Daye Health Platform (DHP)

PRIVACY NOTICE

Version 2.0

Effective Date: September 1, 2025

We at Daye are conscious that when using the Daye Health Platform (“DHP”), our customers entrust their most intimate health-related details to us. This is why when developing, improving and offering DHP, we prioritise transparency to our customers and security of their information. The DHP Privacy Notice aims to inform you how Daye handles and protects your personal information when you use the different services and products offered through DHP as detailed in our DHP Terms and Conditions. All capitalised terms used in this Notice shall have the meaning ascribed to them in the DHP Terms and Conditions.

It is important that you read this document together with our Website Privacy Policy available at this link which contains more general information about how we process data about general visitors of Daye’s Website.

To use DHP, Daye customers are required to create a dedicated account on Daye’s Website (“DHP Account” or “Account”) which includes going through an identity verification procedure requiring the provision of a selfie and an up to date identity document. Before using DHP and creating a DHP Account please read this Privacy Notice carefully. By accessing or using DHP or any products and services offered through DHP, you acknowledge that you’ve read this Privacy Notice and you agree with its content. If you do not agree to this Privacy Notice, please do not use DHP.

__________________________________________________________________

Important information and who we are

We are Anne’s Day Ltd., a company established in the UK under company number 11044785 (just “Daye”, “we” or “us”). Daye is made up of different legal entities registered throughout the United Kingdom, the European Union and the United States of America. So when we mention Daye in this document, we are referring to the relevant company in the Daye Company Group which provides the DHP services and products to you and is therefore responsible for the processing of your personal information.

For the purposes of data protection laws, we are the data controller and responsible for the processing of your personal data when you use DHP. If you have any questions about this privacy notice or our data protection practices with regard to DHP please contact us at hello@yourdaye.com.

The data we collect about you and how we use it

When you use DHP, incl. any products or services offered on DHP, we will collect, use, store transfer and process different kinds of personal information about you as described below:

Data categoryWhat it isHow we will use it
Order IDA randomly generated unique identifier for each Kit ordered on DHPTo process and execute your orders for DHP products and services
Order details and order historyShipping address, post code, contact details, products or services purchased on the DHP, etc.To deliver our products and services and to comply with our contractual obligations to you.
Payment detailsInformation such as your bank account number, payment instrument you’ve used, payment provider, etc.To comply with our contractual obligations to you and exercise our rights under the DHP Terms and Conditions.
Identity detailsNames and address, selfie, copy of your up to date identity document, ethnicity, government identifier number or code.To comply with our regulatory obligations and those of our partners. To achieve our legitimate business interests of enforcing the DHP Terms and Conditions and preventing incidents on the DHP.
Account IDA randomly generated unique identifier assigned to every customer who has successfully registered on the DHP.To identify you as an individual DHP customer and to allow you to log into your DHP account.

To obtain your Medical ID once you log in the DHP (see next row for what a Medical ID is).
Medical IDA randomly generated unique identifier assigned to every DHP customer for the purposes of managing our medical database. This identifier is linked to your Account ID via a separate database, and only you as an authenticated customer are able to obtain your Medical ID. This is a privacy-enhancing technique called pseudonymization which safeguards our customers’ identity and privacy when they use DHP.To link the pseudonymised medical records in our medical database with individual customers without using direct identifiers. The Medical ID will only be accessible to you, after you’ve authenticated yourself within the DHP.
Kit activation codeThe Kit activation code is a unique identifier assigned to the Kit you’ve ordered. This is a randomly generated number that allows Daye to attribute a Kit to a particular customer and to generate a barcode image which is printed as a label included in your Kit.To link a particular physical Kit and sample to a customer and to allow you to obtain your Screening Data when ready.

To allow the lab to submit the Screening Data in Daye’s lab frontend system without knowledge of the customer’s identity.
Screening Data (includes special categories of data)These are the results provided by the laboratories we work with after analysis of the vaginal or blood sample you’ve sent to us after using your Kit. Where possible, the results of such tests are provided to us by the laboratories without any knowledge of your identity.Those results will be recorded by Daye in our patient medical database and will be retrievable to you as a holder of the activation code through the DHP.

Screening Data about sexually transmitted infections and human papillomavirus will be stored in our database for 10 years as legally required. They will be kept in strict confidentiality and will be made available only to Daye employees and agents who have a “need-to-know” to the extent this is necessary for the purpose of treatment of the STI, prevention of the spread thereof or further testing required.
Questionnaires and surveys you’ve filled on the DHP (may include special categories of data)Any information contained in responses to questionnaires and surveys that we or our partners (e.g. Pharmacies) have provided to you and that you’ve filled on the DHP, for example - the questionnaire you have to fill when activating your Kit or questionnaires part of the Daye Period & Pelvic Pain Clinic.To gain extra knowledge of our customers, their health status and their customer experience in order to provide you with more accurate healthcare recommendations tailored to your lifestyle, to provide you with the services you’ve requested and to also improve the quality of our services.
Correspondence between you and Daye or between you and our partners (may include special categories of data)This may include any written (e.g. email or physical mail) correspondence between you and Daye or Pharmacies and medical experts, incl. attachments thereof, and phone call recordings.To provide service support to our customers.
To deliver our products and services and to comply with our contractual obligations to you.
Behaviour on the DHPDetails about your usage of the DHP, incl. log-ins, time spent on particular webpages, journey through our Website, history of orders placed, etc.To gain extra knowledge of our customers, to provide recommendations, products and services tailored to their lifestyle and unique medical status, and to also improve the quality of the DHP products and services.

We may collect the information above in different ways, including:

  • Directly from you, for example – when you fill in questionnaires or when you participate in surveys.
  • By generating it ourselves, e.g. our systems generate randomly your Medical ID, your Kit Activation Code, etc. when you place an order.
  • By receiving it from third parties, for example - when laboratories we work with share your Microbiome, STI, HPV or Hormone Screening Data with us.

Lawful bases for processing your personal data

We will process the personal data categories described in Section 1 above when at least one or more of the conditions below are met:

  1. This is required to meet our contractual legal obligations to you or to exercise our rights;
  2. You’ve consented to this;
  3. It is within our legitimate business interests to do that when this will not cause disproportionate harms to your privacy and data protection rights, e.g.
    • to send you direct marketing messages;
    • to detect, prevent, investigate and report crime;
    • to improve our existing and to develop new products and services;
    • to enforce the DHP Terms and Conditions;
    • to comply with our contractual obligations vis-a-vis our partners;
    • to conduct gynae health research.
  4. When we are required by law to do so; or
  5. When this is necessary to protect your or someone else’s life.

We may also process medical information about you which is afforded a higher level of protection under data protection laws. We will do that only if:

  1. You’ve given us explicit consent to do so;
  2. This is necessary for the establishment, exercise or defence of legal claims by Daye;
  3. This is necessary for reasons of substantial public interest, incl. in the area of public health;
  4. This is necessary for the purposes of preventive medicine;
  5. This is necessary for archiving purposes in the public interest, scientific, historical research or statistical purposes; and
  6. When this is necessary to protect your or someone else’s life.

How we share your personal data

3.1. Members of the Daye Company Group. We will share your personal data with other entities part of the Daye Company Group insofar this is necessary for the delivery of the DHP products and services or for the management of our business.

3.2. Laboratories we work with. We will also share your blood or vaginal sample and your Kit activation code/barcode with the laboratories we work with for the purpose of analysing your sample and producing Screening Data. We will share your postcode and ethnicity data with laboratories who help us provide screening for sexually transmitted infections. This is to support with reporting positive results to the competent public authorities (legal requirement to monitor spread of infections). Remember - we will share any directly identifiable attributes (such as names, personal identity number and addresses) with the laboratories we work with only when this is required under our contract with the laboratories or under applicable law.

3.3. Other partners and service providers. We will share your personal data with other service providers or partners of our choice insofar this is necessary for the provision of DHP products and services or where we have a lawful basis for that, e.g. - our hosting service provider – Google, the provider of our electronic patient medical record services - Cliniko, healthcare specialists, pharmacies we work with such as Cedarwood, Blueco and Phlo, accountants, etc. We will make sure that all those third parties are bound by contractual confidentiality and data protection undertakings and will not use your information in a way different than as described in this document.

3.4. Public authorities. If your Screening Data indicates a positive result for a sexually transmitted infection or human papillomavirus, we or the laboratories we work with may also share anonymised Screening Data with the UK healthcare public authorities for statistical purposes and to comply with relevant legal obligations for reporting such diseases. In those cases, we may also notify your intimate partners and share your personal data, if you explicitly consent to that and authorise us to do so.

Please note that we may anonymise your data and we may share it with other third parties in a format in which your data is no longer attributable to you as an individual. For more information, please see “Research” section of the DHP Terms and Conditions.

International transfers

We will transfer, store and process your personal data in the UK and the European Economic Area (EEA) but we will also transfer it to countries outside the UK and the EEA such as the United States of America.

When we do that, we will ensure compliance with the applicable rules on transfers of personal data to third countries. Particularly, when your personal data is stored or otherwise processed in a country that is not considered to offer an adequate level of protection to your personal data compared to UK or EU standards, we will make sure the recipient of the data in that third country is bound by the standard contractual clauses as approved by the UK Parliament or respectively the EU Commission and by relying on any other supplementary safeguards necessary to ensure your personal information continues to enjoy the same level of protection as if still in the UK or EU.

Your legal rights

Under certain circumstances, data protection laws grant you rights in relation to the information Daye holds about you as detailed in our Website Privacy Policy available here.

Please note that if you’d like to receive a copy of your health information or Screening Data, Daye allows you to download a file with all that information through the DHP so you can then send it to your own doctor or print it for your own archives.

We are not obligated to comply with your right to erasure in contexts in which we have to retain your personal data for regulatory or other legal reasons.

Further details

If you are looking for more information on how we process your personal data including what your rights are, what are the data retention periods and lawful processing bases we rely on, etc. please consult our Website Privacy Policy available here.