GlucoRx Voyager – Privacy Policy
Last updated 1 August 2025
Revision 1.1
- Who we are
GlucoRx Limited (“GlucoRx”, “we”, “us”, “our”)
Registered office: Unit 1C, Henley Business Park, 1C Pirbright Road, Normandy, Guildford GU3 2DX, United Kingdom
Data-protection contact: info@glucorx.co.uk | +44 (0)1483 755 133
We are the data controller for personal data processed in the GlucoRx Voyager mobile application and we decide how your personal data is processed when using our application.
If you have any questions about this privacy policy or would like to make a request to exercise your legal rights, please contact us using the contact details set out above.
It is important that you read this privacy notice together with any other privacy notice or fair processing notice we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data. This privacy notice supplements other notices and privacy policies and is not intended to override them unless this is clear from the context.
- What data we collect
|
Category |
Examples |
Source |
|
Account data |
Email address (required to register) |
You |
|
Device readings (special-category health data) |
Blood-glucose, Ketones, Uric Acid, Cholesterol, Lactate, Blood-Pressure, Pulse Oximetry, Temperature, Weight, Steps |
Your paired GlucoRx Bluetooth devices |
|
App usage & diagnostics |
Crash reports, anonymised event logs |
Firebase Crashlytics & Firebase Analytics |
|
Marketing preferences |
Opt-in flag |
You |
We do not process your name, address, date of birth, location, or any payment details.
- How & why we use your data
We use your data for the following:
|
Purpose |
Lawful basis (UK GDPR) |
Article 9 condition (health data) |
|
To provide the app, to sync readings, to display charts, and to export to Apple Health or Google Fit |
Contract – Art 6 (1)(b) |
Explicit consent – Art 9 (2)(a) |
|
To maintain and secure our services, fix bugs, measure performance, and to ensure the app is working as intended |
Legitimate interests – Art 6 (1)(f) (you can object) |
n/a – only aggregated, non-identifiable diagnostics |
|
To make improvements to our services and products, to help us to develop new products |
Legitimate interests – Art 6 (1)(f) (you can object) |
n/a – only aggregated, non-identifiable diagnostics |
|
To understand how our app and our services are used and can be optimised |
Legitimate interests – Art 6 (1)(f) (you can object) |
n/a – only aggregated, non-identifiable diagnostics |
|
To communicate with you, such as to notify you of upcoming changes or improvements to our services |
Consent – Art 6 (1)(a) |
n/a (no health content) |
|
If you contact us, to help resolve any issues you raise |
Consent – Art 6 (1)(a) |
n/a (no health content) |
|
To help improve the safety and reliability of the app, including preventing and responding to fraud, abuse, security risks, loss prevention and technical issues that could harm us, our uses or the public |
Legitimate interests – Art 6 (1)(f) (you can object) |
n/a – only aggregated, non-identifiable diagnostics |
|
To send optional tips, product news, and app updates |
Consent – Art 6 (1)(a) |
n/a (no health content) |
Principally, you provide your personal data to us when you pair your GlucoRx Bluetooth device to your account(s), when you register with our software applications or when you buy our products.
You are not required to provide personal data that we request, but, if you choose not to, in many cases we will not be able to provide you with our products or services or respond to any queries you may have.
We will only use your data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is lawful and compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us.
If we intend to use your personal data for an unrelated purpose, we will notify you and explain the legal basis which allows us to do so, unless we are prevented from informing you by law.
Please note that, in limited circumstances (e.g. to comply with a binding Court order), we may process your personal data without your knowledge or consent where this is required or permitted by law.
- Special category personal data
Special category personal data (including health data and biometric data) attracts a higher level of protection. Data protection law requires us to have an additional condition where we are collecting, storing and using special category personal data.
The conditions that we most commonly rely on to collect, use or share your special category personal data include:
- In limited circumstances, your explicit consent;
- Where we need to carry out our legal obligations or exercise rights in the field of employment; or
- Where it is needed in the public interest, such as for equal opportunities monitoring.
Less commonly, we may process this type of information where it is needed in relation to legal claims or where it is needed to protect your vital interests (or someone else’s vital interests) and you are not capable of giving your consent, or where you have already made the information public.
- Automated decision making
Automated decision-making takes place when an electronic system uses personal information to make a decision without human intervention. At present we do not carry out automated decision making or profiling that produces legal or similarly significant effects on you.
If we were to carry out any such processing, in future, we would only use automated decision-making in the following circumstances:
- where we have notified you of the decision and given you the opportunity to request a reconsideration of that decision;
- where it is necessary to perform the contract with you and appropriate measures are in place to safeguard your rights; or
- in limited circumstances, with your explicit written consent and where appropriate measures are in place to safeguard your rights.
If the automated decision-making is based on special category personal data (see above), we will only proceed if:
- we have your explicit written consent; or
- there are substantial public interest grounds to justify the decision and we have put in place appropriate measures to safeguard your rights.
- 6. Sharing your data
|
Recipient / role |
What & why |
Lawful Basis for processing |
Safeguards |
|
Google (Firebase Crashlytics & Analytics) |
Pseudonymised app-usage and crash data |
Legitimate interests (to improve the quality of the service delivered) |
Data is pseudonymised (i.e. we use a code to hide the identity of individuals).
The UK Addendum to EU Standard Contractual Clauses (SCCs) are used for international transfers. |
|
Apple Inc. (Apple Health) |
Health readings you choose to export |
Consent |
Actioned only on your explicit in-app request |
|
Google (Google Fit) |
Health readings you choose to export |
Consent |
Actioned only on your explicit in-app request |
|
Cloudflare, Inc. |
Transit-only content delivery & firewall |
Legitimate interests (to protect the security of the data) |
SCCs are used for international transfers + we apply encryption in transit |
We never sell your data, and we will share it with the NHS or carers only if you choose to export or if we are legally required to do so.
Your health and wellness data will be shared with third-party partners in health, technology and life-science sectors to enhance user experience and services in future, and you are required to provide this information on registration with the application. This exchange is made via our application programming interface which connects to our healthcare professionals’ back end systems.
We never share your data with advertising platforms, data brokers or information resellers.
If you choose to share your data with a third-party service, the information you provide to the third-party services is governed by the third-party’s Terms and Conditions and Privacy Policy over which we have no control.
If we engage in a merger, acquisition, bankruptcy, dissolution, reorganization, sale of some or all of our assets or stock, financing, public offering of securities, acquisition of all or a portion of our business, a similar transaction or proceeding, or steps in contemplation of such activities (e.g. due diligence), some or all other information may be shared or transferred, subject to standard confidentiality arrangements.
- 7. International transfers
Primary storage is in an ISO 27001-certified UK cloud region (London).
Whenever we transfer your personal data outside of the UK, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
- transferring your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the UK;
- using approved standard contractual clauses which give personal data the same protection it has in the UK; or
- transferring when one or more of the conditions set out in Article 49 GDPR are met.
- 8. Data retention
We will only retain your personal data for as long as reasonably necessary to fulfil the purposes for which we collected the data.
- Readings are stored until you delete them in the app or delete your account.
- Diagnostic logs are kept for 12 months then aggregated or erased.
- Marketing-consent records are kept for the life of your account.
If you want to know more about how long we keep your data please contact us using the contact details below. In some circumstances you can ask us to delete your data: see “Your Rights” section below for more details.
- 9. Security
We have put in place appropriate security measures to prevent your personal information from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. We apply industry-standard technical and organisational measures, including:
- TLS 1.3 encryption in transit via Cloudflare with SSL certificates
- AES-256 encryption at rest in our UK cloud database
- Role-based staff access, MFA, annual penetration testing.
We have also put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
- 10. Your rights
Under the UK GDPR, Data Protection Act 2018 and the Data (Use and Access) Act 2025, you can:
- Access a copy of your data
- Correct inaccurate data
- Delete data or your entire account (“right to erasure”) where there is no good reason for us to process it
- Restrict or object to certain processing
- Export your readings (data portability)
- Withdraw consent at any time (marketing or Apple Health / Google Fit exports)
To exercise any right, email info@glucorx.co.uk or use the in-app controls. We will respond within one month.
If you believe we have not handled your request properly, you may complain to the Information Commissioner’s Office (ICO) at ico.org.uk or +44 303 123 1113. You may also contact the ICO to make a complaint by accessing their website: https://ico.org.uk/make-a-complaint.
- 11. Marketing
We send emails or push notifications only if you have opted in. You can opt out at any time via the app settings or the unsubscribe link in any email.
If you opt out of receiving marketing communications while your account remains active, you may still receive non-marketing service-related communications that are essential for administrative or customer service purposes.
- 12. Changes to this policy
We reserve the right to revise, alter and reissue this Privacy Notice at any time. If we make changes to our Privacy Notice we will update this page and would therefore ask that you check it from time to time and contact us if you have any queries, please contact the Data Protection Officer whose details are below. If we make material changes to our Privacy Notice, we may also provide you with additional notification of those changes via email therefore we would also ask that you notify us if your contact details change. This version of the Privacy Notice was last updated on [3 July 2025]
Account Deletion & Right to Erasure
You have the right to request deletion of your account and associated personal data (“right to erasure”) under the UK GDPR and the Data Protection Act 2018.
How to request deletion
Choose any of the following:
-
Online form: Submit a request via our Data
-
Email: Write to info@glucorx.co.uk with the subject line “Data Deletion Request”.
-
Phone: Call our Customer Care team (insert phone number).
Please include your full name, the email or phone number linked to your account, and any relevant app or device identifiers so we can locate your records.
Identity verification
To protect your data, we may ask for reasonable information to verify your identity before actioning the request. If you are acting on behalf of someone else, we may require proof of authority.
What we delete (and when)
Once verified, we will delete or irreversibly anonymise:
-
Your account profile and app data stored by us (e.g., logs, preferences, uploaded content).
-
Support tickets and communications, unless we must retain them for compliance.
-
Data held by our processors (we will instruct them to delete it where appropriate).
Backups are not actively edited, but data scheduled for deletion will be purged on the next routine backup rotation.
Lawful retention and limitations
We may retain limited information where required or permitted by law, for example:
-
Product safety, vigilance, and incident reporting (e.g., medical device safety obligations).
-
Audit, tax, and accounting records.
-
Fraud prevention, security, or dispute resolution.
Where we cannot delete specific records, we will restrict processing to the permitted purpose only.
Timeline and confirmation
We aim to respond within one month of receiving your verified request. We may extend by up to two further months for complex or numerous requests (we will tell you if we need more time). We will confirm once deletion is completed or explain any lawful retention we must apply.
- 13. Contact us
For any questions about this policy or your data, please contact:
Data Protection Officer
GlucoRx Limited
Unit 1C, Henley Business Park, 1C Pirbright Road, Normandy, Guildford GU3 2DX
Email: info@glucorx.co.uk | Tel: 0800 007 5892 | +44 (0)1483 755 133
Thank you for trusting GlucoRx Voyager to help you manage your health securely and privately.