Privacy policy

Last updated: July 2026

Who we are

Velo Health Ltd (“Velo Health”, “we”) provides asynchronous text consultations with GMC-registered UK doctors who can issue medical certificates. We are the data controller for the personal information described in this policy. Contact: privacy@velohealth.co.uk.

What we collect

Identity and contact details: name, date of birth, email, mobile number, postal address, and a photo of your ID document (passport or driving licence) used to verify who you are.

Health information you give us: the purpose and reason for your request, your symptom description, absence dates, any documents you upload, and the messages you exchange with our clinicians. This is special-category data under UK GDPR; we process it to provide the consultation you have asked for (Article 9(2)(h), provision of health care, under the responsibility of registered professionals).

Payment records: we never see or store your card details - payment is processed by Stripe. We keep the order, invoice and receipt records of your purchase.

How we use it

To deliver the consultation and, where clinically appropriate, issue your certificate; to email you about your consultation (replies, outcome, receipts, certificate expiry); to keep a medico-legal record of the consultation; to handle complaints; and to prevent fraud and abuse of the service.

No decision about your certificate is automated: every request is reviewed individually by a GMC registered doctor.

We do not sell your data and we do not use your health information for marketing.

Where it lives and who sees it

Your data is stored in the UK/EU (Supabase, AWS eu-west-1). Files such as your ID and certificate PDFs are held in private storage and accessed only through short-lived signed links.

It is visible only to the clinician handling your case, our clinical administrators, and the service providers who process data for us: Supabase (hosting and storage), Stripe (payments), Resend (email delivery), and Vercel (application hosting). Contentsquare (website analytics) receives only public-page browsing activity from visitors who consent - never your consultation, documents, or clinical messages.

Certificate verification: if an employer, university, or insurer contacts us quoting your certificate's unique reference, we confirm only that we issued the certificate, who it was issued to, and the dates it covers. We never share your symptoms, messages, or any other clinical detail with them.

Cookies

We set two strictly necessary cookies: one that keeps you signed in to your account, and one that remembers your enquiry draft while you complete the questionnaire. Because these are essential to provide the service you ask for, UK law (PECR) does not require your consent for them.

With your consent, we also use Contentsquare, an analytics tool that shows us how visitors move through our public information pages so we can improve them. It runs only if you press Accept on the cookie banner, and only on those public pages - it is never active on the consultation questionnaire, your dashboard, or the messages between you and your clinician, so it cannot see your symptoms, documents, or clinical conversation. You can withdraw consent at any time by clearing this site's cookies and site data in your browser, then choosing Reject.

We set no advertising cookies and do not sell or share your data with advertisers. When you pay, Stripe may set its own cookies on its checkout pages, covered by Stripe's privacy policy.

How long we keep it

Consultation records, including messages and issued certificates, are retained in line with UK medical record-keeping guidance for adult records. Incomplete enquiry drafts are deleted automatically after 24 hours, including any uploaded files.

Your rights

You can ask for a copy of your data, ask us to correct it, and - where it is not part of the clinical record we are required to keep - ask us to delete it. You can complain to the Information Commissioner’s Office (ico.org.uk) if you are unhappy with how we handle your information. To exercise any right, email privacy@velohealth.co.uk.