Privacy Notice (UK)

This privacy statement was last updated on May 4, 2025 and applies to citizens and legal permanent residents of the United Kingdom.

In this privacy statement, we explain what we do with the data we obtain about you via https://health.coleebri.com/en. We recommend you carefully read this statement. In our processing we comply with the requirements of privacy legislation. That means, among other things, that:

  • we clearly state the purposes for which we process personal data. We do this by means of this privacy statement;
  • we aim to limit our collection of personal data to only the personal data required for legitimate purposes;
  • we first request your explicit consent to process your personal data in cases requiring your consent;
  • we take appropriate security measures to protect your personal data and also require this from parties that process personal data on our behalf;
  • we respect your right to access your personal data or have it corrected or deleted, at your request.

If you have any questions, or want to know exactly what data we keep of you, please contact us.

1. Purpose, data and retention period

We may collect or receive personal information for a number of purposes connected with our business operations which may include the following: (click to expand)

2. Sharing with other parties

We only share or disclose this data to processors for the following purposes:

Processors

Name: COLEEBRI sub-brands
Country: France & United Kingdom
Purpose: In order to process orders and deliver services ordered.
Name: Suppliers
Country: France & United Kingdom
Purpose: In order to process orders and deliver services ordered.

3. Cookies

Our website uses cookies. For more information about cookies, please refer to our Cookie Policy

4. Disclosure practices

We disclose personal information if we are required by law or by a court order, in response to a law enforcement agency, to the extent permitted under other provisions of law, to provide information, or for an investigation on a matter related to public safety.

If our website or organisation is taken over, sold, or involved in a merger or acquisition, your details may be disclosed to our advisers and any prospective purchasers and will be passed on to the new owners.

5. Security

We are committed to the security of personal data. We take appropriate security measures to limit abuse of and unauthorised access to personal data. This ensures that only the necessary persons have access to your data, that access to the data is protected, and that our security measures are regularly reviewed.

The security measures we use consist of:

  • Vulnerability Detection
  • Website Hardening/Security Features
  • (START)TLS / SSL / DANE Encryption

6. Third-party websites

This privacy statement does not apply to third-party websites connected by links on our website. We cannot guarantee that these third parties handle your personal data in a reliable or secure manner. We recommend you read the privacy statements of these websites prior to making use of these websites.

7. Amendments to this privacy statement

We reserve the right to make amendments to this privacy statement. It is recommended that you consult this privacy statement regularly in order to be aware of any changes. In addition, we will actively inform you wherever possible.

8. Accessing and modifying your data

If you have any questions or want to know which personal data we have about you, please contact us. You can contact us by using the information below. You have the following rights:

  • You have the right to know why your personal data is needed, what will happen to it, and how long it will be retained for.
  • Right of access: You have the right to access your personal data that is known to us.
  • Right to rectification: you have the right to supplement, correct, have deleted or blocked your personal data whenever you wish.
  • If you give us your consent to process your data, you have the right to revoke that consent and to have your personal data deleted.
  • Right to transfer your data: you have the right to request all your personal data from the controller and transfer it in its entirety to another controller.
  • Right to object: you may object to the processing of your data. We comply with this, unless there are justified grounds for processing.

Please make sure to always clearly state who you are, so that we can be certain that we do not modify or delete any data of the wrong person.

9. Submitting a complaint

If you are not satisfied with the way in which we handle (a complaint about) the processing of your personal data, you have the right to submit a complaint to the Information Commissioner’s Office:


Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

10. Children

Our website is not designed to attract children and it is not our intent to collect personal data from children under the age of consent in their country of residence. We therefore request that children under the age of consent do not submit any personal data to us.

11. Contact details

COLEEBRI LIMITED
7 Bell Yard
London
Greater London
WC2A 2JR
England
United Kingdom
Website: https://health.coleebri.com/en
Email: dpo@health.coleebri.com
Phone number: 0033972399855

12. Data Requests

For the most frequently submitted requests, we also offer you the possibility to use our data request form

×

13. Healthcare Services: Additional Information

Coleebri Health provides healthcare services (mobile phlebotomy). This section provides additional information about how we process your personal data when you use our clinical services, beyond the general website data processing described above.

Regulatory status:

Care Quality Commission (CQC): Registration in progress
ICO Registration: ZB943661
Clinical Governance: Guillaume Gual, Registered Manager

 

14. What Healthcare Data We Collect

14.1 Before Your Appointment

When you book a phlebotomy appointment through our website or contact forms, we collect:

Full name, date of birth, address
Email address and phone number
Information about the blood test you need
Which laboratory or service has ordered your test
Whether you take blood-thinning medications
Any previous problems with blood collection
Whether you are under 16 years old (for safeguarding)
Any allergies to plasters, latex, or antiseptics
– Whether you require DNA testing (paternity, ancestry, relationship, or health DNA)
-If under 16: parent/legal guardian name, contact details, and relationship to patient

 

Why we collect this:

To deliver safe phlebotomy services tailored to your needs, prepare appropriately for your appointment, identify any risks or special requirements, and obtain informed consent.

Legal basis:

Article 6(1)(b) UK GDPR: Contract – necessary to provide the service you’ve requested
Article 9(2)(h) UK GDPR: Health care – necessary for medical diagnosis and healthcare provision

Additional legal basis for DNA testing:

-Article 6(1)(a) UK GDPR: Explicit consent (required for genetic data processing); Article 9(2)(a) UK GDPR: Explicit consent for processing genetic data. DNA testing involves processing genetic data, which is a distinct special category under UK GDPR. We will always obtain your explicit, specific consent before collecting or processing any DNA samples.

Additional processing for patients aged 13-16:

When a patient is aged 13-16, we collect additional information from their parent or legal guardian, including their name, contact details, and relationship to the young person. Results are communicated to the parent/guardian rather than directly to the young person. Parental/guardian consent is mandatory for all patients in this age group. A Gillick competence assessment is conducted to determine the young person’s level of involvement in the consent process
 

15. How We Store Your Healthcare Data Securely

15.1 Our Technology Partners

 

Halaxy (Clinical Patient Management System):

What we store: Patient clinical records, medical history, procedure notes, consent forms

Location: European Union data centers (eu.halaxy) – Germany, Netherlands, Ireland
 
Security: 256-bit bank-grade encryption at rest and in transit, TLS/SSL, daily backups
 
Data residency: All patient data stored and processed within EU; no transfers outside EU
 
GDPR compliance: Full GDPR compliance for EU users
 
Data Processing Agreement: Signed 09 February 2026
 
Access: Restricted to authorised clinical staff only, secure login
 

Connecteam (Workforce and Appointment Management):

What we store: Staff records, appointment scheduling, GPS tracking, training documentation, non-clinical operational data
 
Location: Primary servers in Germany (AWS Frankfurt), additional infrastructure in Netherlands (Azure) and Ireland (backup)
 
Data residency: All core data processing in EU; any US sub-processors use Standard Contractual Clauses
 
Security: ISO 27001 certified, SOC 2 Type II compliant, encrypted
 
Data Processing Agreement: Signed 09 February 2026
 
Access: Restricted to authorised staff only, protected by two-factor authentication
 

Infomaniak (Document Storage, Email, and Website Hosting):

What we store: Archived records, policies, email communications, website hosting
 
Location: Switzerland (GDPR adequate country)
 
Security: ISO 27001 certified, encrypted data centers, TLS/SSL
 
Data Processing Agreement: Signed 07 February 2026
 
Email: Our business emails are also hosted by Infomaniak
 
Website: Forms hosted securely with SSL/TLS encryption
 

Egress (UK) – Secure Email Platform for Results Delivery:

What we use it for: Sending your blood test results and DNA test results securely as password-protected PDF documents

How it works: You receive two separate emails – one containing your results as a password-protected PDF, and a second email containing the password to open it

Location: UK data centres

Security: End-to-end encryption, password protection, delivery confirmation tracking

Data Processing Agreement: Signed 07 February 2026.

Access: Only the Registered Manager sends results via Egress

For patients aged 13-16: Results are sent to the parent/legal guardian’s email address, not the young person’s

 

16. Who We Share Your Healthcare Data With

We only share your information when necessary and lawful:

16.1 The Laboratory Processing Your Samples

We send your blood samples with: name, date of birth, test requested, and any clinically relevant information
Purpose: So the laboratory can process your samples and return results
Examples: NHS hospitals, private testing companies (Blue Horizon, Medichecks, Thriva, etc), GP-ordered tests
Legal basis: Contract (part of service you requested) + Healthcare provision

 

16.2 Your GP or Referring Clinician

We may share: confirmation that sample was collected, any procedural complications, test results (when received and authorized)
Results sharing: Test results may be securely transmitted to your referring clinician via encrypted email or secure clinical systems (with your authorization)
Purpose: Continuity of care, clinical responsibility, ensuring results reach appropriate healthcare provider
Security: All results transmitted via secure, encrypted means only (never plain email)
Legal basis: Healthcare provision, Contract (as part of service arrangement)

 

16.3 DNA Testing Laboratories

  • We send your DNA samples with: name, date of birth, sample identification, and test requested
  • Purpose: So the laboratory can process your DNA test and return results
  • Examples: EasyDNA, DDC (DNA Diagnostics Center), and other accredited partner laboratories
  • Legal basis: Explicit consent (mandatory for genetic data) + Contract
  • Results: Returned to Coleebri Health and forwarded to you securely via Egress
  • Important: Your DNA data is classified as ‘genetic data’ under UK GDPR and receives additional protection. We will always obtain your explicit consent before any DNA sample is collected or processed.

 

16.4 We NEVER Share Your Data With

Marketing companies
Social media platforms
Data brokers or list sellers
Third parties for their own purposes
Anyone outside UK/EEA without appropriate safeguards

 

17. How Long We Keep Your Healthcare Data

Section 17: How Long We Keep Your Data

Data Type

Retention Period

Reason

Clinical records (blood tests)

8 years after last treatment

NHS guidance, clinical claims

Photos (bedside ID verification)

30 days (automated deletion)

Appointment verification only

Staff records

6 years after leaving service

Employment law, CQC compliance

DNA test results

8 years after test

Clinical records retention, legal claims

DNA samples (at laboratory)

Destroyed after testing

Laboratory policy, data minimisation

Egress email delivery confirmations

8 years

Clinical records audit trail

 

18. Your Rights Regarding Healthcare Data

You have the same rights over your healthcare data as described in the main privacy policy, plus healthcare-specific considerations:

 

18.1 Right of Access (Subject Access Request)

You can request a copy of your complete clinical record
All photos taken during your appointment
Audit logs showing who accessed your records and when
We will respond within 1 month 
Contact: health@coleebri.com 

 

18.2 Right to Erasure

We CANNOT delete:

Clinical records within the 8-year legal retention period
Records needed for legal claims or regulatory investigation
Records required by professional standards

 

19. Changes to This Privacy Policy

We review this privacy policy:

Annually (minimum)
Following any data breach or security incident
When data processing activities change significantly
When laws or regulations change
After CQC inspections or ICO guidance updates