Your Privacy
It Matters
Here at Vitall we take your privacy very seriously.
We understand how sensitive your health information is and we handle it with strict safeguards to protect its confidentiality, integrity and security.
Your data is not something we trade or use beyond what you have asked us to do. It isn’t sold, and it isn’t treated as part of any big data operation. It is used only to run your account, process your tests, keep you updated and help you get the most from the service.
Our full policy below explains exactly what we collect, how we use it and the rights you have.
Set Cookies Consent ›
Our Privacy Policy
Effective date: 11th November 2025
This privacy policy applies between you, the User of this Website, and Vitall, the owner and provider of this Website. Vitall takes the privacy of your information seriously. This policy explains how we collect, use, store and protect your Data when you use our Website and services.
This policy should be read alongside our Terms and Conditions, available at: https://vitall.co.uk/terms.
Please read this privacy policy carefully.
Definitions and interpretation
In this privacy policy, the following definitions are used:
Data
Any information you submit to Vitall through this Website. This includes Personal Data and Special Category Data as defined under the Data Protection Laws.
Cookies
Small text files placed on your device when you visit certain parts of the Website or use features. Details of cookies used are found below under "Cookies".
Data Protection Laws
All applicable UK privacy legislation, including the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
UK GDPR
The UK version of the General Data Protection Regulation (EU) 2016/679.
Vitall, or us
Healthy Human Labs Limited, trading as Vitall. Company number 11263709. Registered office: 71 - 75 Shelton Street, Covent Garden, London, WC2H 9JQ.
User or you
Any third party accessing the Website who is not employed by Vitall or acting on behalf of Vitall professionally.
Website
The website https://vitall.co.uk and any sub-domains unless expressly excluded.
- In this policy, unless the context requires otherwise:
- the singular includes the plural and vice versa;
- references to clauses or appendices are to those in this policy;
- a reference to a person includes individuals, companies and organisations;
- "including" means "including without limitation";
- statutory references include amendments or replacements; and
- headings do not affect interpretation.
Scope of this privacy policy
- This policy applies only to Vitall and your use of this Website. It does not apply to external websites linked from our Website.
- Vitall is the "data controller" for the purposes of UK GDPR and determines how your Data is processed.
Data collected
- We may collect the following Data, including Personal Data and Special Category Data:
- name;
- date of birth;
- sex;
- ethnicity;
- information relating to your physical or mental health;
- information relating to your family health history;
- contact information such as email address, delivery address, telephone numbers;
- demographic information such as postcode and preferences;
- IP address (automatically collected);
- browser type and version (automatically collected);
- operating system (automatically collected);
- navigation path, activity and interaction on the Website (automatically collected);
- any other information you provide when using our services.
How we collect Data
- We collect Data in the following ways:
- Data you provide directly;
- Data received from third parties (see below);
- Data collected automatically when using the Website.
Data that is given to us by you
- Vitall collects Data when:
- you contact us via the Website, email, post or phone;
- you register an account or purchase services;
- you complete surveys (optional);
- you enter promotions or competitions;
- you make payments;
- you consent to marketing communications;
- you use our services, including test ordering and result access;
- analytics or advertising partners share Data you have consented to provide.
Data that is received from third parties
- Vitall may receive Data from:
- clinical partners, laboratory services or healthcare organisations involved in delivering your tests;
- service providers supporting the fulfilment of orders, sample logistics, results delivery or technical support;
- business partners who integrate or refer services to Vitall.
We do not list individual partners, but they only process your Data under strict contractual agreements and in compliance with Data Protection Laws.
Data that is collected automatically
-
- We automatically collect certain information about your visit to improve Website performance and security. This includes IP address, timestamps, frequency, and usage patterns.
- Cookies may collect Data in accordance with your browser settings. See the "Cookies" section below.
Our lawful basis for processing
- We process your Data under the following lawful bases:
- Contract - to provide testing services, process orders and manage your account.
- Legal obligation - to meet legal, financial or regulatory requirements.
- Legitimate interests - for security, fraud prevention, analytics and service improvement. You may object to this processing.
- Consent - for marketing and non-essential cookies.
- For health-related data (Special Category Data), processing is justified under:
- Article 9(2)(h) UK GDPR - processing necessary for health or diagnostic purposes required to deliver the testing services you request;
- Article 9(2)(a) - where explicit consent is provided by you.
Our use of Data
- We may use your Data for:
- processing orders and delivering testing services;
- internal record keeping;
- improving products and services;
- customer support;
- website analytics and performance optimisation;
- sending marketing materials (with consent);
- conducting research or surveys (optional).
Artificial intelligence and anonymised data
We may use anonymised or aggregated information with third party artificial intelligence tools to support service improvement, internal analysis and quality assurance. This information cannot identify you.
Automated processing
We use automated systems to support internal workflows such as routing, quality checks and processing of testing information. These systems do not make decisions that produce legal or similarly significant effects for you.
Any informational insights, automated suggestions or internal data processing are subject to human oversight and are not a substitute for professional medical judgement. Our services are informational only, as described in our Terms and Conditions.
Who we share Data with
- We may share your Data with:
- clinical and laboratory partners needed to deliver your testing service;
- technical service providers including hosting, analytics, payment and communication tools;
- professional advisers where required;
- customer service and operational tool providers.
All third parties process Data only under our instruction and under binding legal agreements.
International transfers
Some service providers operate outside the UK, including technology platforms, cloud providers and communication tools. When Data is transferred internationally, we ensure appropriate safeguards are in place, such as:
- UK adequacy decisions;
- the UK Addendum to the EU Standard Contractual Clauses;
- appropriate technical and organisational protections.
We assess international transfers to ensure your Data remains protected in accordance with UK GDPR requirements.
Keeping Data secure
- We use technical and organisational measures to secure your Data, including encryption, secure servers and controlled access.
- If you suspect misuse, loss or unauthorised access to your Data, contact us immediately at [email protected].
- For guidance on staying safe online, visit www.getsafeonline.org.
Data retention
- We retain health-related Data for ten years in line with widely recognised clinical record retention practices unless law requires a longer period.
- Deleted Data may remain in backups for regulatory or auditing purposes.
Your rights
- You have the right to:
- Access your Data;
- Correct inaccurate or incomplete Data;
- Erase your Data;
- Restrict our use of your Data;
- Port your Data to another provider;
- Object to processing based on legitimate interests.
- To exercise any rights or withdraw consent, email [email protected].
- If dissatisfied, you may complain to the Information Commissioner's Office (ICO) at https://ico.org.uk/.
Links to other websites
- External websites linked from this Website are not covered by this policy. You should review their privacy policies before use.
Business ownership changes
- If Vitall undergoes restructuring or is acquired, your Data may be transferred to new owners under the same privacy commitments.
- We may disclose Data to prospective purchasers under confidentiality obligations.
Cookies
- This Website uses Cookies to support essential functionality and improve user experience.
- We comply with PECR, meaning non-essential cookies are only set with your consent.
- When visiting the Website, you will be asked to consent to analytical, functionality or targeting cookies.
Types of Cookies used:
| Type of Cookie | Purpose |
| Strictly necessary cookies | Required to operate secure areas, manage sessions and process orders. |
| Analytical/performance cookies | Measure usage to help improve the Website. Only used with your consent. |
| Functionality cookies | Remember preferences and improve user experience. |
| Targeting cookies | Used by third party advertising partners to show relevant adverts. Only set with your consent. |
Some cookies used on our Website may be placed by third party analytics or advertising partners. These will only operate if you provide consent through our cookie management tools.
General
- You may not transfer your rights under this policy. We may transfer ours where your rights are not affected.
- If any clause is found invalid, the remainder of the policy will still apply.
- No delay in exercising rights constitutes a waiver.
- This policy is governed by the laws of England and Wales, and disputes will be subject to English and Welsh courts.
Changes to this privacy policy
- We may update this policy to reflect legal or operational changes. Updates will be posted on this Website, and continued use indicates acceptance.
Contact
You may contact Vitall by email at [email protected].