Privacy policy
Effective Date: 3 April 2025
Introduction
At Nurture®, we know that your privacy is important — especially when it comes to health information. This policy explains how we collect, use, and protect your data, so you feel confident and informed every step of the way. Whether you're completing a health questionnaire, ordering supplements, or using NurtureKit®, we want you to know exactly what’s happening with your information — and why.
Purpose of This Privacy Policy
This Privacy Policy sets out how Nurturelife Tech Limited (“we”, “our”, “us”) handles your personal data. It explains what information we collect, how we use it, your rights, and how we ensure your data is protected. It applies to all personal data we collect through our website, mobile applications, subscription platform, customer support, at-home tests, and any other interactions you have with us.
What Is Not Covered by This Privacy Policy
This Privacy Policy applies only to Nurture®’s own services and platforms. It does not apply to third-party websites, platforms, or services that we do not control. If you follow a link to a third-party service (e.g. Meta, Stripe, or laboratory portals), please note that those services have their own privacy policies. We are not responsible for how third parties collect or use your data, and we recommend reviewing their privacy policies directly or contacting them if you have questions.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal obligations, or for other operational reasons. When we do, we will revise the “Effective Date” at the top of the policy. If the changes are material, we will notify you by email (if we have your contact details) or through our website. We encourage you to review this Privacy Policy regularly to stay informed about how we are protecting your data.
Nurturelife Tech Limited ("we", "our", "us" or "Nurture®") is committed to protecting and respecting your privacy. Our website is available at www.nurture-life.co.uk. This Privacy Policy explains how we collect, use, store, and share your personal data when you use our services, including through our website, mobile applications, subscription platform, and at-home testing services.
1. Who We Are
Nurturelife Tech Limited is a company registered in England and Wales under company number 15317299, with its registered virtual office at 12 Old Bond Street, London, W1S 4PL.
We act as the data controller in respect of personal data we process.
For any data protection queries, you can contact our Privacy Officer at: data@nurture-life.co.uk.
2. Types of Data We Collect
We may collect and process the following categories of personal data:
a. Identity & Contact Information
-
- Name
- Email address
- Postal address
- Date of birth
- Contact number
b. Health & Special Category Data (processed with explicit consent)
-
- Pregnancy stage and due date
- Previous history of pregnancy
- Responses to onboarding health questionnaires
- Test results from NurtureKit® (e.g. DHA levels, Nutrient deficiencies)
- Supplement usage and related health information
- Declared allergies or confirmations of no known allergies
c. Subscription & Order Data
-
- Order history and product selections
- Subscription preferences and status
- Delivery and fulfilment details
d. Payment & Transaction Data
-
- Payment method and transaction ID (via secure third-party processors e.g. Shopify payments)
- Billing address
e. Technical & Usage Data
-
- IP address
- Browser and device type
- Website usage behaviour
- Cookies and similar tracking technologies
f. Marketing & Communication Preferences
-
- Email and communication opt-in status
- Interaction with marketing emails (e.g. opens, clicks)
3. How We Collect Your Data
We collect data:
- Directly from you via web forms, account setup, questionnaire submissions, and NurtureKit®
- Automatically through cookies and analytics tools
- From third-party services that help us deliver or improve our offering (e.g. payment platforms, laboratories)
4. Purposes and Lawful Basis for Processing
|
Purpose |
Lawful Basis |
|
Fulfilling orders and subscriptions |
Contractual necessity |
|
Delivering at-home test results and analysis |
Explicit consent |
|
Tailoring supplement recommendations |
Explicit consent |
|
Customer support and communications |
Contractual necessity / Legitimate interest |
|
Marketing communications |
Consent |
|
Analytics and service improvements |
Legitimate interest (with safeguards) |
|
Legal and financial compliance |
Legal obligation |
5. Special Category Data
Health-related data, including pregnancy status, test results, and allergy declarations, is processed only with your explicit consent. This data is securely stored and used solely to provide tailored recommendations, improve our services, and ensure your safety.
Please note: In certain circumstances, such as reported adverse reactions, we may retain allergen declarations (including where a user has confirmed no known allergies) even if a request for erasure has been made. This is necessary to comply with our legal obligations and to ensure consumer safety in the event of a reported product issue.
Where we use health data for internal research and development purposes, this is done only after obtaining your explicit consent. All research data is anonymised and cannot be traced back to any individual.
You may withdraw your consent at any time by contacting us at data@nurture-life.co.uk, except where retention is required by law or to fulfil our regulatory obligations.
6. Sharing Your Data
We may share your data with trusted third-party processors who help us deliver our services, such as:
- Fulfilment providers (e.g. delivery couriers)
- Laboratories for test result processing
- IT service providers (e.g. hosting, cloud services)
- Marketing platforms (e.g. Meta, Google) where consent has been given
- Payment processors (e.g. Shopify Payments)
All third parties are contractually bound to process your data only on our instructions and in compliance with data protection law.
7. International Data Transfers
Where we transfer your personal data outside the UK (e.g. cloud storage providers or analytics tools), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions.
8. Data Retention
We retain personal data only for as long as necessary:
- Identity, contact, and subscription data: up to 7 years after last interaction (for legal/regulatory purposes)
- Health data (e.g. test results): retained for up to 24 months after cancellation or until consent is withdrawn, unless longer retention is required for safety or legal purposes
- Allergen declarations: retained for product safety purposes where necessary, even following a deletion request
- Marketing preferences: retained until consent is withdrawn
Data may be anonymised for internal research and development where separate explicit consent is obtained.
9. Data Storage & Hosting
All personal data processed by Nurture® is stored on secure servers hosted by trusted third-party providers with data centres located in the United Kingdom and European Economic Area (EEA). We may use cloud platforms (such as AWS or Azure) that meet international security certifications including ISO 27001 and SOC 2.
Data is encrypted at rest and in transit using industry-standard protocols. Access is restricted to authorised personnel on a need-to-know basis, with multi-factor authentication and audit logging in place.
We regularly review and update our storage infrastructure, conduct penetration testing, and maintain detailed data flow and system maps to ensure ongoing compliance and security.
All data backups are encrypted and follow a secure deletion cycle when no longer required.
10. Your Rights
You have the following rights under the UK GDPR:
- To access your personal data
- To request rectification or erasure
- To object to or restrict processing
- To withdraw consent at any time
- To request data portability
- To lodge a complaint with the Information Commissioner's Office (ICO)
To exercise any of these rights, contact us at data@nurture-life.co.uk.
11. Cookies
We use cookies to enhance your browsing experience, personalise content, and analyse traffic. You can manage your cookie preferences via our website banner or browser settings.
12. Data Security
We implement appropriate technical and organisational measures to safeguard your data, including:
- Encryption of sensitive data
- Secure hosting environments
- Role-based access controls
- Regular security audits
13. Profiling and Supplement Recommendations
We use your health data (e.g. test results, pregnancy stage) to tailor supplement recommendations based on evidence-based guidelines. This constitutes profiling under UK GDPR. However, we do not carry out any automated decision-making that produces legal or similarly significant effects. You can contact us at any time if you would like more information or to object to this processing.
14. Children’s Data
Our services are intended for adults aged 18 and over. We do not knowingly collect or process personal data from individuals under 18 years of age.
15. Contact Us
For any privacy-related queries, contact: Privacy Officer
Nurturelife Tech Limited
data@nurture-life.co.uk
If you are not satisfied with our response, you may lodge a complaint with the Information Commissioner's Office at www.ico.org.uk.
This Privacy Policy is kept under regular review and may be updated from time to time.