Omea Back

Privacy Policy

Last update: 20 August 2026

1. This Privacy Notice

1.1This Privacy Notice (this "Notice") sets out what personal information Omea Group Ltd collects, why we collect it, who we share it with, how long we keep it, and what rights you have. It applies to the Omea website at omea.io (our "Site") and the Omea app (our "App").

1.2It covers the personal information we collect from you, or obtain about you from someone else, in each of the following situations: when you use our Site or App; when you register an account with us; when you join our waitlist; when you take part in the Omea programme; when you give us feedback; and where you provide services to us as a supplier.

1.3Our Site, App and services are intended for adults aged 18 or over who live in the United Kingdom. They are not intended for children, and we do not knowingly collect information relating to anyone under 18. If you believe that a person under 18 has given us their details, please tell us and we will delete them.

1.4Omea is a preventive health and wellbeing service. We do not provide medical advice, diagnosis, treatment or prescriptions, and we do not hold a registration with the Care Quality Commission. This affects why we hold health information and what we do with it.

1.5If you do not agree with this Notice, please do not register an account, join our waitlist, or otherwise send us your information.

2. Who collects information about you

2.1Omea Group Ltd is responsible for the personal information it collects, stores, uses and shares. When we do so, we are acting as a controller of that information. Where this Notice refers to "Omea", "we", "us" or "our", it means Omea Group Ltd, a company registered in England and Wales under company number 17035493, whose registered office is at 46 New Cavendish Street, London, W1G 8TP.

2.2We are registered with the Information Commissioner’s Office under reference ZC113910. Andrea Holmboe, a director of Omea, is responsible for data protection. Details of how to reach us are in section 17.

3. Useful terms

3.1"Participants" means individuals taking part in the Omea programme.

3.2"Waitlist Subscribers" means individuals who have given us their email address through our Site to be told when Omea becomes available, and nothing more.

3.3"Suppliers" means external advisers, contractors and vendors who provide services to Omea.

3.4"Personal information" means any information about an individual from which that person can be identified, directly or indirectly. It does not include information from which identity has been removed.

4. What personal information we collect

4.1We collect, use, store and transfer different kinds of personal information about you, which we have grouped as follows.

4.2"Identity Data" such as your first name, last name, date of birth, sex at birth, and the password on your account, which is stored as a hash rather than as text.

4.3"Contact Data" such as your email address and your telephone number.

4.4"Health Data" means information about your health. This includes your blood panel and urine results, which we receive from our testing partner after you attend an appointment for sample collection and analysis; your physical measurements; and any medical history, symptoms or health concerns you choose to share with us through your account.

4.5"Assessment Data" means the answers you give in our intake questionnaire, including your health goals, lifestyle and habits. Assessment Data will usually include Health Data.

4.6"Wearable Data" means the measurements we read from Apple Health if you choose to connect it: your heart rate variability, resting heart rate and sleep stages, together with the name of the device or app that recorded each measurement. Wearable Data is Health Data.

4.7"Plan Data" means the items in your personalised plan, the record of our clinician’s review of it, your check-ins, and what you record as having completed.

4.8"Technical Data" such as your internet protocol (IP) address, device and operating system information, and records of the requests your device makes to our systems, which are kept in our server logs. Technical Data also includes the automatic reports our systems produce when something goes wrong in the App or on our servers, described in paragraph 10.7.

4.9"Feedback Data" means any feedback you give us about the programme. Depending on what you tell us, Feedback Data may include Health Data.

4.10"Marketing and Communications Data" means your preferences about hearing from us, including whether you have joined our waitlist.

4.11You do not have to give us any of this information, and you do not have to consent to our use of your health information. But if you do not, we will not be able to provide the programme to you.

5. How we use your personal information

Participants

5.1When you register an account with Omea we collect your Identity Data and Contact Data. To run and administer your account, and to deliver the programme to you, we process your Identity Data, Contact Data, Assessment Data, Health Data, Wearable Data, Plan Data and Technical Data.

5.2We use your Health Data, Assessment Data and Wearable Data to produce your personalised plan and to compare your first set of results against your later ones. Section 9 explains how your plan is produced and reviewed. The record of that review is part of your Plan Data.

5.3We also use:

5.4Where you separately agree to it, we may use your Health Data, Assessment Data, Wearable Data and Plan Data in aggregated and pseudonymised form to understand whether Omea works, to improve it, and to share what we learn. We will not share information that identifies you personally unless you have given explicit, informed consent to that, or there is a legal reason requiring it.

5.5If we invite you to take part in an optional activity such as a survey, an interview or a feedback session, taking part is voluntary and separate from the programme. Declining or withdrawing will not affect your participation or anything else we do for you. We will ask for your consent at the time.

Waitlist Subscribers

5.6If you have given us your email address through our Site and done nothing further, we hold your Contact Data and Marketing and Communications Data, and the standard server records our website host keeps when any device connects to it. We use your email address to tell you when Omea becomes available, and for nothing else.

5.7Joining the waitlist does not enrol you in the Omea programme and creates no obligation on either side. You can ask us to stop at any time, using the unsubscribe link in any message we send or by writing to us.

Suppliers

5.8If you are a Supplier, we collect Identity Data and Contact Data about you, or about individuals at your organisation, in the course of agreeing and managing our arrangements with you. We use it to keep your details current, to manage our relationship and receive services from you, to meet our legal and accounting obligations, and to establish, exercise or defend legal claims.

6. Our legal basis for processing your personal information

If you are a Participant

6.1Where we process your personal information to create and administer your account and to deliver the programme to you, that processing is necessary to perform the contract we have entered into with you.

6.2Where that processing involves your Health Data, Assessment Data or Wearable Data, we rely on two things together: your explicit consent, which we ask for separately before you join; and the provision of preventive health care within the meaning of Article 9(2)(h) of the UK GDPR, which is available to us because a doctor bound by professional confidentiality reviews your results and your plan.

6.3Where we process your personal information to send service messages, to provide support, to keep the service secure and working, to improve the programme, for the day-to-day running of our business, or to establish, exercise or defend legal claims, we consider this necessary for our legitimate interests, and we have weighed those interests against your rights and freedoms.

6.4Where we use your information in aggregated and pseudonymised form to improve the service or to share findings, we rely on your separate explicit consent for any element involving Health Data, and on our legitimate interests otherwise.

6.5Where we are legally required to process your information, for example to disclose it to a regulator, we rely on compliance with a legal obligation.

6.6You may withdraw any consent you have given at any time, by writing to us. If you withdraw consent to our processing of your Health Data we will not be able to continue providing the programme to you, and we will delete your information except where we are required to keep some of it. Withdrawing consent does not affect anything we did lawfully before you withdrew.

If you are a Waitlist Subscriber

6.7We rely on your consent. You can withdraw it at any time and we will remove your details.

If you are a Supplier

6.8Where we process your information in the course of agreeing and managing our arrangements with you, that processing is necessary to perform our contract with you. We rely on compliance with a legal obligation where we are required to hold or disclose information, and on our legitimate interests in managing our business for the remaining purposes described above.

7. How we collect personal information about you

7.1Directly from you. This is the information you give us when you register an account, join our waitlist, complete our intake questionnaire, use our App, or contact us by email or through the App.

7.2From our testing partner. We receive your blood and urine results from Randox, where you have attended an appointment for sample collection and analysis. Randox is a separate controller of the information it holds about you, rather than a processor acting on our instructions, and it handles that information under its own privacy notice as well as under our written agreement with it. Section 10 sets out what we send to Randox and why.

7.3From your device. If you choose to connect Apple Health, we read Wearable Data from your device, as described in section 8.

7.4Automatically. When you use our Site or our App, certain Technical Data is collected automatically by our systems and by our website host.

8. Apple Health

8.1Connecting Apple Health is optional. The programme works without it, and you can turn it off at any time in the iOS Settings app under Privacy & Security, then Health.

8.2If you connect it, we read three measurements and nothing else: your heart rate variability, your resting heart rate, and your sleep stages. Anything that is not one of those three, in the expected unit, is discarded on your device and is never sent to us. This is a property of how our App is built: it is incapable of sending anything else without a new version being released.

8.3We never write anything into Apple Health, and we never read any clinical records held there. Our App has no ability to do either. When you open the App it reads a rolling seven-day window; we do not read data in the background, and we do not import your history.

8.4Every measurement stored in Apple Health carries a record of which device or app wrote it. This means that when we read your sleep or heart data, we also receive the name of the device or app it came from, which can indicate which health apps you use.

9. How your plan is produced

9.1Your plan is produced in two steps. A protocol engine applies fixed rules to your results and your questionnaire answers. A doctor registered with the General Medical Council then reviews the output before it reaches you, and can change or reject any part of it.

9.2This means you are not subject to a decision based solely on automated processing. Nothing is generated and delivered to you by software alone. You can ask us how a recommendation was reached, ask for it to be reviewed again by a person, and tell us if you disagree with it.

9.3Omea is not a screening service and is not designed to detect disease. If a result suggests that you should speak to a doctor, we will tell you and recommend that you contact your GP. We will not diagnose the finding or advise you on treatment.

10. Who we share your personal information with

10.1We do not sell your personal information, and we do not share it for advertising.

10.2Our testing partner. Your blood sample is collected and analysed by Randox Health London Ltd and its partner laboratory, Randox Clinical Laboratory Services. To book your appointment and have your sample tested, we send Randox your name, date of birth, sex at birth and email address, together with the details of the sample itself. We do this because it is necessary to deliver the programme you have signed up for.

10.2.1Randox is a separate controller of that information. It handles it under its own privacy notice rather than on our instructions, and our agreement with it requires it to comply with data protection law. Randox does not use your information to market to you.

10.2.2If one of your results is significantly outside the expected range and needs prompt attention, a member of the Randox clinical team may contact you directly, usually by telephone. Randox is also required by law to report certain results to UK public health bodies.

10.2.3Your results are issued by Randox and we present them to you exactly as issued. We do not alter or reinterpret them. Testing is carried out at UKAS Accredited Testing Laboratory No. 9329.

10.3Service providers. We use providers who perform functions on our behalf, including cloud hosting and storage, and email and message delivery. They are required to keep your information confidential and may not use it for any purpose other than performing the service they provide to us. We enter into data processing agreements with all of them.

10.4Professional advisers. We may disclose personal information to our lawyers, accountants and insurers where necessary as part of the professional services they provide to us.

10.5Business transfers. If we sell, transfer or merge part of our business or our assets, personal information may be shared with the parties involved. If that happens, the new owners may use your information in the ways set out in this Notice.

10.6Compliance with law. We may occasionally be required to disclose personal information in order to comply with the law, or to establish, exercise or defend a legal claim.

10.7Error and crash reporting. When something goes wrong in the App or on our servers, our systems send an automatic technical report so that we find out about the fault and can fix it, rather than waiting for someone to tell us. The report records the type of error and the point in our own code where it happened. It does not carry your name, your contact details, your results or any other health information, and we strip out the text of the error message itself so that nothing personal can be carried through inside it. These reports are handled for us by Sentry, which acts as our processor under a written agreement, and are stored on servers in the European Union. We rely on our legitimate interest in keeping Omea secure and working correctly.

10.8Product analytics. To understand how the App is used and where people get stuck, we record a small set of events describing your progress through the programme — for example that a check-in was submitted on a given day, or that a day of the plan was opened. These records are linked to a random identifier that we generate for this purpose alone; they do not carry your name, your contact details, your results, your answers, your notes, or any other health information. They are handled for us by PostHog, which acts as our processor under a written agreement, and are stored on servers in the European Union. We rely on our legitimate interest in understanding and improving the programme. If you ask us to delete your information, these records are deleted too.

11. Security and international data transfers

Security

11.1Your information is encrypted at rest, using encryption keys we control, with separate keys for different classes of data. It is encrypted in transit using TLS 1.2 or above, and requests that are not encrypted are refused. Our database sits in a private network with no public access.

11.2We limit access to your personal information to those who have a genuine need for it. Access is enforced by role: your results, biomarkers, medical history, conditions and medication can be read only under our Chief Medical Officer role. Every time someone reads a Participant’s clinical record it is logged, and that log cannot be edited or deleted, including by the person who made the entry. Participants can only ever see their own record.

11.3No method of electronic storage or transmission is entirely secure. We have put appropriate technical and organisational measures in place, but we cannot guarantee absolute security. We have procedures for handling any suspected breach, and we will tell you promptly if a breach is likely to put you at serious risk.

International data transfers

11.4Your Health Data, Assessment Data, Wearable Data and Plan Data — everything connected with the programme itself — is stored in the United Kingdom, on Amazon Web Services in the London region.

11.5Some members of our own team are based in the European Economic Area and may access your information from there in the course of their work for us. The United Kingdom recognises the European Economic Area as providing an adequate level of protection for personal information.

11.6Some of the providers we use to run our Site and to send messages may process limited personal information, such as your email address or telephone number, outside the United Kingdom. Where that happens, we make sure a similar degree of protection travels with your information, by relying on an adequacy decision for the destination country or by putting an International Data Transfer Agreement in place.

11.7The error and crash reports described in paragraph 10.7 are stored in the European Union, which the United Kingdom recognises as providing an adequate level of protection.

11.8The product-analytics records described in paragraph 10.8 are stored in the European Union, which the United Kingdom recognises as providing an adequate level of protection.

12. Our use of cookies and similar technologies

12.1We use only those cookies that are strictly necessary for our Site to function, and only equivalent storage in our App where it is needed to keep you signed in and to run the App. We do not use advertising cookies, and we do not track you across other websites. We use one third-party analytics provider to understand how the App is used, described in paragraph 10.8.

12.2You can set your browser to refuse some or all cookies, or to alert you when a site sets one. If you do, parts of our Site may not work properly.

13. Other websites

13.1Our Site and our App may contain links to other websites and services that we do not control. We are not responsible for their content or for how they handle your information. When you leave our Site or App, we encourage you to read the privacy notice of any site you visit.

14. How long we keep your personal information

14.1We keep your personal information only for as long as we need it for the purposes we collected it for, including to meet any legal, professional or accounting requirements.

14.2In deciding how long to keep information we consider its nature and sensitivity, the potential harm that unauthorised use or disclosure could cause, the purposes we are using it for, whether we can achieve those purposes another way, and what the law requires.

14.3In practice this means we keep your Health Data, Assessment Data, Wearable Data and Plan Data, including the record of clinical review, for 8 years from your last contact with us, following recognised standards for the retention of private health records in the United Kingdom. Identity Data and Contact Data are kept while your account is open and are then deleted along with the rest of your record. Correspondence is kept for up to two years after your participation ends. Waitlist details are kept until you unsubscribe, or for 24 months from sign-up if we have not launched by then.

14.4The error and crash reports described in paragraph 10.7 are deleted after 30 days.

14.5Aggregated and pseudonymised information has no fixed retention period, because it can no longer be linked to you. When information is deleted it is removed from our live systems immediately; copies may remain in our encrypted backups, put beyond use, and expire within 30 days.

15. Marketing

15.1If you receive marketing messages from us, you can ask us to stop at any time by using the unsubscribe link in any message, or by writing to us at the address in section 17.

15.2Opting out of marketing does not opt you out of service messages that are necessary to run your account, such as password resets or information about your appointment.

16. Your rights

16.1Subject to any exemptions provided by law, you may have the right to:

16.2If you would like to exercise any of these rights, please contact us using the details in section 17 and give us enough information to identify you. We may need to ask for specific information to confirm your identity. This is a security measure, to make sure that personal information is not disclosed to anyone who has no right to receive it.

16.3There is currently no button in our App to delete your account or to download your information. Both are done by us on request, by email.

16.4You will not have to pay a fee to exercise any of these rights. We may charge a reasonable fee, or decline to act, if a request is clearly unfounded, repetitive or excessive.

16.5We will respond to your request within one month. If a request is particularly complex, or you have made several, we may need up to a further two months. If so, we will tell you within the first month and explain why. If we cannot meet a request, we will explain why.

17. How to contact us

17.1Please address any request or question about this Notice to connect@omea.io, or by post to Omea Group Ltd, 46 New Cavendish Street, London, W1G 8TP.

18. How to complain

18.1If you are unhappy with how we have handled your personal information, please tell us first. We will acknowledge your complaint within three working days and respond fully within twenty.

18.2You also have the right to complain to your supervisory authority. In the United Kingdom this is the Information Commissioner’s Office, at ico.org.uk or on 0303 123 1113. You may approach them at any point and do not have to come to us first.

19. Changes to this Notice

19.1This version was last updated on 20 August 2026. We will update this Notice from time to time to reflect changes in how we use your personal information and to comply with changes in the law. If a change is significant we will tell you by email rather than rely on you noticing, and we encourage you to review this Notice from time to time.

19.2It is important that the information we hold about you is accurate and current. Please tell us if your details change.

Omea Group Ltd  ·  Company number 17035493, England and Wales
46 New Cavendish Street, London, W1G 8TP
connect@omea.io
Terms of Service  ·  Privacy Policy