NABLA UK PRIVACY POLICY AND COOKIES POLICY

PART A – PRIVACY POLICY

Date of policy: 14th January 2022

  1. Purpose of this privacy policy.

Nabla respects your privacy and is committed to protecting your personal data. This privacy policy will inform you as to how we look after your personal data when you use our App (as defined below) and tell you about your privacy rights and how the law protects you.

This privacy policy is provided in a layered format so you can click through to the specific areas set out below.

This policy (together with our terms and conditions) applies to

This policy sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us.

Please read the following carefully to understand our practices regarding your personal data and how we will treat it.

  1. Data controller

Nabla Services Ltd is a company registered in England and Wales. Our company registration number is 13441595 and our registered office is at 8th Floor South, 11 Old Jewry, London, EC2R 8DU. We are a subsidiary company of Nabla Technologies SAS, a company established and operating in France.

Nabla Services Ltd is the data controller and is referred to in this privacy policy as “Nabla”, “we”, “us” or “ours”.

We are committed to protecting your personal data and respecting your privacy.

If you have any questions about this privacy policy, please contact us using the details set out below.

  1. Contact details

Our contact details are:

  1. Changes to the privacy policy and your duty to inform us of changes

We keep our privacy policy under regular review. It may change and if it does, these changes will be posted on this page and, where appropriate, notified to you by email and/or when you next start the App. The new policy may be displayed on-screen and you may be required to read and accept the changes to continue your use of the App.

It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during our relationship with you.

  1. Third party links

Our App may, from time to time, contain links to and from the websites of our partner networks and affiliates, for example, our payment services providers. Please note that these websites and any services that may be accessible through them have their own privacy policies and that we do not accept any responsibility or liability for these policies or for any personal data that may be collected through these websites or services. Please check these policies before you submit any personal data to these websites or use these services.

  1. The data we collect about you

Depending on the level of your engagement with our App and our Services, we may collect, use, store and transfer different kinds of personal data about you as follows:

Identity Data:

Includes first name, last name, username or similar identifier, title, date of birth, sex and gender.

This is information you provide to us when you create an account on our App. Creating and maintaining an account with Nabla is necessary to receive all of our Services, so if you cannot provide us with this information, we may not be able to provide you with all of our Services. You will still be able to access our “Chat” services without providing us with this data.

Contact Data:

Includes billing address, residential address, email address and telephone number. It also includes the content of your communications with us.

We require this information from you in order to communicate with you in relation to our Services. Without this data, we will be unable to respond to your queries, contact you to inform you about important matters and provide the Services to you.

Transaction Data:

Includes details about when you registered your account on the App, payments to and from you and details of purchases of the Services you have made, your subscription status in respect of the Services.

We will record and keep this information to maintain a record of your purchases.

Technical Data:

In relation to the use of our App, this includes: the type of mobile device you use, a unique device identifier (for example, your device’s IMEI number, the MAC address of the device’s wireless network interface, or the mobile phone number used by the device), mobile network information, your mobile operating system, the type of mobile browser you use, time zone setting.

Please see our cookies policy at Part B below for more details about why and how we use cookies and other tracking technologies.

Profile Data:

Includes your username and password, purchase history, preferences, feedback and survey responses.

This is all data that relates to your interactions with us. It is necessary to provide you with services relating to your registered account with Nabla.

Usage Data:

Includes details of your use of our App, including but not limited to, traffic data and other communication data, and the resources that you access.

We collect this data to monitor and measure the performance of our App.

Health Data

Includes information regarding your usual General Practitioner (“GP”) and about your health and wellbeing that you submit in connection with your use of the Services (e.g. the details of the GP, your NHS number, any health information received from your usual GP), including but not limited to your conversations with any clinical professionals you chat to as part of the Services (the Clinical Professionals), any document, picture or video you may share when using the Services, any advice or treatment recommended by our Clinical Professionals, your medical records and details of any prescriptions ordered through the Services.

We require this information in order to provide you with a healthcare service and to help protect your vital interests. Additional information on the use of your health data is set out in section 8 below.

We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data could be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific App feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy policy.

Any Health Data that we collect in connection with our Services will include special categories of personal data. Data protection laws impose certain additional obligations on data controllers in relation to such special categories of personal data and we will take extra care to keep it safe and secure, to process it only if it is necessary in connection with our Services and only in the manner described in this privacy policy.

  1. How is your personal data collected?

Most of the personal data that we process about you will be provided by you, for example during registration on our App, when you complete an application to subscribe to the Services, when you interact with any Clinical Professionals and/or when you otherwise interact with us, whether via the App or by telephone or email. The provision of such information is voluntary, but if you cannot provide it to us, we may not be able to provide our Services to you. For example, if you cannot provide us with your name or age, we will not be able to register your account with Nabla.

We may also, with your consent, collect some of your Identity and Health Data from your usual GP.

Each time you visit our App we will automatically collect personal data including Technical Data and Usage Data. We collect this data using cookies and other similar technologies. Please see our cookie policy at Part B below for further details.

We will also receive Contact and Transaction Data about you from various third party providers of payment services, including Apple and Google.

  1. How we use your personal data

We will only use your personal data when the law allows us to do so. Most commonly we will use your personal data in the following circumstances:

The table below explains what we use (process) your personal information for (other than the special category of data) and our reasons for doing so.

Purpose/activity

Type of data

Lawful basis for processing

Installation of the App

Technical

Consent

To register you as a new user

Identity

Contact

Technical

Performance of a contract with you

To process purchases and deliver Services and our products including managing payments and collecting money owed to us

Identity

Contact

Transaction

Technical

Marketing and Communications

Performance of a contract with you

Necessary for our legitimate interests (to recover debts due to us)

To manage our relationship with you including responding to your queries and requests, notifying you of changes to the App, any Services and/or our terms and conditions or this privacy policy

Identity

Contact

Profile

Performance of a contract with you

Necessary for our legitimate interests (to keep records updated and to analyse how customers use the Services)

Necessary to comply with legal obligations (to inform you of any changes to our terms and conditions)

To enable you to complete a survey or questionnaire about the Services or the App

Identity

Contact

Technical

Profile

Your consent

Performance of a contract with you

Necessary for our legitimate interests (to analyse how customers use the Services and to develop them and grow our business)

To send you updates (by email or via notifications/messaging service) about the Services, , promotions or new services

Identity

Contact

Technical

Profile

Necessary for our legitimate interest (to promote the Services, develop the Services, and grow our business) – if you have purchased our services in the past and we are sending you information about similar services

Consent – if you have not purchased the Services in the past

To administer and protect our business and our App, including troubleshooting, data analysis and system testing

Identity

Contact

Technical

Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security)

To deliver content and advertisements to you

To measure and analyse the effectiveness of the advertising we serve you

To monitor trends so we can improve the App

Identity

Contact

Technical

Profile

Usage

Necessary for our legitimate interests (to develop our Services and grow our business)

To ensure that our Clinical Professionals are able to meet their regulatory obligations and provide an appropriate level of care to you

Identity

Contact

Vital Interests

To comply with a legal or regulatory obligation or expectation

To facilitate public authorities in carrying out their functions, including to report suspected safeguarding issues or criminal activity to the police or local authorities

Identity

Contact

Vital Interests

To comply with a legal or regulatory obligation or expectation

In relation to your Health Data, we use this data to provide you with the Services (a healthcare service), including giving your health and wellbeing advice, and diagnostic and treatment advice when you are speaking to a Clinical Professional.

With due regard for your anonymity, we may also use your personal information and Health Data in the context of statistical analyses and studies and for the purposes of quality control and improvement of the Services. This may include, for example, the development of machine learning models.

Your Health Data may also be reused under the responsibility of researchers for studies of public interest in the field of health and aimed at improving knowledge and patient management: you will be regularly informed of each study that will be implemented from your Health and Personal Data and may object to it if you wish.

These studies in the field of health conducted from the reuse of your Health Data:

- will be aimed at improving patient knowledge and management,

- must be of public interest within the meaning of the legal and regulatory provisions in force,

- will be conducted by researchers who have previously complied with the formalities applicable before the authorities, and in particular the ICO,

- will be validated by a scientific committee set up for this purpose.

We have set out a description of the detailed purposes which we use your Health Data in connection to providing you a healthcare service, and the lawful bases we rely on to do so.

Purpose/Activity

Lawful Basis

We obtain from you, or your GP on your behalf, medical and wellbeing data as is necessary to deliver effective and safe healthcare services to you.

Explicit consent

Provision of health or social care

We send your medical records (including your prescribed medicine history) to Clinical Professionals you are speaking to. This helps our Clinical Professionals safely provide you with medical and wellbeing care, and is for your safety.

Provision of health or social care

Vital interests

We are required to keep a record of the medical and wellbeing care you receive, including records of all conversations with Clinical Professionals. This helps our Clinical Professionals safely provide you with future medical and wellbeing care, and is for your safety and in accordance with legal and regulatory obligations.

Provision of health or social care

We send your data to your GP or and NHS provider to assist with the provision of your medical care. This data may include your prescribed medicine history and your medical record.

This may include providing your data to a hospital or other healthcare provider in an emergency.

Explicit consent

Provision of health or social care

Vital interests

We make available your prescription together with some Identity and Contact data to the pharmacy of your choice where you will pick up your drugs

Provision of health or social care

To ensure that our Clinical Professionals are able to meet their regulatory obligations and provide an appropriate level of care to you

Provision of health or social care

To facilitate public authorities in carrying out their functions, including to report suspected safeguarding issues or criminal activity to the police or local authorities.

Substantial public interest

To complete scientific studies and develop new features or services based for example on machine learning models to help Clinical Professionals to provide better and personalized care services

Substantial public interest

Provision of health or social care

Necessary for our legitimate interests (to develop our Services and grow our business)

NOTICE: You may be asked by Clinical Professionals to share intimate pictures or videos in the course of a consultation to help Clinical Professionals establish a diagnosis or provide advice. When judged relevant, the Clinical Professionals will ask you for your consent to retain the pictures or videos in your Health Data. No record will be kept without your consent. The Clinical Professionals may also decide that it is not relevant to store the picture in your Health Data, in which case they will inform you of the reasons for this decision.

  1. Disclosures of your personal data

The above purposes and activities may require us to pass on some of your personal data to the following third parties:

We only allow our service providers to handle your personal information if we are satisfied they take appropriate measures to protect your personal information. We also impose contractual obligations on service providers to ensure they can only use your personal information to provide services to us and to you and for no other reasons.

We may disclose and exchange information with law enforcement agencies and regulatory bodies to comply with our legal and regulatory obligations.

  1. Data security

All information you provide to us is stored on our secure servers. Any payment transactions carried out by us or our chosen third-party provider of payment processing services will be encrypted. Where we have given you (or where you have chosen) a password that enables you to access certain parts of our App, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.

Once we have received your information, we will use strict procedures and security features to try to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator when we are legally required to do so.

We do not transfer or process your personal data outside of the UK and/or the EEA.

We do transfer certain Aggregated Data to the USA (however for the avoidance of doubt, such does not contain any personal data) to help us improve our services to you and other users of the App.

  1. Data retention

We retain your personal data for as long as we need it for the purposes we have collected it for, such as providing the Services and/or the App to you. We may retain your personal data for a longer period if you make a complaint under this privacy policy or our terms and conditions, or if we have a reasonable belief that litigation may arise in relation to our relationship with you. We may also be required to retain certain personal data from you to comply with our legal and regulatory requirements.

In some circumstances you can ask us to delete your data: see your legal rights section below for further information.

In some circumstances, we will anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.

  1. Your legal rights

Under certain circumstances, you have the following rights under data protection laws in relation to your personal data.

You also have the right to ask us not to continue to process your personal data for marketing purposes.

If you would like to exercise any of those rights, please contact us (see contact details in paragraph 3 above) and:

We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

  1. How to complain

If you are unhappy with the way in which we have handled your personal please get in touch with us by sending an email to dpo@nabla.com.

You are also entitled to make a complaint to the Information Commissioner’s Office (“ICO”) (https://ico.org.uk) – however we would appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.

  1. Changes to this privacy policy

We keep this privacy policy under regular review and may update it from time to time without notice to you, so please check it regularly. We will however aim to bring any significant changes to your attention.


PART B - NABLA COOKIES POLICY

Date of policy: 7th October 2021

This cookies policy explains how Nabla uses cookies and other tracking technologies on the App. This cookies policy is to be read alongside our privacy policy above which explains how we use personal information.

  1. What are web cookies?

Web cookies are small files that are placed on your computer or mobile device by a website when you visit it. They contain details of your browsing history on that website and distinguish you from other users. Cookies send data back to the originating website on each subsequent visit or allow another website or app to recognise the cookie. Cookies are useful because they allow a website or app to recognise a user’s device and, for instance, remember your preferences and generally improve your online user experience. Like most websites and apps, we use cookies.

Although this cookies policy refers to the general term “cookie”, which is the main method used by the App to store information, the browser’s local storage space is also used for the same purpose and we may use other tracking technologies through the App. As a result, the information included in this cookie policy is likewise applicable to all such tracking technologies that we use.

  1. Why do we use cookies?
  1. What cookies do we use?

The table below provides more information about the cookies and other tracking technologies we use and why.

Name of cookie

Owner

Purpose of the cookie

Duration

Amplitude Growth Platform

Amplitude Inc (San Francisco, USA)

This is a web analytics service provided by Amplitude, Inc which uses cookies to show us how users use our App, and how we can enhance their experience. It provides us with anonymised information about the behaviour of our users (e.g., how long they stayed on the App, the tab they used) and also tells us how many users we have had

Persistent

Purchasely

Purchasely

The App uses Purchasely to manage trial versions and paid subscriptions.

Persistent

  1. Cookie acceptance

By logging into the App you have consented to our use of cookies as updated from time to time. In particular, you consent to cookies being stored on your computer and/or mobile device (unless rejected or disabled by your browser).

  1. Updating our cookies policy

We may update our use of cookies from time to time and consequently, we may update this policy. We, therefore, recommend that you check this cookies policy regularly.