Privacy policy

Effective Date: 3 April 2025

Introduction

At Nurture®, we know that your privacy is important — especially when it comes to health information. This policy explains how we collect, use, and protect your data, so you feel confident and informed every step of the way. Whether you're completing a health questionnaire, ordering supplements, or using NurtureKit®, we want you to know exactly what’s happening with your information — and why.

Purpose of This Privacy Policy

This Privacy Policy sets out how Nurturelife Tech Limited (“we”, “our”, “us”) handles your personal data. It explains what information we collect, how we use it, your rights, and how we ensure your data is protected. It applies to all personal data we collect through our website, mobile applications, subscription platform, customer support, at-home tests, and any other interactions you have with us.

What Is Not Covered by This Privacy Policy

This Privacy Policy applies only to Nurture®’s own services and platforms. It does not apply to third-party websites, platforms, or services that we do not control. If you follow a link to a third-party service (e.g. Meta, Stripe, or laboratory portals), please note that those services have their own privacy policies. We are not responsible for how third parties collect or use your data, and we recommend reviewing their privacy policies directly or contacting them if you have questions.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal obligations, or for other operational reasons. When we do, we will revise the “Effective Date” at the top of the policy. If the changes are material, we will notify you by email (if we have your contact details) or through our website. We encourage you to review this Privacy Policy regularly to stay informed about how we are protecting your data.

Nurturelife Tech Limited ("we", "our", "us" or "Nurture®") is committed to protecting and respecting your privacy. Our website is available at www.nurture-life.co.uk. This Privacy Policy explains how we collect, use, store, and share your personal data when you use our services, including through our website, mobile applications, subscription platform, and at-home testing services.



 

1. Who We Are

Nurturelife Tech Limited is a company registered in England and Wales under company number 15317299, with its registered virtual office at 12 Old Bond Street, London, W1S 4PL.

We act as the data controller in respect of personal data we process.

For any data protection queries, you can contact our Privacy Officer at: data@nurture-life.co.uk.

2. Types of Data We Collect

We may collect and process the following categories of personal data:

a. Identity & Contact Information

    • Name
    • Email address
    • Postal address
    • Date of birth
    • Contact number 

b. Health & Special Category Data (processed with explicit consent)

    • Pregnancy stage and due date
    • Previous history of pregnancy
    • Responses to onboarding health questionnaires
    • Test results from NurtureKit® (e.g. DHA levels, Nutrient deficiencies)
    • Supplement usage and related health information
    • Declared allergies or confirmations of no known allergies

c. Subscription & Order Data

    • Order history and product selections
    • Subscription preferences and status
    • Delivery and fulfilment details

d. Payment & Transaction Data

    • Payment method and transaction ID (via secure third-party processors e.g. Shopify payments)
    • Billing address

e. Technical & Usage Data

    • IP address
    • Browser and device type
    • Website usage behaviour
    • Cookies and similar tracking technologies

f. Marketing & Communication Preferences

    • Email and communication opt-in status
    • Interaction with marketing emails (e.g. opens, clicks)

3. How We Collect Your Data

We collect data:

  • Directly from you via web forms, account setup, questionnaire submissions, and NurtureKit®
  • Automatically through cookies and analytics tools
  • From third-party services that help us deliver or improve our offering (e.g. payment platforms, laboratories)

4. Purposes and Lawful Basis for Processing

Purpose

Lawful Basis

Fulfilling orders and subscriptions

Contractual necessity

Delivering at-home test results and analysis

Explicit consent

Tailoring supplement recommendations

Explicit consent

Customer support and communications

Contractual necessity / Legitimate interest

Marketing communications

Consent

Analytics and service improvements

Legitimate interest (with safeguards)

Legal and financial compliance

Legal obligation


5. Special Category Data

Health-related data, including pregnancy status, test results, and allergy declarations, is processed only with your explicit consent. This data is securely stored and used solely to provide tailored recommendations, improve our services, and ensure your safety.

Please note: In certain circumstances, such as reported adverse reactions, we may retain allergen declarations (including where a user has confirmed no known allergies) even if a request for erasure has been made. This is necessary to comply with our legal obligations and to ensure consumer safety in the event of a reported product issue.

Where we use health data for internal research and development purposes, this is done only after obtaining your explicit consent. All research data is anonymised and cannot be traced back to any individual.

You may withdraw your consent at any time by contacting us at data@nurture-life.co.uk, except where retention is required by law or to fulfil our regulatory obligations.

6. Sharing Your Data

We may share your data with trusted third-party processors who help us deliver our services, such as:

  • Fulfilment providers (e.g. delivery couriers)
  • Laboratories for test result processing
  • IT service providers (e.g. hosting, cloud services)
  • Marketing platforms (e.g. Meta, Google) where consent has been given
  • Payment processors (e.g. Shopify Payments)

All third parties are contractually bound to process your data only on our instructions and in compliance with data protection law.

7. International Data Transfers

Where we transfer your personal data outside the UK (e.g. cloud storage providers or analytics tools), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions.

8. Data Retention

We retain personal data only for as long as necessary:

  • Identity, contact, and subscription data: up to 7 years after last interaction (for legal/regulatory purposes)
  • Health data (e.g. test results): retained for up to 24 months after cancellation or until consent is withdrawn, unless longer retention is required for safety or legal purposes
  • Allergen declarations: retained for product safety purposes where necessary, even following a deletion request
  • Marketing preferences: retained until consent is withdrawn

Data may be anonymised for internal research and development where separate explicit consent is obtained.

9. Data Storage & Hosting

All personal data processed by Nurture® is stored on secure servers hosted by trusted third-party providers with data centres located in the United Kingdom and European Economic Area (EEA). We may use cloud platforms (such as AWS or Azure) that meet international security certifications including ISO 27001 and SOC 2.

Data is encrypted at rest and in transit using industry-standard protocols. Access is restricted to authorised personnel on a need-to-know basis, with multi-factor authentication and audit logging in place.

We regularly review and update our storage infrastructure, conduct penetration testing, and maintain detailed data flow and system maps to ensure ongoing compliance and security.

All data backups are encrypted and follow a secure deletion cycle when no longer required.

10. Your Rights

You have the following rights under the UK GDPR:

  • To access your personal data
  • To request rectification or erasure
  • To object to or restrict processing
  • To withdraw consent at any time
  • To request data portability
  • To lodge a complaint with the Information Commissioner's Office (ICO)

To exercise any of these rights, contact us at data@nurture-life.co.uk.

11. Cookies

We use cookies to enhance your browsing experience, personalise content, and analyse traffic. You can manage your cookie preferences via our website banner or browser settings.

12. Data Security

We implement appropriate technical and organisational measures to safeguard your data, including:

  • Encryption of sensitive data
  • Secure hosting environments
  • Role-based access controls
  • Regular security audits

13. Profiling and Supplement Recommendations

We use your health data (e.g. test results, pregnancy stage) to tailor supplement recommendations based on evidence-based guidelines. This constitutes profiling under UK GDPR. However, we do not carry out any automated decision-making that produces legal or similarly significant effects. You can contact us at any time if you would like more information or to object to this processing.

14. Children’s Data

Our services are intended for adults aged 18 and over. We do not knowingly collect or process personal data from individuals under 18 years of age.

15. Contact Us

For any privacy-related queries, contact: Privacy Officer
Nurturelife Tech Limited
data@nurture-life.co.uk

If you are not satisfied with our response, you may lodge a complaint with the Information Commissioner's Office at www.ico.org.uk.

This Privacy Policy is kept under regular review and may be updated from time to time.