Why GetScanned?
Last Updated: 27 February 2026
This privacy notice for GetScanned Ltd, trading as CoreVitals and GetScanned (“we”, “us”, or “our”), explains how and why we collect, store, use and share (“process”) personal information when you use our services (“Services”), including when you:
This privacy notice is intended to describe our processing under United Kingdom data protection laws, including the UK GDPR and the Data Protection Act 2018 (each as amended from time to time, including by the Data (Use and Access) Act 2025), the Privacy and Electronic Communications Regulations 2003 (as amended), and other related legislation
Summary of Key Points
Questions or concerns?
If you do not agree with our policies and practices, please do not use our Services. If you have questions or concerns, please contact us at [email protected].
What personal information do we process?
We process personal information depending on how you interact with the Services and what you choose to book or use.
Do we process any sensitive personal information?
Yes. Where necessary to provide the Services, we process health information (special category personal data) and (where relevant) payment information.
Do we collect any information from third parties?
Yes. Depending on the Service you use, we may receive information from our clinical and operational partners (for example, scan centres, radiologists, diagnostic laboratories, and phlebotomy providers) to deliver Services and provide results.
How do we process your information?
We process personal information to provide and administer the Services, communicate with you, provide access to results and consultations, keep systems secure, prevent fraud, and comply with legal obligations.
Do you transfer or allow access to information internationally?
We are UK-based. Some members of our operations and development team are located in India and may access personal information strictly on a need-to-know basis with appropriate safeguards. Details are set out in Section 6.
How do we keep your information safe?
We apply appropriate technical and organisational measures. However, no system can be guaranteed to be 100% secure.
What are your rights?
Depending on your location (including the UK/EEA/Switzerland), you may have rights to access, correct, delete, restrict or object to processing, and other rights explained in Section 12.
TABLE OF CONTENTS
ANNEXURE A — Clinical and Operational Partners
ANNEXURE B — List of Sub-processors
We collect personal information you provide to us.
For example, we collect personal information you voluntarily provide when you create an account, book Services, attend consultations, request support, or otherwise contact us.
Personal information may include (depending on the Service):
Where a parent or legal guardian books Services for a child, we may also collect personal information about the child as necessary to deliver the Services.
Where necessary to provide the Services, and where permitted by applicable law, we process:
Some information is collected automatically when you use our Services.
We automatically collect certain technical information when you visit, use, or navigate the Services (for example: IP address, device/browser characteristics, operating system, language preferences, referring URLs, country/location, and usage information). This information helps maintain security and operation of our Services, and supports analytics and reporting.
Automatic data may include:
We process personal information to provide and administer Services, communicate with you, keep systems secure, and comply with law.
We process personal information for purposes that include:
We process personal information only where we have a lawful basis under UK Data Protection Laws. Where we process health information, we also rely on a special category condition.
3.1. Lawful basis for personal information (UK GDPR Article 6)| What we use your information for | Examples of personal information | Our legal basis | Why this is necessary |
|---|---|---|---|
Create your account and provide the Platform | Name, email/phone, login credentials, basic profile | Performance of a Contract (to provide the Services you request) | When you sign up or use our Platform, you are asking us to provide the Services. We need these details to set up, authenticate, and manage your access. |
Take bookings and coordinate your scan/blood test/consultation | Appointment details, preferences, contact details, relevant logistics | Performance of a Contract (to deliver your booking and coordinate Service delivery) | We must process this information to schedule appointments, coordinate providers, and ensure you receive the Service you booked. |
Bookings made by a parent/legal guardian for a child | Guardian contact/account info; child identity/booking details | Contract (to provide the Services booked) and/or Legitimate interests (to administer bookings and ensure safety) | To administer the booking, deliver the Services, and communicate with the guardian about instructions, scheduling and results access (where applicable). |
Communicate with you about your booking and Service (service messages) | Email/phone, booking status, messages | Performance of a Contract (to run the Service) and/or Legitimate interests (to provide support and service quality) | We need to send confirmations, reminders, instructions, and operational updates so the Service works properly and you receive what you booked. |
Payments, invoicing, refunds (where applicable) | Billing address, payment information, transaction records | Performance of a Contract (to take payment for Services) and/or Legal obligation (tax/accounting) | We need to process payment and maintain financial records to charge for Services and meet legal obligations. |
Provide customer support and handle complaints | Support messages, call/chat logs, account details | Our legitimate interests (support, service improvement) and sometimes Contract | We need to understand and resolve issues, respond to questions, and improve how the Service operates. |
Clinical safety escalation / urgent outcomes (where required) | Contact details and relevant service/clinical flags (as necessary) | Your vital interests (to protect someone’s safety) and/or Contract (to deliver the Service responsibly) | Where an urgent outcome is identified, we may need to contact you promptly and coordinate follow-up steps. |
Keep our systems secure; prevent fraud; monitor access | IP address, device info, log data, audit logs, security events | Our legitimate interests (security and integrity) and sometimes our Legal obligation | We need to protect the Platform, prevent misuse, and maintain auditability of access to sensitive information. |
Operate and improve the Platform (analytics, debugging, product improvement) | Usage data, device data, feature interactions | Our legitimate interests (improving and maintaining Services) and/or Consent (where required for certain cookies) | We use technical and usage information to understand performance, fix bugs, and improve user experience. |
Marketing communications (if used) | Email, preferences, engagement history | Consent (where required) or our legitimate interests (where permitted, with opt-out) | We only send marketing where lawful and you can opt out at any time. |
Comply with law and manage disputes | Records, communications, audit logs | Legal obligation and/or our legitimate interests (defend legal claims) | We may need to keep or disclose information to meet legal requirements or to establish, exercise, or defend legal claims. |
Where we rely on legitimate interests as our lawful basis, we will carry out a Legitimate Interests Assessment (LIA) to ensure that our interests are not overridden by your rights and interests.
For certain processing activities, in particular, maintaining the security and integrity of our Platform and systems, and preventing fraud and misuse, we may additionally rely on 'recognised legitimate interests' under the Data (Use and Access) Act 2025. Processing for these purposes does not require a separate balancing test, but we continue to apply appropriate safeguards and to process only the minimum information necessary.
Activities where we may rely on recognised legitimate interests include:
Where we process health information, including biomarker results, HL7 reports, scan images, scan reports, referrals, and clinical notes, we do so primarily on the basis of Article 9(2)(h) UK GDPR, as processing necessary for the purposes of preventive medicine, medical diagnosis, the provision of health care or treatment, and the management of health care systems and services, carried out under the responsibility of GetReal Health Limited, a CQC-registered provider, and the health professionals it engages (Schedule 1, paragraph 2, Data Protection Act 2018). GetScanned Ltd operates under contractual obligations of confidentiality to GetReal Health Limited in respect of all health information processed in this context..
Depending on the context, we may additionally or alternatively rely on one or more of the following conditions, as set out in the table below.
| Health-related activity | Examples of health information involved | Article 9 basis | Why this is necessary |
|---|---|---|---|
Process and display your results in the Platform (CV Bloods) | Biomarker results; HL7 report; result status flags | Health care / health system purposes — as a CQC-registered provider of health care activities (Article 9(2)(h) UK GDPR, Schedule 1, paragraph 2, Data Protection Act 2018 | To receive, store, and show your results so the Service you booked can be delivered and viewed. |
Process and display scan outputs (Full Body / imaging services) | Scan images (DICOM); scan report; referral form and relevant clinical notes | Health care / health system purposes and/or Explicit consent (where used) | To enable the scan reporting process, results access, and follow-up consultations connected to the Service you have booked. |
Facilitate review by GPs and radiologists | Results; reports; relevant clinical notes; referral details | Health care / health system purposes and/or Explicit consent (where used) | So that the clinicians involved in your care can review relevant information, explain findings, and complete reporting and consultations. |
Book consultations and communication of consultation notes | Consultation notes; clinical commentary; recommendations | Health care / health system purposes and/or Explicit consent (where used) | To deliver the consultation you requested and record/publish the outcome within the Platform. |
Urgent outcome handling / escalation | Urgent findings indicators; limited relevant result details needed to act | Vital interests (where necessary to protect safety) and/or Health care purposes | To contact you promptly and coordinate appropriate next steps where an urgent outcome is identified. |
Quality assurance and safety checks linked to clinical workflows | Limited extracts of results/report status; audit/access logs tied to clinical records | Health care / health system purposes and/or Substantial public interest / legal claims (only if applicable to the situation) | To ensure the clinical workflow operates safely, is auditable, and issues can be investigated where needed. Audit logs and quality records may also be retained to establish, exercise, or defend legal claims. |
Create anonymised datasets and aggregated statistics (where appropriate) | Anonymised outputs derived from results/reports | Not personal information once anonymised | To support service improvement, quality assurance, research, and analytics using permanently anonymised information that cannot be linked back to any individual. |
Explicit consent (Article 9(2)(a))
Although GetScanned's primary Article 9 condition is Article 9(2)(h), we may in some circumstances additionally seek your explicit consent — for example, where a specific use of your health information falls outside the scope of the health care services you have booked, or where we consider it appropriate to do so as a matter of good practice. Where we rely on explicit consent, you can withdraw it at any time by contacting us. Withdrawal of consent does not affect the lawfulness of any processing already carried out on that basis, and does not affect our ability to continue processing under Article 9(2)(h) or any other applicable condition.
Professional confidentiality obligations
Article 9(2)(h) requires that processing be carried out subject to obligations of professional secrecy. The health professionals engaged in delivering the Services are subject to professional and regulatory confidentiality obligations under applicable law and their respective regulatory frameworks. GetScanned Ltd is contractually bound to equivalent obligations of confidentiality by virtue of its arrangements with GetReal Health Limited. Strictly need to know
We only process health information where necessary for the Services you have requested, and we restrict access to health information on a strict need-to-know basis, including within our own organisation and across our clinical and operational partners.
Processor note (business customers)
Where we act as a processor for a business customer, the customer is responsible for identifying and communicating the applicable Article 6 lawful basis and Article 9 condition(s) for their processing. We process personal information in accordance with the customer's documented instructions and the terms of the applicable Data Processing Agreement.
We do not make decisions about you that are based solely on automated processing and that produce legal or similarly significant effects on you.
Our platform provides an interactive visual representation of your blood test results as uploaded by you or our laboratory partners. This display function, including any visual indicators such as out-of-range markers, is a presentation tool only. It does not constitute a clinical decision, medical advice, or a diagnosis, and is not intended to be relied upon as such. All clinical interpretation is carried out by qualified healthcare professionals as part of the Services you have booked with such healthcare professionals. For more information, read our General Terms and Conditions.
We share personal information only as needed to deliver Services, operate our Platform, and meet legal and safety obligations. We may share personal information with:
5.1. Scan centres and radiology providers (imaging services)Where you book a scan, we may share the necessary information with the scan centre (and their radiologists) to arrange appointments, complete safety checks, perform the scan, and generate scan reports. We may receive scan images and reports back from the scan centre (typically via secure clinical transfer tools used in healthcare settings).
5.2. Diagnostic laboratories and phlebotomy providers (CV Bloods)Where you book a blood test, we may share the necessary information with relevant providers to arrange kits, appointments, nurse visits (if applicable), sample processing and results reporting. We may receive results back (including HL7 reports) for display in our systems and to enable clinical review.
5.3. Clinicians (GPs and nutritionists)We may make relevant information available to the clinician(s) involved in your consultation(s) so they can provide consultations, explain results, and make recommendations. Access is granted on a strict need-to-know basis.
5.4. Platform and support providers (sub-processors)We use vendors who support hosting, communications, customer support, security, analytics, collaboration tools and other operational functions. These providers process personal information only on our instructions and subject to contractual safeguards. A list of key providers is set out in Annexure “B”.
5.5. Corporate transactions and legal requirementsWe may share personal information where required for a merger or acquisition, to comply with law, respond to lawful requests, or to protect rights, property and safety.
We are based in the United Kingdom. However, some of our operations and development team are located in India and may access personal information on a controlled basis.
6.1. Where information is accessed fromPersonal information we process may be accessed from the United Kingdom and, where required for operational support or product development, from India.
6.2. India-based team members are our employeesOur India-based team members are employees of GetScanned Ltd (not third-party providers). They access personal information only where required for their role and only through controlled systems.
6.3. Safeguards we applyWe apply appropriate technical and organisational measures to protect personal information accessed from India, including (as applicable):
Some service providers listed in Annexure B may process personal information outside the UK.
When transferring personal information outside the United Kingdom, we comply with applicable UK data protection law, including the requirements introduced by the Data (Use and Access) Act 2025. In particular:
You may request more information about the applicable transfer mechanism by contacting us
6.5. Business-to-business customers (processor arrangements)Where we provide Services to a business customer and act as a processor, the customer’s principal agreement will address the relevant international access/transfers position. Where required for restricted transfer elements, we will enter an appropriate UK transfer mechanism with the customer (for example, the UK IDTA or the UK Addendum to the EU SCCs), together with appropriate technical and organisational controls.
We may use cookies and similar technologies.
We use analytics cookies (including Google Analytics) to understand how our Services are used, monitor performance, and improve user experience. Under the Data (Use and Access) Act 2025, analytics cookies that are low-risk and do not involve tracking across third-party sites may be used without your prior consent, provided we make it easy for you to opt out.
You can opt out of Google Analytics tracking at any time by visiting: https://tools.google.com/dlpage/gaoptout
For more information on the privacy practices of Google, please visit the Google Privacy & Terms.
We keep personal information for as long as necessary for the purposes described, unless a longer period is required or permitted by law.
We retain personal information only for as long as necessary to fulfil the purposes set out in this notice, unless a longer retention period is required or permitted by law (e.g., tax/accounting, regulatory, or legal requirements). Where deletion is not immediately possible (e.g., backups), we will securely store and isolate the data until deletion is possible.
We apply organisational and technical measures to protect personal information.
We use appropriate and reasonable technical and organisational security measures designed to protect personal information. We may publish and update certain security-related information available on our website from time to time.
However, no electronic transmission or storage can be guaranteed to be 100% secure. You use the Services at your own risk and should access them from a secure environment.
Our Services are primarily designed for use by adults. However, a parent or legal guardian may book certain Services for a child.
10.1 Our approach to children's privacyWe recognise that children merit specific protection when their personal information — including health information — is processed, given that they may be less aware of the risks involved and of their rights. In accordance with the Data (Use and Access) Act 2025 and UK GDPR, we take the following approach when designing and operating Services that may involve children:
Where a parent or legal guardian books Services for a child, we may collect and process:
By booking Services for a child, the parent or legal guardian confirms that they:
If we become aware that a child's personal information has been provided to us without appropriate parental or legal guardian authority, we will take reasonable steps to investigate and, where appropriate, delete or restrict access to the information. To raise a concern, contact [email protected].
We may permanently transform health information into an anonymised form so it can no longer be used to identify you. We use anonymised and aggregated insights to improve our Services.
“Anonymised” means information has been processed so that it can no longer identify you, and we do not attempt to re-identify you. Where information remains capable of being linked back to you (for example, via a key), it is not anonymised and continues to be treated as personal information.
Once information has been genuinely anonymised in accordance with the standard described above, it is no longer personal information and falls outside the scope of UK data protection law, including the UK GDPR and the Data (Use and Access) Act 2025. We apply this standard consistently and do not treat pseudonymised data (where a key could link information back to you) as anonymised.
Where we use anonymised or aggregated information for research or analytical purposes, this may include commercial research and product development purposes. In all cases, we apply safeguards to minimise the risk of re-identification, including data minimisation, access controls, and restricting outputs to aggregated or statistical formats. We do not attempt to re-identify anonymised information.
If you are located in the UK/EEA/Switzerland, you may have rights under applicable data protection laws, which may include:
You can exercise your rights by contacting us using the details in Section 16. You also have the right to lodge a complaint with the Information Commission (formerly the Information Commissioner's Office / ICO) at www.ico.org.uk if you believe we are unlawfully processing your personal information.
Marketing opt-out: You can opt out of marketing emails at any time (unsubscribe link or contact us). We may still send service-related communications.
We currently do not respond to Do-Not-Track signals because no uniform standard has been adopted. If a standard is adopted that we must follow, we will update this notice.
We may update this notice from time to time. The updated version will be indicated by an updated “Last Updated” date. If we make material changes, we may notify you via the Services, by email or by other appropriate means.
We take privacy complaints seriously and are committed to resolving them promptly and fairly.
How to submit a complaintIf you have a concern about how we have handled your personal information, please contact us in writing:
Jactin House
24 Hood Street
Ancoats M4 6WX
Please include your name, contact details, a description of your concern, and (if applicable) what outcome you are seeking.
What happens nextWe will acknowledge receipt of your complaint within 30 days of receiving it. We will then investigate your complaint and aim to provide a substantive response as quickly as reasonably practicable.
If you remain dissatisfiedIf you are not satisfied with our response, or if we fail to respond within a reasonable period, you have the right to escalate your complaint to the Information Commission (formerly the ICO) at any time:
Making a complaint to us does not affect your right to complain directly to the Information Commission at any time.
If you are a resident in the United Kingdom, we are the 'data controller’ of your personal information. We have appointed Adil Mohammed to be our representative in the UK.
You can contact our representative directly regarding our processing of your information, by email or post, using the same contact details above.
Depending on applicable law and your location, you may have the right to:
How to make a request
To make a request, please contact us at:
Jactin House
24 Hood Street
Ancoats M4 6WX
Please include your full name, contact details, and a clear description of what you are requesting so we can locate the relevant information and respond effectively.
How we respond
We will respond to your request within one calendar month of receiving it. Where your request is complex or we receive a high volume of requests, we may extend this period by up to a further two months; if so, we will notify you within the first month.
Where we need clarification or additional information from you to process your request, we may pause the response period until we receive what we need. We will contact you promptly to explain what information is required.
We will search for your personal information in a reasonable and proportionate manner, having regard to the nature and scope of your request.
Verification
To protect your privacy, we may need to verify your identity before processing your request. We will ask for the minimum information necessary to do so.
No fee
We do not usually charge a fee for subject access requests. However, we reserve the right to charge a reasonable administrative fee, or to decline a request, where it is manifestly unfounded or excessive.
ANNEXURE A — Clinical and Operational PartnersThis table describes parties involved in delivering scans/bloods/consults. Many of these will be independent controllers for their own clinical services. Where they process personal information based on our instructions, they are our processors.
Partner | Category | Role | What they do | Data they receive from us | Data we receive back | Processing locations |
GetReal Health Limited | Clinical governance / CQC-registered provider | Controller | Holds the CQC registration under which regulated clinical activities are currently delivered; contracts and manages the clinicians engaged for consultations and reporting. GetScanned Ltd processes health information under its responsibility and is subject to contractual confidentiality obligations. | Customer identity/contact; booking details; results, reports and referrals needed for clinical review. | Consultation notes; referrals; clinical commentary; reporting outputs | UK |
Tuli Health Ltd | Pharmacy partner | Controller | Pharmacy blood draw appointments. | Customer identity/contact; appointment booking details; kit/order reference (as applicable). | Appointment confirmation/status (as applicable) | UK |
Inuvi Diagnostics Ltd | Lab, kits, nurse network | Processor | Ships kits; arranges nurse visits; processes samples; issues HL7 report. | Customer identity/contact; address; booking details; request details; health context necessary to fulfil test. | HL7 report; test status; logistics status | UK |
Scan centre(s) | Scan provider | Controller | Performs scan; safety questionnaire; protocols scan; radiology reporting. | Identity/contact; referral; appointment details; safety info. | Images (DICOM) + scan report | UK |
Radiologist org / radiologists (entity or individuals) | Radiology | Controller | Views images; produces report. | Images; referral; relevant notes. | Report; clarifications | UK |
GPs | Clinicians | Controller | Consults; referrals; explains results; urgent escalation. | Relevant results; referral/report; contact details. | Referral form; consult notes; messages | UK |
Nutritionists | Clinicians | Controller | Consults; recommendations/supplement plan. | Relevant biomarker results; consult notes. | Nutrition notes; recommendations | UK |
This Annexure details the list of Sub-processors material to GetScanned’s provision of the Services. Depending upon a Customer’s use of the Services e.g. geographical location of the Customer and the type of Services used, not all Sub-Processors will be needed to deliver the Services.
| Sub-processor | Service / product | Typical data processed | Processing location(s) |
|---|---|---|---|
Amazon Web Services, Inc. | Hosting / infrastructure | Platform data; logs; files | EU |
Atlassian Pty Ltd | Jira / Confluence - Internal tooling used for project and tasks management and as knowledge base. | Support tickets; project/admin content; customer identifiers (if included in tickets) | United States / EU |
Bueno Technologies Inc CallHippo | Cloud Telephony and Customer support | Call metadata; recordings | United States |
Figma (No customer PI) | Product design | Design files; screenshots (no real customer data) | United States |
GitHub, Inc (no customer PI) | Code Management and Repository | Developer/repo metadata; limited personal data (primarily staff) | United States |
Google LLC. Workspace, Cloud, Analytics | Cloud Service Provider, Analytics, Email, File Storage | Email content; documents; meeting links and communications metadata | United States |
Intercom, Inc. | Customer Support, Email | Contact details; support messages; service metadata | United States |
Microsoft Corporation | Hosting / infrastructure | Platform data; logs | United Kingdom |
Miro (no customer PI) | Team planning and collaboration tool | Collaboration content (no real customer data) | United States |
Notion Labs, Inc (no customer PI) | Internal documentation | Internal docs; operational content | United States |
PayPal | Payment processing merchant | PCI-compliant payment processing service provider | United States |
Red Guava Pty Ltd Cliniko | Clinic/admin workflow tool | Appointments; referrals; admin notes | United Kingdom |
Slack Technologies, Inc | Internal collaborative and instant messaging tool | Internal messages; may include customer info if shared by staff | United States |
Stripe Payments Europe, Ltd. | Customer Billing, Subscription Management | Billing and invoicing data (customer identifiers and contact details, billing address, subscription status, invoices and payment history) and payment method data, fraud/security metadata (IP address, device and transaction signals). | United Kingdom |
Trengo B.V | Customer support / messaging | Contact details; support messages; service metadata | Netherlands (Utrecht) |
Twilio, Inc. Sendgrid | Transactional Email | Email addresses; message metadata; email content | United States |
Xero Limited | Accounting / invoicing | Billing and invoice data (non-health data) | United Kingdom |

