Last updated: April 2025
Health-Shared is operated by Axiom Medical Ltd ("we", "us", "our"). We are committed to protecting the privacy, confidentiality, and security of your personal information.
This Privacy Notice explains how we collect, use, store, and protect personal data when you use the Health-Shared website and services.
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the General Data Protection Regulation (GDPR), and other applicable data protection laws.
This notice may be updated from time to time to reflect regulatory or operational changes.
The organisation responsible for processing personal data is:
Axiom Medical LtdAxiom Medical Ltd acts as the Data Controller.
Health-Shared processes personal data based on different user roles:
We may collect:
Users may voluntarily share health-related experiences, including medical conditions or personal health journeys.
Under the General Data Protection Regulation, this is classified as special category data.
We process such data only where explicit consent is provided, including when users:
By submitting such content, you explicitly consent to its processing and potential publication.
Health-Shared does not provide medical advice, diagnosis, or treatment.
We collect data when users:
We collect technical data through:
We use personal data to:
We rely on:
For health data and voluntary submissions.
To provide account and platform services.
To comply with applicable laws.
To improve services, maintain security, and analyse usage.
Users may withdraw consent at any time via: info@health-shared.com
We may use trusted third-party providers, including:
All providers are required to comply with GDPR/UK GDPR and maintain appropriate security standards.
Personal data is stored securely within the European Economic Area (EEA).
Some historical data was stored using Google Firebase (United States). We are migrating all data to European infrastructure.
We implement security measures aligned with ISO/IEC 27001, including:
Where data is transferred outside the EEA, safeguards such as Standard Contractual Clauses (SCCs) are used.
| Data Type | Retention Period |
|---|---|
| Account data | While account is active |
| User contributions | Until deleted or anonymised |
| Technical logs | Up to 12 months |
| Support communications | Up to 24 months |
After this period, data is securely deleted or anonymised.
You have the right to:
Requests can be made to: info@health-shared.com. We respond within one month.
In the event of a data breach affecting your rights, we will notify:
as required by law.
Health-Shared is intended for users aged 18 years or older. We do not knowingly collect data from individuals under 18.
We use cookies to improve website functionality and analyse usage patterns. See our Cookie Policy for details.
UK Users
If you have any concerns about our use of your personal data, you can contact our Data Protection Officer:
Data Protection OfficerYou may also contact the Information Commissioner's Office (ICO).
U.S. Users
You may contact the Federal Trade Commission (FTC).
We may update this Privacy Notice from time to time. The latest version will always be available on the Health-Shared website.
Date of last review: April 2025