Zivala Ltd
Website and App Privacy Notice
Last Updated: 21st July 2026
Purpose
Zivala Ltd (“Zivala”, “we”, “us” or “our”) respects your privacy and is committed to protecting your personal data. This privacy notice explains how we collect, use, store and share your personal data when you interact with us through the Zivala website, mobile application (app) and related services (together the Platform).
Zivala is a personal health intelligence and lived-experience app that allows individuals to organise their health information, track symptoms and outcomes, receive AI-assisted insights, publish structured health journeys and engage with others experiencing similar health conditions.
Territorial scope
This privacy notice explains how we process personal data and informs you of your rights under applicable Data Protection Laws including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and where applicable the EU General Data Protection Regulation (EU GDPR) and other relevant privacy laws.
Where users access the app from other jurisdictions including the United States, we will comply with applicable local privacy laws where they apply to our processing activities. For example, where relevant US health privacy or consumer protection laws apply, we will process personal data in accordance with those requirements.
Controller for Personal Data
A data controller is the organisation responsible for determining the purposes and means of processing personal data. Unless we notify you otherwise, Zivala is the controller responsible for the processing of personal data described in this privacy notice.
- Controller: Zivala Ltd
- Registered Address: 131 Finsbury Pavement, London, EC2A 1NT. England.
- ICO Registration Number: ZC144836.
Data Protection Officer
Zivala has appointed a Data Protection Officer (DPO) responsible for overseeing questions in relation to this privacy notice. The Data Protection Officer details can be found at the Contact Us section.
EU Article 27 Appointed Representative
Where required under Article 27 of the EU GDPR, Zivala will appoint an authorised EU Representative to act on its behalf in relation to EU data protection matters. Details of the appointed representative will be published in this notice once confirmed.
Scope
This privacy notice applies to the processing of personal data by Zivala in connection with the following categories of individuals.
- Users: Individuals who create an account or use the Zivala app to organise health records, track symptoms, receive AI insights, publish health journeys, participate in community discussions or interact with other users.
- Suppliers: Individuals representing organisations that provide products or services to Zivala including technology providers, consultants and other service providers.
- Website Visitors: Individuals who browse or interact with the Zivala website or online content, regardless of whether they create an account or use the app services.
Privacy by Design and Default
Zivala applies privacy by design and privacy by default principles when developing and operating the Platform. Personal data is processed only where necessary for specific purposes and health information is private by default. Your health records, tracking data and AI interactions are visible only to you unless you choose to share or publish specific information using the app’s visibility controls.
Types of Personal Data
Personal data means any information about an individual from which that person can be identified. It does not include anonymised data where the identity has been removed. Depending on your relationship with us, we may collect, use, store and transfer different categories of personal data.
Please refer to the relevant Processing Table(s) below for further details about how we process your personal data. Depending on your relationship with us (for example, as a User, Supplier or Website Visitor), more than one table may be relevant to you.
Lawful Bases: How We Use Your Personal Data
Zivala will only use your personal data when the law allows us to. Most commonly, we rely on the following lawful bases.
- Performance of a Contract: Where processing is necessary to perform the contract we have entered into with you or are about to enter into with you.
- Consent: Where we rely on consent as a legal basis for processing your personal data including the processing of health data and the use of certain optional features such as AI tools or wearable integrations.
- Legal Obligation: Where we need to comply with a legal obligation.
- Legitimate Interests: Where processing is necessary for our legitimate interests or those of a third party and your interests and fundamental rights do not override those interests.
- Vital Interests: Where processing is necessary to protect your vital interests or those of another individual in emergency circumstances.
- Public Interest: Where processing is required to comply with obligations relating to public interest or public health.
Health information processed through the app constitutes special category personal data under Article 9 GDPR and is processed with your explicit consent.
Processing Tables
The processing tables explain why we process personal data and the lawful basis for doing so. Depending on your relationship with us, you may need to refer to different tables relevant to your specific interactions or services.
User Processing Information
In this section you can find information about how we collect and process your personal data when you use our app as a user.
How We Collect Personal Data
Directly from you: You may provide personal data directly when you create or manage your account, upload clinical documents or other health information, record symptoms or tracking data, use AI features, publish stories or participate in community discussions, communicate with other users or contact us through forms, email or support channels.
From third-party sources: We may also receive personal data from third parties in certain circumstances. For example, where you choose to connect wearable integrations such as device health platforms, where authentication providers confirm your login credentials or where vendors and service providers support the operation of the app.
Categories of personal data collected
- Identity Data: First name, last name, username, display name, title and profile photograph.
- Contact Data: Email address and other contact information you provide.
- Profile Data: Usernames, biographies, interests, preferences, feedback, survey responses, follower relationships and other profile information.
- Health Data (Special Category Data): Health data entered into the app including clinical documents such as test results, referrals and discharge summaries, diagnosed or suspected conditions, medications, supplements and treatments, care timeline events and appointment records, safety notes such as allergies or adverse drug reactions and other physical and wellbeing-related information which you decide to upload onto the app.
- Wearable and Device Data: Health metrics imported from connected services such as Apple HealthKit or Google Health Connect including activity data, heart rate data and sleep information where you choose to enable such integrations.
- Story and Community Data: Content created or shared within the app including published health stories, journey updates, posts, comments, reactions, group participation and direct messages.
- AI Interaction Data: Information provided when interacting with AI-enabled features including prompts submitted to AI tools, AI-generated outputs and information used to generate AI insights or reports.
- Technical Data: Internet protocol (IP) address, login information, browser type and version, device type, operating system, application version, session timestamps and diagnostic information.
- Usage Data: Information about how you interact with the app including navigation patterns, feature usage and engagement with stories or community content.
- Marketing and Communications Data: Your preferences in receiving marketing communications and communication settings.
- Transaction and Subscription Data: Subscription status, plan information, billing identifiers, purchase history, transaction records and payment provider information.
- Authentication and Security Data: Login/session information, authentication data, security logs, user agent, IP address and diagnostic information.
- Privacy and Consent Data: Privacy settings, notification settings, consent choices, data sharing preferences and data export or deletion requests.
- Support and Communications Data: Enquiries, support requests, feedback, survey responses and communications with us.
- Moderation, Safety and Compliance Data: Reports, blocks, content moderation records, account status, audit logs and records required for legal, regulatory or compliance purposes.
- Health Advocate Verification Data: Evidence links, supporting documents, statements, verification status and review outcomes where you apply for health advocate verification.
Note: Information you choose to publish on the app such as stories, posts or comments may be visible to other users depending on your chosen visibility setting.
|
Processing activity |
Categories of personal data |
Lawful basis |
|
To create and manage your user account and profile on the app |
Identity Data, Contact Data, Profile Data |
Performance of a contract |
|
To authenticate users and enable secure login (including authentication processes such as one-time codes or magic links) |
Identity Data, Contact Data, Technical Data |
Performance of a contract |
|
To provide the personal health record functionality of the app including storing and organising your health information |
Identity Data, Health Data |
Performance of a contract and explicit consent |
|
To allow you to upload, store and manage clinical documents such as test results, referral letters and discharge summaries |
Health Data |
Explicit consent |
|
To record and manage health information including conditions, medications, supplements, care timelines and appointment records |
Health Data |
Explicit consent |
|
To enable symptom tracking and health monitoring features including logs relating to pain, sleep, mood, digestion, menstrual cycle, fatigue, skin conditions and food triggers |
Health Data |
Explicit consent |
|
To integrate and import health metrics from connected wearable services where you choose to enable them |
Wearable and Device Data, Health Data, Technical Data |
Explicit consent |
|
To provide AI-enabled features including AI chat, health insights, care reports, track reports, appointment preparation tools and story drafting assistance |
Health Data, AI Interaction Data, Usage Data |
Explicit consent |
|
To generate insights, summaries or pattern analysis from the health and tracking data you record in the app |
Health Data, Usage Data |
Explicit consent |
|
To enable you to create, edit and publish health stories or journey updates |
Identity Data, Story and Community Data, Health Data (where included in a story) |
Performance of a contract and explicit consent |
|
To make published stories discoverable within the app through search, filtering and personalised Explore feeds |
Story and Community Data, Profile Data, Usage Data |
Performance of a contract and legitimate interests (improving discoverability and community engagement) |
|
To enable community features including groups, posts, comments, reactions, bookmarks and event participation |
Identity Data, Story and Community Data, Profile Data |
Performance of a contract |
|
To facilitate direct messaging between users |
Identity Data, Story and Community Data |
Performance of a contract |
|
To personalise the app experience including recommending stories, discussions, groups or content relevant to your interests or profile |
Profile Data, Usage Data, Story and Community Data |
Legitimate interests (improving user experience and engagement) |
|
To generate analytics relating to stories or other content including views, engagement and interaction trends |
Usage Data, Story and Community Data |
Legitimate interests |
|
To monitor and review user content for safety, app integrity and compliance with community guidelines |
Identity Data, Story and Community Data, Profile Data |
Legitimate interests |
|
To administer and protect the Platform including troubleshooting, system maintenance, testing, data analysis, fraud prevention and security monitoring |
Technical Data, Usage Data, Identity Data |
Legitimate interests and legal obligation |
|
To communicate with you about your account including service notifications, security alerts and updates to our services or policies |
Identity Data, Contact Data |
Performance of a contract and legitimate interests |
|
To provide customer support and respond to enquiries, requests or feedback |
Identity Data, Contact Data, Profile Data |
Performance of a contract and legitimate interests |
|
To send newsletters, product updates or marketing communications where permitted by law |
Identity Data, Contact Data, Marketing and Communications Data |
Consent or soft opt-in (legitimate interests where applicable) |
|
To maintain records necessary for compliance with legal, regulatory, audit or reporting obligations |
Identity Data, Technical Data, Transaction Data (where applicable) |
Legal obligation |
|
To manage subscriptions, billing and purchases |
Identity Data, Contact Data, Transaction and Subscription Data |
Performance of a contract and legal obligation |
|
To manage privacy choices, consent and data rights requests |
Identity Data, Contact Data, Privacy and Consent Data |
Legal obligation, consent and performance of a contract |
|
To moderate content, investigate reports and protect users |
Identity Data, Story and Community Data, Moderation, Safety and Compliance Data |
Legitimate interests and legal obligation |
|
To process support requests, feedback and user communications |
Identity Data, Contact Data, Support and Communications Data |
Performance of a contract and legitimate interests |
|
Optional only if health advocate verification is live: To process health advocate verification requests |
Identity Data, Health Data, Health Advocate Verification Data |
Performance of a contract and explicit consent |
Special Category Data
Some of the personal data processed through the app constitutes special category data under Data Protection Laws. In particular, this includes health data that you choose to enter into the app such as clinical documents, conditions, medications, treatments, symptom tracking information and other health-related records.
We process this health data only where you have provided your explicit consent. Explicit consent is obtained when you create and use your account to record or upload health information, enable relevant app features (such as symptom tracking or wearable integrations) or publish stories that contain health-related information.
You may withdraw your consent at any time by contacting us or by adjusting your settings within the app. However, if you withdraw consent for the processing of health data, certain features of the app may no longer be available, as they rely on the processing of that information to function.
Suppliers: Processing Information
How We Collect Personal Data: We collect personal data about suppliers primarily directly from you in the course of our business relationship.
Directly from you: You may provide personal data when entering into a supplier relationship with us including when negotiating or managing contracts, providing contact details for service delivery, submitting invoices or payment information or communicating with us regarding the services you provide.
From third-party sources: In some cases, we may receive personal data from third parties such as where colleagues within your organisation provide your contact details for business purposes or where professional advisers or service providers assist with supplier management, payments or compliance processes.
Categories of Personal Data Collected
- Identity Data: First name, last name, job title and other identifiers used to identify individuals representing a supplier organisation.
- Contact Data: Business email address, telephone number, business address and other contact details provided in connection with the supplier relationship.
- Financial Data: Bank account details and payment information necessary to process payments for goods or services provided to us.
- Transaction Data: Details relating to payments made to you, invoices, billing information and other transaction records relating to the services you provide.
- Contractual and Business Relationship Data: Information relating to supplier agreements, service delivery, communications regarding services, performance of contractual obligations and other records relating to the supplier relationship.
- Technical Data: Limited technical information such as IP address or system access information where suppliers interact with our systems, Platform or infrastructure.
- Communications Data: Records of communications between you and Zivala including emails, correspondence, support enquiries or service-related discussions.
|
Processing activity |
Categories of personal data |
Lawful basis |
|
To onboard suppliers and manage supplier relationships including entering into and administering supplier agreements |
Identity Data, Contact Data, Contractual and Business Relationship Data |
Performance of a contract |
|
To manage communications with suppliers regarding the provision of services, support, operational matters and service delivery |
Identity Data, Contact Data, Communications Data |
Performance of a contract and legitimate interests |
|
To process payments, invoices and financial administration relating to goods or services provided to us |
Identity Data, Financial Data, Transaction Data |
Performance of a contract and legal obligation |
|
To administer and protect our business including managing access to systems, maintaining records and ensuring service continuity |
Identity Data, Contact Data, Technical Data |
Legitimate interests |
|
To comply with legal, regulatory, accounting or audit obligations applicable to our business operations |
Identity Data, Financial Data, Transaction Data, Contractual and Business Relationship Data |
Legal obligation |
Website Visitors Processing Information
How We Collect Personal Data
Directly from you: You may provide personal data when you contact us through the website, for example by submitting an enquiry through a contact form or by emailing us.
Automatically through your use of the website: When you visit the website, we may automatically collect certain technical and usage information such as your IP address, browser type, device information and how you interact with the website. This information may be collected through cookies and similar technologies used to support website functionality and improve performance.
Categories of Personal Data Collected
Where you visit or interact with the Zivala website, we may collect and process the following categories of personal data.
- Identity Data: First name and last name where you choose to provide this information through website forms or enquiries.
- Contact Data: Email address and other contact details provided when you contact us through the website, for example through enquiry forms or email links.
- Technical Data: Internet protocol (IP) address, browser type and version, device type, operating system, time zone setting and other technology on the devices used to access the website.
- Usage Data: Information about how you interact with and navigate the website including pages visited, time spent on pages and general website usage patterns.
- Communications Data: Information contained in messages or enquiries submitted through website contact forms, email links or other communication channels available on the website.
|
Processing activity |
Categories of personal data |
Lawful basis |
|
To respond to enquiries submitted through website forms, email links or other contact methods |
Identity Data, Contact Data, Communications Data |
Legitimate interests (responding to enquiries and communications) |
|
To manage and administer the website including maintaining functionality, performance monitoring and troubleshooting |
Technical Data, Usage Data |
Legitimate interests |
|
To analyse how visitors use the website in order to improve website content, usability and services |
Technical Data, Usage Data |
Legitimate interests or consent where cookies are used |
|
To maintain the security of the website and prevent fraud, misuse or unauthorised access |
Technical Data, Usage Data |
Legitimate interests |
|
To comply with legal or regulatory obligations applicable to the operation of the website |
Identity Data, Contact Data, Technical Data |
Legal obligation |
|
To manage cookies settings |
Technical Data |
Consent (for non-essential cookies) |
Use of Artificial Intelligence
Zivala uses artificial intelligence tools to support certain app features including AI chat, uploaded document analysis, consultation transcription and summarisation, AI-generated health reports, appointment preparation, condition search support and story drafting, improvement and verification.
These tools analyse information you provide or store within the app including health records, tracking logs, consultations, appointments, medications, supplements, wearable data and story content, to generate summaries, insights, reports and responses.
AI outputs are generated automatically and may be incomplete or inaccurate. They are provided for informational and organisational purposes only and do not constitute medical advice, diagnosis or treatment recommendations. You should review AI outputs for accuracy and seek advice from a qualified healthcare professional for medical concerns.
AI tools support the services provided through the Platform and do not make automated decisions that produce legal, medical or similarly significant effects about you.
AI tools are used to support the services provided through the Platform and do not make automated decisions that produce legal or similarly significant effects about individuals.
Cookies and Similar Technologies
Zivala gathers information and statistics collectively about visitors to our website. Analysis of this information helps us understand which sections of the website are used most frequently and allows us to improve the quality and performance of our services.
Cookies and similar technologies may be used to:
- maintain secure sessions
- analyse website usage and traffic patterns
- improve the functionality and performance of the Platform
Further details are available in our Cookie Notice.
Providing Personal Data
Where we need to collect personal data by law or under the terms of a contract and you fail to provide that information when requested, we may not be able to perform the contract we have or are trying to enter into with you. For example, we may not be able to provide certain app services. In such cases we may have to cancel or suspend those services.
Marketing Communications
Zivala may send marketing communications about services, updates or features. You have the right to object to the processing of your personal data for direct marketing purposes. You can unsubscribe using the links included in marketing communications or by contacting us directly. Opting out of marketing communications does not affect communications required for providing services to you.
Third-Party Service Providers
We may share personal data with carefully selected third-party service providers who perform services on our behalf and support the operation of the Zivala Platform. These providers process personal data only under our instructions and in accordance with contractual obligations requiring appropriate security and confidentiality safeguards.
The categories of service providers we use include:
- Cloud infrastructure and hosting providers: Providers that host the Platform and securely store account data, health records, tracking information and other Platform data.
- AI service providers: Technology providers that support AI-enabled features including AI chat, AI reports, appointment preparation tools and story drafting assistance.
- Wearable device providers (for users only): Where you choose to connect a wearable or health platform (such as Apple HealthKit or Google Health Connect), we may receive health metrics and activity data from those services to import into your personal health record and support app features. These integrations operate only where you have chosen to enable them and provided your consent and you may disconnect them at any time through your device or app settings.
- Analytics and performance monitoring providers: Services that help us understand how users interact with the Platform and allow us to improve functionality and reliability.
- Communications and email delivery providers: Providers that deliver transactional communications such as account verification emails, authentication links and security notifications.
- Payment providers: Providers that process payments, manage subscriptions and administer billing transactions.
- Customer support providers: Providers that support customer service operations and help manage enquiries or technical support requests.
- Security and fraud prevention providers: Providers that help protect the Platform against unauthorised access, malicious activity and fraud.
- Infrastructure monitoring and error reporting providers: Providers that monitor system performance and detect application errors or service disruptions.
- Professional advisers: Lawyers, accountants, auditors, insurers and other professional advisers who support legal compliance and business operations.
- Business transactions (M&A): This is in connection with a business transaction such as a merger or acquisition. Where this is the case, your personal data shall continue to be processed in accordance with this Privacy Notice.
All third-party service providers are required to process personal data only for the purposes specified by Zivala and in accordance with Data Protection Laws.
International transfers for UK/EU
We may transfer and process your personal data outside of the United Kingdom (UK) /European Union (EU) to countries where Data Protection Laws are less stringent than those in the UK/EU. When we transfer your personal data outside of the UK/ EU we only do so to entities that offer our users the same level of data protection as that afforded by Data Protection Laws.
- We will only transfer your personal information to countries that have been deemed to provide an adequate level of protection for personal information; or
- We will use specific contracts approved for use in the UK or EU which give personal information the same protection it has in the UK/EU. For example, the use of Article 46 UK and EU GDPR safeguard mechanisms to transfer personal data endorsed by the UK Government or European Commission.
For other countries we will use local law guidance to ensure personal data is transferred securely where there is a requirement in law to do so.
Data Security
We have implemented appropriate security measures designed to protect personal data from accidental loss, unauthorised access, disclosure or misuse.
Access to personal data is limited to employees, contractors and service providers who require access for legitimate business purposes. However, the transmission of information over the internet cannot be guaranteed to be completely secure.
Data retention
We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means and the applicable legal, regulatory, tax, accounting or other requirements.
Data Subject Rights
Under certain circumstances, you have rights under Data Protection Laws. Not all rights are absolute and depending on where you are located, not all rights are given to you. You can:
Request access to your personal data: This is known as a "subject access request" and enables you to receive a copy of the personal data we hold about you.
Request correction of your personal data: This enables you to have any incomplete or inaccurate information we hold about you corrected.
Request erasure of your personal data: This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. We may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you at the time of your request.
Object to processing of your personal data: This is where we are processing your personal data based on a legitimate interest or those of a third party and you may challenge this. However, we may be entitled to continue processing your information based on our legitimate interests or where this is relevant to any legal claims. See also Marketing communications.
Request restriction of processing your personal information: This enables you to ask us to suspend the processing of your personal data in the following scenarios: (a) if you want us to establish the information's accuracy (b) where our use of the information is unlawful but you do not want us to erase it (c) where you need us to hold the information even if we no longer require it as you need it to establish, exercise or defend legal claims or (d) you have objected to our use of your information but we need to verify whether we have overriding legitimate grounds to use it.
Request transfer of your personal information (“data portability”): This is where in some circumstances we will provide to you or a third party you have chosen your personal data in a structured, commonly used, machine-readable format.
Right to withdraw consent: This is where we are relying on consent to process your personal data. This will not affect the lawfulness of any processing carried out before you withdraw your consent. Depending on the processing activity, we may not be able to provide certain services to you if you withdraw your consent. We will advise you if this is the case at the time you withdraw your consent.
Automated decision making: This is where decisions are made about you by automated means. Zivala does not carry out automated decision-making producing legal or similarly significant effects.
Carrying Out Your Data Subject Rights
You will not have to pay a fee to access your personal data or exercise other rights. However, we may charge a reasonable fee where a request is clearly unfounded or excessive. We may request information to verify your identity before responding to a request. We aim to respond to legitimate requests within one month.
To exercise your rights please contact security@zivala.health.
Keeping personal information accurate and current
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us. Please contact us if you wish to update your personal data.
Concerns and complaints
We would appreciate the chance to deal with your concerns in the first instance. Please see Contact us section. If you have unresolved issues, you have the right to complain at any time to a data protection supervisory authority for data protection issues such as the UK data protection regulator – the Information Commissioner’s Office (ICO).
You may lodge a complaint with a supervisory authority if you live or work outside the UK or you have a complaint concerning our personal data processing activities.
Changes to our privacy notice
This privacy notice may be changed from time to time in response to legal, technical or business developments. We will take appropriate measures to inform you when we update our privacy notice. We will obtain your consent to any material privacy notice changes if and where this is required by applicable Data Protection Laws.
Contact us
If you would like more information about the way we manage personal information that we hold about you please contact us the DPO at:
DPO: Zeeshanali
Email: security@zivala.health