What we collect, and what we never do with it.
biomarkr exists to help you understand your own blood test results over time. That only works if you trust us with sensitive information, so this policy sets out exactly what we hold, why we hold it, and the limits we place on ourselves.
Who we are
biomarkr is an early stage product, operated from London in the United Kingdom by its founder as an individual. It is not yet an incorporated company. For the purposes of UK data protection law, the operator of biomarkr is the data controller for the information described in this policy. If we incorporate later, we will update this page with the company details.
If you have any question about how we handle your data, you can reach us at [email protected] before reading any further. If our processing grows to the point where registration with the Information Commissioner's Office (ICO) is required, we will register and add the details here.
Data we collect
We collect only what we need to give you a useful picture of your results. That falls into a few clear groups.
We do not buy data about you from anyone else, and we do not try to infer sensitive details you have not given us.
How we use your data
We use your information to provide and improve biomarkr, and for nothing you would find surprising. Specifically, we use it to:
- build your personal picture across results, trends and the nine systems we track
- produce your reports after each test, and at the end of each quarter and year
- answer your questions, grounded in NHS and NICE guidance and current research
- keep the service secure, diagnose faults, and understand which features help
- contact you about your account, important changes, and support requests
We do not use your health data to advertise to you, and we do not use it to make automated decisions that have a legal or similarly significant effect on you.
Our lawful basis
Under UK GDPR we rely on a small number of lawful bases. For your account and the core service, we rely on the performance of our contract with you. For health information, which is special category data, we rely additionally on your explicit consent, which you can withdraw at any time. For keeping the service secure and improving it, we rely on our legitimate interests, balanced against your rights. Where we send you optional updates, we rely on your consent.
Sharing and storage
We never sell your data, and we never share your health information with advertisers. We share data only with the service providers that help us run biomarkr, and only to the extent they need it. Today those are:
Each provider acts as our processor under a written agreement, may use your data only on our instructions, and must protect it to the standard the law requires. Your records are held in the United Kingdom or the European Economic Area. If we ever need to transfer data outside that area, we will put approved safeguards in place first. We may also disclose information if the law requires it, or to protect someone's safety.
How long we keep it
We keep your information for as long as you have an account, because the value of biomarkr grows with your history. If you close your account, we delete or anonymise your health data within 90 days, unless the law requires us to keep certain records for longer. You can ask us to delete your data sooner at any time.
Your rights
UK data protection law gives you strong rights over your information. You can ask us to:
- give you a copy of the data we hold about you
- correct anything that is wrong or out of date
- delete your data, where there is no legal reason to keep it
- export your data in a portable format
- restrict or object to certain uses, and withdraw consent at any time
To exercise any of these, email [email protected] and we will respond within one month. If you are not happy with how we handle your request, you can complain to the ICO at ico.org.uk, though we would always rather hear from you first so we can put things right.
Security
We protect your data with encryption in transit and at rest, strict access controls, and regular review of who can see what. Access to health information is limited to the people who genuinely need it to run the service. No system is perfectly secure, but we treat your trust as the thing we cannot afford to lose, and we design accordingly.