.org.uk

Phone number: 01905969843

  1. HOW DO WE COLLECT YOUR DATA?

We collect and process your data via one  of the following ways:

-Data you directly provide to us

When you fill out inquiry forms on our website, when you place an order, and when you make a payment, you voluntarily and directly provide your personal data to us. 

-Data we automatically collect about you

When you visit and browse our website, content, and services, we use cookies and similar technologies to automatically collect data about you such as how you browse our website, what content you click, your IP address, and your device information. 

  1. WHAT PERSONAL DATA DO WE COLLECT ABOUT YOU?
  • Basic details and contact information

A first and last name

A home or other physical address, including street name and name of a city or town

An email address

A telephone number

Date of birth

  • Financial information

Financial information such as bank account number or credit card number

  • Technical information 

-IP Address

-Device information such as device name, device model, screen resolution, operating system, network information

-Information about how the referral page

-You geolocation when you access and use our website and services

  • Analytics information

Information about how you browse through our website, content, and services such as content you interact with, your clicks, your purchases, data you submit, time you spend on each page.

  • Account related information

Photos

Social Media accounts

A signature

  • Health data

Your physical characteristic

Your health information such as your height, weight, your BMI score

Your medical history

Your dietary habits

Your health Insurance information

Whether you are pregnant, breastfeeding, or trying to conceive

Whether you have a pre-existing medical condition such as diabetes or blood pressure

Whether you have allergic reaction to certain substances

  • Sensitive data about your nationality, your marital status

We ask for your passport, driving license, or ID card to confirm that you are based in the UK. 

  1. FOR WHAT PURPOSES DO WE COLLECT AND PROCESS YOUR DATA?

We collect and process your data for the following purposes:

-To provide you with our core services of assessing your eligibility for our product and prescribing the product 

-To dispatch and deliver the ordered products to your address

-To process payments

-To verify your identity

-To share your data with our clinicians so that they can assess your eligibility and prescribe the product to you

-To share your data with your GP

-To comply with our legal obligations

-To ensure and maintain the security of our website and platform

-To analyze user behavior on our website

-To offer personalized products to you

-To improve our website, product, content and services

To protect our rights and those of third parties

To send you marketing emails and newsletters 

  1. LEGAL BASIS FOR THE COLLECTION AND  PROCESSING OF YOUR DATA

We rely on the following legal bases to collect and process your personal data: 


Purpose of data collection and processing

The legal basis we rely on under the UK GDPR 

-To provide you with our core services of assessing your eligibility for our product and prescribing the product 

Contractual necessity under article 6.1.b of the UK GDPR 
Explicit consent under article 9.2.a of the GDPR 

-To dispatch and deliver the ordered products to your address

Contractual necessity under article 6.1.b of the UK GDPR 

-To process payments

Contractual necessity under article 6.1.b of the UK GDPR 

-To verify your identity





Contractual necessity under article 6.1.b of the UK GDPR 
-To share your data with our clinicians so that they can assess your eligibility and prescribe the product to youContractual necessity under article 6.1.b of the UK GDPR 
Explicit consent under article 9.2.a of the GDPR 

-To share your data with your GP
Legitimate Interests under Article 6.1.f of the UK GDPR 
Explicit consent under article 9.2.a of the GDPR 
-To comply with our legal obligationsTo comply with our legal obligation under article 6.1.c of the UK GDPR 
-To ensure and maintain the security of our website and platformLegitimate interests under article 6.1.f of the UK GPDR 

To protect our rights and those of third parties

Legitimate interests under article 6.1.f of the UK GPDR 
-To analyze user behavior on our websiteConsent under article 6.1.a of the UK GDPR 
-To offer personalized products to youConsent under article 6.1.a of the UK GDPR 
-To improve our website, product, content and services Consent under article 6.1.a of the UK GDPR 

To send you marketing emails and newsletters  

Soft opt-in under the PECR and legitimate interests under article 6.1.f of the UK GDPR 
  1. SHARING YOUR DATA WITH CLINICIANS 

We share your submitted health data with our third-party service provider clinician so that he/she can prescribe you the product you ordered.

We share the following categories of health data you submitted with the third-party clinician:

Your physical characteristic

Your health information such as your height, weight, your BMI score

Your medical history

Your dietary habits

Your health Insurance information

Whether you are pregnant, breastfeeding, or trying to conceive

Whether you have a pre-existing medical condition such as diabetes or blood pressure

Whether you have an allergic reaction to certain substances

We rely on “Contractual Necessity” legal ground to share your data with third-party clinicians so that we can assess your eligibility for the product and prescribe the product to you. 

We share this data only for the purposes of providing our services to you. 

  1. SHARING YOUR DATA WITH GP

We share the following categories of health data you submitted with your GP:

Your physical characteristic

Your health information such as your height, weight, your BMI score

Your medical history

Your dietary habits

Your health Insurance information

Whether you are pregnant, breastfeeding, or trying to conceive

Whether you have a pre-existing medical condition such as diabetes or blood pressure

Whether you have allergic reaction to certain substances

We rely on “Legitimate Interests” legal ground to share your data with your GP so that your GP will have access to the types of medicines you are taking and will be able to take this into account. 

We share this data only for the purposes of protecting your health. 

  1. DISCLOSURE OF YOUR DATA WITH THIRD PARTIES

We disclose personal information if we are required by law or by a court order, in response to a law enforcement agency, to the extent permitted under other provisions of law, to provide information, or for an investigation on a matter related to public safety.

If our website or organization is taken over, sold, or involved in a merger or acquisition, your details may be disclosed to our advisers and any prospective purchasers and will be passed on to the new owners.

We have concluded a data processing agreement with Google.

  1. INTERNATIONAL DATA TRANSFERS

When we transfer your personal data abroad to a inadequate country, we rely on one of the transfer mechanisms described under Article 46 of the UK GDPR. 

  1. DATA SECURITY

We are committed to the security of personal data. We take appropriate security measures to limit abuse of and unauthorised access to personal data. This ensures that only the necessary persons have access to your data, that access to the data is protected, and that our security measures are regularly reviewed.

  1. DATA RETENTION

We retain your data for as long as necessary for the purpose for which it is collected. 

When determining the specific data retention period, we take into account the statutory retention periods, sensitivity of data, your reasonable expectations, and our legitimate interests. 

We retain your submitted data for 12 months from the date on which you submit it. 

You can contact us to find out about the applicable retention periods for each specific data category. 

  1. YOUR RIGHTS

You have the following rights in relation to your personal data:

  • You have the right to know why your personal data is needed, what will happen to it, and how long it will be retained.
  • Right of access: You have the right to access your personal data that is known to us.
  • Right to rectification: you have the right to supplement, correct, delete, or block your personal data whenever you wish.
  • If you give us your consent to process your data, you have the right to revoke that consent and to have your personal data deleted.
  • Right to transfer your data: you have the right to request all your personal data from the controller and transfer it in its entirety to another controller.
  • Right to object: you may object to the processing of your data. We comply with this unless there are justified grounds for processing.
  • Right to deletion: You have the right to request that we delete your data.

Please make sure to always clearly state who you are, so that we can be certain that we do not modify or delete any data of the wrong person.

  1. HOW TO EXERCISE YOUR RIGHTS

To exercise your rights described above, you can contact us via one of the following methods: 

By post: SW Healthcare Services 38 Kenilworth Close, Redditch, Worcestershire, B97 5JX

United Kingdom

By email: team@wearewell.org.uk

  1. HOW TO FILE A COMPLAINT WITH THE UK DATA PROTECTION AUTHORITY

If you are not satisfied with the way in which we handle (a complaint about) the processing of your personal data, you have the right to submit a complaint to the Information Commissioner’s Office:

The ICO’s contact details can be found on their website at https://ico.org.uk.

The ICO’s address:           

Information Commissioner’s Office

Wycliffe House

Water Lane

Wilmslow

Cheshire

SK9 5AF

Helpline number: 0303 123 1113

ICO website: https://www.ico.org.uk

Jersey Office of The Information Commissioner
2nd Floor 5 Castle Street
St. Helier
Jersey
JE2 3BT


St Martin’s House
Le Bordage
St. Peter Port
Guernsey
GY1 1BR

  1. AMENDMENTS TO THIS PRIVACY POLICY

We reserve the right to make amendments to this privacy statement. It is recommended that you consult this privacy statement regularly in order to be aware of any changes. In addition, we will actively inform you wherever possible.

  1. THIRD-PARTY WEBSITES 

This privacy statement does not apply to third-party websites connected by links on our website. We cannot guarantee that these third parties handle your personal data in a reliable or secure manner. We recommend you read the privacy statements of these websites prior to making use of these websites.

  1. DATA PROTECTION OFFICER

Our Data Protection Officer has been registered with the Information Commissioner’s Office. If you have any questions or requests with respect to this privacy statement or for the Data Protection Officer, you may contact Claire Goodall, or via claire.goodall5@nhs.net.

  1. CHILDREN 

Our website is not designed to attract children and it is not our intent to collect personal data from children under the age of consent in their country of residence. We therefore request that children under the age of consent do not submit any personal data to us.

  1. CATEGORIES OF THIRD-PARTY DATA PROCESSORS 

In processing your data, we use the following categories of service providers: 

-Payment processors to process payments

-Cloud service providers to store your data

-Email marketing tools to manage our email marketing activities 

-User authentication service providers to verify your ID 

  1. NOTICE ABOUT STRIPE 

We use Stripe to process your payment. 

Stripe may use a variety of additional data about you such as the time and date of your purchase, your card information, and your bank details. 

To learn more about how Stripe collects and processes your data, visit the Stripe’s privacy policy at: 

https://stripe.com/privacy

  1. HOW TO CONTACT US 

SW Healthcare Services

38 Kenilworth Close, Redditch, Worcestershire, B97 5JX

United Kingdom

Website: https://www.wearewell.org.uk

Email: team@wearewell.org.uk

Phone number: 01905969843