facebook
self pay health logo

PRIVACY POLICY

Introduction


Self Pay Health is a service operated by Self-Pay Health Ltd ("we", "us", "our"), a company registered in England and Wales under company number 16594421, with its registered office at Unit 2.02 High Weald House, Glovers End, Bexhill-on-Sea, East Sussex, TN39 5ES. This Privacy Policy explains how we collect, use, and protect your personal information when you use our website www.selfpayhealth.co.uk ("Website") and the services provided through it ("Services").

We are committed to protecting your privacy. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. For the purposes of this legislation, Self-Pay Health Ltd is the data controller.

Who We Are and How to Contact Us


Self Pay Health is a healthcare marketplace that helps patients find and contact private medical providers. Self-Pay Health Ltd is the controller responsible for your personal information.

Email: info@selfpayhealth.co.uk

Registered office: Unit 2.02 High Weald House, Glovers End, Bexhill-on-Sea, East Sussex, TN39 5ES

Information We Collect


We may collect the following types of information:

Personal Information

  • Name and contact details (email address, phone number, and postal address where provided)

  • Date of birth

  • Information about your health, symptoms, or medical conditions that you choose to share with us or enter when searching for or booking care

  • Booking and enquiry details, including the providers you contact through the Website

  • Payment reference information (we do not store complete payment card details — see Service Providers and International Transfers)

Technical Information

  • IP address

  • Browser type and version, and operating system

  • Referral source

  • Pages viewed, length of visit, and website navigation

  • Information collected through cookies and similar technologies (see our Cookie Policy)

AI Assistant Information

If you use the AI assistant (chatbot) on our Website, we log your first three messages together with the assistant's responses. These messages may contain health-related information. See the AI Assistant section below for how this is used and retained.

How We Use Your Information


We use your information for the following purposes:

  • To provide the Services and help you find and contact private healthcare providers

  • To facilitate bookings and enquiries you make through the Website

  • To process payments

  • To provide post-booking customer care, and to request feedback (where you have consented)

  • To respond to your enquiries

  • To operate and improve our Website, Services, and AI assistant

  • To send you information about our Services, where you have consented

  • To comply with our legal and regulatory obligations

Legal Basis for Processing


We rely on the following legal bases under UK GDPR to process your personal information:

  • Consent — for marketing communications, non-essential cookies, and the retention of your data for post-booking care and feedback

  • Performance of a contract — to provide the Services you request and process related payments

  • Legitimate interests — for limited purposes such as securing the Website, preventing fraud, and maintaining a minimal transaction record. Where we rely on legitimate interests, we balance those interests against your rights

  • Legal obligation — where we must process data to comply with the law

Health Data (Special Category Data)


Information about your health is "special category data" under UK GDPR and receives extra protection. We process your health data only on the basis of your explicit consent, which you give at the point of enquiry or booking.

We do not rely on any other condition (such as preventive medicine, vital interests, or substantial public interest) to process your health data, and we do not rely on legitimate interests for this data. You can withdraw your consent at any time, which will stop further processing and, where you ask us to, lead to deletion of your health data held by us. Withdrawing consent does not affect processing carried out before the withdrawal.

Sharing Your Information


We may share your personal information with:

  • Healthcare providers you choose to contact or book through the Website. Once your information is passed to a provider, that provider becomes an independent data controller and is responsible for your information under its own privacy policy. We put a data sharing agreement in place with each provider

  • Service providers who process data on our behalf (see the section below)

  • Professional advisers, such as lawyers and accountants, where necessary

  • Government bodies or law enforcement, where required by law

We require all third parties to respect the security of your personal information and to process it in accordance with the law.

Service Providers and International Transfers


We use the following third-party processors to run our Services. Each is bound by a data processing agreement:

  • Stripe — payment processing. We use Stripe’s hosted payment fields, so your full card details are entered directly with Stripe and never pass through or get stored on our servers

  • OpenAI — processing of AI assistant interactions

  • Heroku — hosting of our application backend

  • Netlify — hosting and delivery of our website frontend

Some of these providers are based in, or process data in, the United States. Where your personal information is transferred outside the UK, we rely on appropriate safeguards — in particular the UK's International Data Transfer Agreement or Standard Contractual Clauses — to ensure your data receives an equivalent level of protection.

AI Assistant (Chatbot)


Our Website offers an AI assistant to help answer your questions. When you use it, we log your first three messages and the assistant's responses so that we can monitor and improve the quality of the service. These interactions may contain health-related information, so please avoid sharing more personal detail than necessary.

We retain these logs for 90 days. The AI processing is carried out by OpenAI on our behalf, and your interactions are not used to train OpenAI's models. A notice is shown before you begin a chat to remind you that the conversation is logged.

Your Account (Magic Link)


We do not require you to create a password-protected account. Instead, we use a "soft account" linked to your email address. When you need to manage your preferences, review your information, or request deletion, we send a secure single-use link (a "magic link") to your email. This lets you manage your data without registering or remembering a password.

Cookies


Our Website uses cookies and similar technologies to operate the site, understand how it is used, and improve your experience. We use analytics tools including Google Analytics 4 and PostHog. You can control non-essential cookies through our cookie banner. For full details of the cookies we use and how to manage them, please see our Cookie Policy.

Data Retention


We keep your personal information only for as long as we need it for the purposes described in this policy, or to meet legal, accounting, or reporting requirements. Our retention periods are set out below.

Data categoryRetention periodBasis
Consenting patient booking data (identity, contact, booking details)Until you withdraw consent, or 24 months of inactivity, whichever is soonerExplicit consent
Health / special-category data (condition, referral context)As above — held under the same consentExplicit consent
Non-consenting transaction record (date, payment reference, amount)30 daysLegitimate interests / legal obligation
AI assistant logs (first 3 interactions plus AI response)90 daysConsent / legitimate interests
Analytics data (GA4, PostHog)GA4 user data up to 14 months; PostHog session data up to 12 monthsConsent
Account identity (email, consent and preference state)For the life of your soft account; deleted on withdrawal or after 24 months of inactivityExplicit consent
Marketing / email preferencesUntil you unsubscribe, or 24 months of inactivity, whichever is soonerConsent

Where retention is tied to consent, we also apply an inactivity backstop: if you have not interacted with us for 24 months, we will either ask you to renew your consent or delete your information. This ensures we do not hold your data indefinitely.

Data Security


We have put in place appropriate technical and organisational measures to protect your personal information against accidental loss, unauthorised access, alteration, or disclosure. This includes encryption of data in transit, restricting access to those who need it, and using reputable processors. Where you make a payment, card details are handled directly by Stripe and never stored on our systems.

Your Rights


Under data protection law, you have rights including:

  • The right to be informed about how we use your data

  • The right to access the personal information we hold about you

  • The right to rectification if your information is inaccurate or incomplete

  • The right to erasure (the "right to be forgotten")

  • The right to restrict processing

  • The right to data portability

  • The right to object to processing

  • The right to withdraw consent at any time, where we rely on consent

  • Rights in relation to automated decision making and profiling

To exercise any of these rights, please contact us using the details provided above. You can also use the magic link sent to your email to manage your preferences and request deletion.

Children's Privacy


Our Services are intended for adults aged 18 and over. We do not knowingly collect personal information from anyone under 18. If you are under 18, please do not use the Website or provide any information through it.

Changes to This Privacy Policy


We may update this Privacy Policy from time to time by posting a revised version on our Website. Where changes are significant, we will notify you by email or through a notice on our Website. The date below shows when it was last updated.

Complaints


If you have a concern about how we handle your personal information, please contact us first so we can try to resolve it. You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection, at www.ico.org.uk - ICO reference number ZC154602.

Last updated: 05.07.2026