General Data Protection Regulation (GDPR)

UK GDPR — Last Updated: 3 August 2026

We process personal data, including special category health data, in line with the UK GDPR and the Data Protection Act 2018. This page is a summary; full detail is in our Privacy Policy.

Controller. Lola Health Ltd, registered in England and Wales (Company No. 15961806), registered office 167-169 Great Portland Street, 5th Floor, London W1W 5PF. ICO registration: ZB752885. Data protection contact: [email protected].

Lawful bases. We rely on contract (to provide the Services), legal obligation, legitimate interests, and consent (for optional things like marketing, partner sharing and wearable data). For health data we rely primarily on Article 9(2)(h) — health assessment under a GMC-registered doctor bound by professional secrecy — and on explicit consent (Article 9(2)(a)) where Article 9(2)(h) does not apply.

Partner sharing — independent controllers. Where you give explicit consent to share your results with a partner (such as a clinic, practitioner, or wellness provider), Lola Health and that partner each act as independent controllers of the shared data — not joint controllers, and neither processes it on the other's behalf. Once results have been shared, you exercise your data rights, including erasure, directly with that partner, because Lola Health cannot delete data a partner independently holds. Full detail is in our Partner Data Sharing Agreement.

Your rights. You can access, rectify, erase, restrict and object to processing, request portability, and withdraw consent where we rely on it. To exercise any right, email [email protected] or use the app; see our Data Subject Access Request page. We respond within one calendar month. That month runs from the later of receiving your request, verifying your identity where we reasonably need to, and receiving any fee that applies. If we ask you to clarify an access request, the clock pauses until you reply (Article 12A). We may extend by up to two further months for complex or numerous requests, and will tell you within the first month if we do.

Retention. We keep data only as long as needed to provide the Services and to meet legal, tax and clinical record-keeping obligations and resolve disputes. See the Privacy Policy for the criteria we apply.

Data breaches. Where a breach is likely to result in a risk to people's rights and freedoms, we report it to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the risk is high, we also tell the people affected without undue delay.

Complaints. Since 19 June 2026, section 164A of the Data Protection Act 2018 gives you a statutory right to complain to us directly about how we process your personal data. You can complete our data protection complaint form online, or email [email protected]. We will acknowledge your complaint within 30 days, take appropriate steps to look into it, keep you informed of progress, and tell you the outcome.

You can also complain to the Information Commissioner's Office at any time — you do not have to come to us first: ico.org.uk, 0303 123 1113. You have the right to seek a remedy through the courts as well.