Welcome to our Privacy Policy! This document explains how we protect and use your personal information to ensure peace of mind. We are committed to safeguarding your data and maintaining transparency in its usage. Please review this policy carefully and proceed with our services only if you fully understand and agree to the terms outlined. Your trust is our priority; we’re here to safeguard your information – because that is our number one responsibility to uphold.
If you have any concerns or enquiries, do not hesitate to contact us at: info@becauseyolo.health
- This Privacy Policy sets out how YOLO Health Ltd with registered office at 124 City Road, London (“YOLO Health”) and its subsidiaries, related bodies corporate and franchisees (collectively referred to in this policy as “YOLO Health”, “we” or “us”) protects the privacy of your Personal Information (as defined below) and the basis on which any Personal Information we collect from you, or that you or third parties provide to us, will be processed and used by us.
- We are committed to protecting your privacy and processing your Personal Information following applicable laws and regulations (as amended or replaced from time to time) that protect the confidentiality of Personal Information in the jurisdictions where we operate (‘Applicable Laws’). For this Privacy Policy, ‘Personal Information’ refers to information about you as an identified individual, such as personal health information or other personal information as defined by the applicable laws. ‘Special Category Personal Data’ refers to personal information that reveals an individual’s racial or ethnic origin, political opinions, religious beliefs, philosophical beliefs, or trade union membership, genetic and biometric data (when processed to identify an individual uniquely), and data concerning health, sexual orientation, and lifestyle. YOLO Health will only collect, use, retain, disclose, and transfer your Personal Information in compliance with this Privacy Policy, any relevant Privacy Notices, and Applicable Laws, including the UK General Data Protection Regulation (GDPR).
- Please read the following carefully to understand our policies and procedures surrounding your Personal Information and how we will handle it. Using our nutrition and wellness service, which provides software applications to read and analyse your genetic data to provide you insights to personalise your nutrition, diet, and exercise and assist in making it easy to take action on those insights in your daily life (the ‘Service’), you confirm that you have read, understood, and agree to the collection, use, storage, disclosure, and transfer of your Personal Information under this Privacy Policy. If you disagree or withdraw your consent, you should not use the Service.
- If you are under the age of 18, you may only use the Service or provide Personal Information to us if you have the agreement and supervision of a parent or guardian. YOLO Health does not intentionally collect information from those under 18 without consent.
- This privacy policy was last updated on date/month/year and is effective as of that date. YOLO Health retains the right, as its sole discretion, to change, edit, remove, or update this Privacy Policy occasionally. We shall make reasonable efforts to notify you in advance of any changes to the terms of this Privacy Policy. If you do not agree with the modifications, revisions, deletions, or updates, your only option is to discontinue using the Service. Using the Service after those modifications are implemented, you will be assumed to have accepted and consented to the changes.
What Personal Information Do We Collect From You?
- YOLO Health collects the following types of information when you use the Service, this is done toreceive payment and/or deliver your DNA test, andmake our guidance and services as personalised as possible. Collected information may include, but is not limited to:
- Lifestyle details, such as habits (smoking, drinking, eating patterns, etc)
- Contact details, such as your email address, phone number, and shipping address (for DNA kit delivery).
- Genetic and biological health data, including any genetic profiles provided by third parties (‘Genetic Information)
- Your name or preferred nickname, gender, and date of birth
- Details about your personal and family health history
- Contact information, including your phone number and physical address (used for shipping DNA kits, if applicable)
We collect your payment information, such as your bank account or credit card details, which are securely processed through Stripe SDK. Along with your phone number and any relevant details enteredintothe app, this information is solely to process payments for our services.
Cookies and Mobile Analytics
- We, along with our third-party partners, utilise cookies and similar technologies (such as web beacons, tags, scripts, and device identifiers) to recognise users, enhance your experience, and ensure the security of our services. These tools help us analyse usage patterns, customise content, gather demographic data, and offer relevant products or services. These tools help us analyse usage patterns, customise content, gather demographic data, and offer relevant products or services. They also allow us to measure the effectiveness of our marketing efforts and deliver targeted advertising across our site and other websites. However, we do not use sensitive information, including Genetic Information, for targeted advertising. If you choose to decline cookies, you can still access our site, but some features or sections may be restricted.
- In addition, when visitors interact with our website, we automatically collect certain information about them and store it in log files. This data might include internet protocol (IP) addresses, browser type, internet service provider (ISP), referring/exit sites, operating systems, date/time stamp, and/or clickstream data. We may combine the automatically obtained log information with other information about you, such as your user profile ID or order number. We do this to enhance the services we provide you and the marketing, analytics, and site performance.
- When you access YOLO Health’s website through a mobile device, we may collect and store certain information unique to your device or our app. This may include identifiers such as UDID, advertising IDs (e.g., IDFA, Google Ad ID, or Windows Advertising ID), and details about your mobile carrier, device type, model, manufacturer, and operating system brand and version. Additionally, if enabled in your device settings, we may collect location data, including GPS coordinates (latitude and longitude) or other information that helps identify your device’s location.
- We utilise mobile analytics software to gain insights into how usersinteract with our mobile application. This software tracks metrics such as app usage frequency, in-app events, overall performance, and the source from which the app was downloaded. While this data helps us enhance the app’s functionality, it is aggregated and not linked to any personal information you provide through the application.
Why We Collect YourData and What We Do with It
- Under data protection law, we can only use your personal data if we have a proper reason to, e.g.:
- when you have provided consent;
- to fulfil our legal and regulatory duties;
- to carry out a contract with you or to take necessary steps at your request before finalising a contract;
- to pursue our legitimate interests or those of a third party
- A legitimate interest arises when we have a business or commercial purpose for using your information, provided it does not override your rights and interests. We will conduct an evaluation to ensure that our interests are balanced against yours when relying on legitimate interests.
- YOLO Health (and third-party data processors acting on our behalf) may collect, store, and process your Personal Information as described above for the following purposes:
- To manage and operate the Service and any associated services and programs.Including:
- Opening your account, communicating with you, and fulfilling your requests.
- Processing payments for DNA tests, subscriptions, and in-app purchases (via Stripe SDK)
- Running our mobile app and website, authenticating visits, delivering personalised content and information, and tracking use of our Services;
- Processing and analysing your Genetic Information and other Personal Information;
- Offering health, nutritional, and wellness analyses and recommendations based on your Genetic Information and other Personal Information, including insights into weight gain risk, exercise behaviours, exercise motivation, optimal macronutrient percentages for weight loss, micronutrient deficiency risks, and advice on behavioursto reduce genetic risk;
- To connect you with other users of our Service who have similar conditions, enabling the exchange of information, strategies, and insights;
- To perform analytics aimed at enhancing and improving our Service;
- To introduce new products, programs, or services, including through emails, promotions, or contests, under applicable laws;
- For internal record-keeping purposes, such as collecting anonymised usage data to compile aggregate statistics or generate internal reports;
- To share your Personal Information with selected third parties, as detailed in Section 4 of this Privacy Policy;
- To send or allow authorised third parties to send information via SMS, email, or other electronic messages about products or services that may interest you, including brochures, promotions, events, and new offerings, in compliance with applicable laws.
- To use or disclose your information as required by law, including crime prevention, fraud detection, and related legal obligations;
- To anonymise and aggregate Personal Information (including Genetic Information) for other purposes, ensuring no identifiable data can be traced back to you.
- To manage and operate the Service and any associated services and programs.Including:
- When processing special category personal data, we will ensure compliance with data protection laws by ensuring that:
- We have obtained your explicit consent;
- Processing is necessary to protect your vital interests (or those of another person) when you are physically or legally unable to provide consent or
- Processing is required to establish, exercise, or defend legal claims.
We will retain your Personal Information only for as long as reasonably necessary to fulfil the purposes for which it was collected. After this period, the information will be deleted unless Applicable Law requires retention. YOLO Health will retain any anonymised and aggregated data for continued use.
Disclosure of Your Personal Information
- YOLO Health may share your Personal Information, either collected from you or provided by you, with selected third parties for the following purposes:
- to operate the Service and provide the programs in connection with the Services or any other purposes as set out in paragraph 3.1 above;
- to enforce or apply the Service’s Terms and/or other agreements and/or to investigate potential breaches of such contracts;
- to protect YOLO Health’s rights, property or safety or the rights, property or safety of other users of the Service or others (e.g., for fraud protection, etc.); and
- to take payment from you for any purchases (including via Stripe SDK) – your telephone number and information already input into the app will be passed to Stripe SDK to take payment; and
- to comply with applicable laws, regulations, governmental and quasi-governmental requests, court orders or subpoenas.
- To clarify, your Genetic and Personal Information will only be disclosed as necessary to provide the Service unless we have obtained your explicit consent. Yolo will not share your genetic or personal information with insurance companies or marketing agencies without your permission.
- YOLO Health may share your Personal Information with, without limitation:
- Companies that offer statistical analysis services.
- Analytics and search engine providers, such as Google Inc., to help us enhance and optimise our website.
- Stripe SDK for processing payments; and
- A qualified practitioner will assist with personal consultations upon your request.
- YOLO Health will ensure that any third parties receiving Personal Information from us provide a comparable level of protection, as outlined in this Privacy Policy, through contractual or other safeguards. To the fullest extent allowed by Applicable Law, YOLO Health disclaims liability for the use of your Personal Information by third parties. Upon request, we can provide the names of all third parties to whom your Personal Information is or will be transferred. We use Stripe SDK for payment processing, and their privacy policy can be accessed at Privacy Policy.
- Unless otherwise specified in this Privacy Policy, we will not disclose, sell, distribute, rent, or lease your Personal Information to third parties without your permission or unless it is necessary to complete a transaction on your behalf. We do not share your identifiable Personal Information with third parties for their direct marketing purposes without your explicit consent.
- If a third party proposes to acquire all or part of our business or assets, we may share your Personal Information with them in connection with the proposed or actual acquisition. Similarly, if we become insolvent or face a similar situation, we may disclose your Personal Information as part of a business or asset sale, provided such disclosure complies with Applicable Laws.
- YOLO Health may also have to
- Share personal data with external auditors for ISO or Investors in People accreditation and account auditing.
- Disclose and exchange information with law enforcement and regulatory bodies to fulfil legal obligations.
- Share some personal data with third parties, such as potential buyers or during restructuring. While information is usually anonymised, this is not always the case. However, the recipient of the data will be subject to confidentiality responsibilities.
Where your Personal Data is Held
- As previously indicated, personal data may be stored at ouroffices as well as those of our third-party agencies, service providers, representatives, and agents.
- Some of these third parties may be based outside the UK
International Transfers of Data
- To deliver the Service, YOLO Health may transmit and/or keep the Personal Information acquired from you with our overseas associated businesses, subsidiaries, linked bodies corporate, and franchisees. In order to fulfil the objectives outlined in this Privacy Policy, we may also need to transmit and/or disclose your Personal Information to third parties in the United Kingdom, Europe, or other jurisdictions.
- By providing your Personal Information, you agree that it may be transferred, stored, and/or processed beyond the jurisdiction in which it was originally acquired. We will take all reasonable efforts to ensure that your Personal Information is handled securely and in compliance with this Privacy Policy. Where we have employed overseas third parties to perform services in connection with the Service, we will utilise contractual or other mechanisms to guarantee that such third parties provide a comparable degree of security for the Personal Information. However, Applicable Laws in other may not safeguard your Personal Information to the same extend as your own state.
- According to data protection laws, we can only send your personal data to a country or international entity outside the UK[/EEA] where:
- The UK government [or, where the EU GDPR applies, the European Commission] has decided that the specific country or international organisation ensures an adequate level of protection of personal data (known as a ‘adequacy decision’);
- There are appropriate safeguards in place, along with enforceable rights and effective legal remedies for data subjects;
- or a specific exception applies under data protection law
These are explained below.
Adequacy decision
- We may transmit your personal information to specific countries based on adequatejudgment. Examples include (but are not limited to):
- The ‘EEA’, which includes all European Union nations, Iceland, Liechtenstein, and Norway, as well as Gibraltar,and Andorra, Argentina, Canada, Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Switzerland, and Uruguay.
- The list of countries that benefit from adequacy decisions will change from time to time. We will always seek to rely on an adequacy decision where one exists.
- Other countries or international organisations to whom we are likely to transmit personal data do not benefit from an adequacy judgment. This does not necessarily imply that they provide inadequate protection for personal data; nonetheless, we must consider other justifications for transmitting personal data, such as providing proper protections or relying on an exemption, as detailed below.
Transfers with appropriate safeguards
- In the absence of an adequacy decision, we may transfer your personal data to another country or international organisation if we are satisfied that the transfer complies with data protection law, appropriate safeguards are in place, and data subjects have enforceable rights and effective legal remedies.
- The safeguards will usually include using legally approved standard data protection contract clauses.
- To obtain a copy of the standard data protection contract clauses and further information about relevant safeguards, please contact us.
Transfers under an exception
- In the absence of an adequacy determination or adequate measures, we may transmit personal data to a third country or international organisation when an exemption applies under applicable data protection law, eg:
- You have given your explicit consent to the proposed transfer after being informed of the risks.
- The transfer is necessary for the performance of a contract or pre-contract measures at your request.
- It is also necessary for a contract in your interests between us and another person or to establish, exercise, or defend legal claims.
- We may also share information for compelling, legitimate reasons as long asthey do not conflict with your interests, rights, and freedoms. Specific circumstances apply to such transfers, and we will give relevant information if and when we seek to transfer your personal data on this basis.
Data Security
- YOLO Health has implemented security measures to ensure the secure storage of all Personal Information gathered and received. We utilise suitable technological, organisational, administrative, and physical safeguards to secure your Personal Information in our system against accidental damage, deletion, misuse, loss, and unauthorised access or change. We will do our utmost to secure your Personal Information, but we cannot guarantee the security of any Personal Information submitted to us by a third party. Once we have received your Personal Information, we will employ a variety of protocols and security mechanisms (including encryption) to try to prevent unauthorised access, use, or disclosure. We shall also restrict access to your personal data to those who have a legitimate business reason to do so.Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.
- We also have mechanisms in place to address any suspected data security violation. We shall notify you and any applicable regulators of a suspected data security breach if we are legally obligated to.
- You are also responsible for protecting your personal information. We ask that you be responsible for securing your password, secret questions and answers, and any authentication information used to access our Service. You must not divulge your authentication credentials to any third party and must tell us immediately if your password is used without your permission. We cannot protect Personal Information that you disclose on your own or that you request we release.
Your Rights
- You can access, rectify, or update parts of your Personal Information via our mobile application. You also have the right, upon written request, to view any and all details of your Personal Information that we keep on you, as well as to seek rectification or erasure of such Personal Information if the Applicable Laws allow it.
- You may change your mind about consenting to the use, disclosure, and transfer of your Personal Information in line with this Privacy Policy by contacting us at the address stated below. If you withdraw your agreement for YOLO Health to handle your Personal Information in line with this Privacy Policy, YOLO Health may be unable to offer you with all aspects of the Service.
- You have the right to require us to restrict processing of your personal data in certain circumstances, eg if you contest the accuracy of the data.
- In some cases, you have the right to receive the personal data you gave to us in a structured, frequently used, and machine-readable format, as well as to transfer such data to a third party.
- You may opt out of receiving messages from us by responding UNSUBSCRIBE to any communications you get from us. You may unsubscribe from any email from us by following the instructions in the email; however, this will not prevent us from sending emails concerning your account, transactions with us, or other information necessary for your use of the Service. You have the right to object, in some additional cases, to our ongoing processing of your personal data, such as processing carried out for the sake of our legitimate interests.
- You have the right to file a complaint with us over a probable infraction of the Applicable Laws. We will evaluate any complaints we receive and react within a fair timeframe. You may also file a complaint regarding the treatment of your Personal Information with the supervisory body in your jurisdiction if the Applicable Laws allow it.
- You have the right not to be subjected to a decision based entirely on automated processing (including profiling) that has legal consequences for you or otherwise significantly affects you.
- You can exercise your rights above by contacting us at the address listed below.
Marketing
- We may use your personal information to send you service updates (by email, text message, telephone, or post), such as special offers, promotions, or new services.
- We have a legitimate interest in utilising your personal information for marketing reasons. This means that we normally do not require your permission to send you marketing materials. Where consent is required, we will ask for it individually and unambiguously.
- You have the right to opt out of receiving marketing communications at any time by:
- contacting us at info@becauseyolo.health; or
- using the ‘unsubscribe’ link in emails or ‘STOP’ number in texts.
- We may ask you to confirm or alter your marketing choices if you want additional services from us in the future, or if the legislation, regulations, or structure of our business changes.
- We will always treat your personal information with the highest care, never selling or sharing it with other companies for marketing reasons.