Privacy

How we handle your personal and health data.

Draft — pending legal review

This document describes how the platform is built and intended to operate, but it has not yet been reviewed by a qualified solicitor and is not a binding agreement. It must not be relied on until that review is complete.

Who we are

Nesema is the data controller for the account and health data you provide through this platform. Practitioners you work with are independent and act as controllers for the clinical records they create about you.

What we collect

  • Account data — your name, email address and role.
  • Health data — health background and goals from onboarding, daily check-ins (mood, energy, sleep, digestion, symptoms, supplements, notes), care plans, clinical notes written by your practitioner, meal plans, and lab results or documents uploaded by you or your practitioner.
  • Appointments and messages — bookings, session notes, and messages exchanged with your practitioner.
  • Payment data — handled by Stripe. We do not store your card details.

Health data is special category data under UK GDPR. We process it on the basis of your explicit consent, and for the provision of health care under Article 9(2)(h).

Who can see your data

Your records are visible to you and to the practitioner responsible for your care. They are not visible to other patients, and not to other practitioners unless you consent.

If you see more than one practitioner, sharing anything between them — including lab results — requires your explicit, recorded consent each time. Our staff can access records only where necessary to operate the platform or to respond to a support request, and such access is logged.

Processors we use

  • Supabase — database, authentication and file storage
  • Vercel — application hosting
  • Stripe — payment processing
  • Daily.co — video consultations
  • Resend — transactional email

Each is bound by a data processing agreement and processes data only on our instructions.

How long we keep it

Clinical records are retained in line with UK professional guidance on health record retention, which is generally longer than the life of your account. Account data is deleted when you close your account, subject to those retention requirements.

Your rights

Under UK GDPR and the Data Protection Act 2018 you have the right to access your data, correct it, request its deletion, restrict or object to processing, and request a portable copy. You can withdraw consent to data sharing at any time, though this will not undo sharing that has already taken place.

To exercise any of these, email privacy@nesema.com. If you are unhappy with our response you can complain to the Information Commissioner's Office at ico.org.uk.

Security

Data is encrypted in transit and at rest. Access is controlled at the database level so that records are reachable only by the account they belong to and the practitioner responsible for that patient's care.