Apexion Biolabs

Apexion One Privacy Policy

1. Who we are

Apexion BioLabs is operated by APEXION BIOLABS UK, trading as Apexion BioLabs.

In this Privacy Policy, “Apexion”, “we”, “us” and “our” refer to that organisation.

We are the controller of personal information collected through:

  • The Apexion BioLabs website
  • Apexion One accounts and dashboards
  • Blood-report uploads
  • Biomarker tracking
  • Connected health sources
  • Research Navigator
  • Apexion+ memberships
  • Product orders and customer support

Contact us about privacy at:

Email: contact@apexionbiolabs.co.uk


 

2. What this policy covers

This policy explains:

  • What personal information we collect
  • Why we collect it
  • How it is used and shared
  • How long it is retained
  • How we protect it
  • Your privacy rights
  • How Google Health, wearable, AI and payment integrations work

A privacy notice must identify the organisation, explain its purposes and lawful bases, identify recipients, describe retention and explain individual rights.


 

3. Information we collect

Account information

When you create or use an Apexion One account, we may collect:

  • First and last name
  • Email address
  • Password in encrypted or hashed form
  • Account preferences
  • Membership level
  • Login and account-security records
  • Consent choices
  • Support communications

Health and blood-report information

When you use Apexion One, you may choose to provide:

  • Blood-test reports
  • Screenshots or photographs of test results
  • Biomarker names, values, units and reference ranges
  • Test date and laboratory information
  • Weight, body-fat and waist measurements
  • Blood-pressure measurements
  • Notes you add to your health records
  • Historical values, trends and Timeline entries
  • AI-generated report summaries
  • Health-profile completion and engagement scores

Health information is considered sensitive or special-category information.

We only process this information where necessary to provide the features you request and where an appropriate legal condition applies.

Connected health-source information

Where you connect a supported source, we may receive information such as:

  • Profile information
  • Daily steps and activity
  • Weight and body-fat measurements
  • Resting heart rate
  • Heart-rate variability
  • Sleep duration and summaries
  • Synchronisation dates and provider identifiers

Connected sources may include:

  • Fitbit through Google Health API
  • Apple Health exports or the Apexion One iPhone companion app
  • Oura
  • Garmin
  • Other integrations that we clearly identify before connection

You control whether to connect these services. You can disconnect a source through your Apexion One account.

Orders and payments

When you purchase a product or Apexion+ membership, we may collect:

  • Billing name and address
  • Order and product details
  • Amount paid
  • Payment-provider name
  • Transaction or subscription identifier
  • Payment status
  • Membership plan
  • Renewal or paid-through date
  • Refund and cancellation records

Payment providers such as Fena and Elite Pay process bank or card credentials. Apexion normally receives transaction and subscription information rather than your complete card or online-banking credentials.

Research Navigator and AI information

When you use Research Navigator or AI-powered Apexion One features, we may process:

  • Questions and prompts
  • Product or research searches
  • Confirmed biomarker values
  • Extracted report text
  • Report comparisons
  • Generated summaries
  • Safety-filter and diagnostic records

Website and technical information

We may automatically collect:

  • IP address
  • Browser and device type
  • Operating system
  • Pages viewed
  • Date and time of access
  • Referring page
  • Session and security logs
  • Cookie preferences
  • Error and performance information

 

4. How we collect information

We collect information:

  • Directly from you
  • From files or images you upload
  • From your use of Apexion One
  • From a health service you authorise
  • From payment and ecommerce providers
  • From cookies and similar technologies
  • From customer-support communications
  • From automated OCR and AI extraction tools

 

5. Why we use your information

PurposeInformation involvedLawful basis
Create and manage your accountIdentity, email and account dataContract
Provide Apexion One featuresAccount, report and biomarker dataContract
Process health informationBlood reports, biomarkers and connected health dataExplicit consent and an applicable UK GDPR lawful basis
Extract information from reportsUploaded files, extracted text and valuesContract and explicit consent where health data is involved
Generate optional AI summariesConfirmed health data and promptsExplicit consent
Process purchases and membershipsOrder, billing and transaction dataContract and legal obligation
Protect accounts and investigate abuseLogin, IP and security recordsLegitimate interests and legal obligation
Respond to enquiriesContact and support informationContract or legitimate interests
Send marketing communicationsName, email and preferencesConsent, where required
Maintain accounting recordsOrders, payments and refundsLegal obligation
Improve service reliabilityTechnical, error and usage informationLegitimate interests

Processing needed to deliver a requested service may rely on contract, but special-category health data still requires a separate Article 9 condition.

Where we rely on legitimate interests, those interests may include:

  • Maintaining service security
  • Preventing fraud and misuse
  • Diagnosing technical problems
  • Improving reliability
  • Managing customer relationships
  • Protecting our legal rights

We balance these interests against your rights and reasonable expectations.


 

6. Health information and explicit consent

Before Apexion processes uploaded blood reports, biomarkers or connected health information, we may ask you to provide a separate, affirmative consent.

Your consent will identify:

  • The health information being processed
  • The purpose of processing
  • Any connected provider involved
  • Whether AI processing is enabled
  • How to withdraw consent

You can withdraw consent through your account or by contacting us. Withdrawal does not make earlier lawful processing unlawful, but it may prevent certain Apexion One features from continuing.

Explicit consent must be specific, affirmative, unambiguous and capable of being withdrawn.


 

7. Google Health and Fitbit information

When you connect Fitbit through Google Health API, Apexion may request read-only access to:

  • Google Health profile information
  • Activity and fitness information
  • Health metrics and measurements
  • Sleep information

We use this information only to provide visible Apexion One features such as:

  • Connected-source summaries
  • Personal metric history
  • Dashboard cards
  • Timeline events
  • Trend visualisations
  • User-requested health summaries

We comply with the Google Health API Developer and User Data Policy, including its Limited Use requirements, when using Google Health information.

In particular:

  • We request only permissions needed for active Apexion One features.
  • We do not sell Google Health information.
  • We do not use it for advertising or ad targeting.
  • We do not transfer it to data brokers.
  • We do not use it to determine creditworthiness or lending eligibility.
  • We do not allow staff to read it unless you provide specific consent, access is required for security, or disclosure is legally required.
  • We do not use it for unrelated research without appropriate approval and separate consent.
  • We do not use it to make medical diagnoses.
  • We honour valid requests to disconnect and delete imported information.

Google requires health applications to clearly explain what data they collect, why it is collected, how it is stored and shared, what happens when an account is deleted, and to prohibit uses such as selling health information or using it for advertising.

Disconnecting Google Health stops future synchronisation. Information already imported into Apexion One can be deleted through your account controls or by contacting us.


 

8. Blood-report OCR and AI processing

Apexion One may use text extraction, optical character recognition and artificial intelligence to identify:

  • Biomarker names
  • Results
  • Units
  • Reference ranges
  • Test dates
  • Laboratory details

Detected information is shown to you for review. You can edit, remove or reject detected values before saving them.

Where AI processing is enabled:

  • We ask for consent before sending health-related content to an AI provider.
  • We aim to send only information needed for the requested feature.
  • Processing may involve extracted report text or structured values.
  • We identify the relevant AI provider in the consent interface.
  • AI results are not guaranteed to be correct.
  • You remain responsible for confirming extracted information.

AI processing does not make decisions that produce legal or similarly significant effects. Apexion’s scores, summaries and trends are educational and organisational features, not diagnoses or treatment recommendations.


 

9. Who we share information with

We may share information with carefully selected providers where necessary to operate Apexion, including:

Hosting and infrastructure providers

Providers that host the website, database, private files, backups and security services.

Payment providers

Such as:

  • Fena
  • Elite Pay
  • WooCommerce payment services

These providers process payments, standing orders, payment status, refunds and fraud checks.

AI and extraction providers

Where you enable an AI feature, relevant extracted information may be processed by a configured provider such as Google Gemini.

Connected health providers

Such as:

  • Google Health and Fitbit
  • Apple
  • Oura
  • Garmin

Information is exchanged only when you initiate and authorise the connection.

Communication providers

Email-delivery, customer-support and transactional-message providers.

Professional advisers and authorities

We may disclose information to lawyers, accountants, insurers, regulators, law-enforcement bodies or courts where reasonably necessary or legally required.

We require service providers to process information only for agreed purposes and to apply appropriate confidentiality and security protections.

We do not sell blood-report data, biomarker data or connected health information.


 

10. International transfers

Some service providers may process information outside the United Kingdom.

Where personal information is transferred internationally, we take reasonable steps to use an appropriate safeguard, such as:

  • A UK adequacy regulation
  • The UK International Data Transfer Agreement
  • The UK Addendum to approved standard contractual clauses
  • Another lawful transfer mechanism

Details of applicable safeguards can be requested using the contact information in this policy.


 

11. How long we retain information

We retain personal information only for as long as needed for the purpose for which it was collected, including legal, accounting, security and dispute-resolution requirements.

The intended retention schedule is:

InformationIntended retention
Apexion One account informationWhile the account remains active
Blood reports and biomarkersUntil deleted by the user or the account is closed
Connected health informationUntil deleted, consent is withdrawn or the account is closed
OAuth access and refresh tokensUntil disconnection, revocation or account closure
AI prompts and summariesWhile required for the user’s saved history or until deleted
Orders and payment recordsUp to six years where required for tax, accounting or legal purposes
Customer-support recordsNormally up to three years after the enquiry is closed
Security and technical logsNormally up to twelve months
Marketing preferencesUntil consent is withdrawn, plus a suppression record where required
BackupsRemoved through the normal backup-rotation process

Confirm these periods against the actual plugin, hosting and backup configuration before publishing.

When an Apexion One account is deleted, we remove or anonymise information from active systems unless retention is required by law. Residual copies may remain temporarily in secured backups until those backups rotate.


 

12. Security

We use technical and organisational measures designed to protect personal information, including:

  • Password hashing
  • Role-based access controls
  • Private report storage
  • Encrypted communications using HTTPS
  • Restricted administrative access
  • Secure OAuth tokens
  • Security logging
  • Backups
  • Software updates
  • Provider-access controls

No website, database or transmission method is completely secure. Users should use a unique password and protect access to their email and devices.


 

13. Cookies and analytics

We may use cookies or similar technologies for:

  • Account login
  • Security
  • Shopping-cart functions
  • Remembering preferences
  • Measuring website performance
  • Understanding website usage
  • Marketing, where you have consented

Non-essential analytics and marketing cookies should not be activated until the user has made a valid cookie choice.

More information should be provided in a separate Cookie Policy and cookie-preference panel.


 

14. Marketing

We may send product news or promotional messages where:

  • You have consented; or
  • Another lawful marketing rule permits it.

You can unsubscribe using the link in an email or by contacting us.

We do not use blood reports, biomarkers or Google Health information to target advertising.

You have an absolute right to object to direct marketing.


 

15. Your privacy rights

Depending on the circumstances, you may have the right to:

  • Be informed about processing
  • Request access to your information
  • Correct inaccurate or incomplete information
  • Request deletion
  • Restrict processing
  • Receive portable information
  • Object to certain processing
  • Withdraw consent
  • Object to direct marketing
  • Request human review of certain automated decisions

These rights are not always absolute, and legal exemptions may apply. The UK GDPR provides rights including access, correction, erasure, restriction, portability and objection.

Send a request to:

info@apexionbiolabs.co.uk

We may need to verify your identity before acting on a request.


 

16. Account deletion and connected-service controls

You may:

  • Delete individual reports
  • Delete biomarker results
  • Disconnect connected health providers
  • Revoke Google Health access
  • Delete your Apexion One account
  • Request deletion by contacting us

Disconnecting a provider prevents new information from being imported. It does not automatically delete information already saved in Apexion One unless you also delete that information or your account.


 

17. Children

Apexion One is not intended for anyone under 18 years of age.

We do not knowingly collect health information from children. Where we discover that information has been provided by someone under 18, we may suspend the account and delete the information, subject to applicable legal requirements.


 

18. Third-party websites

Our website may contain links to external websites, payment pages, laboratories, wearable providers or research sources.

Those services operate under their own privacy policies. We are not responsible for how an independent third party processes information after you leave Apexion.


 

19. Complaints

Contact us first so we can try to resolve your concern:

Email: contact@apexionbiolabs.co.uk

You also have the right to complain to the UK Information Commissioner’s Office if you believe your information has been handled unlawfully.


 

20. Changes to this policy

We may update this policy when:

  • Apexion introduces new features
  • Connected providers change
  • Our data practices change
  • Legal or regulatory requirements change
Scroll to Top