Privacy policy
Intended purpose
The Lola Health mobile application is a wellness and lifestyle software product. It is not a medical device, is not registered with the MHRA and does not carry a UKCA, CE or FDA mark. It is not intended for the diagnosis, prevention, prediction, prognosis, monitoring, treatment or alleviation of disease, and it does not interpret your results, generate diagnoses or produce treatment recommendations.
Samples are analysed by partner laboratories that vary by product. Blood and urinalysis go to our UKAS-accredited (ISO 15189) UK partner laboratory. Biological-age (epigenetic) tests are processed by TruDiagnostic, Inc. in the United States. Gut microbiome tests are processed by Intus Bio, Inc. in the United States. Where a product includes a review by a GMC-registered doctor, the clinical interpretation comes from that doctor, not the software; not every product includes one and the product page says which. Biological-age and microbiome results come from the laboratory's own analysis without a Lola doctor's review.
Who we are
Lola Health Ltd ("Lola Health", "we", "us", "our") is the data controller for your personal information. Registered in England and Wales, Company No. 15961806, registered office 167-169 Great Portland Street, 5th Floor, London W1W 5PF. ICO registration ZB752885.
We have appointed a Data Protection Officer, contactable at [email protected].
Who delivers the service
Parts of our service are delivered by independent providers, not by us. We do not own or operate any clinic, phlebotomy service, laboratory or pharmacy. Sample collection is carried out by qualified, professionally registered practitioners, at your home or at a partner clinic arranged through an independent clinic network. They are responsible for their own clinical practice, registration and insurance and are not our employees. Laboratory analysis is done by accredited partner laboratories.
In data protection terms those providers act on our instructions as our processors, so we remain the controller of your information throughout and remain accountable to you for how it is handled — even where the person you meet does not work for us.
Our lawful bases
- Contract — to provide what you buy: fulfilling your order, arranging sample collection, processing your sample, and releasing your results including, where the product has one, a doctor's review.
- Consent — for anything optional, and for specialist tests we resell where no Lola clinician is involved. That covers TruAge, TruHealth and GutID, marketing, sharing your results with a partner you connect, and syncing wearable or health-app data. For those we rely on Article 6(1)(a) as well as Article 9(2)(a). You can withdraw consent at any time; that switches the optional thing off but does not affect processing under another basis.
- Legal obligation — tax, accounting, clinical record-keeping and other regulatory requirements.
- Legitimate interests — securing the service and preventing fraud, supporting you, and improving our products, where those interests do not override your rights.
Health data
We process special category health data under Article 9 of the UK GDPR: blood test results (biomarker values, reference ranges, clinical interpretations), health questionnaire answers, doctor review notes, wearable data you sync, and epigenetic (DNA-methylation) data for TruDiagnostic products.
Where a test includes a review by a GMC-registered doctor — our blood and urinalysis tests — our Article 9 condition is 9(2)(h), health or social care carried out by, or under the responsibility of, a health professional bound by professional secrecy. Our condition in UK law is Schedule 1, Part 1, paragraph 2 of the Data Protection Act 2018. We keep an Appropriate Policy Document explaining how we meet the Schedule 1 safeguards and will send you a copy on request.
Where a test does not include a doctor's review — TruAge, TruHealth and GutID — we rely on your explicit consent (Article 9(2)(a)) with Article 6(1)(a). You give it by confirming a separate consent statement on the profile form we send after your order. We ask for it for every test, record it separately for each person tested, and do not process a sample without it. We keep a record of the exact wording shown and the date you confirmed it.
Your health data is stored on encrypted servers in the UK and the European Economic Area, is accessible only to authorised personnel including reviewing doctors bound by GMC obligations, and is never sold or used for insurance underwriting. Some colleagues work outside the UK; they have the same role-based access limits, confidentiality obligations and training as colleagues here, do not store data locally, and where their country is not covered by UK adequacy we put a transfer instrument in place before access begins.
We share health data only where it is needed to provide your test: with the partner laboratory that analyses your sample, identified in International Transfers below; and, for a home visit or clinic appointment, with the independent clinic network that arranges it. They get your name, contact details and address so the appointment can happen — they do not get your results.
Safeguarding
There is one situation where we may share information about you without your consent: where we have reason to believe a child or an adult at risk is at risk of harm. We may then share what is necessary with the relevant local authority safeguarding team, the police, or a healthcare provider, to protect that person. We do not do this lightly, we record what we shared and why, and we will tell you unless doing so would increase the risk to someone.
What we collect
From you: contact and account details, order information, health questionnaire answers, and anything you include when you contact us. Automatically: usage and device data through cookies and similar technologies. From others: information from the vendors and service providers who support the service, such as Shopify and our payment processors.
The app and connected health data
The app is where you see your results, your doctor's review and educational content. With your permission it can also collect health and fitness data you sync from device integrations such as Google Health Connect (activity, heart rate, sleep and similar), data from connected wearables and sensors, and your location if you enable it, to suggest nearby clinics and phlebotomists.
We only collect this if you connect it, and you can disconnect or revoke permission at any time in the app or your device settings. Our access to and use of Google Health Connect data complies with the Google Health Connect Permissions Policy, including the Limited Use requirements: we use it only for the features you have turned on, we do not sell it, and we do not use it for advertising.
We do not use your health, wearable or test data to make decisions producing legal or similarly significant effects about you. AI features give general wellness information only, and where a blood test includes a doctor's review, that review is done by a GMC-registered doctor before the result is released.
AI wellness features
We use third-party AI services to help prepare and check some of the wellness content you receive, including the summary with your blood test result and the chat and insight features in the app. We share only what those features need. Where your product includes a doctor's review our condition is Article 9(2)(h), because it forms part of preparing the assessment the doctor reviews; otherwise we rely on your explicit consent. Some of these providers are outside the UK, including in the United States — see International Transfers.
Where a doctor's review is included, a GMC-registered doctor reviews and signs the comment on your result, and can amend or reject it, before it reaches you. Other wellness content in the app is generated automatically and is not individually reviewed. These features make no clinical decisions and are not a substitute for professional advice.
SMS
If you opt in to text messages we collect your phone number for transactional updates and, where you consent, promotional messages. SMS opt-in data and consent are never shared with third parties. Reply STOP to unsubscribe.
Sharing your results with a partner
We share your results with a partner only where you have given explicit consent. Connecting a partner in the app does not by itself share anything: it sends you a consent request, and we share only after you tap "Agree and share". A referral or coupon code at checkout is for billing attribution only — it links your order to a partner commercially and is not consent to share your results.
When you do consent, we share your results, including health data, with that specific named partner. Partner categories are regulated clinical partners (clinics, practitioners, pharmacies) and non-clinical wellness partners (gyms, personal trainers, beauty clinics, coaches). Our basis is your explicit consent under Article 9(2)(a) with Article 6(1)(a) — for every partner, clinical or not.
Each partner is an independent controller of what we share. Unlike the providers who deliver our service on our instructions, a partner decides for itself how it uses your results, is responsible for keeping them secure, and may retain them under its own policies and legal obligations.
You can withdraw consent and disconnect a partner at any time in the app or by contacting us, and we stop sharing further results. Results already shared stay with that partner. If you ask us to erase, correct or restrict your data we will notify anyone we shared it with and tell you who we told (Article 19).
Other disclosures
We may disclose personal information to vendors who perform services for us — IT, payment processing, analytics, customer support, cloud storage, fulfilment and shipping; in connection with a business transaction such as a merger; to comply with legal obligations; and to protect our rights and those of our users. We keep a register of every supplier that receives personal data and will send you the current list on request at [email protected]. Content you post in public areas of the service is public. We do not sell your personal information.
Cookies
We use cookies to operate and improve the service, run analytics, and support abandoned-cart reminders. We set non-essential cookies — functionality, performance and analytics, and targeting — only with your consent, which we ask for through the cookie banner on your first visit. You can change or withdraw your preferences at any time through the cookie settings or your browser, though blocking some may affect how the site works. Strictly necessary cookies are always on because the site cannot work without them. Our Cookies Policy has the detail; Shopify's own cookies are covered at shopify.com/legal/cookies.
International transfers
Your personal data is processed and stored on encrypted servers in the UK and the European Economic Area. Some of it goes outside the UK.
Two of our products require it. If you order an epigenetic test (TruAge, TruHealth) or a microbiome test (GutID), your sample and the resulting data are analysed by a specialist laboratory in the United States. That transfer is part of what you agree to when you order, and you can choose not to order those products — if you would prefer nothing of yours to be analysed in the United States, do not order them, or contact us beforehand and we will confirm which products are UK-analysed. The United States is not covered by UK adequacy regulations, so the protection is not the same as here: public authorities there may be able to access data in circumstances UK law would not allow, and enforcing your rights can be harder.
Some service providers also process data outside the UK. These cover identity and authentication, payments, subscription management, transactional email, SMS, push notifications, customer support, product analytics and error monitoring, and the AI services described above. Where we transfer data outside the UK we use the transfer mechanisms permitted by UK data protection law.
Retention
| What | How long | From when |
|---|---|---|
| Health and test data — results and any doctor's review | 8 years | Your last contact with us |
| Clinical correspondence, including in-app messages that form part of your clinical record | 8 years | Closure of the enquiry |
| Other in-app conversations and general support messages | 2 years | Date of the last message |
| Invoices and transaction records | 6 years plus the current year | End of the tax year |
| Complaint records | At least 8 years | The date the complaint is closed |
| The record of your consent, and clinicians' review logs | Kept beyond the above, pseudonymised in place | Article 17(3)(b) and (e) |
The 8-year period follows clinical record-keeping guidance and the limitation period for clinical negligence claims, so we may need to keep it after you close your account.
To be straightforward about how this works in practice: reaching the end of a retention period does not yet trigger deletion automatically in our systems. We are building that, and until it is in place records are deleted or pseudonymised when you ask us to or when they are dealt with individually. You can ask us to delete at any time and we will action it, except where we are required to keep something — in which case we tell you which part and why. See Account Deletion.
Withdrawing your consent to a test
Email [email protected] at any time. If your sample has not been analysed we stop and can destroy it on request. If analysis has happened, withdrawal stops anything further but cannot undo work already done, and we may need to keep the result and the consent record for clinical record-keeping and legal reasons. Withdrawing consent does not affect what we did before. Full detail is in the Consent to testing section of our Terms & Conditions.
Your rights
You can access, rectify, erase, restrict and object to processing, ask for portability, and withdraw consent where we rely on it. These rights are not absolute and some will not apply in every case. Contact [email protected] or use the app's account settings.
We respond within one calendar month, running from the later of receiving your request, verifying your identity where we reasonably need to, and receiving any fee that applies. If we ask you to clarify an access request the clock pauses until you reply (Article 12A). We may extend by up to two further months for complex or numerous requests and will tell you inside the first month if we do.
One narrow limit applies to health data: the right of access does not extend to information likely to cause serious harm to your physical or mental health, or someone else's. That is a doctor's judgement, made in writing, and it is rare. If we withhold anything on that basis we tell you. Our Data Rights page explains this, the fee rules, and the route for the records of someone who has died.
Section 164A of the Data Protection Act 2018 also gives you a statutory right to complain to us directly about how we process your data. You can complete our data protection complaint form online, or email [email protected]. We aim to acknowledge within 3 working days and will always do so within the 30-day statutory backstop, then look into it, keep you informed and tell you the outcome. You can complain to the Information Commissioner's Office at any time and do not have to come to us first (ico.org.uk, 0303 123 1113). You can also go to court.
If there is a data breach
Where a breach is likely to result in a risk to people's rights and freedoms we report it to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the risk to you is high we tell you too, without undue delay, in plain language: what happened, what it means for you, what we have done, what you can do, and who to contact.
Children
Our services are for adults aged 18 and over. They are not intended for children under 18 and we do not knowingly collect their data. If you believe a child has given us data, contact us and we will delete it.
Security
We use encryption in transit and at rest, access controls and other safeguards. No method is perfectly secure, so please do not send sensitive information through unsecured channels.
Changes
We may update this policy. We post the revised version, update the date at the top, and take any further steps the law requires.
Contact
Data protection and our Data Protection Officer: [email protected]. Feedback: [email protected]. Everything else: [email protected].
Lola Health Ltd is registered in England and Wales (Company No. 15961806), registered office 167-169 Great Portland Street, 5th Floor, London W1W 5PF, and is registered with the ICO (Ref: ZB752885).