Aevisa Holdings Ltd. ("AEVISA", "we", "our", "us") is committed to protecting your privacy and handling your personal data transparently and lawfully. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and your rights under UK data protection law.
This policy applies to
- Website visitors — anyone using aevisaglobal.com and its subdomains
- Waitlist / newsletter subscribers — anyone who signs up to hear from us
- Contact form users — anyone who reaches out via our website
- App users — anyone who creates an account and uses the AEVISA mobile app (iOS via Apple TestFlight, Android via Google Play Closed Testing, or the web application)
- Founding 50 pilot participants — our current cohort testing the app pre-launch
- Clinical-validation study participants — where you give separate additional consent
The app is intended for adults aged 18 and over. It is not directed at, and must not be used by, anyone under 18.
1. Who we are
Aevisa Holdings Ltd. is a private limited company registered in England and Wales.
Company number: 17049989
Registered office: Unit 19, Maidstone Innovation Centre, Gidds Pond Way, Weavering, Maidstone, Kent ME14 5FY, United Kingdom
Contact: hello@aevisaglobal.com
For all personal data covered by this policy, AEVISA is the data controller — we decide what data is collected and why.
2. What data we collect
We collect different data depending on how you interact with us.
2.1 If you visit our website
- Your name (if provided in forms)
- Your email address
- The date you signed up or contacted us
- Message content if you use the contact form
- Approximate location, browser type, device, and pages visited (via our hosting provider's server logs)
2.2 If you use the AEVISA app
Account and profile data
- Name (or display name) and email address
- Age or date of birth, and sex/gender (used to calibrate scores and reference ranges)
- Your health goals and focus areas
- Profile photo, if you choose to upload one
Health and wellness data you enter (special-category data — see section 3)
- Daily logs: sleep duration, how rested/recovered you feel, activity/movement, nutrition quality, hydration, calmness/stress, mood and energy
- Habits you track and your logging streaks
- Body-composition measurements, if you choose to record them (weight, body fat %, visceral fat, muscle/lean mass, body water)
- Any notes you add
Scores and insights we generate about you
- Your daily AEVISA Score and its component breakdown
- Your Healthspan Index and any biological age estimate
- Trends, patterns, and personalised insights derived from your data
Data from connected wearables, only if and when you connect them
- Currently supported: Oura Ring, Whoop, Garmin, Fitbit — connected via our aggregator Terra (see section 5)
- Coming August 2026 (V1.1): Apple Health (iOS) and Samsung Health (Android) via native SDK integrations
- Data may include heart rate, heart-rate variability, resting heart rate, sleep stages, steps, activity/exercise data, and other biometrics your device records
- This is collected only with your explicit action to connect a device and separate consent shown to you at the point of connection
Biomarker and lab data — bring-your-own-bloodwork
- Results you choose to upload — for example, blood test PDFs from any UK laboratory (Randox, Medichecks, Thriva, private clinics, GP printouts, NHS results)
- We extract structured biomarker values (e.g. HbA1c, ApoB, cholesterol panel, Vitamin D, thyroid function) via OCR/parsing of the PDF you upload
- Values flagged outside standard reference ranges are routed to our clinical review pathway with your consent
- Coming V1.1: optional paid tier for a UK-licensed clinician's written interpretation of your uploaded bloodwork
Technical and usage data (automatically)
- Device type, operating system, app version
- In-app events and feature usage (for product analytics — health values are never sent to analytics; see section 8)
- IP address (truncated where possible) and approximate region
- Error and diagnostic logs
3. Special-category (health) data and our lawful basis
Most of the data we collect through the app is special-category data concerning your health under Article 9 UK GDPR, which has extra protection. To process it lawfully we rely on two things together.
A lawful basis under Article 6:
Consent (Art 6(1)(a)) and/or performance of a contract (Art 6(1)(b)) — to provide the app and the features you ask for.
A specific condition under Article 9 for health data:
Your explicit consent (Art 9(2)(a)). You give this when you sign up and agree to this policy. For the clinical-validation study, you give separate additional explicit consent, and may also rely on the scientific-research condition (Art 9(2)(j)) where applicable.
For website processing (waitlist, contact, newsletter), our lawful basis is your consent (Art 6(1)(a)) when you subscribe, or our legitimate interest (Art 6(1)(f)) in responding to enquiries and maintaining our business relationships.
You can withdraw consent at any time (see section 7). Withdrawing consent stops future processing; it does not affect processing already carried out, and some limited data may be retained where the law requires.
4. Why we use your data (purposes)
Website
- To send our newsletter and updates to subscribers who have opted in
- To respond to contact-form enquiries
- To manage our waitlist and inform you when the app is available
- To keep the website secure and prevent abuse
- To understand how visitors use the site (via privacy-respectful analytics)
App
- To provide the core service: calculate your AEVISA Score, Healthspan Index, trends, and insights
- To operate your account, streaks, reminders, and the features you enable
- To route flagged biomarker values (e.g. HbA1c above safe threshold) to our clinical review pathway with your explicit routing consent
- To power the AEVISA AI Assistant (coming V1.1 August 2026), which answers your natural-language questions using your logged data, connected wearables, and biomarker history
- To send you service communications you have asked for (e.g. weekly summaries, reminders) — you control these in settings
- To improve the product and understand engagement, using anonymised analytics
- To carry out the clinical-validation study, if you have given separate consent
- To keep the service secure and prevent abuse
We do not use your health data for advertising, and we do not sell or rent your personal data.
5. Who we share your data with
We share personal data only with the service providers ("processors") we need to run the business, each bound by a written data-processing agreement. We do not sell or trade your data.
Framer Sites B.V.
Purpose: Website hosting and content delivery · Location: EU / US — Standard Contractual Clauses
Fromer
Purpose: Receiving and storing contact-form and signup submissions · Location: EU
Microsoft (Microsoft 365)
Purpose: Operating our hello@aevisaglobal.com email account · Location: Ireland (EU)
Mailchimp (Intuit Inc.)
Purpose: Sending our newsletter and managing subscriber lists · Location: US — Standard Contractual Clauses
Supabase Inc.
Purpose: Database, authentication, file storage · Location: EU (Ireland) · Data: All account, health log, biomarker data
Resend Inc.
Purpose: Transactional email · Location: US, EU option · Data: Email address, notification content
PostHog Inc.
Purpose: Product analytics · Location: EU (Frankfurt) · Data: Anonymised event data — no health values
Terra (Terra Enabling Developers, Inc.)
Purpose: Wearable data aggregator (Oura, Whoop, Garmin, Fitbit) · Location: US — DPA with UK-adequacy Standard Contractual Clauses · Data: Wearable-derived physiological data (HRV, HR, steps, sleep, activity)
Cloudflare Inc.
Purpose: DNS management, CDN · Location: Global · Data: Domain records only; no user data
Apple Inc.
Purpose: iOS app distribution via App Store Connect / TestFlight · Location: US · Data: Apple ID email, install analytics
Google LLC
Purpose: Android app distribution via Google Play Console; Play App Signing · Location: US, EU · Data: Google Play account email, install analytics
Codemagic Ltd.
Purpose: iOS build infrastructure (CI/CD) · Location: EU (Estonia) · Data: Source code artefacts only; no user data
UK-licensed clinical partner
Purpose: Clinical review of flagged biomarker values · Location: UK — with your explicit routing consent per case · Data: Only the specific flagged values you consent to route
A current list of processors is available on request. We may disclose data if required by law, by a regulator, or to protect the rights and safety of users.
6. Automated processing
Your AEVISA Score and Healthspan Index are produced by an automated calculation from the data you provide. The AEVISA AI Assistant (V1.1) generates personalised responses using automated processing of your data.
These are informational wellness indicators and educational responses, not medical diagnoses or decisions, and they do not produce legal or similarly significant effects about you, so they are not "solely automated decision-making" of the kind restricted by Article 22 UK GDPR. The app does not provide medical advice (see the Terms of Use).
Clinical review routing (where a flagged value is escalated to a UK-licensed clinician) is a human process — the clinician exercises their own professional judgement.
7. How long we keep your data
Website
- Newsletter / waitlist subscribers: until you unsubscribe, then deleted within 30 days
- Contact form / email enquiries: up to 24 months after the enquiry is closed, then deleted
- Server logs: retained for a short period (typically up to 30 days) for security and diagnostics
- Records we are legally required to keep: for the period required by law
App
- Account and health-log data: for as long as your account is active. If you delete your account, we soft-delete immediately and permanently erase within 30 days, except where the law requires longer retention.
- Uploaded bloodwork PDFs and extracted biomarker values: kept while your account is active; deleted with the account or on your specific per-record deletion request (V1.1 feature)
- Wearable data received via Terra: stored in our database with the same retention as other health data; you can disconnect a wearable at any time to stop future syncing
- Clinical-validation study data: for the period set out in the study consent form and research plan, after which it is deleted or fully anonymised
- Analytics/usage data: retained in identifiable form for no longer than 14 months, then aggregated/anonymised
You can export or delete your app data at any time from within the app (see section 8).
8. Your rights
Under UK GDPR you have the right to:
- Be informed — through this policy
- Access — request a copy of the personal data we hold about you
- Rectification — correct inaccurate personal data
- Erasure — request deletion of your personal data (subject to legal exceptions)
- Restriction — restrict our processing of your data
- Data portability — receive your data in a structured, machine-readable format
- Object — to processing based on legitimate interests or for direct marketing
- Withdraw consent — at any time, where consent is our lawful basis
How to exercise these rights:
- In-app account deletion (app users): Settings → Account → Delete Account (soft-delete + 30-day purge)
- Web deletion page: https://aevisaglobal.com/delete-account for users who no longer have the app installed
- Data export (app users): Settings → Account → Export My Data (JSON download)
- Per-record deletion/correction of wearable and biomarker data: coming V1.1 late August 2026; interim requests via email to hello@aevisaglobal.com
- Newsletter unsubscribe: use the link at the bottom of any newsletter email
- All other requests: email hello@aevisaglobal.com — we respond within one calendar month
If you are unhappy with how we handle your data you can complain to the UK Information Commissioner's Office (ICO): https://ico.org.uk · 0303 123 1113. If you are in the Gulf region, you may also contact the relevant national data protection authority (see section 10).
9. Security
We protect your data with technical and organisational measures, including:
- Encryption in transit (HTTPS/TLS) for both website and app
- Row-level access controls in Supabase so each app user can only reach their own data
- Least-privilege role model with no self-assignable admin access
- Private file storage with time-limited signed access to uploaded bloodwork PDFs and profile images
- Analytics minimisation — no biomarker values, no free-text notes, no wearable-derived health metrics sent to PostHog
- Processor due diligence and signed Data Processing Agreements
- Automated security scans on each release with dependency vulnerability monitoring
- iOS/Android app signing via Apple and Google managed keys respectively
No system is perfectly secure. If a breach affects your rights, we will notify you and the ICO as required by law. Our internal security baseline is documented and reviewed before each release.
10. International users and transfers (UK, EU, Gulf, US)
The Founding 50 pilot runs primarily across the United Kingdom and the Gulf region, and some of our processors operate in the EU or US.
Data residency:
- Your account and health data is stored in Supabase's EU region (Ireland) — inside the UK GDPR / EU GDPR adequacy zone
- Wearable data flows via Terra (US) with a Data Processing Agreement including UK-adequacy-compliant Standard Contractual Clauses
- Analytics data resides in PostHog's EU (Frankfurt) region
- Marketing / newsletter data (Mailchimp) may be processed in the US under Standard Contractual Clauses
When we transfer personal data outside the UK we rely on UK adequacy regulations, EU adequacy decisions, or on Standard Contractual Clauses approved by the ICO, with additional safeguards where needed.
EU residents: if we process the data of people in the EU, EU GDPR also applies and we will designate an EU representative under Article 27 where required
UAE / Qatar / Saudi residents: processing may also be subject to national data protection laws (e.g. UAE Federal Decree-Law No. 45 of 2021, Qatar's Law No. 13 of 2016, Saudi Personal Data Protection Law); we will comply with applicable local requirements
11. Cookies and similar technologies
We use strictly-necessary cookies required to deliver the site securely. We do not use analytics, advertising, or tracking cookies on the marketing website. Our separate Cookies Notice at https://aevisaglobal.com/cookies explains this in full. If we introduce any non-essential cookies in future, we will request your consent before they are set, as required by PECR and UK GDPR.
12. Children
Neither the website nor the app is directed at children under 18. During Founding 50 pilot signup, app users self-attest age. We do not knowingly collect data from anyone under 18. If you believe someone under 18 has created an account or subscribed, email hello@aevisaglobal.com and we will delete it.
13. Changes to this Policy
We may update this Policy. The "Last updated" date will change, and we will notify you in-app or by email of material changes. Where a change requires it, we will ask for fresh consent.
14. Contact
Aevisa Holdings Ltd.
Unit 19, Maidstone Innovation Centre
Gidds Pond Way, Weavering
Maidstone, Kent ME14 5FY
United Kingdom
General contact: hello@aevisaglobal.com
Data protection queries: hello@aevisaglobal.com
Founder / Data controller point of contact: Dr Paradzai Chitongo, pchitongo@aevisaglobal.com

