Home/Privacy policy
Legal

Privacy policy

Last updated: [date — to be added]. How Interval would handle your information, and the rights you would have under UK data protection law.


Placeholder — pending legal review; not binding. This is a draft procedure, pending review before the service opens. It is not legal advice and does not describe live data processing, because the concept collects no personal data. The final policy will be drafted and reviewed by a qualified adviser before Interval processes any personal data. Bracketed items are placeholders for real details.

This policy would explain how [registered company name — to be added] ("Interval", "we", "us") collects and uses personal data, and would be the data controller for that data. Because discretion is the product, the guiding rule would be simple: collect the minimum needed, and no more.

What we collect

To provide care, we would collect only what is necessary, which is likely to include: your name and contact details; account and order information; payment details processed by our payment provider; and relevant health information you choose to share so a clinician can review your plan. Health information is a special category of data and would be handled with particular care.

Why we collect it (lawful basis under UK GDPR)

We would rely on the lawful bases set out in UK GDPR, which for a service of this kind are typically: performance of a contract with you; our legitimate interests in running the service safely; consent where required; and, for health information, the conditions relating to the provision of health care and treatment by or under the responsibility of a health professional. The exact bases would be confirmed here: [lawful bases — to be confirmed by counsel].

Data minimisation and retention

We would keep only what your care requires, for only as long as we need it or the law requires us to. Retention periods would be set out here: [retention schedule — to be added]. Where information is no longer needed, it would be securely deleted or anonymised.

Who we share with

We would share your information only where it is needed to provide care, plainly and never more widely than necessary. This is likely to include: the dispensing pharmacy that prepares and sends your order; the registered clinician who reviews your plan; and service providers such as our payment processor and delivery partner. We would not sell your data or use it for third-party advertising. The full list of processors would be published here: [list of data processors — to be added].

Your rights

Under UK data protection law you would have rights to access your data, to have it corrected or erased, to restrict or object to certain processing, and to data portability, alongside the right to withdraw consent where processing relies on it. You would be able to exercise these by contacting us at [privacy contact email — to be added].

Cookies and analytics

The website would use only the cookies needed to make it work, plus any analytics we set out and ask your consent for where required. A full cookie notice would be published here: [cookie notice — to be added].

Complaints to the ICO

If you were unhappy with how we handled your data, you would be able to complain to the Information Commissioner's Office (ICO), the UK data protection regulator, at ico.org.uk. We would ask for the chance to put things right first, but you can go to the ICO at any time.

Contact

Questions about this policy, or about your data, would go to our data protection contact: [data protection officer or contact — to be appointed], at [privacy contact email — to be added], or by post to [registered company name and address — to be added]. You can also use the contact page.

See also the terms of service and the complaints procedure, both placeholder templates pending review. Our approach to discretion in everyday use is described on privacy and discretion.