Vision Health Privacy Policy

Dated - 12 May 2026

Vision Health is a United Kingdom-based health, wellbeing, and fitness platform designed around privacy-by-design, safeguarding-by-design, and security-by-design principles. The platform processes special category health-related information and therefore applies enhanced operational, technical, and organisational protections appropriate for confidential health and wellbeing systems.

1. Nature of Data and Confidentiality

Vision Health processes Personally Identifiable Information (“PII”), health-related data, physical assessment information, wellbeing assessments, exercise activity records, and associated coaching information. This information is classified as highly confidential under UK GDPR and the Data Protection Act 2018. The platform has been specifically designed to support private health, fitness, rehabilitation, and wellbeing services. Vision Health recognises that users may include individuals referred through healthcare providers, schools, affiliates, or other wellbeing organisations. Accordingly, Vision Health seeks to apply enhanced confidentiality, safeguarding, and audit controls appropriate for sensitive health-related systems. The platform seeks to collect only the minimum amount of information necessary to safely operate the Services and support user wellbeing journeys.

2. UK Data Residency and Hosting

Vision Health is intended solely for use within the United Kingdom. All production systems, databases, operational services, backups, disaster recovery environments, replicas, and associated hosting infrastructure containing production information are intended to be hosted and processed within the United Kingdom. Vision Health seeks to ensure that production data is not routinely transferred, processed, replicated, or accessed outside the UK unless explicitly authorised and compliant with UK GDPR obligations. Vision Health requires suppliers, hosting providers, cloud infrastructure providers, and operational sub-processors to maintain appropriate contractual obligations relating to confidentiality, UK GDPR compliance, and UK-based data processing. Where technically feasible, Vision Health may restrict application availability within the Apple App Store and Google Play Store to UK-based users only through regional distribution controls.

3. Age Verification, Safeguarding, and Under-18 Protections

Vision Health is intended only for individuals aged 16 years or over. Users under the age of 16 are prohibited from creating accounts or accessing the platform. Users aged 16–17 are treated as safeguarded users and are subject to enhanced verification, consent, and operational controls. During registration, users aged 16–17 may be required to provide parent or guardian details, including parent or guardian name, email address, and contact telephone number. Accounts for users aged 16–17 remain restricted until Vision Health has verified the user’s date of birth and obtained explicit parent or guardian consent. Vision Health may manually contact the parent or guardian before account activation is approved. Consent records, including the date, method of consent, and identity of the parent or guardian, may be retained as part of the platform audit trail. Restricted accounts for users aged 16–17 may include enhanced safeguarding measures including restricted messaging capabilities, administrative oversight, communication logging, prohibition of public profiles, prohibition of image uploads, prevention of personal contact sharing, and safeguarding review processes. All age-based permissions, safeguarding approvals, restrictions, consent records, and account status changes may be retained within auditable system logs.

4. Information We Collect

Vision Health may collect identity information including name, contact details, date of birth, emergency contact information, and assigned PT Instructor information The platform may collect health and wellbeing information including body measurements, biometrics, blood pressure records, wellbeing assessments, fitness test results, nutrition consistency information, physical activity data, exercise programme participation, pathway information, and lifestyle questionnaire responses. Where users are referred by healthcare providers or affiliates, Vision Health may also collect referral-related information including referral reason, referring organisation, and associated support notes. The platform may collect and store activity logs, plan completion records, timestamps, audit trails, and communication records necessary to support safeguarding, operational oversight, coaching functionality, and system security. Vision Health may additionally collect technical and device information including IP addresses, operating system information, authentication records, session activity, MFA events, audit events, crash logs, and operational telemetry.

5. Medical and Wellbeing Questionnaires

Vision Health may process questionnaire responses relating to physical readiness, lifestyle, mental wellbeing, fitness capability, recovery, and health-related measurements. This may include PAR-Q questionnaires, wellbeing assessments, anxiety questionnaires, depression questionnaires, blood pressure assessments, biometrics, and fitness testing information. Questionnaire submissions, scoring calculations, benchmark references, signatures, timestamps, and associated audit records may be stored to support safeguarding, user safety, operational integrity, progress monitoring, and regulatory accountability. Where reference scales, scoring systems, or measurement ranges change over time, Vision Health may retain the original benchmark or reference data used at the time the assessment was recorded in order to maintain historical accuracy and auditability.

6. Security, Authentication, and Access Controls

Vision Health recognises that the platform processes highly confidential health-related information and therefore applies enhanced security controls designed to align with recognised industry standards for secure health and wellbeing systems. Vision Health seeks to utilise encryption in transit using TLS 1.2 or higher and encryption at rest using AES-256 or equivalent standards. HTTPS is required for all production API communications and secure authentication processes. The platform may support Single Sign-On (“SSO”) authentication providers including Apple and Google. Multi-factor authentication (“MFA”) may be required for administrative access, sensitive account actions, onboarding confirmations, profile updates, and other securitysensitive activities. Role-Based Access Controls (“RBAC”) are applied throughout the platform to restrict access based on operational need. PT Instructors may only access information relating to assigned users. Administrative access to confidential data is restricted to authorised personnel with a regitimate operational or safeguarding requirement. Vision Health may maintain immutable audit logs recording create, read, update, delete, authentication, administrative, and safeguarding actions relating to personal or healthrelated information. Development, testing, and production environments are intended to remain segregated. Production data must not be used within development or testing environments unless appropriately anonymised and authorised.

7. User Rights, Account Deletion, and Anonymisation

Vision Health seeks to support UK GDPR rights including the right of access, correction, portability, restriction, objection, withdrawal of consent, and the Right to Erasure. Users may request deletion of their account directly through the platform interface. Sensitive account deletion actions may require additional security verification, including MFA or OTP confirmation, to reduce the risk of unauthorised deletion requests. Where account deletion is approved, Vision Health seeks to permanently delete or irreversibly anonymise Personally Identifiable Information associated with the user. This may include names, contact details, date of birth, parent or guardian information, and other directly identifying information. Certain non-identifiable operational, safeguarding, statistical, or audit information may be retained where necessary for legal, safeguarding, security, or regulatory obligations. Retained data must not reasonably permit re-identification of the individual.

8. Coaching Communications and Safeguarding Monitoring

Vision Health may provide structured in-app communications between users, PT Instructors, and authorised administrators. The platform is not intended to operate as an unrestricted social networking service. Communications are designed to support coaching, wellbeing guidance, safeguarding oversight, and operational support. All in-app communications may be logged, monitored, reviewed, and retained for safeguarding, security, operational, and audit purposes. Administrative personnel may review communications where necessary to investigate safeguarding concerns, abuse reports, misuse, or operational risks. The platform prohibits disappearing messages, unauthorised sharing of personal contact details, unmonitored communications, and off-platform contact solicitation through Vision Health systems.

9. Consent and Medical Disclaimer

During onboarding, users may be required to confirm acceptance of Vision Health Terms of Use, Privacy Policy, and health-related consent statements. Users may also be required to explicitly acknowledge that Vision Health provides fitness, lifestyle, and wellbeing support only and does not provide medical diagnosis, treatment, or clinical advice. Vision Health encourages users to consult appropriately qualified healthcare professionals before making significant health, fitness, medical, nutritional, or exercise-related decisions.

10. Data Retention and Auditability

Vision Health retains information only for as long as reasonably necessary to support operational, safeguarding, legal, audit, regulatory, and security requirements. Audit logging forms a core operational control within the platform. Vision Health may retain logs relating to authentication activity, account changes, safeguarding actions, measurements, questionnaires, plan assignments, communications, consent events, and access activity. Health-related assessments, safeguarding records, anonymised activity data, and operational audit records may be retained for extended periods where required to support safeguarding, regulatory review, dispute resolution, legal obligations, or security investigations. Deletion, anonymisation, and retention activities may themselves be retained within secure audit logs.