Osiro Health
Home Tests Biomarkers About Contact
Sign in Join Waitlist
Legal

Privacy notice

Your blood results are among the most personal data you will ever generate. This explains exactly what we hold, who touches it, and what you can make us do about it.

Last updated28 July 2026
ControllerOsiro Health Ltd
Data held inUnited Kingdom
Contactinfo@osirohealth.com

Contents

  1. Who we are
  2. What we collect
  3. Why, and on what legal basis
  4. Who else processes it
  5. Software in your care
  6. How long we keep it
  7. How it is protected
  8. Your rights
  9. What we never do
  10. Complaints
Draft pending legal review This notice accurately describes how the Osiro platform actually handles data — it was written from the system itself, not from a template. It has not been reviewed by a solicitor. Have it checked before relying on it, particularly the retention periods and the lawful basis for processing health data, which depend on decisions only you can make.

1. Who we are

Osiro Health Ltd is the data controller for the personal data described here. That means we decide what is collected and why, and we are accountable for it.

Written enquiries about data protection should go to info@osirohealth.com.

To be completed before publication Registered company number and registered office address; ICO registration number; and the name or role of the person accountable for data protection. A UK health business processing special-category data at scale should expect to need a Data Protection Officer — take advice on whether that threshold applies to you.

2. What we collect

When you enquire or join the waitlist

  • Your name, email address and, if you give it, telephone number and country
  • Which panel you are interested in and what you asked us
  • The page you came from, and the date and time you submitted

When you become a member

  • Date of birth, sex and age — these are clinically necessary, because reference ranges and several calculated scores depend on them
  • Contact details and, where relevant, your GP's details
  • Medical history you choose to share: conditions, medications, allergies
  • An emergency contact, if you provide one

Your results

  • Health data — every measured biomarker, every calculated index derived from them, and the laboratory's specimen reference
  • Your clinician's written interpretation, and the internal notes made while preparing it
  • Any documents uploaded to your record
  • A log of who changed your record and when

Health data is special-category data under Article 9 of the UK GDPR and attracts stronger protection than ordinary personal data. We treat it accordingly.

Your account

An email address and a password. Passwords are stored only as a bcrypt hash — we cannot read your password, and neither can anyone who obtains a copy of our database.

3. Why, and on what legal basis

What forLawful basis
Answering your enquiry or waitlist request Legitimate interests — you asked us to
Providing the testing service you bought Performance of a contract
Processing your blood results and clinical interpretation Article 9(2)(h) — provision of health care by a health professional, supported by your explicit consent at the point of testing
Keeping clinical records after your results are released Legal obligation and legitimate interests — a clinical record must be retainable for the period in which a question about care could arise
Securing accounts and preventing abuse Legitimate interests

We do not send marketing without your consent, and consent to marketing is never a condition of receiving care.

4. Who else processes it

We use a small number of processors. Each acts on our instructions and cannot use your data for its own purposes.

ProcessorWhat they doWhere
Supabase Hosts the database holding your record and results London, United Kingdom
Hostinger Hosts the application itself European Union
The analysing laboratory Analyses your blood sample. UKAS-accredited to ISO 15189 United Kingdom
Partner clinics Take your sample. CQC-registered United Kingdom
HighLevel Manages enquiries and waitlist contacts. Receives your name, email, phone and what you asked — never your results United States, under appropriate safeguards
An AI provider Helps clinicians draft interpretations. Receives de-identified marker values only — see section 5 United States, under appropriate safeguards
To be completed before publication A signed Data Processing Agreement with each processor above, and the specific transfer mechanism (UK International Data Transfer Agreement or the Addendum to the EU Standard Contractual Clauses) for any processor outside the UK. Name the laboratory and the AI provider once contracts are in place — naming them is better practice than the generic descriptions used here.

5. Software in your care

We use software to help our clinicians prepare your summary. Two things about that are worth stating plainly, because they are the parts people reasonably worry about.

No machine-generated interpretation ever reaches you. Software may produce a draft; a doctor then reads your results in full, edits that draft and signs it off. Nothing is released to you until they do. The clinician is the author of your summary, not the reviewer of a machine's opinion.

The AI provider does not receive anything identifying you. Before any request is made, your record is reduced to marker names, values, units and an indication of whether each is in range, together with an age band and sex. Your name, date of birth, email address, telephone number, address, policy number and specimen number are never included. This is enforced in the software rather than left to whoever writes the request.

If you would prefer no software assistance in preparing your summary, tell us and we will note it on your record.

6. How long we keep it

DataRetained
Enquiries that don't become memberships24 months, then deleted
Waitlist entriesUntil you ask to be removed, or 24 months after the last contact
Clinical records and resultsTo be confirmed — see below
Account and login recordsFor the life of the account, then 12 months
Audit logs of record changesRetained with the clinical record
To be confirmed Clinical record retention is a decision to take with clinical and legal advice, not a number to guess at. UK guidance for adult private health records commonly points to a period measured in years after last contact, and it interacts with the limitation period for claims. Set it deliberately, write it here, and build the deletion process to match — a retention policy nobody implements is worse than none.

7. How it is protected

  • All traffic between you and us is encrypted with TLS
  • The database connection is encrypted and the server's identity verified against a pinned certificate authority — encryption without verification is not enough
  • Data is encrypted at rest by our database provider
  • Passwords are stored only as bcrypt hashes
  • Access to clinical records requires an authenticated clinician account; members can only ever see their own record
  • Every change to a clinical record is logged with who made it and when
  • Results are held in the United Kingdom

No system is perfectly secure, and we would rather say so than imply otherwise. If we suffer a breach likely to risk your rights, we will notify the ICO within 72 hours and tell you without undue delay.

8. Your rights

Under UK GDPR you can ask us to:

  • Give you a copy of everything we hold about you
  • Correct anything inaccurate
  • Delete your data, subject to clinical records we may be required to retain — we will tell you what we cannot delete and why
  • Export your data in a portable format
  • Restrict or object to particular processing
  • Withdraw consent at any time, without affecting care already provided

Email info@osirohealth.com. We respond within one month. There is no charge.

9. What we never do

  • We do not sell your data. Not aggregated, not anonymised, not ever
  • We do not share your results with insurers or employers, and we will not do so on request from either
  • We do not use your results to target advertising
  • We do not use your identifiable data to train AI models
  • We do not run advertising or analytics trackers on this website

On that last point, see our cookie notice — it is unusually short, because there is little to disclose.

10. Complaints

Tell us first if you can: info@osirohealth.com. We would rather fix something than have it escalated.

You also have the right to complain directly to the Information Commissioner's Office, the UK data protection regulator, at ico.org.uk or on 0303 123 1113. Complaining to us first is not a precondition.

Osiro Health

A new standard in preventive blood testing. Built by clinicians, designed for the people who refuse to wait for symptoms.

Product
  • Test packages
  • Biomarker library
  • How it works
  • Join waitlist
Company
  • About
  • Science
  • Contact
  • Careers
Resources
  • FAQ
  • Journal
  • Clinic locations
  • Press
© 2026 Osiro Health Ltd. All rights reserved.
Privacy Terms Cookies