GLOBAL PRIVACY POLICY
Last updated: July 2026
1. INTRODUCTION
1.1 Purpose
This Privacy Policy explains how pH7 collects, uses, stores, shares and protects personal information when you use the pH7 platform (the Platform).
It also explains your privacy rights and how applicable privacy laws protect you.
pH7 is committed to processing personal information lawfully, fairly, transparently and securely across every jurisdiction in which it operates.
1.2 Scope
This Privacy Policy applies to all users of the Platform, including:
Patients;
Healthcare Professionals;
Pharmacies;
Business customers;
Visitors to our website; and
Any other individual whose personal information is processed through the Platform.
Country-specific privacy requirements are contained within the applicable country schedules, which form part of this Privacy Policy.
1.3 About pH7
pH7 is a healthcare technology platform.
We provide technology that enables Patients, independent Healthcare Professionals and Pharmacies to interact securely through a single digital platform.
pH7 does not provide medical advice, diagnose medical conditions, prescribe medicines or dispense medications.
Clinical decisions remain solely the responsibility of independent Healthcare Professionals.
1.4 Controller and Processor Roles
Depending on the service being provided, pH7 may act as either:
a Data Controller;
a Joint Controller, where permitted by law; or
a Data Processor acting on behalf of another organisation.
Independent Healthcare Professionals remain responsible for the processing of personal information relating to the healthcare they provide.
Independent Pharmacies remain responsible for personal information processed for prescription dispensing and pharmaceutical care.
The precise allocation of responsibilities is explained throughout this Privacy Policy and within the applicable country schedule.
2. WHO WE ARE
The pH7 Platform is operated through separate legal entities depending upon the country in which Services are provided.
Country-specific operating entities are set out in the applicable country schedules.
For general privacy enquiries:
Email: privacy@ph7.health
3. OUR PRIVACY PRINCIPLES
pH7 is committed to processing personal information in accordance with the following principles:
lawfulness;
fairness;
transparency;
purpose limitation;
data minimisation;
accuracy;
storage limitation;
integrity;
confidentiality; and
accountability.
Where applicable, these principles are applied in accordance with:
the EU General Data Protection Regulation (GDPR);
the UK GDPR;
the Australian Privacy Act 1988;
and other applicable privacy legislation.
4. DEFINITIONS
For the purposes of this Privacy Policy:
Personal Information means any information relating to an identified or identifiable individual.
Health Information means information relating to a person’s physical or mental health, medical treatment, prescriptions or healthcare.
Processing means any operation performed on personal information including collection, storage, use, disclosure or deletion.
Patient means an individual seeking healthcare services through the Platform.
Healthcare Professional means an independent licensed healthcare practitioner using the Platform.
Pharmacy means an independent pharmacy connected to the Platform.
Platform means the pH7 software platform, website and mobile applications.
5. OUR ROLE
pH7 operates a healthcare technology platform that facilitates interactions between Patients, Healthcare Professionals and Pharmacies.
Our services include:
patient onboarding;
appointment booking;
identity verification;
secure messaging;
video consultations;
payment processing;
prescription workflow management;
pharmacy integration;
notifications;
customer support; and
platform administration.
pH7 does not make clinical decisions on behalf of Healthcare Professionals.
pH7 does not use automated decision-making or artificial intelligence to diagnose patients or determine clinical treatment.
6. WHO THIS POLICY APPLIES TO
This Privacy Policy applies to personal information processed about:
Patients;
prospective Patients;
Healthcare Professionals;
Pharmacies;
business partners;
website visitors;
suppliers; and
authorised representatives.
7. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect:
changes in legislation;
regulatory guidance;
Platform functionality;
business operations; or
security practices.
Where changes are material, we will notify users through appropriate channels including:
the Platform;
email;
website notices; or
in-app notifications.
The latest version will always be available on our website.
8. CONTACT
For questions relating to this Privacy Policy, please contact:
Privacy Team
privacy@ph7.health
If required by applicable law, country-specific privacy contacts or regulatory representatives are listed within the relevant country schedule.
This Global Privacy Policy should be read together with:
the pH7 Terms and Conditions;
the Cookie Policy;
the applicable Country Privacy Schedule (United Kingdom, Portugal or Australia); and
any additional privacy notices presented when using specific Platform features.
9. PERSONAL INFORMATION WE COLLECT
9.1 Information You Provide
Depending on your use of the Platform, we may collect:
Identity Information
Full name
Date of birth
Gender (where applicable)
Government identification documents
Identity verification information
Photographs or selfie verification
National health identifiers where required by law
Contact Information
Residential address
Email address
Telephone number
Emergency contact information (where applicable)
Account Information
Username
Password (encrypted)
Security preferences
Multi-factor authentication settings
Notification preferences
Language preferences
Health Information
Where required to provide healthcare services, we may process:
Medical history
Current symptoms
Existing medical conditions
Allergies
Current medications
Previous treatments
Consultation notes
Medical questionnaires
Clinical assessments
Uploaded medical documents
Laboratory results
Referral letters
Prescriptions
Healthcare correspondence
Health information is classified as Special Category Personal Data (or equivalent under applicable law) and receives additional legal protections.
9.2 Information Collected Automatically
When you use the Platform, we automatically collect certain technical information, including:
Device Information
Device type
Operating system
Browser type
App version
Device identifiers
Technical Information
IP address
Internet service provider
Login timestamps
Authentication logs
Session identifiers
Error logs
Performance metrics
Usage Information
Features accessed
Pages visited
Time spent using the Platform
Navigation behaviour
Appointment activity
Communication timestamps
Security Information
To protect users and the Platform we maintain security logs including:
Login attempts
Failed authentication attempts
Device changes
Suspicious activity
Audit logs
Fraud prevention records
9.3 Information We Receive From Third Parties
Where permitted by law, we may receive personal information from:
Healthcare Professionals
Including:
Consultation outcomes
Clinical documentation
Prescriptions
Referral information
Follow-up recommendations
Pharmacies
Including:
Prescription fulfilment status
Dispensing confirmations
Delivery status
Medication availability
Identity Verification Providers
Including:
Identity verification results
Fraud prevention checks
Sanctions screening (where applicable)
Payment Providers
Including:
Payment confirmations
Transaction references
Refund status
Fraud monitoring information
pH7 does not receive or store full payment card details.
Regulatory Bodies
Where required by law we may receive information relating to:
Professional registration
Practitioner licensing
Compliance investigations
Regulatory sanctions
Business Partners
Where authorised, we may receive information from:
Referral partners
Healthcare organisations
Employers (where healthcare services are employer-sponsored)
Insurance providers (where applicable)
9.4 Information You Choose to Upload
You may voluntarily upload information including:
Identification documents
Medical reports
Referral letters
Diagnostic imaging
Laboratory results
Insurance documentation
Supporting correspondence
You are responsible for ensuring uploaded information is accurate and that you have the legal right to provide it.
9.5 Information We Do Not Intentionally Collect
The Platform is not intended for children unless expressly permitted under applicable law and supervised by an authorised parent or guardian.
We do not knowingly collect personal information from children where prohibited by law.
If we become aware that such information has been collected unlawfully, we will delete it as soon as reasonably practicable.
9.6 Sensitive Information
Depending on the services provided, we may process sensitive or special category personal information, including:
Health information
Prescription information
Biometric verification data
Government identification data
Racial or ethnic information where required for healthcare
Genetic information where provided during treatment
Other information protected under applicable privacy legislation
Such information is processed only where permitted by law and subject to appropriate technical, organisational and legal safeguards.
9.7 Information Required to Use the Platform
Some personal information is mandatory in order to:
verify identity;
provide healthcare services;
comply with legal obligations;
facilitate consultations;
process payments;
issue prescriptions; and
enable pharmacy fulfilment.
If mandatory information is not provided, some Platform services may be unavailable.
10. HOW WE USE YOUR PERSONAL INFORMATION
We process personal information only where we have a lawful basis to do so and only for legitimate healthcare, operational, security, or legal purposes.
10.1 Providing the Platform
We use your personal information to:
create and manage your account;
verify your identity;
authenticate access to the Platform;
provide Platform functionality;
manage consultations;
facilitate secure communication between users;
support healthcare workflows;
enable prescription processing;
facilitate pharmacy fulfilment where requested;
provide customer support; and
administer your relationship with pH7.
10.2 Facilitating Healthcare Services
Where you choose to use healthcare services through the Platform, we process personal information to:
facilitate appointments;
provide healthcare professionals with relevant information;
enable clinical documentation;
support prescription workflows;
facilitate referrals where appropriate;
maintain consultation records;
improve continuity of care; and
comply with applicable healthcare regulations.
Healthcare professionals remain independently responsible for all clinical decisions.
pH7 does not provide medical advice or influence clinical judgement.
10.3 Identity Verification and Fraud Prevention
We process personal information to:
verify user identities;
comply with Know Your Customer (KYC) requirements where applicable;
detect fraud;
prevent misuse of the Platform;
investigate suspicious activity;
maintain Platform security; and
protect patients, healthcare professionals and pharmacies.
10.4 Payments and Financial Administration
Where payments are processed through the Platform, we use personal information to:
process consultation payments;
manage invoices and receipts;
administer refunds;
detect payment fraud;
comply with financial reporting obligations; and
maintain transaction records.
Payment card information is processed by authorised payment providers and is not stored by pH7.
10.5 Communications
We may use personal information to communicate with you regarding:
appointments;
account activity;
security notifications;
service updates;
regulatory notices;
changes to our legal documents;
customer support requests; and
operational announcements.
Where required by law, marketing communications are sent only with your consent.
You may opt out of marketing communications at any time.
10.6 Improving the Platform
We analyse Platform usage to:
improve functionality;
identify technical issues;
enhance performance;
improve user experience;
develop new features;
understand user behaviour; and
monitor service quality.
Where possible, this analysis uses aggregated or anonymised information.
10.7 Regulatory and Legal Compliance
We process personal information where necessary to:
comply with applicable laws;
comply with healthcare regulations;
comply with data protection legislation;
comply with financial crime legislation;
respond to lawful requests from regulators;
respond to court orders;
protect legal rights; and
establish, exercise or defend legal claims.
10.8 Information Security
We process personal information to:
secure the Platform;
monitor unauthorised access;
detect cybersecurity threats;
investigate incidents;
maintain audit logs;
protect confidential information; and
ensure business continuity.
10.9 Research, Analytics and Service Improvement
Where permitted by law, we may use anonymised or aggregated information to:
improve healthcare delivery;
improve Platform functionality;
understand usage trends;
develop new services;
produce statistical reports; and
support internal business planning.
We do not use identifiable patient medical information for research without an appropriate legal basis or required consent.
10.10 Corporate Transactions
If pH7 undergoes:
a merger;
acquisition;
restructuring;
investment;
financing;
sale of assets; or
business transfer,
personal information may be disclosed to professional advisers and prospective purchasers subject to appropriate confidentiality obligations and applicable law.
10.11 Automated Decision-Making
pH7 does not make automated decisions that produce legal or similarly significant effects on individuals without appropriate human involvement, unless permitted by applicable law.
Where automated systems are used for fraud detection, identity verification or security monitoring, appropriate safeguards are implemented.
10.12 Legal Bases for Processing
Depending on the circumstances and jurisdiction, we process personal information on one or more of the following legal bases:
your consent;
performance of a contract;
compliance with legal obligations;
protection of vital interests;
provision of healthcare services;
substantial public interest where permitted by law; and
our legitimate interests, provided those interests are not overridden by your rights and freedoms.
Where consent is relied upon, you may withdraw that consent at any time, although this may affect your ability to use certain Platform services.
11. WHO WE SHARE YOUR PERSONAL INFORMATION WITH
We do not sell your personal information.
We share personal information only where necessary to provide Platform services, comply with legal obligations, protect users, or operate our business.
11.1 Healthcare Professionals
Where you request healthcare services through the Platform, we share relevant personal information with the independent healthcare professional providing your care.
This may include:
identity information;
contact information;
medical history;
consultation information;
uploaded medical documents;
prescriptions;
laboratory results; and
other information you choose to provide.
Healthcare professionals are independent data controllers (or equivalent under applicable law) in relation to the medical care they provide.
They are independently responsible for complying with applicable healthcare and privacy legislation.
11.2 Pharmacies
Where you choose to have a prescription fulfilled through the Platform, we may share relevant information with your selected pharmacy.
This may include:
identity information;
contact details;
prescription information;
delivery information; and
information necessary to dispense medication.
Pharmacies are independently responsible for their own legal and regulatory obligations.
11.3 Payment Providers
Payments are processed by authorised third-party payment providers.
We may share information necessary to:
process payments;
detect fraud;
issue refunds;
verify transactions; and
comply with financial regulations.
pH7 does not receive or store full payment card details.
11.4 Identity Verification Providers
Where identity verification is required, we may share information with specialist identity verification providers.
This may include:
identification documents;
photographs;
identity verification data; and
fraud prevention information.
These providers process information solely for identity verification and compliance purposes.
11.5 Technology Service Providers
We use carefully selected third-party providers to operate the Platform.
These may include providers of:
cloud hosting;
infrastructure;
cybersecurity;
data storage;
email delivery;
SMS services;
video consultations;
customer support;
analytics;
monitoring;
authentication;
payment processing; and
software development tools.
All providers are contractually required to implement appropriate security and confidentiality measures.
11.6 Professional Advisers
We may disclose information where reasonably necessary to our:
lawyers;
accountants;
auditors;
insurers;
regulatory advisers; and
other professional advisers.
Such disclosures are subject to professional confidentiality obligations.
11.7 Regulatory Authorities
We may disclose personal information where required or authorised by law to:
healthcare regulators;
medicines regulators;
data protection authorities;
courts;
law enforcement agencies;
tax authorities;
financial regulators; and
other competent public authorities.
We disclose only the information reasonably necessary to comply with our legal obligations.
11.8 Corporate Transactions
If pH7 undergoes:
investment;
fundraising;
merger;
acquisition;
restructuring;
sale of assets; or
business transfer,
personal information may be disclosed to:
prospective investors;
purchasers;
lenders;
legal advisers;
financial advisers; and
transaction advisers,
provided appropriate confidentiality obligations are in place and applicable law is complied with.
11.9 International Service Providers
Some of our service providers operate internationally.
Where personal information is transferred internationally, we implement appropriate legal safeguards as described in the “International Data Transfers” section of this Privacy Policy.
11.10 We Never Sell Personal Information
pH7 does not sell personal information.
We do not sell health information.
We do not sell prescription information.
We do not permit third parties to purchase identifiable patient information for advertising or marketing purposes.
11.11 Disclosure Required by Law
We may disclose personal information where we reasonably believe disclosure is necessary to:
comply with legal obligations;
respond to lawful government requests;
protect public safety;
prevent fraud;
investigate criminal activity;
enforce our legal rights;
protect Platform security; or
defend legal proceedings.
Where legally permitted, we will seek to limit the scope of any disclosure to the minimum information reasonably required.
12. INTERNATIONAL DATA TRANSFERS
pH7 operates internationally. Depending on where you are located and which services you use, your personal information may be transferred to, stored in, or accessed from countries outside your country of residence.
We take appropriate legal, technical and organisational measures to ensure that all international transfers comply with applicable privacy laws.
12.1 Where Information May Be Transferred
Your personal information may be processed in countries where:
pH7 operates;
our affiliated companies operate;
healthcare professionals are located;
pharmacies are located;
our cloud infrastructure is hosted;
authorised service providers operate; or
our professional advisers are located.
12.2 Our Safeguards
Where required by law, international transfers are protected through one or more of the following mechanisms:
adequacy decisions recognised by the relevant regulator;
Standard Contractual Clauses (SCCs);
International Data Transfer Agreements (IDTAs);
Binding Corporate Rules (where applicable);
contractual confidentiality obligations;
encryption during transmission and storage; and
appropriate technical and organisational security measures.
12.3 Healthcare Services Across Borders
Where you voluntarily receive healthcare services from a healthcare professional or pharmacy located in another jurisdiction, your personal information may be transferred to that jurisdiction as necessary to provide the requested services.
Such transfers occur only where permitted by applicable law.
12.4 Cloud Infrastructure
The Platform uses reputable cloud infrastructure providers that may process personal information in multiple jurisdictions.
These providers are contractually required to maintain appropriate security, confidentiality and privacy protections.
12.5 Service Providers
Some authorised service providers supporting the Platform operate internationally.
These providers may include:
cloud hosting providers;
payment processors;
identity verification providers;
communications providers;
cybersecurity providers;
analytics providers; and
customer support providers.
All providers are subject to contractual obligations requiring appropriate protection of personal information.
12.6 Your Rights
Where applicable law grants you rights relating to international data transfers, you may request further information about:
the countries to which your information is transferred;
the legal safeguards relied upon; and
how those safeguards protect your personal information.
Requests may be submitted using the contact details provided at the end of this Privacy Policy.
12.7 Continuous Review
As pH7 expands internationally, we regularly review our international transfer arrangements to ensure they remain compliant with applicable privacy and healthcare legislation in every jurisdiction in which we operate.
13. DATA RETENTION
We retain personal information only for as long as necessary to fulfil the purposes described in this Privacy Policy, comply with applicable legal and regulatory obligations, resolve disputes, and enforce our legal rights.
Retention periods vary depending on the type of information, the services used, and the jurisdiction in which those services are provided.
13.1 General Principles
When determining how long personal information should be retained, we consider:
applicable legal requirements;
healthcare record retention obligations;
regulatory requirements;
contractual obligations;
ongoing patient care;
limitation periods for legal claims;
information security requirements; and
legitimate business needs.
When personal information is no longer required, it is securely deleted or irreversibly anonymised.
13.2 Patient Information
Patient information may include:
account information;
consultation records;
medical questionnaires;
prescriptions;
communications;
uploaded documents; and
appointment history.
Healthcare records are retained for the period required by applicable healthcare legislation in the jurisdiction where care was provided.
Where multiple legal requirements apply, we retain records for the longest mandatory period.
13.3 Healthcare Professional Information
Information relating to healthcare professionals may be retained while the professional maintains an account and for an appropriate period afterwards to:
demonstrate regulatory compliance;
maintain audit records;
resolve disputes;
investigate complaints; and
comply with legal obligations.
13.4 Financial Records
Invoices, payment records, accounting information and taxation records are retained for the periods required under applicable financial and taxation legislation.
13.5 Identity Verification Information
Identity verification information is retained only for as long as necessary to:
comply with legal obligations;
satisfy anti-fraud requirements;
comply with healthcare regulations; and
protect Platform security.
13.6 Technical Logs
Security logs, authentication records and system logs may be retained for longer than ordinary usage data where necessary to:
investigate security incidents;
prevent fraud;
protect the Platform;
comply with legal obligations; or
establish or defend legal claims.
13.7 Anonymised Information
Where personal information has been irreversibly anonymised so that individuals can no longer be identified, it may be retained indefinitely for:
statistical analysis;
Platform improvement;
business reporting;
service optimisation; and
research permitted by applicable law.
Anonymised information is no longer considered personal information.
13.8 Deletion Requests
Where you request deletion of your personal information, we will comply where required by applicable law.
However, we may retain information where necessary to:
comply with legal obligations;
maintain healthcare records;
prevent fraud;
resolve disputes;
enforce legal rights;
comply with regulatory requirements; or
protect the safety of users.
13.9 Secure Disposal
When personal information reaches the end of its retention period, we securely delete, destroy or anonymise it using appropriate technical and organisational measures designed to prevent unauthorised access, recovery or disclosure.
14. DATA SECURITY
Protecting personal information is a core part of pH7’s operations.
We maintain appropriate technical, organisational and administrative measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.
As no system can be guaranteed to be completely secure, users should also take reasonable steps to protect their own devices and account credentials.
14.1 Security Controls
We maintain security measures including, where appropriate:
encryption of data in transit;
encryption of data at rest;
role-based access controls;
least-privilege access principles;
multi-factor authentication for administrative systems;
network security monitoring;
intrusion detection and prevention;
vulnerability management;
security logging and audit trails;
backup and disaster recovery procedures; and
secure software development practices.
Security measures are reviewed regularly and updated where appropriate.
14.2 Access Controls
Access to personal information is restricted to authorised personnel who require access to perform their duties.
Access permissions are granted according to business need and reviewed periodically.
Administrative access is monitored and recorded.
14.3 Confidentiality
Employees, contractors and authorised service providers with access to personal information are subject to contractual confidentiality obligations and are expected to comply with applicable privacy and information security requirements.
14.4 Security Monitoring
We continuously monitor the Platform to detect:
unauthorised access;
suspicious activity;
attempted fraud;
cybersecurity threats;
malware;
unusual authentication events; and
other security incidents.
Security events are investigated in accordance with our internal incident response procedures.
14.5 Data Breaches
If we become aware of a personal data breach, we will:
investigate the incident promptly;
take reasonable steps to contain and remediate the issue;
assess any risks to affected individuals;
notify relevant supervisory authorities where required by law; and
notify affected individuals where legally required.
14.6 Business Continuity
We maintain business continuity and disaster recovery procedures designed to support the availability and resilience of Platform services.
These procedures are periodically reviewed and tested where appropriate.
14.7 User Responsibilities
Users are responsible for maintaining the security of their own accounts and devices.
You should:
keep your password confidential;
use strong, unique passwords;
enable multi-factor authentication where available;
promptly notify us of suspected unauthorised access; and
keep your devices reasonably secure.
14.8 Independent Healthcare Professionals
Healthcare professionals using the Platform remain independently responsible for protecting patient information within their own clinical systems and complying with their own professional, regulatory and legal obligations.
14.9 Continuous Improvement
Information security is an ongoing process.
We regularly review our technical, organisational and administrative safeguards to address evolving security risks, changes in technology and applicable legal requirements.
15. YOUR PRIVACY RIGHTS
Depending on where you are located, you may have certain rights regarding your personal information under applicable privacy legislation.
These rights are subject to legal limitations and may vary between jurisdictions.
15.1 Right of Access
You may request confirmation as to whether we process your personal information.
Where applicable, you may also request a copy of the personal information we hold about you.
15.2 Right to Rectification
You may request that inaccurate or incomplete personal information be corrected or updated.
Where appropriate, you may also update certain information directly through your Platform account.
15.3 Right to Erasure
You may request that we delete your personal information where:
it is no longer necessary for the purposes for which it was collected;
you withdraw consent where consent is the legal basis;
the information has been processed unlawfully; or
deletion is otherwise required by applicable law.
We may refuse deletion where we are legally required to retain the information, including for healthcare, regulatory, taxation or legal purposes.
15.4 Right to Restrict Processing
Where permitted by law, you may request that we temporarily restrict the processing of your personal information in certain circumstances, including where:
you dispute its accuracy;
processing is unlawful;
the information is no longer required by us but is required by you for legal claims; or
you have objected to processing pending verification of our legitimate interests.
15.5 Right to Data Portability
Where applicable, you may request a copy of personal information you have provided to us in a structured, commonly used and machine-readable format.
Where technically feasible and legally permitted, you may also request that the information be transferred directly to another organisation.
15.6 Right to Object
Where we rely on legitimate interests as the legal basis for processing, you may object to that processing.
We will consider your objection and cease processing unless we have compelling legitimate grounds or another lawful basis to continue.
Where personal information is processed for direct marketing, you may object at any time.
15.7 Right to Withdraw Consent
Where processing is based on your consent, you may withdraw that consent at any time.
Withdrawal does not affect processing carried out before consent was withdrawn.
Withdrawal of consent may affect your ability to use certain Platform services.
15.8 Rights Relating to Automated Decision-Making
Where applicable law provides such rights, you may request:
human review of certain automated decisions;
an explanation of significant automated processing; or
to challenge an automated decision.
As described in this Privacy Policy, pH7 does not make automated decisions producing legal or similarly significant effects without appropriate safeguards.
15.9 Exercising Your Rights
You may exercise your privacy rights by contacting us using the details provided at the end of this Privacy Policy.
Before responding, we may request additional information to verify your identity.
We will respond within the timeframes required by applicable law.
15.10 Complaints
If you believe your personal information has been processed unlawfully, you may lodge a complaint with the relevant data protection or privacy regulator in your jurisdiction.
We encourage you to contact us first so that we have the opportunity to investigate and resolve your concerns promptly.
16. COOKIES AND SIMILAR TECHNOLOGIES
The pH7 website uses cookies and similar technologies to operate securely, remember privacy choices and, where you give consent, support analytics and optional website functionality.
Optional cookies and similar technologies are disabled by default unless you actively accept them or save your preferences.
16.1 What Are Cookies?
Cookies are small text files stored on your device when you visit a website or use certain online services.
Cookies allow websites and applications to recognise your device, remember your preferences and improve functionality.
We may also use similar technologies such as:
local storage;
pixels;
web beacons;
session storage; and
other technologies performing similar functions.
16.2 Types of Cookies We Use
On the public pH7 website, we use the following categories:
Strictly Necessary Cookies
These technologies are essential for the operation of the website.
They enable functions such as:
website security;
navigation;
consent storage;
language and region preferences; and
core website functionality.
These technologies cannot be disabled because the website cannot operate correctly without them.
Functional Cookies
Functional technologies support optional website features and third-party features.
The pH7 website uses Shapo to display testimonial content. Shapo is blocked unless you enable functional cookies.
Performance and Analytics Cookies
Analytics technologies help us understand how visitors use the website and improve performance.
The pH7 website uses Google Analytics only after analytics consent is given.
Analytics may help us understand:
page usage;
navigation patterns;
session duration;
referral sources; and
website performance.
Where possible, analytics information is configured to be aggregated or privacy protective.
Marketing Cookies
Marketing technologies may be used for advertising, campaign measurement and audience analytics where enabled.
At the date of this Privacy Policy, the public pH7 website does not load Meta Pixel, LinkedIn Insight Tag, Hotjar, Microsoft Clarity or equivalent marketing pixels.
If we add a marketing provider in the future, we will update this Privacy Policy and the consent mechanism where required.
16.3 Managing Cookies
You can manage your cookie choices using the cookie banner or the Cookie Settings control in the website footer.
You may:
accept all cookies;
reject non-essential cookies;
customise your cookie preferences; or
withdraw previously granted consent.
Rejecting optional cookies will not prevent access to the website.
Strictly necessary technologies remain active because they are required to operate the website and remember your choices.
Most web browsers also allow cookies to be managed through browser settings. Please note that disabling certain browser storage may affect core website functionality.
16.4 Third-Party Technologies
The public pH7 website currently uses the following third-party technologies:
Google Analytics, used for website analytics only after analytics consent is given.
Shapo, used to display testimonial content only after functional consent is given.
We also use infrastructure and content delivery services that may be necessary to load the website, fonts, images, scripts and security features. These are treated separately from optional analytics, functional and marketing technologies.
Third-party providers process information in accordance with their own privacy obligations and contractual arrangements with pH7 where applicable.
Cookie consent records are stored for approximately six months unless you update or withdraw your choices earlier, the consent version changes, or a material provider/category change requires renewed consent.
16.5 Updates
As the Platform evolves, we may update our use of cookies and similar technologies.
Any material changes will be reflected in this Privacy Policy and, where required by law, through updated consent mechanisms.
17. CHILDREN’S PRIVACY
The Platform is intended for use by adults unless applicable law permits healthcare services to be provided to minors through an authorised parent, guardian or other legally authorised representative.
We do not knowingly collect personal information from children in circumstances where doing so would violate applicable law.
17.1 Use by Minors
Where permitted by applicable law, healthcare services may be accessed on behalf of a minor by:
a parent;
a legal guardian; or
another person legally authorised to act on the minor’s behalf.
Additional verification may be required before access is granted.
17.2 Information Relating to Children
Where healthcare services are lawfully provided to a child or young person, we process only the personal information reasonably necessary to:
verify identity;
provide healthcare services;
facilitate consultations;
support prescription fulfilment;
comply with legal obligations; and
maintain healthcare records.
Such information receives the same level of protection as all other health information processed through the Platform.
17.3 Unauthorised Collection
If we become aware that personal information relating to a child has been collected unlawfully or without the necessary authorisation, we will take reasonable steps to:
investigate the circumstances;
restrict access where appropriate; and
delete the information where required by applicable law.
17.4 Parent or Guardian Requests
Where permitted by law, parents or legal guardians may contact us regarding:
access to a child’s personal information;
correction of inaccurate information;
deletion requests; or
questions regarding our processing of children’s information.
Requests may be subject to identity and authority verification before action is taken.
17.5 Healthcare Records
Nothing in this section affects any legal obligation to retain healthcare records where retention is required by applicable healthcare legislation.
18. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, regulatory requirements, security practices or business operations.
Where required by applicable law, we will notify users of material changes before they take effect.
18.1 Why We May Update This Policy
We may revise this Privacy Policy to reflect changes including:
new Platform features or services;
changes to applicable laws or regulations;
guidance issued by regulatory authorities;
improvements to our privacy or security practices;
changes to our service providers or business operations; or
other operational or legal requirements.
18.2 Notification of Material Changes
Where required by law, we will notify users of material changes using one or more of the following methods:
publication on the Platform;
email to the registered email address associated with your account;
in-app notifications;
updates on our website; or
other reasonable communication methods.
We encourage users to review this Privacy Policy periodically to remain informed about how their personal information is processed.
18.3 Effective Date
The “Last Updated” date shown at the beginning of this Privacy Policy indicates when this version became effective.
Unless otherwise stated, amendments become effective on the date they are published.
Where required by applicable law, changes requiring your consent will not take effect until such consent has been obtained.
18.4 Continued Use of the Platform
Where permitted by applicable law, your continued use of the Platform after this Privacy Policy has been updated constitutes your acknowledgement of the revised Privacy Policy.
If you do not agree with any changes, you should stop using the Platform and, where applicable, request closure of your account in accordance with your rights under this Privacy Policy.
19. CONTACT INFORMATION
If you have any questions about this Privacy Policy, your personal information, or how pH7 processes your data, please contact us using the details below.
We encourage you to contact us first so that we have the opportunity to investigate and resolve any concerns promptly.
19.1 General Privacy Enquiries
For general questions relating to privacy, data protection or this Privacy Policy, please contact:
Email: privacy@ph7.health
19.2 Data Protection Requests
If you wish to exercise any of your privacy rights described in this Privacy Policy, including requests to:
access your personal information;
correct inaccurate information;
delete personal information;
restrict processing;
object to processing;
request data portability; or
withdraw consent where applicable,
please contact:
Email: privacy@ph7.health
To help us protect your personal information, we may request reasonable evidence to verify your identity before responding to your request.
19.3 Security Incidents
If you believe your account has been compromised or you become aware of a potential security incident affecting the Platform, please notify us as soon as reasonably possible.
Email: security@ph7.health
19.4 Registered Entities
Depending on the jurisdiction in which you access the Platform, your personal information may be processed by the relevant pH7 operating entity.
United Kingdom
Tetrodaxol GB Limited
Company Number: 16340858
Blayds House, 2nd Floor
21 Blayds Yard
Leeds
England LS1 4AD
Portugal
Tetrodaxol, Unipessoal Lda.
NIPC: 516762184
Avenida do Brasil, 43, 11.Âş Direito
1700-062 Lisbon
Portugal
Australia
Tetrodaxol AUS Pty Ltd
ACN: 698 563 816
C/- Suite 302
Level 3
191 Clarence Street
Sydney NSW 2000
Australia
19.5 Response Times
We aim to respond to all privacy enquiries as promptly as reasonably practicable.
Requests relating to privacy rights will be handled within the timeframes required by applicable privacy legislation.
20. COMPLAINTS AND REGULATORY AUTHORITIES
If you believe that we have processed your personal information in a manner that is inconsistent with applicable privacy laws, you have the right to lodge a complaint with the relevant privacy or data protection authority in your jurisdiction.
We encourage you to contact us first at privacy@ph7.health so that we have the opportunity to investigate your concerns and, where appropriate, resolve them promptly.
20.1 Internal Complaints
If you have concerns regarding:
the collection of your personal information;
the use or disclosure of your personal information;
the security of your information;
the exercise of your privacy rights; or
this Privacy Policy,
please contact us using the details provided in the Contact Information section.
We will investigate your complaint fairly, promptly and in accordance with applicable law.
20.2 United Kingdom
Individuals located in the United Kingdom may lodge a complaint with the:
Information Commissioner’s Office (ICO)
The ICO is the UK’s independent authority responsible for upholding information rights and enforcing UK data protection legislation.
20.3 Portugal
Individuals located in Portugal may lodge a complaint with the:
Comissão Nacional de Proteção de Dados (CNPD)
The CNPD is the Portuguese supervisory authority responsible for monitoring compliance with the General Data Protection Regulation (GDPR) and Portuguese data protection legislation.
20.4 Australia
Individuals located in Australia may lodge a complaint with the:
Office of the Australian Information Commissioner (OAIC)
The OAIC regulates privacy obligations under the Privacy Act 1988 (Cth) and investigates complaints relating to the handling of personal information.
20.5 European Economic Area
Individuals located in another Member State of the European Economic Area may lodge a complaint with the competent supervisory authority in their country of residence, place of work or the location of the alleged infringement, in accordance with Article 77 of the General Data Protection Regulation (GDPR).
20.6 No Effect on Other Legal Rights
Nothing in this Privacy Policy limits your right to seek another remedy available under applicable law or to pursue any other legal rights that may be available to you.