GDPR Policy
—-
1. Introduction
Early Health Ltd ("Early", "we", "us") is committed to protecting the personal data of individuals we interact with. This policy sets out how we comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Early Health Ltd is the data controller for personal data collected through its marketing and waitlist activities. Our registered address is 11-21 Northdown Street, London, N1 9BN. Registration number: 14551793.
—-
2. Scope
This policy applies to all personal data processed by Early Health Ltd in connection with its marketing and waitlist operations. It covers data collected via our website (earlyhealth.com), our email communications, and our use of third-party advertising and analytics platforms (including but not limited to Meta and LinkedIn).
This policy does not cover clinical or health data collected as part of Early's regulated device programme - that is subject to separate data governance documentation.
—-
3. Data Protection Principles
Early processes personal data in accordance with the six principles set out in Article 5 UK GDPR:
Lawfulness, fairness and transparency - we only process data where we have a lawful basis and we are transparent about how we use it via our Privacy Policy.
Purpose limitation - data is collected for specified, explicit, and legitimate purposes and is not processed in ways incompatible with those purposes.
Data minimisation - we only collect personal data that is necessary for the purpose. Data collected will not include special category data. The types of personal data collected are set out in the Privacy Policy and may be updated from time to time.
Accuracy - we take reasonable steps to keep personal data accurate and up to date.
Storage limitation - data is not kept longer than necessary. See the Marketing Data Retention, Access Management & Anonymisation Protocol for retention periods.
Integrity and confidentiality - personal data is processed securely, with access restricted to authorised Early Health staff only.
—-
4. Lawful Basis for Processing
Early relies on legitimate interests (Article 6(1)(f) UK GDPR) as the lawful basis for processing waitlist and marketing data. This has been assessed and documented in the Legitimate Interests Assessment - Waitlist Data Processing.
Early does not process special category data (Article 9 UK GDPR) through its marketing channels.
—-
5. Individual Rights
Early Health Ltd respects and upholds the rights of individuals under UK GDPR, including the right to:
Access personal data we hold about them
Correct inaccurate data
Request erasure of their data
Object to processing
Restrict processing
Data portability
Requests are handled by authorised Early Health staff via help@earlyhealth.com and fulfilled within the legally required timeframe (currently [30 days] under UK GDPR).
Individuals can also unsubscribe from marketing emails at any time via the unsubscribe link included in every email.
—-
6. Data Security
Personal data is accessible only to authorised Early Health staff.
Access follows a least-privilege principle - staff only access data relevant to their role.
No raw personal data is shared with third-party agencies or contractors without a signed Data Processing Agreement (DPA).
Personal data uploaded to advertising platforms is hashed upon upload - plain-text data is not exposed to those platforms' ad systems.
Access permissions are reviewed whenever there is a change to relevant personnel.
—-
7. Data Processors
Early uses the following third-party data processors for marketing activities. Each is bound by appropriate data processing terms:
Squarespace Inc. - website platform and subscriber/mailing list storage (US-based; SCCs in place)
KickoffLabs LLC - waitlist signup collection and referral tracking (US-based; DPA in place)
Meta Platforms Ireland Ltd - custom audience and lookalike audience advertising
LinkedIn Ireland Unlimited Company - custom audience and lookalike audience advertising
This list will be updated as new processors are added.
—-
8. International Transfers
Where personal data is transferred outside the UK (for example, to Squarespace in the US), Early relies on appropriate legal safeguards such as Standard Contractual Clauses (SCCs) to protect it. All processors are required to comply with UK GDPR transfer requirements.
—-
9. Data Retention
Personal data is retained only for as long as necessary for the purpose for which it was collected. Full details are set out in the Marketing Data Retention, Access Management & Anonymisation Protocol.
—-
10. Data Breaches
In the event of a personal data breach, Early will:
Assess the risk to individuals without undue delay
Where required, notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach
Where required, notify affected individuals without undue delay
Document the breach and the steps taken in response
All suspected breaches should be reported immediately to the person responsible for data protection at Early Health Ltd.
—-
11. Roles & Responsibilities
Data Controller: Early Health Ltd is responsible for ensuring compliance with this policy and UK GDPR.
PRRC / Regulatory lead: Tehelj is responsible for reviewing and signing off this policy.
Authorised staff: All staff handling personal data are responsible for complying with this policy.
—-
12. Related Documents
Privacy Policy - Early Health Ltd
Cookie Policy - Early Health Ltd
Legitimate Interests Assessment - Waitlist Data Processing
Marketing Data Retention, Access Management & Anonymisation Protocol
—-
13. Review
This policy will be reviewed and updated on any material change to Early Health Ltd's data processing activities, personnel, or applicable law.
—-
Prepared by: Early Health Ltd
Date: June 2026