Privacy Policy
How we collect, use, and protect your personal data
Last updated: 14 February 2026
Please note: This policy describes the full PRÆTOR platform, which is currently under development. Some features and services described below may not yet be available.
1. Introduction
PRÆTOR ("we", "us", "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our blood testing and health analytics platform.
We are the data controller for the personal data we process and are registered in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. For any questions about this policy, please contact us at [email protected].
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, password, and contact details when you create an account.
- Profile Information: Date of birth, biological sex, height, weight, and other health-related demographic information.
- Health Data: Blood test results, biomarker data, health history, and any information you voluntarily provide about your health goals.
- Payment Information: Billing address and payment card details (processed securely via Stripe).
- Communications: Any correspondence you send to us, including support requests.
2.2 Information We Collect Automatically
- Usage Data: Pages visited, features used, time spent on the platform, and interaction patterns.
- Device Information: Browser type, operating system, device identifiers, and IP address.
- Cookies: We use essential and optional cookies as described in our Cookie Policy.
2.3 Information from Third Parties
- Laboratory Partners: Blood test results from our UKAS-accredited laboratory partners.
- Authentication Providers: Basic profile information if you sign in using a third-party provider.
4. How We Use Your Information
We use your personal data for the following purposes:
5. Legal Basis for Processing
Under UK GDPR, we process your data on the following bases:
6. Who We Share Your Data With
We may share your personal data with:
- Laboratory Partners: UKAS-accredited laboratories that process your blood samples.
- Payment Processors: Stripe processes your payment information securely.
- Cloud Service Providers: Microsoft Azure hosts our platform and stores your data within the UK/EEA.
- Authentication Services: Auth0 manages secure account authentication.
- Advertising Partners: Meta receives limited advertising measurement events, and only if you accept marketing cookies. We never share your health results or account details with Meta.
- Professional Advisors: Lawyers, accountants, or auditors when required.
- Law Enforcement: When legally required or to protect our legal rights.
We do not sell your personal data to third parties. All data processors we use are bound by contractual obligations to protect your data.
7. International Data Transfers
Your data is primarily stored and processed within the United Kingdom and European Economic Area. Where we transfer data outside these regions (for example, to service providers in the United States), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the UK Information Commissioner's Office.
8. How Long We Keep Your Data
We retain your personal data for as long as necessary to:
- Provide you with our services while your account is active
- Comply with legal obligations (e.g., financial records for 7 years)
- Resolve disputes and enforce our agreements
Health data is retained for 10 years from your last test to enable longitudinal health tracking, unless you request earlier deletion. When you delete your account, we will anonymise or delete your personal data within 30 days, except where retention is legally required.
9. Your Rights
Under UK GDPR, you have the following rights:
To exercise any of these rights, please contact us at [email protected]. We will respond within one month. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
10. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256)
- Secure authentication via Auth0 with multi-factor authentication options
- Regular security audits and penetration testing
- Access controls limiting data access to authorised personnel
- Employee training on data protection best practices
11. Children's Privacy
Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately, and we will take steps to delete such information.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice on our platform or sending you an email. The "Last updated" date at the top of this policy indicates when it was last revised.