At Babylon our mission is to put an accessible and affordable health service in the hands of every person on earth. We are passionate about high-quality and convenient healthcare. We are also passionate about privacy. We strive to comply with the General Data Protection Regulation (GDPR) and the Data Protection Act 2018 (DPA), and to be market leaders when it comes to healthcare and privacy.

This policy explains how we use your personal data. We want to help you understand how we work with your data, so that you can make informed choices and be in control of your information. We invite you to spend a few moments understanding this policy. We may update this policy from time to time and, if we make any material changes, we will notify you when we do so. We will provide you with the opportunity to review such changes. By continuing to use our products and services after the changes have been made and we have notified you of them, the way we use your personal data will be subject to the terms of the updated policy.

This policy explains how we use your personal data for our healthcare services and products, including, amongst others, our private service, and our NHS service (Babylon GP at hand). It also governs the use of your data through our App, or any of our websites, including the Babylon website and the Babylon GP at hand website (and any reference to our App in this policy shall also include a reference to our websites).

This policy covers:

1. Who we are;

2. What personal data we hold and how we get it;

3. What we use your personal data for;

4. Sharing your personal data;

5. Retention;

6. Data security and transfers; and

7. Your rights.

If you have any further questions about how we process your information, please don't hesitate to get in touch by contacting our Data Protection Officer:

Address: Data Protection Officer, Babylon Health, 60 Sloane Avenue, London, SW3 3DD

Email: DPO@babylonhealth.com

1. Who we are

Our healthcare services are delivered by two companies within our group which are both registered in England and Wales: Babylon Healthcare Services Limited (number 09229684) provides you with medical treatment, and Babylon Partners Limited (08493276) provides the technology that supports our services. The registered office and principal place of business for both companies is 60 Sloane Avenue, London, SW3 3DD.

Our NHS service is called GP at hand. The Babylon GP at hand partnership, whose registered address is 139 Lillie Road, London, SW6 7SX (Babylon GP at hand Partnership), provides primary care services, commissioned by NHS England, to patients registered with its NHS GP practice in accordance with its GMS contract. The GP at hand Partnership offers the GP at hand service, a digital-first service to its patients, which is provided by Babylon under a sub-contract arrangement.

When this policy talks about ‘Babylon’, ‘us’ or ‘we’, it means Babylon Healthcare Services Limited. We provide your data to other companies within our corporate group, including Babylon Partners Limited, which develops and maintains our software.

Babylon Healthcare Services Limited and Babylon Partners Limited are joint controllers of your personal data provided to, or collected by or for, or processed in connection with our healthcare services. This policy applies to both companies.

Your relationship is with Babylon Healthcare Services Limited. If for example, you would like to access your data, Babylon Healthcare Services Limited is the entity to which you would make such a request.





2. What personal data we hold and how we get it

We use the following categories of personal data:

Personal details

When you register with us, you complete forms and provide us with basic information about yourself, such as your name, date of birth, physical address and email address. You will also provide us with a copy of identification documentation for ID checks to be carried out by one of our commercial partners. You are responsible for the accuracy of the information that you provide to us.





Health and medical information

The main type of information we hold about you is health and medical information: information about your health, symptoms, treatments, consultations and sessions, medications and procedures. This includes details of your consultations with our doctors, and interactions with our digital services, including interactions with our chatbot, symptom checker, ‘Ask a doctor’, ‘Ask a nurse’, Healthcheck, Digital Twin services, health monitoring, women’s health and condition management services. Your interactions with our digital services may be shared with our doctors in order to provide you with a better experience and for the purposes of providing you health care.

We get some of this information directly from you, when you register with us and when you use our healthcare services. If you use our Babylon GP at hand, we will receive your medical history from your previous GP. If you use our other services (including our private service), and if you have given consent for us to do so, we will send the consultation notes that we take during your use of the private service to your NHS GP (for minors, we will share such notes, in line with medical guidelines, without such consent). Any correspondence we receive from you is uploaded electronically to your Babylon medical record.

We retain recordings of our consultations and interactions with you. This can include your use of our chatbot service (which includes our symptom checker, ‘Ask a doctor’ and ‘Ask a nurse’), video and audio recordings or audio-only recordings. This is in order to provide you with an easy way to check your consultations where you wish to, so that we can ensure high quality care is provided to you, and, with your consent, to allow us to learn from them to improve our services. To monitor our service quality, we may retain records of when you contact our support teams via email, phone or our interactive livechat service on the App. Recordings are held securely in accordance with our retention policy. You can access recordings or transcripts of your consultations or interactions with us (depending on the format) for a limited time through the App or from us. Please refer to the ‘Retention Periods’ section of this policy.

We may also hold information about you and your health from other apps, devices and services where you have given your consent to that data being shared with us. Examples include where you decide to share information collected from a smart watch or similar device with our App.

Financial information

If you make any payments on the App, your credit/debit card details are processed directly by a third party processor that will store all payment information and transaction details. We will only retain details of transactions on secure servers and we will not retain your credit or debit card information.

Technical information and analytics

When you use our App or visit our website, we may automatically collect the following information where this is permitted by your device or browser settings:

technical information, including the address used to connect your mobile phone or other device to the Internet, your login information, system and operating system platform type and version, device model, browser or app version, time zone setting, language and location preferences, wireless carrier and your location (based on IP address); and

information about your visit (such as when you first used the App and when you last used it, and the total number of sessions you have had on that App), including products and services you viewed or used, App response times and updates, interaction information (such as button presses or the times and frequency of your interactions with the communications we deliver to you in the App or otherwise) and any phone number used to call our customer service number.

We work with partners who provide us with analytics and advertising services (for our services only and not for third party advertising). This includes helping us understand how users interact with our services, providing our advertisements on the internet, and measuring performance of our services and our adverts. Cookies and similar technologies may be used to collect this information, such as your interactions with our services. Our Cookie Policy is available at: babylonhealth.com/terms/cookies. You can prevent the setting of cookies by adjusting the settings on your browser or your mobile phone.

Information obtained from third party services

You may choose to connect your existing accounts with other providers (such as a social media provider) , for example, when signing up to make it easier to create an account with us. If you choose to do this, we will receive limited information about you from that provider, such as your email address and name. Provided we are acting in accordance with data protection laws, we may also use information from other sources, such as specialist companies that supply information, online media channels, our commercial partners and public registers. This information can for example, help us to improve and measure the effectiveness of our services.



3. What we use your personal data for

The purposes for which we use your personal data and the legal grounds on which we do so are as follows:

Providing you a service

We obtain and use your personal details and financial details in order to establish and deliver our contract with you and (if applicable) charge you correctly.

We obtain and use your medical information because this is necessary for medical purposes, including medical diagnosis and the provision of healthcare or treatment. This includes the information collected through our consultations with you (such as notes and recordings), our digital services, and medical history from your previous NHS GP if you use Babylon GP at hand (in the same way that any GP practice would receive your medical history if they become your NHS GP). It may also include sharing information with other healthcare professionals as necessary for the provision of care to you, such as your GP (if you use our private service), specialist referral services, therapists, pharmacists, hospitals, accident and emergency services, pathology service providers, and diagnosis centres chosen by you for the purpose of imaging request forms.

Making healthcare accessible

Where you have provided your explicit consent, we will use your medical information (always having removed personal identifiers, such as your name, address and contact details) to improve our healthcare products and services, and our artificial intelligence system, so that we can deliver better healthcare to you and other Babylon users. This medical information (with your personal identifiers removed in the way described above) may include your medical record (both records received and created by us), transcripts and recordings of your consultations, and your interactions with our artificial intelligence services, such as our symptom checker. This does not involve making any decisions which would have a significant effect on you – it is only about improving our products, services and software so that we can deliver a better experience to you and other Babylon users, and help achieve our aim of making healthcare affordable and accessible to everyone. Strict confidentiality and data security provisions apply at all times. This consent relates to information that can identify you.

We may obtain and use data about your precise location where you give your consent (through providing us access to your location through your App or browser settings or your address), for example, to help direct you to the nearest pharmacy. We may also derive your approximate location from your IP address.

Keeping you up to date

We use your email address, phone number and/or details to contact you or present you with occasional updates and marketing messages where you have not opted out, based on our legitimate interest in marketing our services to you and subject to your right to opt out at any time.

As part of providing you with high quality preventative and occupational health care services, we may contact you by SMS, email and/or other means to offer you helpful information or invite you to make appointments, for example for free healthcare screening programmes (such as cervical cancer screening).

Other uses

Based on our legitimate interest in managing and planning our business, we may analyse data about your use of our products and services to troubleshoot bugs within the App or our website, forecast demand of service and to understand other trends in use, including which features users use the most and find most helpful, and what features users require from us. This does not involve making any decisions about you that would have a significant legal effect on you – it is only about improving our App so that we can deliver better services to you. Strict confidentiality and data security provisions will apply at all times.

Where necessary, we may need to share personal and financial details for the purposes of fraud prevention and detection.

We also store your medical information, such as notes from consultations, recordings of our consultations with you as well as your interactions with our digital services including interactions with our livechat services, chatbot (including symptom checker and ‘Ask a doctor’ and ‘Ask a nurse’, Healthcheck and Digital Twin services), health monitoring, women’s health and condition management services, for safety, regulatory, and compliance purposes. For example, we may need to review your information and, where necessary, make disclosures in compliance with reasonable requests by regulatory bodies including the General Medical Council, MHRA, and Care Quality Commission, or as otherwise required by law or regulation.

Where necessary for safety, regulatory and/or compliance purposes, we may audit consultations and your other interactions with our services. Strict confidentiality and data security provisions will apply at all times to any such audit and access.

4. Sharing your personal data with others



We may share your personal data with members of our corporate group and our partners (such as the Babylon GP at hand partnership, where you access our NHS service). This is to help us deliver our services to you.

We may share your personal data with companies we have hired to provide services on our behalf, including those who act as data processors on our behalf, acting strictly under contract in accordance with Article 28 GDPR. Those data processors are bound by strict confidentiality and data security provisions, and they can only use your data in the ways specified by us.

Where you access our services through your health insurance provider or any of our commercial partners (including your employer) we may share with such partner your name, date of birth, email address, policy number, location, and the fact you have registered/used the service (and any other similar information). We will not without your consent share any details relating to the content of your consultation with us or your health/medical records. With your consent, we may share the date of the appointment, details of your diagnosis, prescription, pharmacy location, whether or not you had a referral made and other similar information about your appointment with us.

Information sharing with other healthcare providers

We will, where necessary for your treatment or care, share your information with your other health and social care providers. For example, your NHS GP (if you use our private service) and other NHS bodies, specialist referral services, therapists, pharmacists, hospitals, accident and emergency services, pathology service providers, diagnosis centres chosen by you for the purpose of imaging requests, and other health and care bodies. This may include sharing information with such services for safeguarding purposes in accordance with our legal obligations.

Anonymised information

We may display on our website or share with our commercial partners aggregated and anonymised data that does not personally identify you, but which shows general trends, for example, the number of users of our service.

GP at hand service

If you use our GP at hand service, this may also include sharing personal data to support medicines management. This is because North West London Clinical Commissioning Groups (or other Clinical Commissioning Groups that oversee GP at hand services) use pharmacist and prescribing advice services to support local GP practices with prescribing queries, which may require identifiable information to be shared. These pharmacists work with GP at hand to provide advice on medicines and prescribing queries, and review prescribing of medicines to ensure that it is appropriate for your needs, safe and cost-effective. Where specialist prescribing support is required, the CCG medicines management team may provide support relating to obtaining medications on behalf of GP at hand to support your care.

If you use Babylon GP at hand, we will share your records with North West London Whole Systems Integrated Care (or other systems for other locations in which Babylon GP at hand will operate), which provides other members of the scheme (such as, amongst others, NHS Trusts and the ambulance services) with access to your data to promote integrated care for you, and for research and statistical purposes, based on medical purposes and public interest research. You may contact us at any time to opt out of this data sharing by completing and sending the form in the following link to us: https://www.healthiernorthwestlondon.nhs.uk/news-resources/information-sharing/sharing-clinical. More information about WSIC can be found here: https://www.healthiernorthwestlondon.nhs.uk/documents/wsic-dashboard/patients-communication-materials .

If you use Babylon GP at hand, we will share your records with Summary Care Records, which is an electronic record of important patient information, created from GP medical records based on medical purposes. Your data Summary Care Records can be accessed by authorised staff in other areas of the health and care system involved in your direct care. You can contact us at any time to opt out of this data sharing by completing and sending the form contained in the section ‘Security and the SCR’ in the following link: https://digital.nhs.uk/services/summary-care-records-scr (where more information about Summary Care Records can also be found).

We may preserve or disclose information about you to comply with a law, regulation, legal process, or governmental request; to assert legal rights or defend against legal claims; or to prevent, detect, or investigate illegal activity, fraud, abuse, violations of our terms, or threats to the security of our services or the physical safety of any person.

Except as described above, we will never share your personal information with any other party without your consent.





5. Retention periods

We retain your medical records in accordance with national best practice guidance – in particular, advice provided by the Department of Health (2006) Records management: NHS code of practice, and summary guidance issued by the British Medical Association. The below is a summary of our retention policy, but we may retain records that do not identify you for legitimate business purposes such as managing or planning our business, or records for other periods as required by law or regulation.

Type of record Retention period GP records GP Records retained for 10 years after death or after the patient has permanently left the country unless the patient remains in the European Union. In the case of a child, if the illness or death could have potential relevance to adult conditions or have genetic implications for the family of the deceased, the advice of clinicians should be sought as to whether to retain the records for a longer period. Electronic patient records (EPRs) must not be destroyed, or deleted, for the foreseeable future. GP records include medical records, consultations with GPs and chatbot interactions. Video consultations Retained as GP Records above. Available via App for a limited period (currently 14 days, subject to change) after consultation, after which available upon request. Voice (audio) consultations Retained as GP Records above. Chatbot (Including symptom checker, Ask a doctor and Ask a nurse) Retained as GP Records above. Available via App for a limited period (currently 6 months, subject to change), after which available upon request. Healthcheck and Digital Twin records Retained 2 years post account closure. Support telephone voice recordings Retained for 40 days post call. Live chat communications with support teams 1 year after exit from GP at hand service. Maternity records 25 years after the birth of the last child. Records relating to persons receiving treatment for a mental disorder within the meaning of mental health legislation 20 years after the date of the last contact; or 10 years after the patient's death if sooner.

6. Data storage, security and transfers

We do not store your personal health data on your mobile device. We store all your personal health data, including your primary care information, medication information and diagnostic information, on secure servers.

Where you have chosen a password that enables you to access certain parts of our App, you are responsible for keeping this password confidential. We ask you not to share the password with anyone.

We do not store any credit or debit card information. Payments are processed via a third-party payment provider that is fully compliant with Level 1 Payment Card Industry (PCI) data security standards. Any payment transactions are encrypted using SSL technology.

We encrypt data transmitted to and from the App. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this privacy policy.

Your data may be processed or stored via destinations outside of the UK and the European Economic Area (EEA), but always in accordance with data protection law, including mechanisms to lawfully transfer data across borders, and subject to strict safeguards. For example, we work with third parties who help deliver our services to you, whose servers may be located outside the UK or EEA. For further information on the safeguards we take if we transfer data outside of the EEA, contact DPO@babylonhealth.com.





7. Your rights

As indicated above, whenever we rely on your consent to process your personal data, you have the right to withdraw your consent at any time by accessing the privacy settings in the App.

You also have specific rights under the GDPR and DPA to:

wherever we process data based on your consent, withdraw that consent at any time. You can do this via the privacy section of our App;

understand and request a copy of information we hold about you. Subject to our retention periods, recordings of your appointments with us and other medical notes can be accessed via the App. For other information, you can make a request by email;

ask us to rectify or erase information we hold about you, subject to limitations relating to our obligation to store medical or health records for medical diagnoses and treatment for prescribed periods of time;

ask us to restrict our processing of your personal data or object to our processing; and

ask for your data to be provided on a portable basis.

You may also contact the Information Commissioners Office (the data protection regulator in the UK): Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, telephone: 0303 123 1113 (local rate).





Contact us

For any questions or concerns, you can contact us by sending an email to DPO@babylonhealth.com.