GDPR Policy

—-
1. Introduction

Early Health Ltd ("Early", "we", "us") is committed to protecting the personal data of individuals we interact with. This policy sets out how we comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Early Health Ltd is the data controller for personal data collected through its marketing and waitlist activities. Our registered address is 11-21 Northdown Street, London, N1 9BN. Registration number: 14551793.

—-
2. Scope

This policy applies to all personal data processed by Early Health Ltd in connection with its marketing and waitlist operations. It covers data collected via our website (earlyhealth.com), our email communications, and our use of third-party advertising and analytics platforms (including but not limited to Meta and LinkedIn).

This policy does not cover clinical or health data collected as part of Early's regulated device programme - that is subject to separate data governance documentation.

—-
3. Data Protection Principles

Early processes personal data in accordance with the six principles set out in Article 5 UK GDPR:

  • Lawfulness, fairness and transparency - we only process data where we have a lawful basis and we are transparent about how we use it via our Privacy Policy.

  • Purpose limitation - data is collected for specified, explicit, and legitimate purposes and is not processed in ways incompatible with those purposes.

  • Data minimisation - we only collect personal data that is necessary for the purpose. Data collected will not include special category data. The types of personal data collected are set out in the Privacy Policy and may be updated from time to time.

  • Accuracy - we take reasonable steps to keep personal data accurate and up to date.

  • Storage limitation - data is not kept longer than necessary. See the Marketing Data Retention, Access Management & Anonymisation Protocol for retention periods.

  • Integrity and confidentiality - personal data is processed securely, with access restricted to authorised Early Health staff only.

—-
4. Lawful Basis for Processing

Early relies on legitimate interests (Article 6(1)(f) UK GDPR) as the lawful basis for processing waitlist and marketing data. This has been assessed and documented in the Legitimate Interests Assessment - Waitlist Data Processing.

Early does not process special category data (Article 9 UK GDPR) through its marketing channels.

—-
5. Individual Rights

Early Health Ltd respects and upholds the rights of individuals under UK GDPR, including the right to:

  • Access personal data we hold about them

  • Correct inaccurate data

  • Request erasure of their data

  • Object to processing

  • Restrict processing

  • Data portability

Requests are handled by authorised Early Health staff via help@earlyhealth.com and fulfilled within the legally required timeframe (currently [30 days] under UK GDPR).

Individuals can also unsubscribe from marketing emails at any time via the unsubscribe link included in every email.

—-
6. Data Security

  • Personal data is accessible only to authorised Early Health staff.

  • Access follows a least-privilege principle - staff only access data relevant to their role.

  • No raw personal data is shared with third-party agencies or contractors without a signed Data Processing Agreement (DPA).

  • Personal data uploaded to advertising platforms is hashed upon upload - plain-text data is not exposed to those platforms' ad systems.

  • Access permissions are reviewed whenever there is a change to relevant personnel.

—-
7. Data Processors

Early uses the following third-party data processors for marketing activities. Each is bound by appropriate data processing terms:

  • Squarespace Inc. - website platform and subscriber/mailing list storage (US-based; SCCs in place)

  • KickoffLabs LLC - waitlist signup collection and referral tracking (US-based; DPA in place)

  • Meta Platforms Ireland Ltd - custom audience and lookalike audience advertising

  • LinkedIn Ireland Unlimited Company - custom audience and lookalike audience advertising

This list will be updated as new processors are added.

—-
8. International Transfers

Where personal data is transferred outside the UK (for example, to Squarespace in the US), Early relies on appropriate legal safeguards such as Standard Contractual Clauses (SCCs) to protect it. All processors are required to comply with UK GDPR transfer requirements.

—-
9. Data Retention

Personal data is retained only for as long as necessary for the purpose for which it was collected. Full details are set out in the Marketing Data Retention, Access Management & Anonymisation Protocol.

—-
10. Data Breaches

In the event of a personal data breach, Early will:

  • Assess the risk to individuals without undue delay

  • Where required, notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach

  • Where required, notify affected individuals without undue delay

  • Document the breach and the steps taken in response

All suspected breaches should be reported immediately to the person responsible for data protection at Early Health Ltd.

—-
11. Roles & Responsibilities

  • Data Controller: Early Health Ltd is responsible for ensuring compliance with this policy and UK GDPR.

  • PRRC / Regulatory lead: Tehelj is responsible for reviewing and signing off this policy.

  • Authorised staff: All staff handling personal data are responsible for complying with this policy.

—-
12. Related Documents

  • Privacy Policy - Early Health Ltd

  • Cookie Policy - Early Health Ltd

  • Legitimate Interests Assessment - Waitlist Data Processing

  • Marketing Data Retention, Access Management & Anonymisation Protocol

—-
13. Review

This policy will be reviewed and updated on any material change to Early Health Ltd's data processing activities, personnel, or applicable law.

—-

Prepared by: Early Health Ltd
Date: June 2026


© Early 2026