Health data gets the higher bar
Anything you tell a clinician — symptoms, cycle history, scan results, medicines — is special-category data under Article 9 of the UK and EU GDPR, and is handled to that standard.
Health information is the most sensitive category of personal data there is. This page sets out what we collect, why we are allowed to, who else ever sees it, how long we keep it, and what you can require us to do about it.
Last updated: 23 September 2026 · Applies to helioscheck.com and to care delivered through it
The short version. Every point below is set out in full in the numbered sections that follow.
Anything you tell a clinician — symptoms, cycle history, scan results, medicines — is special-category data under Article 9 of the UK and EU GDPR, and is handled to that standard.
No advertising networks, no data brokers, no retargeting pixels following you off the site. HeliosCheck.com is paid for by consultation fees, not by your information.
Access, correction, portability, restriction, objection and complaint routes are all set out below, with the address to write to and the deadlines we work to.
HeliosCheck.com is a consultant-led gynecology and women’s health consultancy. It is operated by [COMPANY LEGAL NAME], a company registered in [COUNTRY OF REGISTRATION] under company number [COMPANY REGISTRATION NUMBER], with its registered office at [REGISTERED OFFICE ADDRESS]. Where this policy says “we”, “us” or “HeliosCheck”, it means that company.
For the purposes of the UK GDPR, the EU GDPR and the Data Protection Act 2018 we are the data controller for the personal data described below. Our clinicians are also bound, independently of data protection law, by professional duties of confidentiality. You can read who they are on our about page, and how a consultation is conducted on how it works.
Our data protection registration number is [ICO / DPA REGISTRATION NUMBER]. This policy sits alongside our terms of service, our medical disclaimer and our cookie policy. Read together, those four documents describe the whole relationship between you and HeliosCheck.com.
When you browse helioscheck.com we collect standard technical data: IP address (truncated before storage wherever analytics consent has been given), browser and device type, referring page, the pages you viewed, and the approximate region the request came from. Strictly necessary cookies operate whatever you choose; analytics cookies are set only after you consent, and the full list is in our cookie policy.
Occasionally a third party sends us data about you: your own doctor or a hospital team, where you have asked for results or a letter to be shared with us; our payment processor, which confirms whether a payment succeeded; and, rarely, a relative or carer contacting us on your behalf. We check that anyone contacting us on your behalf has your authority before we discuss anything clinical with them.
Almost everything a gynecologist needs to know is, in legal terms, special-category personal data under Article 9 of the UK and EU GDPR. That category covers data concerning health, sex life and sexual orientation, and processing it is prohibited outright unless a specific condition in Article 9(2) is met. A lawful basis under Article 6 is necessary but not sufficient — a second condition is always required on top.
For care delivered through HeliosCheck.com we rely primarily on Article 9(2)(h): processing necessary for the provision of health care or treatment, carried out by or under the responsibility of a professional subject to a duty of professional secrecy. In the UK that is coupled with the condition at Schedule 1, Part 1, paragraph 2 of the Data Protection Act 2018. Where processing is not care — for example sending a summary to a third party because you asked us to — we rely on your explicit consent under Article 9(2)(a), recorded at the time you gave it.
In practice this means two things. We ask only for the health information we genuinely need to answer your question, and we do not repurpose it afterwards. Your intake form is not used to build a marketing profile, is not enriched with third-party data, and is not used to train any external model.
The law requires a lawful basis for each purpose, not one basis for the whole business. Ours are set out in full below, alongside the Article 9 condition that applies to health data.
| What we do | Data involved | Lawful basis |
|---|---|---|
| Answering an enquiry you send through helioscheck.com | Name, email address, and whatever you choose to write in the message | Legitimate interests, Art. 6(1)(f) — replying to a person who has deliberately contacted us. If the message itself contains health details, we rely on Art. 9(2)(h) or on your explicit consent under Art. 9(2)(a). |
| Taking a booking and processing payment | Name, contact details, appointment type and time, and the confirmation reference from our payment processor | Contract, Art. 6(1)(b) — the steps needed to provide the consultation you asked for. |
| The intake form, the consultation itself, and your written plan | Cycle and obstetric history, symptoms, medicines, allergies, previous investigations, documents you upload, family history | Contract, Art. 6(1)(b), together with Art. 9(2)(h) — health data processed for the provision of health care by, or under the responsibility of, a professional bound by a duty of confidentiality. |
| Keeping a clinical record and meeting professional obligations | The consultation note, the plan we issued, and the follow-up messages attached to it | Legal obligation, Art. 6(1)(c), and Art. 9(2)(h). Regulators and indemnity providers require a contemporaneous record; this is not something we can delete on request. |
| Escalating a genuine emergency | The minimum clinical detail needed by an emergency service or hospital team | Vital interests, Art. 6(1)(d) and Art. 9(2)(c) — used only where you are physically or legally incapable of giving consent and a delay would put you at risk. |
| Service emails and occasional updates you have opted into | Email address and the record of your consent | Consent, Art. 6(1)(a) — withdrawable at any time, with an unsubscribe link in every message. |
| Understanding how our health information pages are read | Aggregated page views, referrer, approximate region, device class | Consent, Art. 6(1)(a), collected through the cookie banner. Decline it and the analytics cookies are never set. |
| Preventing fraud, defending legal claims, keeping the service secure | Account activity, access logs, technical security data | Legitimate interests, Art. 6(1)(f), and — where health data forms part of a claim — Art. 9(2)(f), the establishment, exercise or defence of legal claims. |
Where we rely on legitimate interests we have carried out a balancing assessment, and you can ask us for a summary of it using the contact details at the end of this page.
We do not carry out automated decision-making that produces legal or similarly significant effects, and we do not profile you for advertising. No clinical decision on HeliosCheck.com is made by software: a named consultant reads your history, speaks to you, and signs the plan.
We share the minimum necessary, with a defined list of recipients, each under a written contract that limits what they may do with it.
What we never do: we do not sell personal data, we do not share it with data brokers, we do not pass it to advertising networks, and we do not place advertising or retargeting pixels on helioscheck.com. No commercial arrangement anywhere in this business depends on your health information leaving it.
HIPAA applies to covered entities and their business associates, and whether it applies to a particular consultation depends on how that consultation is paid for and delivered. [HIPAA covered-entity status to be confirmed by US counsel before launch.] Rather than wait on that determination, we have built the service to HIPAA-aware standards throughout: minimum-necessary disclosure, role-based access control, audit logging of every record access, encryption in transit and at rest, workforce confidentiality training, and Business Associate Agreements with US-based processors that handle protected health information.
Where HIPAA does apply to your care, you additionally have the right to receive a Notice of Privacy Practices, to request an accounting of certain disclosures, to ask for confidential communications by an alternative means or at an alternative address, and to complain to the Office for Civil Rights without retaliation. The CDC’s public health law summary of HIPAA is a readable starting point if you would rather understand the framework than take our word for it. State law may give you further rights: several US states impose stricter rules on reproductive health data than HIPAA does, and where they apply, they apply.
HeliosCheck.com serves patients in more than one country, so some data crosses borders. Where personal data leaves the UK or the EEA we rely on one of the following: a finding of adequacy by the UK government or the European Commission covering the destination country; the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses; or the EU Standard Contractual Clauses themselves, supported by a transfer risk assessment and, where needed, supplementary technical measures such as encryption with keys held in the originating region.
Our primary hosting region is [PRIMARY HOSTING REGION]. Our current sub-processor list is available on request from the address below, and you can ask which transfer mechanism we rely on for any named processor.
We do not keep data indefinitely, and we do not delete clinical records early simply because it would be tidier. Those two constraints pull in opposite directions, so the periods are set explicitly rather than left to judgement.
| Record | Retention period | Why |
|---|---|---|
| Clinical records — intake form, consultation note, written plan, follow-up messages | The minimum period set by the regulator and indemnity provider in the jurisdiction where your clinician is registered. In UK practice that is 8 years from the end of treatment for an adult, 25 years after the birth of the last child for maternity records, and until the 25th birthday for a patient seen as a child. [Practice retention schedule to be confirmed with the regulator and insurer before launch.] | Professional record-keeping duty, continuity of care, and defence of any future claim. |
| Booking and payment records | 7 years from the end of the relevant financial year, or [local tax retention period] where that is longer. | Tax and accounting obligations. |
| Enquiries that never become a booking | 12 months from your last message, then deleted. | Long enough to pick up a conversation you return to; short enough not to hoard it. |
| Consultation video and audio | Not recorded. If a recording is made at your request, it is deleted after 30 days unless you give written consent for it to be added to your clinical record. | Recordings are not needed for care and create risk we would rather not carry. |
| Marketing consent records | Until you withdraw consent, plus 24 months to evidence that the consent was validly obtained. | Accountability under GDPR and PECR. |
| Website analytics | 14 months, held in aggregate and never joined to a clinical record. | Long enough to compare a season with the same season a year earlier, and no longer. |
| Cookie consent choices | 12 months, after which you are asked again. | Consent should be refreshed, not assumed indefinitely. |
| Encrypted backups | Overwritten on a rolling 35-day cycle. | Deleted data may persist in a backup for up to 35 days before the cycle removes it. |
Retention minimums for health records are set by regulators, not by us. If you want to see how a national health system frames the same duty, the NHS explains how patients access their own health records and what is held on their behalf. At the end of the applicable period, records are securely destroyed or irreversibly anonymised.
You have the following rights over your personal data. They are free to exercise, and asking about them will never affect the care you receive.
Write to hello@helioschecks.com with “data rights request” in the subject line, or use the contact page. We will ask you to verify your identity — that protects you, not us — and we will respond within one calendar month. If your request is complex we may extend by up to two further months, and we will tell you why inside the first month. If we decide we cannot do what you have asked, we will name the exemption we are relying on and explain how to challenge that decision.
No system is perfectly secure and we will not pretend otherwise. What we can commit to is collecting less than we could, keeping it no longer than we must, and telling you plainly if something goes wrong. Please do not send clinical details through social media or other unencrypted channels — use the routes described on our contact page.
HeliosCheck.com consultations are intended for people aged 16 and over. We do not knowingly collect personal data from a child under 16 without the involvement of a parent or legal guardian. Where care for a young person under 16 is arranged, it is arranged in advance through the contact page, with a parent or guardian present unless the clinician assesses the young person as competent to consent and judges it appropriate for them to be seen alone. That assessment, and the reasoning behind it, is recorded.
If you believe a child has given us personal data without the right authority, tell us and we will delete it promptly, subject only to any record we are professionally required to keep about the contact itself.
We update this policy when the service changes, when a processor changes, or when the law changes. The date at the top of the page always reflects the current version. Where a change materially affects how we use data you have already given us, we will tell you directly by email rather than rely on you noticing a new date. Previous versions are archived and available on request.
For anything in this policy — a question, a rights request, or a complaint — write to:
If you are not satisfied with our response you can complain to the Information Commissioner’s Office in the UK, to your national data protection authority in the EEA, or to the Office for Civil Rights at the US Department of Health and Human Services where HIPAA applies.
Read next: our terms of service, our medical disclaimer, our cookie policy, and our editorial policy, which explains how the health information published on HeliosCheck.com is written and reviewed. Common questions about privacy and confidentiality are also answered on our FAQ page.
Ask before you book, not after. We will tell you exactly what the intake form covers and what stays on file — or you can read the whole process through first.