GDPR Compliance
Last updated: 1 September 2026
Our Commitment to GDPR
Heath-matrix is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018.
Data Controller
For the purposes of GDPR, the data controller is:
Heath-matrix
47 Clerkenwell Road
London EC1M 5RS
United Kingdom
What Personal Data We Collect
We collect and process the following categories of personal data:
- Identity data: name
- Contact data: email address
- Technical data: IP address, browser type, device information
- Usage data: how you interact with our website
- Communication data: any information you provide in enquiry forms
Lawful Basis for Processing
We process your personal data under the following lawful bases:
- Consent: when you submit forms or accept cookies
- Legitimate interests: to respond to enquiries and improve our services
- Contract: when you engage our services
- Legal obligation: to comply with applicable laws
Your GDPR Rights
Under GDPR, you have the following rights:
Right to Access
You can request a copy of the personal data we hold about you.
Right to Rectification
You can request correction of inaccurate or incomplete data.
Right to Erasure
You can request deletion of your personal data in certain circumstances.
Right to Restriction
You can request that we limit how we use your data.
Right to Data Portability
You can request a copy of your data in a machine-readable format.
Right to Object
You can object to processing based on legitimate interests.
Right to Withdraw Consent
Where processing is based on consent, you can withdraw it at any time.
How to Exercise Your Rights
To exercise any of these rights, send an email to [email protected] with:
- Your full name
- The right you wish to exercise
- Any relevant details to help us locate your data
We will respond to your request within one month. If your request is complex, we may extend this by two additional months and will inform you of the extension.
Data Security
We have implemented appropriate technical and organizational security measures to protect your personal data, including:
- Encryption of data in transit
- Access controls and authentication
- Regular security assessments
- Staff training on data protection
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or as required by law. Standard retention periods:
- Enquiry data: 3 years
- Client data: 7 years after last engagement
- Marketing consent: until withdrawn
International Data Transfers
Your data is processed within the United Kingdom. We do not transfer personal data outside the UK or European Economic Area unless appropriate safeguards are in place.
Complaints
If you believe we have not handled your data properly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
United Kingdom
Website: ico.org.uk
Changes to This Notice
We may update this GDPR notice periodically. Significant changes will be communicated via email to users who have provided contact information.
Contact
For questions about GDPR compliance or data protection, contact [email protected]