Your blood results are among the most personal data you will ever generate. This explains exactly what we hold, who touches it, and what you can make us do about it.
Osiro Health Ltd is the data controller for the personal data described here. That means we decide what is collected and why, and we are accountable for it.
Written enquiries about data protection should go to info@osirohealth.com.
Health data is special-category data under Article 9 of the UK GDPR and attracts stronger protection than ordinary personal data. We treat it accordingly.
An email address and a password. Passwords are stored only as a bcrypt hash — we cannot read your password, and neither can anyone who obtains a copy of our database.
| What for | Lawful basis |
|---|---|
| Answering your enquiry or waitlist request | Legitimate interests — you asked us to |
| Providing the testing service you bought | Performance of a contract |
| Processing your blood results and clinical interpretation | Article 9(2)(h) — provision of health care by a health professional, supported by your explicit consent at the point of testing |
| Keeping clinical records after your results are released | Legal obligation and legitimate interests — a clinical record must be retainable for the period in which a question about care could arise |
| Securing accounts and preventing abuse | Legitimate interests |
We do not send marketing without your consent, and consent to marketing is never a condition of receiving care.
We use a small number of processors. Each acts on our instructions and cannot use your data for its own purposes.
| Processor | What they do | Where |
|---|---|---|
| Supabase | Hosts the database holding your record and results | London, United Kingdom |
| Hostinger | Hosts the application itself | European Union |
| The analysing laboratory | Analyses your blood sample. UKAS-accredited to ISO 15189 | United Kingdom |
| Partner clinics | Take your sample. CQC-registered | United Kingdom |
| HighLevel | Manages enquiries and waitlist contacts. Receives your name, email, phone and what you asked — never your results | United States, under appropriate safeguards |
| An AI provider | Helps clinicians draft interpretations. Receives de-identified marker values only — see section 5 | United States, under appropriate safeguards |
We use software to help our clinicians prepare your summary. Two things about that are worth stating plainly, because they are the parts people reasonably worry about.
No machine-generated interpretation ever reaches you. Software may produce a draft; a doctor then reads your results in full, edits that draft and signs it off. Nothing is released to you until they do. The clinician is the author of your summary, not the reviewer of a machine's opinion.
The AI provider does not receive anything identifying you. Before any request is made, your record is reduced to marker names, values, units and an indication of whether each is in range, together with an age band and sex. Your name, date of birth, email address, telephone number, address, policy number and specimen number are never included. This is enforced in the software rather than left to whoever writes the request.
If you would prefer no software assistance in preparing your summary, tell us and we will note it on your record.
| Data | Retained |
|---|---|
| Enquiries that don't become memberships | 24 months, then deleted |
| Waitlist entries | Until you ask to be removed, or 24 months after the last contact |
| Clinical records and results | To be confirmed — see below |
| Account and login records | For the life of the account, then 12 months |
| Audit logs of record changes | Retained with the clinical record |
No system is perfectly secure, and we would rather say so than imply otherwise. If we suffer a breach likely to risk your rights, we will notify the ICO within 72 hours and tell you without undue delay.
Under UK GDPR you can ask us to:
Email info@osirohealth.com. We respond within one month. There is no charge.
On that last point, see our cookie notice — it is unusually short, because there is little to disclose.
Tell us first if you can: info@osirohealth.com. We would rather fix something than have it escalated.
You also have the right to complain directly to the Information Commissioner's Office, the UK data protection regulator, at ico.org.uk or on 0303 123 1113. Complaining to us first is not a precondition.