Apexion One Privacy Policy
1. Who we are
Apexion BioLabs is operated by APEXION BIOLABS UK, trading as Apexion BioLabs.
In this Privacy Policy, “Apexion”, “we”, “us” and “our” refer to that organisation.
We are the controller of personal information collected through:
- The Apexion BioLabs website
- Apexion One accounts and dashboards
- Blood-report uploads
- Biomarker tracking
- Connected health sources
- Research Navigator
- Apexion+ memberships
- Product orders and customer support
Contact us about privacy at:
Email: contact@apexionbiolabs.co.uk
2. What this policy covers
This policy explains:
- What personal information we collect
- Why we collect it
- How it is used and shared
- How long it is retained
- How we protect it
- Your privacy rights
- How Google Health, wearable, AI and payment integrations work
A privacy notice must identify the organisation, explain its purposes and lawful bases, identify recipients, describe retention and explain individual rights.
3. Information we collect
Account information
When you create or use an Apexion One account, we may collect:
- First and last name
- Email address
- Password in encrypted or hashed form
- Account preferences
- Membership level
- Login and account-security records
- Consent choices
- Support communications
Health and blood-report information
When you use Apexion One, you may choose to provide:
- Blood-test reports
- Screenshots or photographs of test results
- Biomarker names, values, units and reference ranges
- Test date and laboratory information
- Weight, body-fat and waist measurements
- Blood-pressure measurements
- Notes you add to your health records
- Historical values, trends and Timeline entries
- AI-generated report summaries
- Health-profile completion and engagement scores
Health information is considered sensitive or special-category information.
We only process this information where necessary to provide the features you request and where an appropriate legal condition applies.
Connected health-source information
Where you connect a supported source, we may receive information such as:
- Profile information
- Daily steps and activity
- Weight and body-fat measurements
- Resting heart rate
- Heart-rate variability
- Sleep duration and summaries
- Synchronisation dates and provider identifiers
Connected sources may include:
- Fitbit through Google Health API
- Apple Health exports or the Apexion One iPhone companion app
- Oura
- Garmin
- Other integrations that we clearly identify before connection
You control whether to connect these services. You can disconnect a source through your Apexion One account.
Orders and payments
When you purchase a product or Apexion+ membership, we may collect:
- Billing name and address
- Order and product details
- Amount paid
- Payment-provider name
- Transaction or subscription identifier
- Payment status
- Membership plan
- Renewal or paid-through date
- Refund and cancellation records
Payment providers such as Fena and Elite Pay process bank or card credentials. Apexion normally receives transaction and subscription information rather than your complete card or online-banking credentials.
Research Navigator and AI information
When you use Research Navigator or AI-powered Apexion One features, we may process:
- Questions and prompts
- Product or research searches
- Confirmed biomarker values
- Extracted report text
- Report comparisons
- Generated summaries
- Safety-filter and diagnostic records
Website and technical information
We may automatically collect:
- IP address
- Browser and device type
- Operating system
- Pages viewed
- Date and time of access
- Referring page
- Session and security logs
- Cookie preferences
- Error and performance information
4. How we collect information
We collect information:
- Directly from you
- From files or images you upload
- From your use of Apexion One
- From a health service you authorise
- From payment and ecommerce providers
- From cookies and similar technologies
- From customer-support communications
- From automated OCR and AI extraction tools
5. Why we use your information
| Purpose | Information involved | Lawful basis |
|---|---|---|
| Create and manage your account | Identity, email and account data | Contract |
| Provide Apexion One features | Account, report and biomarker data | Contract |
| Process health information | Blood reports, biomarkers and connected health data | Explicit consent and an applicable UK GDPR lawful basis |
| Extract information from reports | Uploaded files, extracted text and values | Contract and explicit consent where health data is involved |
| Generate optional AI summaries | Confirmed health data and prompts | Explicit consent |
| Process purchases and memberships | Order, billing and transaction data | Contract and legal obligation |
| Protect accounts and investigate abuse | Login, IP and security records | Legitimate interests and legal obligation |
| Respond to enquiries | Contact and support information | Contract or legitimate interests |
| Send marketing communications | Name, email and preferences | Consent, where required |
| Maintain accounting records | Orders, payments and refunds | Legal obligation |
| Improve service reliability | Technical, error and usage information | Legitimate interests |
Processing needed to deliver a requested service may rely on contract, but special-category health data still requires a separate Article 9 condition.
Where we rely on legitimate interests, those interests may include:
- Maintaining service security
- Preventing fraud and misuse
- Diagnosing technical problems
- Improving reliability
- Managing customer relationships
- Protecting our legal rights
We balance these interests against your rights and reasonable expectations.
6. Health information and explicit consent
Before Apexion processes uploaded blood reports, biomarkers or connected health information, we may ask you to provide a separate, affirmative consent.
Your consent will identify:
- The health information being processed
- The purpose of processing
- Any connected provider involved
- Whether AI processing is enabled
- How to withdraw consent
You can withdraw consent through your account or by contacting us. Withdrawal does not make earlier lawful processing unlawful, but it may prevent certain Apexion One features from continuing.
Explicit consent must be specific, affirmative, unambiguous and capable of being withdrawn.
7. Google Health and Fitbit information
When you connect Fitbit through Google Health API, Apexion may request read-only access to:
- Google Health profile information
- Activity and fitness information
- Health metrics and measurements
- Sleep information
We use this information only to provide visible Apexion One features such as:
- Connected-source summaries
- Personal metric history
- Dashboard cards
- Timeline events
- Trend visualisations
- User-requested health summaries
We comply with the Google Health API Developer and User Data Policy, including its Limited Use requirements, when using Google Health information.
In particular:
- We request only permissions needed for active Apexion One features.
- We do not sell Google Health information.
- We do not use it for advertising or ad targeting.
- We do not transfer it to data brokers.
- We do not use it to determine creditworthiness or lending eligibility.
- We do not allow staff to read it unless you provide specific consent, access is required for security, or disclosure is legally required.
- We do not use it for unrelated research without appropriate approval and separate consent.
- We do not use it to make medical diagnoses.
- We honour valid requests to disconnect and delete imported information.
Google requires health applications to clearly explain what data they collect, why it is collected, how it is stored and shared, what happens when an account is deleted, and to prohibit uses such as selling health information or using it for advertising.
Disconnecting Google Health stops future synchronisation. Information already imported into Apexion One can be deleted through your account controls or by contacting us.
8. Blood-report OCR and AI processing
Apexion One may use text extraction, optical character recognition and artificial intelligence to identify:
- Biomarker names
- Results
- Units
- Reference ranges
- Test dates
- Laboratory details
Detected information is shown to you for review. You can edit, remove or reject detected values before saving them.
Where AI processing is enabled:
- We ask for consent before sending health-related content to an AI provider.
- We aim to send only information needed for the requested feature.
- Processing may involve extracted report text or structured values.
- We identify the relevant AI provider in the consent interface.
- AI results are not guaranteed to be correct.
- You remain responsible for confirming extracted information.
AI processing does not make decisions that produce legal or similarly significant effects. Apexion’s scores, summaries and trends are educational and organisational features, not diagnoses or treatment recommendations.
9. Who we share information with
We may share information with carefully selected providers where necessary to operate Apexion, including:
Hosting and infrastructure providers
Providers that host the website, database, private files, backups and security services.
Payment providers
Such as:
- Fena
- Elite Pay
- WooCommerce payment services
These providers process payments, standing orders, payment status, refunds and fraud checks.
AI and extraction providers
Where you enable an AI feature, relevant extracted information may be processed by a configured provider such as Google Gemini.
Connected health providers
Such as:
- Google Health and Fitbit
- Apple
- Oura
- Garmin
Information is exchanged only when you initiate and authorise the connection.
Communication providers
Email-delivery, customer-support and transactional-message providers.
Professional advisers and authorities
We may disclose information to lawyers, accountants, insurers, regulators, law-enforcement bodies or courts where reasonably necessary or legally required.
We require service providers to process information only for agreed purposes and to apply appropriate confidentiality and security protections.
We do not sell blood-report data, biomarker data or connected health information.
10. International transfers
Some service providers may process information outside the United Kingdom.
Where personal information is transferred internationally, we take reasonable steps to use an appropriate safeguard, such as:
- A UK adequacy regulation
- The UK International Data Transfer Agreement
- The UK Addendum to approved standard contractual clauses
- Another lawful transfer mechanism
Details of applicable safeguards can be requested using the contact information in this policy.
11. How long we retain information
We retain personal information only for as long as needed for the purpose for which it was collected, including legal, accounting, security and dispute-resolution requirements.
The intended retention schedule is:
| Information | Intended retention |
|---|---|
| Apexion One account information | While the account remains active |
| Blood reports and biomarkers | Until deleted by the user or the account is closed |
| Connected health information | Until deleted, consent is withdrawn or the account is closed |
| OAuth access and refresh tokens | Until disconnection, revocation or account closure |
| AI prompts and summaries | While required for the user’s saved history or until deleted |
| Orders and payment records | Up to six years where required for tax, accounting or legal purposes |
| Customer-support records | Normally up to three years after the enquiry is closed |
| Security and technical logs | Normally up to twelve months |
| Marketing preferences | Until consent is withdrawn, plus a suppression record where required |
| Backups | Removed through the normal backup-rotation process |
Confirm these periods against the actual plugin, hosting and backup configuration before publishing.
When an Apexion One account is deleted, we remove or anonymise information from active systems unless retention is required by law. Residual copies may remain temporarily in secured backups until those backups rotate.
12. Security
We use technical and organisational measures designed to protect personal information, including:
- Password hashing
- Role-based access controls
- Private report storage
- Encrypted communications using HTTPS
- Restricted administrative access
- Secure OAuth tokens
- Security logging
- Backups
- Software updates
- Provider-access controls
No website, database or transmission method is completely secure. Users should use a unique password and protect access to their email and devices.
13. Cookies and analytics
We may use cookies or similar technologies for:
- Account login
- Security
- Shopping-cart functions
- Remembering preferences
- Measuring website performance
- Understanding website usage
- Marketing, where you have consented
Non-essential analytics and marketing cookies should not be activated until the user has made a valid cookie choice.
More information should be provided in a separate Cookie Policy and cookie-preference panel.
14. Marketing
We may send product news or promotional messages where:
- You have consented; or
- Another lawful marketing rule permits it.
You can unsubscribe using the link in an email or by contacting us.
We do not use blood reports, biomarkers or Google Health information to target advertising.
You have an absolute right to object to direct marketing.
15. Your privacy rights
Depending on the circumstances, you may have the right to:
- Be informed about processing
- Request access to your information
- Correct inaccurate or incomplete information
- Request deletion
- Restrict processing
- Receive portable information
- Object to certain processing
- Withdraw consent
- Object to direct marketing
- Request human review of certain automated decisions
These rights are not always absolute, and legal exemptions may apply. The UK GDPR provides rights including access, correction, erasure, restriction, portability and objection.
Send a request to:
info@apexionbiolabs.co.uk
We may need to verify your identity before acting on a request.
16. Account deletion and connected-service controls
You may:
- Delete individual reports
- Delete biomarker results
- Disconnect connected health providers
- Revoke Google Health access
- Delete your Apexion One account
- Request deletion by contacting us
Disconnecting a provider prevents new information from being imported. It does not automatically delete information already saved in Apexion One unless you also delete that information or your account.
17. Children
Apexion One is not intended for anyone under 18 years of age.
We do not knowingly collect health information from children. Where we discover that information has been provided by someone under 18, we may suspend the account and delete the information, subject to applicable legal requirements.
18. Third-party websites
Our website may contain links to external websites, payment pages, laboratories, wearable providers or research sources.
Those services operate under their own privacy policies. We are not responsible for how an independent third party processes information after you leave Apexion.
19. Complaints
Contact us first so we can try to resolve your concern:
Email: contact@apexionbiolabs.co.uk
You also have the right to complain to the UK Information Commissioner’s Office if you believe your information has been handled unlawfully.
20. Changes to this policy
We may update this policy when:
- Apexion introduces new features
- Connected providers change
- Our data practices change
- Legal or regulatory requirements change