Legal · Privacy

Privacy Policy

Last updated: 16 March 2026 Effective: 16 March 2026 Unwritten Health Ltd · Company No. 16561594

1. Introduction

Unwritten Health LTD ("we", "us", "our") is committed to protecting the privacy and security of personal data. We specialise in generating patient insights to improve health equity, clinical trial inclusivity, and healthcare outcomes.

This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you use our platform, services, and website (collectively, the "Services"). It also explains your rights in relation to your personal data.

We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), the common law duty of confidentiality, and the Caldicott Principles where applicable.

This Privacy Policy applies to:

  • Visitors to our website
  • Users of our platform (including healthcare professionals, researchers, and pharmaceutical clients)
  • Patients, carers, and members of the public whose insights or data we process
  • Business contacts, partners, and suppliers

2. Who We Are

Data Controller: Unwritten Health LTD, registered in England and Wales, company number 16561594, whose registered office is at Swan Buildings, 20 Swan Street, Manchester, M4 5JW, UK.

Data Protection Officer (DPO): Ashish Rishi, CEO Email: [email protected] Postal Address: Swan Buildings, 20 Swan Street, Manchester, M4 5JW, UK

For any questions about this Privacy Policy or our data practices, please contact our DPO using the details above.

3. Information We Collect

We may collect and process the following categories of personal data.

3.1 Information You Provide Directly

  • Identity Data: Name, title, date of birth, gender identity, ethnicity (where voluntarily provided)
  • Contact Data: Email address, postal address, telephone number
  • Professional Data: Job title, employer, professional registration number, qualifications
  • Account Data: Username, password, account preferences
  • Patient Insight Data: Health experiences, treatment journeys, patient-reported outcomes, survey responses, interview transcripts, lived experience narratives
  • Consent Records: Records of consent given or withdrawn
  • Financial Data: Bank details, payment information (for service fees or participant reimbursement)

3.2 Information Collected Automatically

  • Technical Data: IP address, browser type, operating system, device identifiers
  • Usage Data: Pages visited, time spent on pages, click patterns, features used
  • Cookie Data: Information collected through cookies and similar technologies (see our Cookie Policy)

3.3 Information from Third Parties

  • Referral Data: Information from healthcare providers, research organisations, or pharmaceutical partners who refer participants to our platform
  • Publicly Available Data: Professional information from public registries or professional directories

3.4 Special Category Data

We recognise that much of the data we process constitutes special category data under the UK GDPR, including:

  • Data concerning health (patient experiences, conditions, treatments, outcomes)
  • Racial or ethnic origin (where collected for health equity and diversity purposes)
  • Genetic data or biometric data (where applicable)

We apply enhanced protections to all special category data and only process it where we have identified a valid legal basis and an additional condition under Article 9 of the UK GDPR and Schedule 1 of the DPA 2018.

4. How We Use Your Personal Data

We process personal data for the following purposes, each linked to a specific lawful basis:

Providing our platform and services to users Lawful Basis: Performance of a contract

Collecting and analysing patient insights to improve clinical trial design and health equity Lawful Basis: Legitimate interests / Consent Special Category Condition: Explicit consent / Substantial public interest / Scientific research purposes

Conducting health equity research and producing anonymised or aggregated reports Lawful Basis: Legitimate interests Special Category Condition: Scientific research purposes (with appropriate safeguards)

Reimbursing patients and participants for their contributions Lawful Basis: Performance of a contract

Creating anonymised or pseudonymised datasets for clients Lawful Basis: Legitimate interests Special Category Condition: Explicit consent / Scientific research purposes

Communicating with you about our services, updates, and opportunities Lawful Basis: Legitimate interests / Consent

Complying with legal and regulatory obligations (e.g., adverse event reporting) Lawful Basis: Legal obligation Special Category Condition: Substantial public interest

Protecting our legal rights and resolving disputes Lawful Basis: Legitimate interests Special Category Condition: Establishment, exercise, or defence of legal claims

Improving our platform, services, and user experience Lawful Basis: Legitimate interests

Marketing and promotional communications (with consent) Lawful Basis: Consent

Website analytics and performance monitoring Lawful Basis: Legitimate interests

Where we rely on legitimate interests, we have conducted a balancing test to ensure that our interests do not override the rights and freedoms of data subjects. Details of these assessments are available upon request.

5. Patient Insights — Additional Protections

Given the sensitive nature of patient insights, we apply the following additional protections.

5.1 Informed Consent

  • Before collecting patient insights, we provide clear, plain-language information about what data we collect, why, and how it will be used
  • Consent is always freely given, specific, informed, and unambiguous
  • Participants are never pressured to take part and are informed that refusal will not affect their care or any other services
  • We use layered consent where appropriate, allowing participants to choose which uses of their data they agree to

5.2 Anonymisation and Pseudonymisation

  • Patient insights are anonymised or pseudonymised wherever possible
  • We conduct re-identification risk assessments before sharing any datasets
  • Aggregated insights reports do not contain any information that could identify an individual
  • Where pseudonymised data is used, the re-identification key is stored separately with strict access controls

5.3 Data Minimisation

  • We collect only the minimum personal data necessary for the stated purpose
  • We adhere to the Caldicott Principles, ensuring that access to confidential information is on a strict need-to-know basis

5.4 Adverse Event and Safety Reporting

If, during the collection of patient insights, we become aware of an adverse event, product complaint, or special reporting situation, we have procedures in place to report this to the relevant pharmaceutical company and/or regulatory authority (e.g., MHRA) in accordance with applicable regulations and BHBIA/ABPI guidelines.

5.5 Participant Rights

  • Participants may withdraw their consent at any time without giving a reason
  • Withdrawal of consent will not affect the lawfulness of processing carried out before withdrawal
  • Where data has already been anonymised and included in aggregated reports, it may not be possible to remove it, and we will explain this clearly at the point of consent

6. Who We Share Your Data With

We may share personal data with the following categories of recipients:

  • Pharmaceutical and life sciences clients: Anonymised or aggregated patient insights for the purpose of improving clinical trial design, patient recruitment strategies, and health equity outcomes. We will never share identifiable patient data with clients without explicit consent.
  • Technology service providers: Hosting, cloud storage, analytics, and communication tools that support the operation of our platform (acting as data processors under written agreements)
  • Research partners: Academic institutions or research organisations collaborating on health equity research (under appropriate data sharing agreements)
  • Professional advisers: Legal, audit, and compliance advisers
  • Regulators and authorities: The Information Commissioner's Office (ICO), the MHRA, NHS bodies, or other regulatory authorities where required by law
  • Payment processors: For the processing of participant reimbursements or client payments

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow third-party service providers to use your data for their own purposes and only permit them to process your data for specified purposes and in accordance with our written instructions.

We will never sell your personal data to any third party.

We will never share identifiable patient data for marketing or insurance purposes.

7. International Data Transfers

We primarily store and process personal data within the United Kingdom and the European Economic Area (EEA).

Where we transfer personal data outside the UK or EEA, we ensure that appropriate safeguards are in place, including:

  • Transfers to countries with an adequacy decision from the UK Secretary of State
  • Standard Contractual Clauses (SCCs) approved by the ICO
  • Binding Corporate Rules (where applicable)
  • The International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs

You may request a copy of the safeguards we have in place by contacting our DPO.

8. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, accounting, or reporting requirements.

Patient insight data (identifiable): 7 years from the date of collection, or until consent is withdrawn, whichever is sooner

Anonymised/aggregated insight reports: Retained indefinitely (as they no longer constitute personal data)

Platform user account data: Duration of the account plus 3 years

Contractual and financial records: 7 years from the end of the contract (in line with HMRC requirements)

Marketing consent records: Duration of consent plus 7 years

Website analytics data: 12 months

At the end of the retention period, personal data will be securely deleted or anonymised.

9. Data Security

We have implemented appropriate technical and organisational measures to protect personal data from unauthorised access, loss, alteration, or destruction. These measures include:

  • Encryption of data in transit and at rest (AES-256 or equivalent)
  • Role-based access controls on a strict need-to-know basis
  • Multi-factor authentication for all platform users
  • Regular penetration testing and vulnerability assessments
  • Staff training on data protection, information security, and the Caldicott Principles
  • Incident response and breach management procedures
  • Regular audits and reviews of our security measures
  • Secure disposal procedures for personal data

In the event of a personal data breach that poses a risk to individuals' rights and freedoms, we will notify the ICO within 72 hours and will inform affected individuals without undue delay where required.

10. Your Rights

Under the UK GDPR, you have the following rights in relation to your personal data:

  • Right to be informed: To know how we collect and use your personal data (this Privacy Policy)
  • Right of access: To request a copy of the personal data we hold about you (a "Subject Access Request")
  • Right to rectification: To request correction of inaccurate or incomplete personal data
  • Right to erasure ("right to be forgotten"): To request deletion of your personal data in certain circumstances
  • Right to restrict processing: To request that we limit how we use your personal data
  • Right to data portability: To request your personal data in a structured, commonly used, machine-readable format
  • Right to object: To object to our processing of your personal data, including for direct marketing purposes
  • Right to withdraw consent: Where we rely on consent, you may withdraw it at any time
  • Rights relating to automated decision-making and profiling: You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects

To exercise any of these rights, please contact our DPO at [email protected]. We will respond to your request within one calendar month. In certain circumstances, we may extend this by a further two months, and we will inform you if this is the case.

If you are dissatisfied with our handling of your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF Telephone: 0303 123 1113 Website: www.ico.org.uk

11. Cookies

By using our website or platform, you consent to the use of essential cookies. For non-essential cookies, we will ask for your explicit consent before they are placed on your device.

11.1. What Are Cookies?

Cookies are small text files that are placed on your device (computer, smartphone, tablet) when you visit a website. Cookies are widely used to make websites work more efficiently and to provide information to website owners.

Cookies may be "session cookies" (deleted when you close your browser) or "persistent cookies" (remain on your device until they expire or are manually deleted).

Similar Technologies

In addition to cookies, we may use similar technologies such as:

  • Web beacons (pixels): Small graphic images embedded in web pages or emails to track user activity
  • Local storage: Browser-based storage that allows websites to store data locally on your device
  • Device fingerprinting: Techniques that collect information about your device configuration

For simplicity, this Cookie Policy refers to all these technologies collectively as "cookies."

11.2. Why We Use Cookies

We use cookies to:

  • Enable essential functionality of our platform and website
  • Remember your preferences and settings
  • Understand how you use our website and platform
  • Improve your user experience
  • Analyse website traffic and performance
  • Deliver relevant content and communications
  • Comply with legal and regulatory obligations

11.3. Types of Cookies We Use

We categorise cookies into four types based on their purpose and function.

11.3.1 Strictly Necessary Cookies (Essential Cookies)

These cookies are essential for the website and platform to function properly. They enable core functionality such as security, network management, authentication, and accessibility.

Legal Basis: These cookies do not require consent under UK PECR because they are strictly necessary for the service you have requested.

Duration: Session or persistent (up to 12 months)

session_id — Maintains your login session — Session csrf_token — Protects against cross-site request forgery attacks — Session load_balancer — Distributes traffic across servers for performance — Session cookie_consent — Records your cookie preferences — 12 months

You cannot refuse these cookies if you wish to use our platform. You can block them by changing your browser settings, but this may prevent you from accessing parts of our website or platform.

11.3.2 Performance and Analytics Cookies

These cookies collect information about how you use our website and platform, such as which pages you visit, how long you spend on each page, and any errors you encounter. We use this information to improve website performance and user experience.

Legal Basis: Your explicit consent is required under UK PECR.

Duration: Typically 12–24 months

_ga — Google Analytics — Distinguishes unique users and tracks site usage — 24 months _gid — Google Analytics — Stores and counts page views — 24 hours _gat — Google Analytics — Throttles request rate — 1 minute

We use Google Analytics to analyse website traffic. Google Analytics collects information such as your IP address (anonymised), browser type, device type, pages visited, and time spent on pages. For more information about how Google uses data, please visit: https://policies.google.com/technologies/partner-sites

Analytics data is retained for 26 months, after which it is automatically deleted.

11.3.3 Functionality Cookies (Preference Cookies)

These cookies allow our website and platform to remember choices you make (such as your username, language preference, or region) and provide enhanced, personalised features.

Legal Basis: Your explicit consent is required under UK PECR.

Duration: Typically 12 months

language_pref — Remembers your language preference — 12 months dashboard_layout — Saves your dashboard customisation settings — 12 months notification_settings — Remembers your notification preferences — 12 months

11.3.4 Targeting and Marketing Cookies (Advertising Cookies)

These cookies are used to deliver content and advertisements that are relevant to you and your interests. They may also be used to limit the number of times you see an advertisement and to measure the effectiveness of marketing campaigns.

Legal Basis: Your explicit consent is required under UK PECR.

Duration: Typically 12–24 months

_fbp — Meta (Facebook) — Delivers and measures the effectiveness of Facebook advertising — 3 months _linkedin_data_partner_id — LinkedIn — Tracks conversions and website visitors for LinkedIn advertising — 90 days

We may work with third-party advertising networks to display relevant advertisements. These networks may track your browsing activity across multiple websites to build a profile of your interests.

You can opt out of targeted advertising by visiting:

  • Your Online Choices (EU/UK): http://www.youronlinechoices.eu/
  • Network Advertising Initiative (US): http://optout.networkadvertising.org/

We do not use targeting or marketing cookies by default. We will only set these cookies if you give us your explicit consent.

11.4. Managing Your Cookie Preferences

11.4.1 Cookie Consent Banner

When you first visit our website, you will see a cookie consent banner that allows you to:

  • Accept all cookies — Consent to all cookie categories (essential, analytics, functionality, and marketing)
  • Reject non-essential cookies — Only allow essential cookies (required for the website to function)
  • Manage preferences — Choose which categories of cookies you wish to allow

Your consent choices will be saved for 12 months. After this period, you will be asked to confirm your preferences again.

11.4.2 Changing Your Cookie Preferences

You can change your cookie preferences at any time by:

1. Clicking the Cookie Settings link in the footer of our website

2. Adjusting your preferences in your account settings (if you are logged in)

3. Clearing your browser cookies (see Section 5.3)

If you withdraw consent for analytics or marketing cookies, any cookies previously set will be deleted, and no new cookies of that type will be placed on your device.

11.4.3 Browser Settings

Most web browsers allow you to control cookies through their settings. You can configure your browser to:

  • Block all cookies
  • Block third-party cookies only
  • Delete cookies when you close your browser
  • Notify you when a website tries to set a cookie

How to manage cookies in common browsers:

  • Google Chrome: Settings > Privacy and security > Cookies and other site data
  • Mozilla Firefox: Settings > Privacy & Security > Cookies and Site Data
  • Safari (Mac): Preferences > Privacy > Cookies and website data
  • Microsoft Edge: Settings > Cookies and site permissions > Manage and delete cookies

For more detailed instructions, visit your browser's help pages:

  • Chrome: https://support.google.com/chrome/answer/95647
  • Firefox: https://support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer
  • Safari: https://support.apple.com/guide/safari/manage-cookies-sfri11471/mac
  • Edge: https://support.microsoft.com/en-us/microsoft-edge/delete-cookies-in-microsoft-edge-63947406-40ac-c3b8-57b9-2a946a29ae09

Please note: Blocking or deleting cookies may affect your ability to use certain features of our website or platform.

11.5 Do Not Track (DNT) Signals

Some browsers include a "Do Not Track" (DNT) feature that signals to websites that you do not want your online activity tracked. Currently, there is no universally accepted standard for how websites should respond to DNT signals.

At present, our website does not respond to DNT signals. However, you can control cookies through the methods described in Section 5.

11.6. Updates to This Cookie Policy

We may update this Cookie Policy from time to time to reflect changes in technology, legislation, our business practices, or for other operational reasons.

When we make significant changes, we will notify you by:

  • Updating the "Last Updated" date at the top of this policy
  • Displaying a prominent notice on our website
  • Sending you an email notification (if you have an account with us)

We encourage you to review this Cookie Policy periodically.

11.7. Contact Us

If you have any questions or concerns about our use of cookies, please contact us:

Data Protection Officer Unwritten Health LTD Swan Buildings, 20 Swan Street, Manchester, M4 5JW, UK Email: [email protected] Telephone: +44 (0) 161 524 8800

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF Telephone: 0303 123 1113 Website: www.ico.org.uk

11.8. Additional Information

11.8.1 Cookies and Personal Data

Some cookies may collect personal data (such as your IP address or device identifiers). Where this is the case, the data is processed in accordance with our Privacy Policy and the UK GDPR.

11.8.2 Cookies for Patient Insights

Where cookies are used in connection with the collection of patient insights or health-related data:

  • We apply the same enhanced data protection measures described in our Privacy Policy
  • We ensure explicit consent is obtained before any health-related data is collected via cookies
  • Cookies are anonymised or pseudonymised wherever possible
  • We conduct regular reviews to ensure cookies are necessary and proportionate

11.8.3 International Data Transfers

Some third-party cookies (such as Google Analytics, Meta, LinkedIn) may transfer data outside the UK or European Economic Area (EEA). Where this occurs, we ensure appropriate safeguards are in place, such as EU-US Data Privacy Framework participation, Standard Contractual Clauses (SCCs), and adequacy decisions. For more information about international data transfers, please see our Privacy Policy.

This Cookie Policy was last reviewed on 16 March 2026

12. Children's Data

Our Services are not directed at children under the age of 16. We do not knowingly collect personal data from children under 16 without parental or guardian consent. Where patient insights are collected from or about individuals under 16, we ensure that appropriate consent is obtained from a parent or guardian.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. Where changes are significant, we will notify you by email or through a prominent notice on our website.

We encourage you to review this Privacy Policy periodically.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact:

Data Protection Officer Unwritten Health LTD Swan Buildings, 20 Swan Street, Manchester, M4 5JW, UK Email: [email protected] Telephone: +44 (0) 161 524 8800

This Privacy Policy was last reviewed on 16 March 2026.

Questions about this document? Contact our Data Protection Officer at [email protected] or write to us at Swan Buildings, 20 Swan Street, Manchester, M4 5JW, UK.