Legal
Last updated: 11 April 2026
This Notice explains how Kyma Health Ltd ("Kyma", "we", "us") collects, uses and protects your personal information when you use our preventive-health Services. It is written in plain English so you can see exactly what happens to your data.
Kyma Health Ltd — Solar House, 282 Chase Road, London, England, N14 6NZ, United Kingdom.
For privacy questions, email help@kymahealth.co.
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email, phone, DOB, address, payment status | You / Stripe |
| Screening data | Lab results, vitals, clinician notes | Network labs, clinicians |
| Wearable data | Steps, heart rate, sleep stage, etc. | Apple Health, Garmin, Oura, etc. (only if you connect) |
| Usage data | Page views, button clicks, error logs | HeapAnalytics (self-hosted, UK) |
| Marketing data | Newsletter opens, UTM codes | Mailchimp, Google Analytics |
| Cookie data | Analytics & marketing cookies (only if you opt-in) | Cookiebot + GA / Meta / LinkedIn pixels |
We do not knowingly collect data from anyone under 18; the Platform blocks under-18 sign-ups.
| Purpose | Lawful basis | Key notes |
|---|---|---|
| Create & manage your Membership | Contract (Art. 6(1)(b)) | To deliver the Services you request. |
| Provide Screenings & AI assistant | Explicit consent (Art. 9(2)(a)) | You give consent during onboarding & each Screening. |
| Payment processing | Contract; legal obligation | Stripe stores limited card data. |
| Analytics & product improvement | Legitimate interests (Art. 6(1)(f)); Health Data anonymised or aggregated | We use HeapAnalytics; no profiling with legal effect. |
| Marketing emails | Soft opt-in under PECR | Unsubscribe anytime via footer link. |
| Optional ad pixels | Consent via Cookiebot banner | No cookies set until you opt-in. |
Licence you grant us. When you upload or connect Member Content you grant Kyma a worldwide, royalty-free licence to host, use, modify and analyse that data for the purposes above. We will not sell identifiable Health Data to third parties.
| Recipient | Reason | Safeguard |
|---|---|---|
| UKAS-accredited labs (e.g. Randox) | Process your samples | Contract + UK GDPR DPA |
| Clinicians (employees / consultants) | Review results, issue advice | Employment / contractor NDA |
| Stripe | Card payments | Data stored in EU data centre |
| Microsoft Azure (UK) | Hosting & backups | Data stays in UK |
| Mailchimp | Transactional / marketing email | EU SCCs in place |
| Regulatory authorities | Legal or safety obligations | Only where required by law |
Kyma never shares identifiable Health Data with employers; employer dashboards are aggregate only.
We host all data in the United Kingdom. If we must transfer data outside the UK (e.g. to Mailchimp EU servers) we use UK Addendum-SCCs or an adequacy decision.
We use Cookiebot to block non-essential cookies until you choose Accept. Essential cookies (session, CSRF) load regardless. See our Cookie Banner link for the full list.
| Data set | Retention rule |
|---|---|
| Health records | 10 years from Membership end, then pseudonymised or securely deleted. |
| Chat transcripts | 10 years (clinical record). |
| Analytics logs | 18 months rolling window. |
| Marketing data | Until you opt-out + 24 hrs to suppress. |
| Cookie consents | 5 years. |
Under the UK GDPR you can: access, correct, erase, restrict, object, port your data, or withdraw consent at any time. Email help@kymahealth.co. We respond within one month.
We use TLS 1.3, AES-256 encryption at rest, MFA for staff accounts, regular penetration testing and role-based access controls. No system is 100% secure, but we work hard to protect your data.
Kyma aims to meet WCAG 2.1 AA. If any feature is not accessible to you, please email us so we can help and fix the issue.
We may update this Notice. Material changes will be emailed to Members 30 days before they take effect. Continued use after that date means you accept the changes.
If you are unhappy with how we handle your data, contact us first. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.