Why GetScanned?

High-quality scans, transparent affordable pricing
Quick appointments, seen in 1 to 3 days
GP referral in under 30 minutes
150+ trusted scan centres

Privacy Policy

Last Updated: 27 February 2026

This privacy notice for GetScanned Ltd, trading as CoreVitals and GetScanned (“we”, “us”, or “our”), explains how and why we collect, store, use and share (“process”) personal information when you use our services (“Services”), including when you:

  • Visit our websites at https://uk.getscanned.me/ or https://www.corevitals.me, or any website of ours that links to this privacy notice;
  • Book scans or blood tests, attend consultations, or access results via our Platform; or
  • Engage with us in other related ways, including sales, marketing, or events.

This privacy notice is intended to describe our processing under United Kingdom data protection laws, including the UK GDPR and the Data Protection Act 2018 (each as amended from time to time, including by the Data (Use and Access) Act 2025), the Privacy and Electronic Communications Regulations 2003 (as amended), and other related legislation

Summary of Key Points

Questions or concerns?

If you do not agree with our policies and practices, please do not use our Services. If you have questions or concerns, please contact us at [email protected].

What personal information do we process?
We process personal information depending on how you interact with the Services and what you choose to book or use.

Do we process any sensitive personal information?
Yes. Where necessary to provide the Services, we process health information (special category personal data) and (where relevant) payment information.

Do we collect any information from third parties?
Yes. Depending on the Service you use, we may receive information from our clinical and operational partners (for example, scan centres, radiologists, diagnostic laboratories, and phlebotomy providers) to deliver Services and provide results.

How do we process your information?
We process personal information to provide and administer the Services, communicate with you, provide access to results and consultations, keep systems secure, prevent fraud, and comply with legal obligations.

Do you transfer or allow access to information internationally?
We are UK-based. Some members of our operations and development team are located in India and may access personal information strictly on a need-to-know basis with appropriate safeguards. Details are set out in Section 6.

How do we keep your information safe?
We apply appropriate technical and organisational measures. However, no system can be guaranteed to be 100% secure.

What are your rights?
Depending on your location (including the UK/EEA/Switzerland), you may have rights to access, correct, delete, restrict or object to processing, and other rights explained in Section 12.

TABLE OF CONTENTS

  1. WHAT INFORMATION DO WE COLLECT?
  2. HOW DO WE PROCESS YOUR INFORMATION?
  3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR PERSONAL INFORMATION?
  4. AUTOMATED PROCESSING
  5. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?
  6. CROSS-BORDER TRANSFERS
  7. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?
  8. HOW LONG DO WE KEEP YOUR INFORMATION?
  9. HOW DO WE KEEP YOUR INFORMATION SAFE?
  10. SERVICES USED BY CHILDREN / MINORS
  11. ANONYMISED AND AGGREGATED DATA
  12. WHAT ARE YOUR PRIVACY RIGHTS?
  13. CONTROLS FOR DO-NOT-TRACK FEATURES
  14. DO WE MAKE UPDATES TO THIS NOTICE?
  15. HOW TO MAKE A PRIVACY COMPLAINT
  16. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

ANNEXURE A — Clinical and Operational Partners

ANNEXURE B — List of Sub-processors

  1. WHAT INFORMATION DO WE COLLECT?
  1. Personal information you disclose to us

We collect personal information you provide to us.

For example, we collect personal information you voluntarily provide when you create an account, book Services, attend consultations, request support, or otherwise contact us.

Personal information may include (depending on the Service):

  • Names
  • Phone number
  • Email address
  • Mailing address
  • Contact preferences
  • Account / authentication data
  • Billing address and payment details (where applicable)
  • Date of birth
  • Insurance information (where applicable)
  • Service details (e.g., scan type; appointment preferences)

Where a parent or legal guardian books Services for a child, we may also collect personal information about the child as necessary to deliver the Services.

  1. Sensitive information (special category personal data)

Where necessary to provide the Services, and where permitted by applicable law, we process:

  • Health information (e.g., biomarkers, results, reports, referrals, clinical notes, imaging and related metadata); and
  • Financial information (e.g., payment details) where applicable.
  1. Information automatically collected

Some information is collected automatically when you use our Services.

We automatically collect certain technical information when you visit, use, or navigate the Services (for example: IP address, device/browser characteristics, operating system, language preferences, referring URLs, country/location, and usage information). This information helps maintain security and operation of our Services, and supports analytics and reporting.

Automatic data may include:

  • Log and Usage Data (e.g., timestamps, pages viewed, actions taken, error reports)
  • Device Data (e.g., device identifiers, browser type, ISP/mobile carrier, OS)
  • Location Data (precise or imprecise depending on your device/settings; you can disable location sharing, but some features may be affected)
  1. HOW DO WE PROCESS YOUR INFORMATION?

We process personal information to provide and administer Services, communicate with you, keep systems secure, and comply with law.

We process personal information for purposes that include:

  • To deliver and facilitate delivery of Services (including bookings, scheduling, results access, and consultations).
  • To respond to enquiries and provide support.
  • To send administrative information (service messages, changes to terms/policies, operational updates).
  • To fulfil and manage orders and payments (where applicable).
  • To maintain platform security, prevent fraud, and troubleshoot.
  • To address urgent outcomes and protect vital interests where necessary (for example, urgent clinical results requiring immediate contact and follow-up).
  • To comply with legal obligations and to establish, exercise or defend legal claims.
  1. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR INFORMATION?

We process personal information only where we have a lawful basis under UK Data Protection Laws. Where we process health information, we also rely on a special category condition.

3.1. Lawful basis for personal information (UK GDPR Article 6)
What we use your information forExamples of personal informationOur legal basisWhy this is necessary

Create your account and provide the Platform

Name, email/phone, login credentials, basic profile

Performance of a Contract (to provide the Services you request)

When you sign up or use our Platform, you are asking us to provide the Services. We need these details to set up, authenticate, and manage your access.

Take bookings and coordinate your scan/blood test/consultation

Appointment details, preferences, contact details, relevant logistics

Performance of a Contract (to deliver your booking and coordinate Service delivery)

We must process this information to schedule appointments, coordinate providers, and ensure you receive the Service you booked.

Bookings made by a parent/legal guardian for a child

Guardian contact/account info; child identity/booking details

Contract (to provide the Services booked) and/or Legitimate interests (to administer bookings and ensure safety)

To administer the booking, deliver the Services, and communicate with the guardian about instructions, scheduling and results access (where applicable).

Communicate with you about your booking and Service (service messages)

Email/phone, booking status, messages

Performance of a Contract (to run the Service) and/or Legitimate interests (to provide support and service quality)

We need to send confirmations, reminders, instructions, and operational updates so the Service works properly and you receive what you booked.

Payments, invoicing, refunds (where applicable)

Billing address, payment information, transaction records

Performance of a Contract (to take payment for Services) and/or Legal obligation (tax/accounting)

We need to process payment and maintain financial records to charge for Services and meet legal obligations.

Provide customer support and handle complaints

Support messages, call/chat logs, account details

Our legitimate interests (support, service improvement) and sometimes Contract

We need to understand and resolve issues, respond to questions, and improve how the Service operates.

Clinical safety escalation / urgent outcomes (where required)

Contact details and relevant service/clinical flags (as necessary)

Your vital interests (to protect someone’s safety) and/or Contract (to deliver the Service responsibly)

Where an urgent outcome is identified, we may need to contact you promptly and coordinate follow-up steps.

Keep our systems secure; prevent fraud; monitor access

IP address, device info, log data, audit logs, security events

Our legitimate interests (security and integrity) and sometimes our Legal obligation

We need to protect the Platform, prevent misuse, and maintain auditability of access to sensitive information.

Operate and improve the Platform (analytics, debugging, product improvement)

Usage data, device data, feature interactions

Our legitimate interests (improving and maintaining Services) and/or Consent (where required for certain cookies)

We use technical and usage information to understand performance, fix bugs, and improve user experience.

Marketing communications (if used)

Email, preferences, engagement history

Consent (where required) or our legitimate interests (where permitted, with opt-out)

We only send marketing where lawful and you can opt out at any time.

Comply with law and manage disputes

Records, communications, audit logs

Legal obligation and/or our legitimate interests (defend legal claims)

We may need to keep or disclose information to meet legal requirements or to establish, exercise, or defend legal claims.

Where we rely on legitimate interests as our lawful basis, we will carry out a Legitimate Interests Assessment (LIA) to ensure that our interests are not overridden by your rights and interests.

For certain processing activities, in particular, maintaining the security and integrity of our Platform and systems, and preventing fraud and misuse, we may additionally rely on 'recognised legitimate interests' under the Data (Use and Access) Act 2025. Processing for these purposes does not require a separate balancing test, but we continue to apply appropriate safeguards and to process only the minimum information necessary.

Activities where we may rely on recognised legitimate interests include:

  • Keeping our systems and networks secure and detecting, preventing, and investigating misuse or fraud;
  • Logging and monitoring access to systems that hold sensitive personal information; and
  • Ensuring the integrity and availability of the Platform.
3.2. Health information (special category data – UK GDPR Article 9)

Where we process health information, including biomarker results, HL7 reports, scan images, scan reports, referrals, and clinical notes,  we do so primarily on the basis of Article 9(2)(h) UK GDPR, as processing necessary for the purposes of preventive medicine, medical diagnosis, the provision of health care or treatment, and the management of health care systems and services, carried out under the responsibility of GetReal Health Limited, a CQC-registered provider, and the health professionals it engages (Schedule 1, paragraph 2, Data Protection Act 2018). GetScanned Ltd operates under contractual obligations of confidentiality to GetReal Health Limited in respect of all health information processed in this context..

Depending on the context, we may additionally or alternatively rely on one or more of the following conditions, as set out in the table below.

Health-related activityExamples of health information involvedArticle 9 basisWhy this is necessary

Process and display your results in the Platform (CV Bloods)

Biomarker results; HL7 report; result status flags

Health care / health system purposes — as a CQC-registered provider of health care activities (Article 9(2)(h) UK GDPR, Schedule 1, paragraph 2, Data Protection Act 2018

To receive, store, and show your results so the Service you booked can be delivered and viewed.

Process and display scan outputs (Full Body / imaging services)

Scan images (DICOM); scan report; referral form and relevant clinical notes

Health care / health system purposes and/or Explicit consent (where used)

To enable the scan reporting process, results access, and follow-up consultations connected to the Service you have booked.

Facilitate review by GPs and radiologists

Results; reports; relevant clinical notes; referral details

Health care / health system purposes and/or Explicit consent (where used)

So that the clinicians involved in your care can review relevant information, explain findings, and complete reporting and consultations.

Book consultations and communication of consultation notes

Consultation notes; clinical commentary; recommendations

Health care / health system purposes and/or Explicit consent (where used)

To deliver the consultation you requested and record/publish the outcome within the Platform.

Urgent outcome handling / escalation

Urgent findings indicators; limited relevant result details needed to act

Vital interests (where necessary to protect safety) and/or Health care purposes

To contact you promptly and coordinate appropriate next steps where an urgent outcome is identified.

Quality assurance and safety checks linked to clinical workflows

Limited extracts of results/report status; audit/access logs tied to clinical records

Health care / health system purposes and/or Substantial public interest / legal claims (only if applicable to the situation)

To ensure the clinical workflow operates safely, is auditable, and issues can be investigated where needed. Audit logs and quality records may also be retained to establish, exercise, or defend legal claims.

Create anonymised datasets and aggregated statistics (where appropriate)

Anonymised outputs derived from results/reports

Not personal information once anonymised

To support service improvement, quality assurance, research, and analytics using permanently anonymised information that cannot be linked back to any individual.

Explicit consent (Article 9(2)(a))

Although GetScanned's primary Article 9 condition is Article 9(2)(h), we may in some circumstances additionally seek your explicit consent — for example, where a specific use of your health information falls outside the scope of the health care services you have booked, or where we consider it appropriate to do so as a matter of good practice. Where we rely on explicit consent, you can withdraw it at any time by contacting us. Withdrawal of consent does not affect the lawfulness of any processing already carried out on that basis, and does not affect our ability to continue processing under Article 9(2)(h) or any other applicable condition.

Professional confidentiality obligations

Article 9(2)(h) requires that processing be carried out subject to obligations of professional secrecy. The health professionals engaged in delivering the Services are subject to professional and regulatory confidentiality obligations under applicable law and their respective regulatory frameworks. GetScanned Ltd is contractually bound to equivalent obligations of confidentiality by virtue of its arrangements with GetReal Health Limited. Strictly need to know

We only process health information where necessary for the Services you have requested, and we restrict access to health information on a strict need-to-know basis, including within our own organisation and across our clinical and operational partners.

Processor note (business customers)

Where we act as a processor for a business customer, the customer is responsible for identifying and communicating the applicable Article 6 lawful basis and Article 9 condition(s) for their processing. We process personal information in accordance with the customer's documented instructions and the terms of the applicable Data Processing Agreement.

  1. AUTOMATED PROCESSING

We do not make decisions about you that are based solely on automated processing and that produce legal or similarly significant effects on you.

Our platform provides an interactive visual representation of your blood test results as uploaded by you or our laboratory partners. This display function, including any visual indicators such as out-of-range markers, is a presentation tool only. It does not constitute a clinical decision, medical advice, or a diagnosis, and is not intended to be relied upon as such. All clinical interpretation is carried out by qualified healthcare professionals as part of the Services you have booked with such healthcare professionals. For more information, read our General Terms and Conditions.

  1. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

We share personal information only as needed to deliver Services, operate our Platform, and meet legal and safety obligations. We may share personal information with:

5.1. Scan centres and radiology providers (imaging services)

Where you book a scan, we may share the necessary information with the scan centre (and their radiologists) to arrange appointments, complete safety checks, perform the scan, and generate scan reports. We may receive scan images and reports back from the scan centre (typically via secure clinical transfer tools used in healthcare settings).

5.2. Diagnostic laboratories and phlebotomy providers (CV Bloods)

Where you book a blood test, we may share the necessary information with relevant providers to arrange kits, appointments, nurse visits (if applicable), sample processing and results reporting. We may receive results back (including HL7 reports) for display in our systems and to enable clinical review.

5.3. Clinicians (GPs and nutritionists)

We may make relevant information available to the clinician(s) involved in your consultation(s) so they can provide consultations, explain results, and make recommendations. Access is granted on a strict need-to-know basis.

5.4. Platform and support providers (sub-processors)

We use vendors who support hosting, communications, customer support, security, analytics, collaboration tools and other operational functions. These providers process personal information only on our instructions and subject to contractual safeguards. A list of key providers is set out in Annexure “B”.

5.5. Corporate transactions and legal requirements

We may share personal information where required for a merger or acquisition, to comply with law, respond to lawful requests, or to protect rights, property and safety.

  1. CROSS-BORDER TRANSFERS

We are based in the United Kingdom. However, some of our operations and development team are located in India and may access personal information on a controlled basis.

6.1. Where information is accessed from

Personal information we process may be accessed from the United Kingdom and, where required for operational support or product development, from India.

6.2. India-based team members are our employees

Our India-based team members are employees of GetScanned Ltd (not third-party providers). They access personal information only where required for their role and only through controlled systems.

6.3. Safeguards we apply

We apply appropriate technical and organisational measures to protect personal information accessed from India, including (as applicable):

  • role-based access controls and least-privilege permissions;
  • access approvals and need-to-know limitations;
  • strong authentication and secure access methods;
  • logging and monitoring of access; and
  • secure development and change-management practices.
6.4. Other cross-border transfers

Some service providers listed in Annexure B may process personal information outside the UK.

When transferring personal information outside the United Kingdom, we comply with applicable UK data protection law, including the requirements introduced by the Data (Use and Access) Act 2025. In particular:

  • Where the Secretary of State has made an adequacy regulation determining that a third country, territory, or international organisation ensures a level of protection for personal information that is not materially lower than that provided under UK data protection law, we may transfer personal information to that destination on that basis.
  • Where no such adequacy regulation applies, we use appropriate safeguards, including the UK International Data Transfer Agreement (UK IDTA) or the UK Addendum to the EU Standard Contractual Clauses (UK Addendum to SCCs), as approved by the Information Commission, to ensure personal information transferred outside the UK receives an equivalent level of protection.

You may request more information about the applicable transfer mechanism by contacting us

6.5. Business-to-business customers (processor arrangements)

Where we provide Services to a business customer and act as a processor, the customer’s principal agreement will address the relevant international access/transfers position. Where required for restricted transfer elements, we will enter an appropriate UK transfer mechanism with the customer (for example, the UK IDTA or the UK Addendum to the EU SCCs), together with appropriate technical and organisational controls.

  1. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?

We may use cookies and similar technologies.

We use analytics cookies (including Google Analytics) to understand how our Services are used, monitor performance, and improve user experience. Under the Data (Use and Access) Act 2025, analytics cookies that are low-risk and do not involve tracking across third-party sites may be used without your prior consent, provided we make it easy for you to opt out.

You can opt out of Google Analytics tracking at any time by visiting: https://tools.google.com/dlpage/gaoptout

For more information on the privacy practices of Google, please visit the Google Privacy & Terms.

  1. HOW LONG DO WE KEEP YOUR INFORMATION?

We keep personal information for as long as necessary for the purposes described, unless a longer period is required or permitted by law.

We retain personal information only for as long as necessary to fulfil the purposes set out in this notice, unless a longer retention period is required or permitted by law (e.g., tax/accounting, regulatory, or legal requirements). Where deletion is not immediately possible (e.g., backups), we will securely store and isolate the data until deletion is possible.

  1. HOW DO WE KEEP YOUR INFORMATION SAFE?

We apply organisational and technical measures to protect personal information.

We use appropriate and reasonable technical and organisational security measures designed to protect personal information. We may publish and update certain security-related  information available on our website from time to time.

However, no electronic transmission or storage can be guaranteed to be 100% secure. You use the Services at your own risk and should access them from a secure environment.

  1. SERVICES USED BY CHILDREN / MINORS

Our Services are primarily designed for use by adults. However, a parent or legal guardian may book certain Services for a child.

10.1 Our approach to children's privacy

We recognise that children merit specific protection when their personal information — including health information — is processed, given that they may be less aware of the risks involved and of their rights. In accordance with the Data (Use and Access) Act 2025 and UK GDPR, we take the following approach when designing and operating Services that may involve children:

  • We apply privacy-by-design principles to limit data collection to what is strictly necessary to deliver the booked Service;
  • Access to children's personal information (including health information) is restricted on a strict need-to-know basis;
  • We do not use children's personal information for marketing or profiling purposes; and
  • We apply additional safeguards when processing children's health information, including audit logging and access approvals.
10.2 Bookings by parents and legal guardians

Where a parent or legal guardian books Services for a child, we may collect and process:

  • The parent/legal guardian's contact and account details; and
  • The child's information necessary to deliver the Services (which may include health information such as scan results or biomarker data).

By booking Services for a child, the parent or legal guardian confirms that they:

  • Are the child's parent or legal guardian (or otherwise have authority to make the booking); and
  • Have authority to provide the child's personal information to us and to the relevant clinical and operational partners involved in delivering the Services.
10.3 If we become aware of a problem

If we become aware that a child's personal information has been provided to us without appropriate parental or legal guardian authority, we will take reasonable steps to investigate and, where appropriate, delete or restrict access to the information. To raise a concern, contact [email protected].

  1. ANONYMISED AND AGGREGATED DATA

We may permanently transform health information into an anonymised form so it can no longer be used to identify you. We use anonymised and aggregated insights to improve our Services.

Anonymised” means information has been processed so that it can no longer identify you, and we do not attempt to re-identify you. Where information remains capable of being linked back to you (for example, via a key), it is not anonymised and continues to be treated as personal information.

Once information has been genuinely anonymised in accordance with the standard described above, it is no longer personal information and falls outside the scope of UK data protection law, including the UK GDPR and the Data (Use and Access) Act 2025. We apply this standard consistently and do not treat pseudonymised data (where a key could link information back to you) as anonymised.

Where we use anonymised or aggregated information for research or analytical purposes, this may include commercial research and product development purposes. In all cases, we apply safeguards to minimise the risk of re-identification, including data minimisation, access controls, and restricting outputs to aggregated or statistical formats. We do not attempt to re-identify anonymised information.

  1. WHAT ARE YOUR PRIVACY RIGHTS?

If you are located in the UK/EEA/Switzerland, you may have rights under applicable data protection laws, which may include:

  • access to your personal information;
  • rectification;
  • erasure;
  • restriction;
  • objection;
  • data portability (where applicable); and
  • withdraw your consent (where applicable).

You can exercise your rights by contacting us using the details in Section 16. You also have the right to lodge a complaint with the Information Commission (formerly the Information Commissioner's Office / ICO) at www.ico.org.uk if you believe we are unlawfully processing your personal information.

Marketing opt-out: You can opt out of marketing emails at any time (unsubscribe link or contact us). We may still send service-related communications.

  1. CONTROLS FOR DO-NOT-TRACK FEATURES

We currently do not respond to Do-Not-Track signals because no uniform standard has been adopted. If a standard is adopted that we must follow, we will update this notice.

  1. DO WE MAKE UPDATES TO THIS NOTICE?

We may update this notice from time to time. The updated version will be indicated by an updated “Last Updated” date. If we make material changes, we may notify you via the Services, by email or by other appropriate means.

  1. HOW TO MAKE A PRIVACY COMPLAINT (Internal Complaints Procedure)

We take privacy complaints seriously and are committed to resolving them promptly and fairly.

How to submit a complaint

If you have a concern about how we have handled your personal information, please contact us in writing:

Jactin House

24 Hood Street

Ancoats M4 6WX

Please include your name, contact details, a description of your concern, and (if applicable) what outcome you are seeking.

What happens next

We will acknowledge receipt of your complaint within 30 days of receiving it. We will then investigate your complaint and aim to provide a substantive response as quickly as reasonably practicable.

If you remain dissatisfied

If you are not satisfied with our response, or if we fail to respond within a reasonable period, you have the right to escalate your complaint to the Information Commission (formerly the ICO) at any time:

  • Website: www.ico.org.uk 
  • Telephone: 0303 123 1113
  • Post: Information Commission, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

Making a complaint to us does not affect your right to complain directly to the Information Commission at any time.

If you are a resident in the United Kingdom, we are the 'data controller’ of your personal information. We have appointed Adil Mohammed to be our representative in the UK.

You can contact our representative directly regarding our processing of your information, by email or post, using the same contact details above.

  1. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

Depending on applicable law and your location, you may have the right to:

  • Request access to the personal information we hold about you (a 'Subject Access Request' or SAR);
  • Request correction of inaccurate or incomplete personal information;
  • Request deletion or restriction of your personal information; or
  • Exercise any other right set out in Section 12.

How to make a request

To make a request, please contact us at:

Jactin House

24 Hood Street

Ancoats M4 6WX

Please include your full name, contact details, and a clear description of what you are requesting so we can locate the relevant information and respond effectively.

How we respond

We will respond to your request within one calendar month of receiving it. Where your request is complex or we receive a high volume of requests, we may extend this period by up to a further two months; if so, we will notify you within the first month.

Where we need clarification or additional information from you to process your request, we may pause the response period until we receive what we need. We will contact you promptly to explain what information is required.

We will search for your personal information in a reasonable and proportionate manner, having regard to the nature and scope of your request.

Verification

To protect your privacy, we may need to verify your identity before processing your request. We will ask for the minimum information necessary to do so.

No fee

We do not usually charge a fee for subject access requests. However, we reserve the right to charge a reasonable administrative fee, or to decline a request, where it is manifestly unfounded or excessive.

ANNEXURE A — Clinical and Operational Partners

This table describes parties involved in delivering scans/bloods/consults. Many of these will be independent controllers for their own clinical services. Where they process personal information based on our instructions, they are our processors.

Partner

Category

Role

What they do

Data they receive from us

Data we receive back

Processing locations

GetReal Health Limited

Clinical governance / CQC-registered provider

Controller

Holds the CQC registration under which regulated clinical activities are currently delivered; contracts and manages the clinicians engaged for consultations and reporting. GetScanned Ltd processes health information under its responsibility and is subject to contractual confidentiality obligations.

Customer identity/contact; booking details; results, reports and referrals needed for clinical review.

Consultation notes; referrals; clinical commentary; reporting outputs

UK

Tuli Health Ltd

Pharmacy partner

Controller

Pharmacy blood draw appointments.

Customer identity/contact; appointment booking details; kit/order reference (as applicable).

Appointment confirmation/status (as applicable)

UK

Inuvi Diagnostics Ltd

Lab, kits, nurse network

Processor

Ships kits; arranges nurse visits; processes samples; issues HL7 report.

Customer identity/contact; address; booking details; request details; health context necessary to fulfil test.

HL7 report; test status; logistics status

UK

Scan centre(s)

Scan provider

Controller

Performs scan; safety questionnaire; protocols scan; radiology reporting.

Identity/contact; referral; appointment details; safety info.

Images (DICOM) + scan report

UK

Radiologist org / radiologists (entity or individuals)

Radiology

Controller

Views images; produces report.

Images; referral; relevant notes.

Report; clarifications

UK

GPs

Clinicians

Controller

Consults; referrals; explains results; urgent escalation.

Relevant results; referral/report; contact details.

Referral form; consult notes; messages

UK

Nutritionists

Clinicians

Controller

Consults; recommendations/supplement plan.

Relevant biomarker results; consult notes.

Nutrition notes; recommendations

UK

ANNEXURE B — List of Sub-processors

This Annexure details the list of Sub-processors material to GetScanned’s provision of the Services. Depending upon a Customer’s use of the Services e.g. geographical location of the Customer and the type of Services used, not all Sub-Processors will be needed to deliver the Services.

Sub-processorService / productTypical data processedProcessing location(s)

Amazon Web Services, Inc.

Hosting / infrastructure

Platform data; logs; files

 EU

Atlassian Pty Ltd

Jira / Confluence - Internal tooling used for project and tasks management and as knowledge base.

Support tickets; project/admin content; customer identifiers (if included in tickets)

United States / EU

Bueno Technologies Inc

CallHippo

Cloud Telephony and Customer support

Call metadata; recordings

United States

Figma (No customer PI)

Product design

Design files; screenshots (no real customer data)

United States

GitHub, Inc (no customer PI)

Code Management and Repository

Developer/repo metadata; limited personal data (primarily staff)

United States

Google LLC.

Workspace, Cloud, Analytics

Cloud Service Provider, Analytics, Email, File Storage

Email content; documents; meeting links and communications metadata

United States

Intercom, Inc.

Customer Support, Email

Contact details; support messages; service metadata

United States

Microsoft Corporation
Microsoft Azure

Hosting / infrastructure

Platform data; logs

United Kingdom

Miro (no customer PI)

Team planning and collaboration tool

Collaboration content (no real customer data)

United States

Notion Labs, Inc  (no customer PI)

Internal documentation

Internal docs; operational content

United States

PayPal

Payment processing merchant

PCI-compliant payment processing service provider

United States

Red Guava Pty Ltd

Cliniko

Clinic/admin workflow tool

Appointments; referrals; admin notes

United Kingdom

Slack Technologies, Inc

Internal collaborative and instant messaging tool

Internal messages; may include customer info if shared by staff

United States

Stripe Payments Europe, Ltd.

Customer Billing, Subscription Management

Billing and invoicing data (customer identifiers and contact details, billing address, subscription status, invoices and payment history) and payment method data, fraud/security metadata (IP address, device and transaction signals).

United Kingdom

Trengo B.V

Customer support / messaging

Contact details; support messages; service metadata

Netherlands (Utrecht)

Twilio, Inc.

Sendgrid

Transactional Email

Email addresses; message metadata; email content

United States

Xero Limited

Accounting / invoicing

Billing and invoice data (non-health data)

United Kingdom

GetScanned is a direct booking platform for private medical scans across the UK.
We help patients, clinicians, and businesses find and book scans at trusted clinics nearby.

CQC Services provided by Get Real Health Limited
© 2026 GetScanned Ltd - Company registration no. 15634790

Jactin House, 24 Hood Street, Ancoats, Manchester M4 6WX