Plan your Baby Privacy Policy
Last modified: 17th of August 2023
PLEASE READ THIS PRIVACY POLICY CAREFULLY BEFORE USING OUR SERVICES.
You must be 18 years old or older to use our Services.
At Plan Your Baby Ltd. (“Plan Your Baby”, “us”, “our” or “we”) we are passionate about privacy. Our privacy policy (the “Privacy Policy”) together with our Terms and Conditions, our Cookies Policy and any other documents referred therein, is an opportunity for us to be transparent with you about our privacy practices when you use our website (planyourbaby.co.uk, hereinafter the “Website”) or our healthcare services including without limitation our telehealth consultations, diagnostic testing and prescription services (together the “Healthcare Services”) or any of our related products and services (together the “Services”).
We invite you to spend a few moments to read this Privacy Policy carefully to understand the type of personal data (as defined under the General Data Protection Regulation (EU) 2016/679, hereinafter the “Personal Data”) we collect from you when you use our Services, how we use it, why we use it, how we protect it, and what are your rights in relations to it.
By requesting access to or using our Services you are agreeing to this Privacy Policy. If you do not agree with this Privacy Policy, please do not use our Services. If after reading this Privacy Policy you still have questions, please do not hesitate to get in touch by contacting our Data Protection Officer: Marija Skujina at mskujina@planyourbaby.co.uk.
Who we are
The Company in charge of your Personal Data (also known as the data controller, as defined under the General Data Protection Regulation (EU) 2016/679, hereinafter the “Data Controller”) is Plan Your Baby Limited, a company registered in England and Wales (number 13669100), with an address at 411 Oxford Street, W1C 2PE, London, United Kingdom, and registered with the UK Information Commissioner’s Officer under the number ZB394674.
What Personal Data do we collect from you, how do we collect it, for what purpose and how long do we retain it
We collect Personal Data from you either automatically when you give it to us directly, or when we receive it from other sources. We do this to operate effectively and provide you with the best experience when using our Services. You have choices about the Personal Data we collect from you. So, when you are asked to provide us with your Personal Data, you always have the right not to do so. If you choose not to provide us with your Personal Data when prompted, you may not be able to fully use our Services.
The Personal Data we collect depends on the context of your interactions with our Services and the choices you make, and includes the following:
When you access our Website
Types of Personal Data:
- Device and technical information: unique device identifiers, device ID, browser type and version, operating system and platform, hardware used, browser plug-in types and versions.
- Location and Usage information: IP address, country, URLs, Referrer URL, date and time of access, information about page response times, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), information about your visit including products and services you viewed or used, error reports and performance data.
Purpose: We collect this Personal Data to provide you with access to our Website and ensure the proper use, functioning, maintenance and improvement of our Website.
How we collect it: We collect this Personal Data automatically when you access our Website.
Legal basis: Legitimate interest
Storage duration: We store your Personal Data for fifteen (15) days. After fifteen (15) days your Personal Data is deleted, unless a security event which requires us to keep your Personal Data occurs. In such a case, your Personal Data will be deleted once the security event is remediated.
When you use our Services
Types of Personal Data:
- Contact and identification information: When you book a consultation with us via our Website we will in the first instance collect your first name, last name, date of birth, e-mail address and phone number. Thereafter, and to effectively provide you with our Services we will also collect your gender, marital status, ethnicity, physical address, photo identification and health insurance information where applicable.
- Health information: To effectively provide you with our Services you will be asked to provide us with general information regarding your health including without limitation, your drinking and smoking habits, your allergies, the medications you take, your menstrual cycle, and your general medical history including any genetic or hereditary illness. While providing you with our Services we will also collect information supplied by you during our medical assessments and telehealth consultations including without limitation consultation notes, symptoms, information about your treatment plan and services provided, as well as your diagnostic test results and treatment outcomes, including your pregnancy status. Please rest assured that we do not collect or store any of your blood samples.
- Payment information: If you make any payments while using our Services, we will retain details of your transactions but not your credit or debit card information. This will be processed directly by our third-party processor.
Purpose: We use your Personal Data to provide you with our Services
How we collect it: When you directly give it to us by using our Services.
Legal basis: Contract performance and consent
Storage duration: Your Personal Data will only be retained for as long as needed to fulfil the aforementioned purposes. You may revoke your consent to such processing at any time by writing to us.
To regulate the quality and safety of our Services
Type of Personal Data:
- Identification information: Age, gender, ethnicity, place of birth (country)
- Health information: general information regarding your health including without limitation your drinking and smoking habits, allergies, the medications you take, your menstrual cycles, your general medical history including any genetic or hereditary illness, information supplied during our medical assessments and telehealth consultations including without limitation consultation notes, symptoms, information about your treatment plan and services provided, as well as your diagnostic test results, and treatment outcome including pregnancy status.
Purpose: We use your Personal Data to guarantee high quality and safety standards of our Services.
How we collect it: Automatically when you use our Services
Legal basis: The processing is required to comply with our legal obligations to ensure the necessary standards of quality and safety of our Services and as provided in Article 9(2)(i)GDPR.
Storage duration: The storage duration of your Personal Data for this purpose corresponds with our obligation to comply with the necessary standards of quality and safety.
To build and improve our artificial intelligence system
Types of Personal Data:
- Identification information: Age, gender
- Usage information: Your interaction with our artificial intelligence system
- Health information: general information regarding your health including without limitation your drinking and smoking habits, allergies, the medications you take, your menstrual cycles, your general medical history including any genetic or hereditary illness, information supplied during our medical assessments and telehealth consultations including without limitation consultation notes, symptoms, information about your treatment plan and services provided, as well as your diagnostic test results, and treatment outcome including pregnancy status.
Purpose: We use your Personal Data to improve our Services. With your consent, we will share your anonymised and aggregated Personal Data with Mixorg Consulting Services Private Limited to build and improve our artificially intelligent system. Please rest assured that we only use this Personal Data in anonymised and aggregate form.
Legal basis: Your consent.
Storage duration: Your Personal Data will only be retained for as long as needed to fulfil the aforementioned purposes. You may revoke your consent to such processing at any time by writing to us.
For marketing purposes and to optimize our marketing initiatives
Types of Personal Data:
- Contact information: First name, last name, e-mail address
- Device and technical information: Device ID, operating system and browser type.
- Location and Usage information: length of visits to certain pages, page interaction information such as scrolling, finger gestures, clicks, and mouse-overs, geographic location, date and time of access.
Purpose: We use your Personal Data to send your marketing communications that we believe will be of interest to you, and to optimise our marketing initiatives.
How we collect it: When you explicitly give it to us by subscribing to our marketing communications. You can always change your marketing preferences at any time by unsubscribing via the link at the bottom of each marketing email.
Legal basis: Consent
Storage duration: We store your Personal Data until you revoke your consent.
For important communication purposes
Types of Personal Data:
- Contact information: First name, last name, e-mail address
Purpose: We use your Personal Data to send you important communications about our Services, for example to update you about changes to our Terms and Conditions. Please note that you cannot unsubscribe from these types of communications as they contain important information about our Services. We will not send your marketing content as part of these communications.
How we collect it: When you directly give it to us by using our Services.
Legal basis: Legitimate interest
Storage duration: We store your Personal Data until you no longer want to use our Services.
For public health purposes
Types of Personal Data:
- Identification information: Age, gender, ethnicity, place of birth (country)
- Health information: general information regarding your health including without limitation your drinking and smoking habits, allergies, the medications you take, your menstrual cycles, your general medical history including any genetic or hereditary illness, information supplied during our medical assessments and telehealth consultations including without limitation consultation notes, symptoms, information about your treatment plan and services provided, as well as your diagnostic test results, and treatment outcome including pregnancy status.
Purpose: We use your Personal Data to conduct research on women’s health with partner organisations such as universities or other academic institutions and publish our findings in peer-reviewed journals. Please rest assured that we will only use your Personal Data in anonymized and aggregated form.
How we collect it: When you directly give it to us by using our Services.
Legal basis: The processing is necessary for reasons of public interest in public health (Article 9(2)(i) GDPR). You may object to such processing at any time by writing to us.
Storage duration: We will store your Personal Data until it is no longer required for the purposes for which it was collected.
For Feedback purposes
Types of Personal Data:
- Feedback provided via surveys. Depending on the survey this may contain some Personal Data and Personal Health Data. Please rest assured that we will only use your Personal Health Data with your consent.
Purpose: To improve our Services.
How we collect it: When you directly provide it to us via a survey.
Legal basis: Consent and where applicable our legitimate interest to improve our Services.
Storage duration: Your Personal Data will be stored until it is no longer required for the survey for which it was collected.
For job application purposes
Types of Personal Data:
- Contact information: First name, last name, e-mail address, phone number
- Location information: Geographic location.
- Social media information: LinkedIn profile.
Purpose: We use your Personal Data to check your suitability for the position and to conduct the application process.
How we collect it: When you directly give it to us when applying for a job at Plan Your Baby.
Legal basis: Consent
Storage duration: In the event of a rejection, your Personal Data will be deleted after six (6) months. If you have agreed for us to keep your Personal Data, we will add your Personal Data to our applicant pool. If you are offered a job in the context of the application process, your Personal Data will be transferred to our human resources.
Who do we share your Personal Data with
Please rest assured that we do not use or share your Personal Data with others except as described in this Privacy Policy, nor do we ever sell your Personal Data. We may however disclose your Personal Data in the following circumstances:
- When the disclosure is requested by you, with your consent or to perform a contract with you.
- When working with our business partners that help us provide our Services.
- When working with our service providers, who act as our processors under Data Processing Agreements or Standard Contractual Clauses as applicable.
- When we sell, merge, or change the control of Plan Your Baby or in preparation for any of these events, in which case the prospective buyer will have the right to continue to use your Personal Data, but only in the manner set out in this Privacy Policy unless you agree otherwise.
– When required by law, subpoenas, court orders, or other legal processes.
Our business partners and service providers
We work with the following business partners and service providers to provide you with our Services:
Healthcare Services business partners
- The Doctors Laboratories Ltd.
- The Doctors Laboratories Genetics Ltd.
- Randox Laboratories Ltd.
- Med Logistics Health Services Ltd.
- Ultrasound Direct Ltd.
- Viva Healthcare Ltd.
- Ovom Ltd.
- Aria Fertility Ltd.
Healthcare management platform service provider
- Semble Technology Limited
- Ideas, Inc
Infrastructure service provider
- Amazon Web Services, Inc.
- Google LLC (Google Cloud Platform)
Web hosting service provider
- Automattic, Inc (WordPress)
Payment service provider
- Worldpay, Inc
- Stripe, Inc
Customer support service provider
- Intuit, Inc (Mailchimp)
Where we store your Personal Data
Your Personal Data is securely stored in the United Kingdom with Semble Technology Limited, our healthcare management platform service provider. Please note that your Personal Data may however be processed by our business partners and service providers operating outside of the European Union. In such cases, we use a legal mechanism known as “Standard Contractual Clauses” to Personal Data transferred outside the European Union. Standard Contractual Clauses refer to contracts between companies transferring Personal Data that contain standard commitments, approved by the European Commission, protecting the privacy and security of the information transferred.
How long we retain your Personal Data
We will hold your Personal Data for as long as it is necessary or required by law. Specific storage periods for the respective processing activities are detailed in Section 2 above.
How We Protect Your Personal Data
Your security really matters to us, this is why we have security systems in place to protect your Personal Data. Once we have received your Personal Data, we will use the following security measures to protect it:
- Use secure servers to store your Personal Data.
- Implement security safeguards designed to protect your Personal Data such as HTTPS.
- Restrict access of your Personal Data to those of our employees who need to know it to do their job, and ensure that all our employees sign a confidentiality clause as part of their employment.
- Follow tight security procedures, such as maintaining physical, electronic and procedural safeguards to protect your Personal Data from unauthorised access.
- Continuously educate and train our employees about the importance of confidentiality.
- Continuously monitor our systems for possible vulnerabilities and attacks.
- Regularly review and update our privacy controls and policy.
Although we do our best to protect your Personal Data we cannot guarantee its security during the transmission of information via the internet, as any such transmission is at your own risk.
Your rights regarding your Personal Data
The GDPR gives you the following rights in relation to your Personal data:
- Right to withdraw consent: You have the right, at any time, to withdraw consent to the processing of your Personal Data.
- Right to object: You have the right, at any time, to object to the processing of your Personal Data.
- Right to be informed: You have the right to obtain, at any time, confirmation from us as to whether we are processing your Personal Data or not.
- Right to erasure: You have the right to obtain from us, at any time, the erasure of your Personal Data.
- Right to restriction of processing: You have the right to obtain from us, at any time, the restriction of processing of your Personal Data.
- Right to data portability: You have the right to receive, at any time and without cost, your Personal Data in a structured, commonly used and machine-readable format.
- Right to rectification: You have the right to receive from us, at any time, the rectification of inaccuracies in your Personal Data.
- Right to complain: You have the right, at any time, to lodge a complaint with a supervisory authority (as set forth in section 10 below).
All of these rights can be exercised by contacting us at info@planyourbaby.co.uk. We will respond to requests to exercise these rights without undue delay and at least within one (1) month.
Cookies and tracking when using our Website
We use cookies and other similar technologies to provide you with a user-friendly experience. Cookies are small text files which our Website may put on your device during your first visit. The cookie helps our Website to recognize your device the next time you visit it. There are many functions cookies serve. For example, they can help us remember your username and preferences, analyze how well the Website is performing, or even allow us to recommend content we believe will be most relevant to you. This processing is carried out on a legal basis and, where required by law, based on your consent. For detailed information on the cookies we use, the purposes for which we use them and to manage your Cookie preferences, please see our Cookies Policy.
How you can make a complaint
If you have a complaint about how we use your Personal Data, please do not hesitate to contact us at info@planyourbaby.co.uk or write to our Data Protection Officer: Marija Skujina at mskujina@planyourbaby.co.uk. If you are unhappy with the way that we have dealt with your complaint, you can refer your complaint to the UK’s Independent Authority, the ICO. For more information, you can visit their website at ico.org.uk.
Changes to this Privacy Policy
Any changes we make to our Privacy Policy in the future will be posted on this page, and where appropriate, notified to you by email, via the App, or by any other available means.
__________