biotrackOS
HomeCustomersSoonPricingSoon
Sign inGet started →
Product
Product overviewProfessional workspacePersonal appAutomationsTrigger follow-ups and recommendations from data.Integrations & capabilitiesMarketplacePartners & programmes.IntelligenceAI-powered health intelligence.API & SDKSoon
Markets
ClinicsPrimary & community careHealth systemsSports teamsGymsCorporate wellnessInsuranceResearch & pharmaPublic healthPersonal
New
A 20-minute walkthrough.

See a real clinic cohort, your data sources, and live alerts.

Book a demo →
Learn
BlogCustomer storiesSoonResearchOne Health CollectiveSoonOur clinician advisory network.
Trust
Trust & securitySoonSecurity disclosure
Where Trust Meets Technology. Inside Our Partnership with TRAIN Health Awareness
Latest
Where Trust Meets Technology. Inside Our Partnership with TRAIN Health Awareness

Inside a community health day TRAIN ran at one of Amsterdam's largest mosques, and why it's a blueprint for the TRAIN app, powered by BiotrackOS.

Read article →
Company
About BiotrackOSCareersPressContactSales, support, partnerships.
Legal
TermsPrivacyCookiesData processing
  • Home→
  • Product
    • Product overview
    • Professional workspace
    • Personal app
    • AutomationsTrigger follow-ups and recommendations from data.
    • Integrations & capabilities
    • MarketplacePartners & programmes.
    • IntelligenceAI-powered health intelligence.
    • API & SDKSoon
    Markets
    • Clinics
    • Primary & community care
    • Health systems
    • Sports teams
    • Gyms
    • Corporate wellness
    • Insurance
    • Research & pharma
    • Public health
    • Personal
  • CustomersSoon
  • PricingSoon
  • Learn
    • Blog
    • Customer storiesSoon
    • Research
    • One Health CollectiveSoon
    Trust
    • Trust & securitySoon
    • Security disclosure
  • Company
    • About BiotrackOS
    • Careers
    • Press
    • ContactSales, support, partnerships.
    Legal
    • Terms
    • Privacy
    • Cookies
    • Data processing
Sign in
Legal

Privacy policy.

Privacy PolicyVersion 1.5 · Effective 4 August 2026

This Privacy Policy describes how BiotrackOS Ltd (“BiotrackOS”, “we”, “our”), registered in Scotland (No. SC737158) with registered office at Canniesburn Gate, 10 Canniesburn Drive, Bearsden, Glasgow, G61 1BF, collects, uses, stores, and shares personal data in connection with our platform, personal app, and biotrackos.com. It applies to Members of customer organisations, individual app Users, administrators, and visitors to our website. Your rights and available complaint routes are described in the Your rights and Supervisory authorities sections below.

Who controls your data

In short

It depends on how you use BiotrackOS. For the personal app and website, we control your data. For organisation deployments, the organisation controls Member data and we process it on their instructions.

Who acts as data controller depends on the context in which your data is processed:

  • Personal App: BiotrackOS is the data controller for your account information, the health data you choose to connect, personal insights generated, and support communications. You determine what sources to connect.
  • Organisation deployment: when BiotrackOS is deployed by a customer organisation (clinic, employer, health system, or similar), that organisation is the data controller for Member data processed through the platform. BiotrackOS acts as data processor and processes that data only on documented instructions under the Data Processing Addendum. The organisation determines and documents the lawful bases for processing its Members’ data. Members with questions about how their data is used in an organisation deployment should contact the relevant organisation directly.
  • Organisation-linked personal account: if you connect your personal App account to an organisation through the platform, the organisation becomes the controller for that shared data and BiotrackOS processes it as the organisation’s processor, on the organisation’s instructions. The organisation’s privacy notice explains its purposes. Disconnecting stops future sharing but does not automatically delete data the organisation may lawfully retain.
  • Administrator and account data: BiotrackOS is the controller for account, billing, and commercial contact data associated with customer organisations.
  • Website visitors: BiotrackOS is the controller for contact form submissions and essential server and security logs. We do not currently use website analytics, advertising, or tracking cookies.

Special category data

In short

Health, genetic, and some biometric data are “special category” data that require a higher level of legal justification before we can process them. We process yours only where a recognised condition under applicable data protection law is satisfied.

Health data, genetic data, and biometric data processed for the purpose of uniquely identifying a natural person are special category personal data under GDPR Article 9. BiotrackOS processes such data only where both a standard lawful basis (Art. 6) and an Article 9 condition are satisfied:

  • Explicit consent (Art. 9(2)(a)): you have given express, informed consent for a specified purpose. You may withdraw consent at any time; withdrawal does not affect the lawfulness of processing carried out before withdrawal, and some data may be retained on a separate lawful basis.
  • Healthcare provision (Art. 9(2)(h)): processing is necessary for preventive or occupational medicine, health assessment, or the provision of healthcare services, carried out by or under the responsibility of a professional bound by appropriate secrecy obligations and applicable national law.
  • Public interest or research (Art. 9(2)(g) or (j)): processing is necessary for substantial public interest or for scientific research purposes in accordance with applicable law and subject to Article 89 safeguards. An ethics protocol may be a relevant factor but does not by itself satisfy this condition; the applicable national implementing legislation must also be met.

We maintain a record of consent events tied to your account. You may review or withdraw consents via your account settings or by contacting dpo@biotrackos.com.

What we collect

In short

Your account details, connected health data, derived insights, integration credentials, usage records, optional app analytics, payment metadata, and anything you send us directly.

  • Account data: name, email address, job role, organisation name, account settings, and consent records.
  • Health data: only what you or your authorised provider explicitly connect, including wearable and device streams, lab results, genomic reports, epigenetic data, and medication and prescription history. We collect health data only where a lawful basis and special category condition are satisfied for the specific purpose.
  • Connection data: identity of connected services, connection status, permissions, and access credentials (such as OAuth tokens) needed to retrieve data from third-party integrations. These credentials are stored securely and used only to retrieve your data from the relevant service.
  • Derived data and insights: trends, summaries, alerts, scores, and other outputs generated from connected health data. These outputs may reveal health information and are treated accordingly.
  • Usage data: feature interactions, session metadata, error logs, IP address, browser type, and device type.
  • Mobile analytics data: in the personal app, usage events and general patterns are collected via Google Firebase, a mobile SDK. Firebase does not use browser cookies and does not receive health data. This is separate from website cookies and is managed through your app settings.
  • Payment data: subscription status, transaction identifiers, billing contact details, and limited payment metadata. Stripe and the relevant app store process full payment card details; BiotrackOS does not store full card numbers.
  • Communications: if you contact us by email or via our contact form, we retain those records to respond and to improve our service.

Why we process it

In short

To run the platform, keep things secure, contact you about your account, and comply with the law. For organisation Member data, the organisation sets the lawful basis.

PurposeLawful basis
Provide and maintain the App (personal app)Contract; consent for health data
Process Member data (organisation deployment)Determined by the customer organisation as controller
Detect and prevent fraud, abuse, and security incidentsLegitimate interests
Account and service communicationsContract
Analytics and product improvementConsent / Legitimate interests
Legal and regulatory complianceLegal obligation

Automated processing and profiling

In short

We use algorithms to surface health trends and insights. These are not clinical decisions. UK and EU law give you rights around automated processing that significantly affects you.

What we do

BiotrackOS uses algorithms and machine learning to surface health trends, anomalies, and personalised insights within the platform and personal app. Models receive normalised health data (wearable streams, lab results, and other connected sources) and generate outputs such as trend summaries, pattern alerts, and general wellness scores. These outputs are shown directly to Users and, in organisation deployments, to authorised organisation users.

What we do not do

BiotrackOS does not make automated decisions that produce legal or similarly significant effects about you. Clinical decisions remain the responsibility of qualified healthcare professionals. Insights generated by the App are not medical diagnoses or clinical recommendations.

UK — Data (Use and Access) Act 2025

The Data (Use and Access) Act 2025 amended UK data protection law, replacing Article 22 of UK GDPR with Articles 22A to 22D. These provisions give UK individuals rights in relation to significant automated decisions, including decisions involving special category data. If you are a UK User and believe automated processing has significantly affected you, or you wish to understand the logic behind a particular output, contact dpo@biotrackos.com.

EU — GDPR Article 22

For EU residents, GDPR Article 22 continues to apply. We do not make solely automated decisions that produce legal or similarly significant effects without meaningful human involvement, so the Article 22 right to object is not currently triggered. If you have questions or concerns, contact dpo@biotrackos.com.

Cookies & tracking

In short

On our website we use only essential cookies. In our mobile app we use Firebase (a mobile SDK, not a browser cookie) for analytics. These are separate systems with separate controls.

Website (biotrackos.com)

We use only essential cookies on biotrackos.com, required for the site to function, including authentication, session management, security, and your stored theme preference. You can block cookies through your browser or device settings, but some features may stop working if you do. We do not currently use analytics, advertising, or tracking cookies on the website. If we add any, we will update this policy and seek your consent where required. Full details are on our Cookie Policy page.

Mobile app

The BiotrackOS personal app uses Google Firebase as a mobile SDK for analytics and crash reporting. This operates at the application layer and is distinct from browser cookies. No health data is passed to Firebase. You can manage app analytics preferences by contacting privacy@biotrackos.com, or through the app’s privacy settings when available.

What we do not do

In short

We don’t sell your data. We don’t use your health data to train AI models. We don’t share with advertisers. We don’t make automated clinical decisions.

  • We do not sell, rent, or otherwise commercialise your personal data.
  • We do not currently use personal app User health data or organisation Member health data to train AI or machine learning models — whether our own or any third party’s. Before introducing any such use we would provide a separate notice, complete any required impact assessment, and obtain a specific voluntary opt-in. Refusal would not affect access to the core Service.
  • Where health data is sent to third-party AI inference providers to generate insights, we ensure those providers are contractually prohibited from using that data for model training or any purpose other than performing the requested inference.
  • We do not share your data with third parties for their own advertising or marketing purposes.
  • We do not make solely automated decisions with legal or similarly significant effects based on your health data.

Who we share data with

In short

Your organisation (if applicable), vetted service providers, connected health platforms you authorise, Apple and Google for app distribution, and legal authorities only when required.

  • Customer organisations: where you are a Member, the customer organisation that controls your data may access it through the platform.
  • Service providers: companies we use to run the Service, including infrastructure, email, error monitoring, analytics, billing, AI inference, push notifications, and customer support. Listed below. When BiotrackOS is a processor for a customer organisation, these companies are our sub-processors; when BiotrackOS is controller, they are our processors.
  • Connected health platforms: wearables, labs, and healthcare providers you choose to connect. Data flows are initiated by you and governed by the relevant provider’s terms.
  • Apple and Google: app distribution, in-app purchase processing, and push notification delivery are subject to Apple’s and Google’s own terms and privacy policies.
  • AI inference providers: where algorithmic insights are generated, pseudonymised data may be processed by vetted AI infrastructure providers under strict contractual controls.
  • Professional advisers and auditors: legal, financial, and security advisers engaged under appropriate confidentiality obligations.
  • Legal authorities: only where required by law, court order, or to protect the rights and safety of individuals, and only to the minimum extent required.
  • Corporate transactions: in the event of a merger, acquisition, or asset sale, data may be disclosed to the counterparty under confidentiality obligations and as permitted by law. We will notify you if your data becomes subject to a different privacy policy.

Current service providers

ProviderPurposeRegion
Amazon Web ServicesInfrastructure hostingEU · UK · US · AU
MailgunTransactional emailEU · US
StripeBilling and payment processingEU · US
SentryError monitoring and crash reportingEU · US
Google FirebaseMobile app analytics and crash reporting (no health data)EU · US

The complete sub-processor list for organisation deployments is maintained in the Data Processing Addendum. We notify customer organisations at least 30 days before adding or replacing any sub-processor.

International data transfers

In short

We use Standard Contractual Clauses, adequacy decisions, and UK transfer instruments to move data across borders legally. We conduct Transfer Impact Assessments where required.

Where personal data is transferred to countries outside the UK or European Economic Area (EEA), we rely on one or more of the following mechanisms:

  • Adequacy decisions: UK-to-EU and EU-to-UK transfers are covered by mutual adequacy decisions. Transfers to other adequacy-recognised countries rely on the applicable decision. Note: Canada’s EU adequacy recognition applies only to commercial organisations subject to PIPEDA; US adequacy under the EU-US Data Privacy Framework applies only to organisations that have self-certified to the Framework.
  • EU Standard Contractual Clauses: for transfers from the EEA to countries without adequacy decisions, we use the European Commission’s SCCs (Decision 2021/914), with the applicable module for the controller/processor relationship.
  • UK transfer instruments: for transfers from the UK, we use either the ICO’s International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs approved by the UK Secretary of State, as appropriate to the specific transfer. These are two distinct instruments.
  • Binding Corporate Rules: where a sub-processor holds BCR approval, those BCRs may be relied on for entities, data types, and transfer routes within their approved BCR scope.

Transfer Impact Assessments are conducted where required. Copies of applicable transfer instruments are available on request at dpo@biotrackos.com.

How long we keep it

In short

Personal app: 30 days after account closure. Organisation deployments: 60-day export window after contract end, then deleted. Account and billing records: 7 years. Security logs: 13 months.

  • Personal app health data: retained for the duration of your active account. Within 30 days of account closure or a verified deletion request, your health data and personal insights are deleted from active systems. Anonymised, aggregated statistics that cannot be re-linked to you may be retained.
  • Organisation Member data: retained for the duration of the relevant contract. After termination, we provide a 60-day export window, then delete or return data at the controller’s written election.
  • Account and billing data: retained for 7 years in accordance with tax and accounting obligations. This covers financial records; profile data for inactive accounts may be deleted sooner where no other retention obligation applies.
  • Security and access logs: retained for 13 months.
  • Support and complaint records: retained while the matter is open and for up to 6 years afterwards where reasonably necessary to document the response or establish, exercise, or defend legal claims; routine enquiries are deleted sooner when no longer needed.
  • Consent and preference records: retained while the relevant processing continues and for up to 6 years after the relevant account or consent ends, to demonstrate compliance with applicable law.
  • Anonymised information: data irreversibly anonymised so that no individual is identifiable is no longer personal data and may be retained for statistical and service-planning purposes without a time limit.
  • Backup copies: encrypted backup copies are overwritten within 90 days as part of our disaster-recovery backup cycle. We do not restore deleted data from backup except where required for disaster recovery, security, or legal compliance; if restored, deletion instructions are reapplied.

Where data is stored

In short

Health data at rest is stored in your selected region. Certain sub-processors, backups, and transient processing may involve data leaving that region under strict controls.

You or your organisation selects a primary storage region at onboarding. Health data at rest is stored in that region on AWS infrastructure. The following may involve data being processed or accessed outside that region:

  • Certain sub-processors operate across multiple regions; no health data is passed to error monitoring or analytics services.
  • Encrypted backup copies may be replicated cross-region for disaster recovery.
  • Support staff may access systems remotely from another country; access controls and audit logging apply to all such access.
  • AI inference processing may involve pseudonymised data being processed by providers in other regions under strict contractual and technical controls.
  • Data you choose to export (for example, a FHIR export to a third-party app) leaves the platform under your direction.

Security measures

In short

Encryption in transit and at rest, role-based access with MFA, annual penetration testing, and a tested incident response plan.

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, or damage:

  • Encryption of data in transit (TLS 1.3 minimum) and at rest (AES-256).
  • Role-based access controls with least-privilege principles and multi-factor authentication required for all staff with access to personal data.
  • Annual third-party penetration testing and continuous vulnerability monitoring.
  • A documented Incident Response Plan that is tested at least annually.
  • We are preparing for a SOC 2 Type II examination; a report will be made available to enterprise customers under NDA upon completion of the examination period.

Further details are available on our Trust & Security page.

Data breach notification

In short

As controller: we notify regulators within 72 hours and affected individuals without undue delay. As processor: we notify the customer organisation within 24 hours.

BiotrackOS as controller (personal app, website, admin data)

  • Notify the Information Commissioner’s Office (ICO) within 72 hours of becoming aware of a breach likely to result in a risk to individuals’ rights and freedoms.
  • For breaches affecting EU residents: as a UK company without an EU establishment, we do not benefit from the GDPR one-stop-shop mechanism. We may be required to notify multiple EEA supervisory authorities where a breach affects residents in different member states.
  • Notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

BiotrackOS as processor (organisation Member data)

  • Notify the relevant customer organisation without undue delay and, where the Data Processing Addendum requires it, within 24 hours of becoming aware of any personal data breach affecting data processed for it. Available information will include the nature of the breach, categories and approximate numbers of affected individuals and records, likely consequences, and measures taken or proposed.
  • The customer organisation, as controller, is responsible for assessing and fulfilling its own notification obligations to supervisory authorities and individuals.

United States

Where the FTC Health Breach Notification Rule applies, we assess and fulfil our notification obligations to affected individuals, the FTC, and, where required, media, within the timeframes prescribed by the Rule. These obligations may apply to the personal App even where HIPAA does not.

Australia

For breaches affecting Australian individuals, we assess whether a notifiable data breach has occurred under the Privacy Act 1988 and, where required, notify the OAIC and affected individuals in accordance with the Notifiable Data Breaches scheme.

Your rights

In short

You can see, correct, delete, or move your data, object to how we use it, or complain to a regulator. Email dpo@biotrackos.com and we respond within the timeframe required by law.

Wherever you are located, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — ask us to delete your data where there is no overriding reason to keep it.
  • Restriction — ask us to pause processing while a dispute is resolved.
  • Portability — receive your data in a structured, machine-readable format.
  • Object — object to processing carried out on the basis of legitimate interests.
  • Automated decisions — rights in relation to processing that significantly affects you.
  • Withdraw consent — at any time where processing is based on consent; withdrawal does not affect prior lawful processing.
  • Complain or appeal — complain about our handling of your data to us or your local supervisory authority, and where local law provides it, appeal a refusal of a rights request.

To exercise any right, contact dpo@biotrackos.com. We respond within the timeframe required by applicable law. We may ask you to verify your identity before acting on a request. Rights are not absolute and legal exceptions may apply. Additional rights may apply depending on where you are located.

For personal data controlled by a customer organisation (organisation deployment), that organisation is responsible for responding to your request; contact them directly and we will assist them.

US healthcare customers requiring a HIPAA Business Associate Agreement should contact legal@biotrackos.com.

Supervisory authorities

In short

If you’re not happy with how we’ve handled your data, you have the right to complain to your local regulator.

  • United Kingdom: Information Commissioner’s Office (ICO) — ico.org.uk
  • European Union: the supervisory authority in your EU member state. BiotrackOS is in the process of appointing an EU representative under GDPR Article 27; details will be published here once appointed.
  • Australia: Office of the Australian Information Commissioner (OAIC) — oaic.gov.au
  • United States: the Federal Trade Commission (FTC) and, for California residents, the California Privacy Protection Agency. To submit a privacy request, contact privacy@biotrackos.com.
  • All other jurisdictions: contact dpo@biotrackos.com and we will direct you to the relevant authority.

Children's data

The BiotrackOS personal app and platform accounts are intended for users aged 18 and over. We do not knowingly collect personal data from anyone under 18 through these routes. If you believe we have inadvertently done so, contact dpo@biotrackos.com and we will delete it promptly.

A customer organisation may not submit or connect Member data relating to a person under 18 unless expressly permitted in its Order Form and all applicable lawful bases, special-category conditions, transparency information, age-appropriate safeguards, and any required parental or professional authorisations are in place. BiotrackOS will apply agreed child-specific safeguards before that processing begins.

Changes to this policy

We will notify you of material changes at least 30 days in advance via the Service or App and to the email address on file. Where a change introduces a new health-data purpose, model-training use, or category of recipient for which consent is required by applicable law, continued use alone will not count as consent; we will request a specific new choice before that processing begins. The current version is always available at biotrackos.com/privacy.

Contact

Data Protection Officer: dpo@biotrackos.com
General privacy enquiries: privacy@biotrackos.com
BiotrackOS Ltd (SC737158) · Canniesburn Gate, 10 Canniesburn Drive, Bearsden, Glasgow, Scotland, G61 1BF

The operating system
for connected health.

Every signal the body generates. One record. Always up to date.

Book a demo →How it works
biotrackOS

Built for the people behind the data.

Product
  • Product overview
  • PricingSoon
  • Professional workspace
  • Personal app
  • Automations
  • Integrations & capabilities
  • Marketplace
  • Intelligence
  • API & SDKSoon
Markets
  • Clinics
  • Primary & community care
  • Health systems
  • Sports teams
  • Gyms
  • Corporate wellness
  • Insurance
  • Research & pharma
  • Public health
  • Personal
Company
  • About BiotrackOS
  • Careers
  • Press
  • Contact
Resources
  • Blog
  • Customer storiesSoon
  • Research
  • One Health CollectiveSoon
  • Trust & securitySoon
  • Status
© 2026 BiotrackOS
TermsPrivacyCookiesAccessibility