Privacy Policy
Effective Date: May 27, 2025
Your privacy matters to us. This policy explains in plain English how we collect, use, and protect your personal information when you use AìNGEL, your voice-first AI health companion for home health care.
Contents
1. Who We Are
AìNGEL is operated by AiNGEL Limited, a company registered in England and Wales.
Company Name: AiNGEL Limited
Company Registration Number: 14749115
Registered Office: London, United Kingdom
ICO Registration: [Application pending/Number to be inserted when available]
We are the "data controller" for the personal information we collect about you. This means we decide how and why your information is processed, and we're responsible for keeping it safe.
2. What is AiNGEL?
AìNGEL is an artificial intelligence (AI) health companion designed to support you with health monitoring, daily care, and healthy ageing at home. Our platform uses advanced AI technology, including voice recognition and analysis, to provide personalised health support.
Important to know:
- AìNGEL is a support tool, not a replacement for medical professionals
- We use AI to analyze your voice and health patterns
- Your interactions help us provide personalised care recommendations
- We may detect health concerns and alert you or your chosen contacts
3. Information We Collect
To provide our services, we need to collect different types of information about you. Here's what we collect and why:
3.1 Account Information
What we collect:
- Full name
- Email address
- Phone number
- Date of birth
- Home address
- Password (encrypted - we never see your actual password)
Why we need it: To create and manage your account, verify your identity, and communicate with you about the service.
3.2 Health Information
What we collect:
- Current health conditions and medical history
- Medications you're taking
- Allergies and dietary requirements
- Mobility aids or assistive devices you use
- Vision, hearing, or cognitive support needs
- Health measurements (blood pressure, heart rate, weight, etc.)
- Symptoms or concerns you report
- Emergency contact details
Why we need it: To personalize your care, provide appropriate health reminders and monitoring, and alert emergency contacts if needed. We only collect this with your explicit consent.
3.3 Voice Interactions and Analysis
What we collect:
- Voice recordings of your conversations with AiLycia (our AI companion)
- Voice patterns and characteristics (pitch, tone, speed, breath patterns)
- Transcripts of conversations
- Voice biomarker data (indicators of health or wellbeing in your voice)
- Timestamps of when you use voice features
Why we need it: Voice is the primary way you interact with AìNGEL. Analyzing your voice helps us understand your instructions, monitor your wellbeing, detect early signs of health changes, and improve how AiLycia responds to you.
3.4 Device and Technical Information
What we collect:
- Device type (smartphone, tablet, smart speaker)
- Operating system and version
- Internet connection type
- IP address and approximate location (for service delivery)
- Browser type and settings
- App version
- Connected health devices (smartwatch, blood pressure monitor, etc.)
Why we need it: To ensure AìNGEL works properly on your devices, troubleshoot technical issues, and improve compatibility.
3.5 Usage and Analytics
What we collect:
- How often you use the service
- Which features you use most
- Time of day you typically interact with AiLycia
- Length of conversations
- Error messages or technical problems
- Response times and performance data
Why we need it: To understand how AìNGEL is being used, identify and fix problems, and continuously improve our service.
4. Legal Basis for Processing Your Data
Under UK data protection law (UK GDPR), we must have a valid legal reason to use your personal information. Here are the legal bases we rely on:
Your Consent
What this means: You've given us clear permission to use your information.
We use consent for:
- Collecting and analyzing your health data
- Voice recording and voice biomarker analysis
- Sharing information with your chosen contacts
- Marketing communications (if you opt in)
You can withdraw your consent at any time through your account settings or by contacting us.
Contract Performance
What this means: We need your information to provide the service you've signed up for.
We use this basis for:
- Creating and managing your account
- Delivering the core AiNGEL services
- Processing payments (when we introduce paid services)
- Providing customer support
Legitimate Interests
What this means: We have a genuine business need to use your information, and this doesn't override your rights.
We use this basis for:
- Improving and developing our services
- Detecting and preventing fraud or misuse
- Network and information security
- Internal research and analytics
- Understanding service performance
We always balance our interests against your rights and only use this basis when it's fair and reasonable.
Vital Interests (Health Emergencies)
What this means: We may need to use your information to protect your life or someone else's.
We use this basis for:
- Detecting potential medical emergencies
- Contacting emergency services on your behalf
- Alerting your emergency contacts
This only applies in genuine emergency situations where we believe there's a risk to health or life.
Legal Obligation
What this means: We're required by law to use your information.
We use this basis for:
- Complying with legal requests from authorities
- Meeting regulatory requirements
- Responding to court orders
5. How We Use Your Information
Here's exactly what we do with the information we collect:
Providing the AiNGEL Service
- Creating and managing your account
- Enabling voice interactions with AiLycia
- Providing medication reminders
- Offering health tips and guidance
- Facilitating communication with your care circle (if you choose)
- Managing appointments and schedules
- Responding to your questions and requests
Personalization (With Your Consent)
- Tailoring health recommendations to your specific needs
- Adjusting AiLycia's responses based on your preferences
- Remembering your routines and patterns
- Suggesting relevant content and features
- Adapting to your communication style
Health Monitoring (With Your Consent)
- Tracking health metrics you choose to share
- Analyzing voice patterns for health indicators
- Identifying potential health concerns
- Monitoring changes in wellbeing over time
- Providing proactive health alerts
- Creating health summaries and reports
Important: We never diagnose conditions or prescribe treatments. We provide information to support conversations with your healthcare professionals.
Emergency Response
- Detecting potential emergencies (falls, distress, unusual patterns)
- Contacting your designated emergency contacts
- Alerting emergency services if necessary and authorized
- Providing relevant medical information to first responders (only essential information)
Service Improvement and Development
- Improving AI accuracy and responses
- Developing new features and services
- Fixing bugs and technical issues
- Training our AI models (using anonymized data)
- Conducting research to improve health support
- Testing new technologies
Communication
- Sending important service updates
- Responding to your questions and support requests
- Providing health and safety notifications
- Sending technical updates about the service
- Marketing communications (only if you've opted in)
You can opt out of marketing emails at any time by clicking "unsubscribe" or through your account settings.
Security and Legal Compliance
- Protecting against fraud and misuse
- Ensuring platform security
- Complying with legal obligations
- Responding to legal requests
- Protecting our legal rights
7. International Data Transfers
Your data is primarily stored and processed in the United Kingdom. However, some of our service providers may process data outside the UK, including in countries that may not have equivalent data protection laws.
How We Protect Your Data Internationally
When we transfer data outside the UK, we ensure appropriate safeguards are in place:
- Adequacy decisions: We only transfer to countries the UK government has deemed to have adequate data protection
- Standard Contractual Clauses: We use UK-approved contracts that require equivalent protection
- Additional security measures: Encryption, access controls, and security audits
- Binding Corporate Rules: For transfers within service provider organizations
Your right to information: You can request details about international transfers and the safeguards in place by contacting us at ark@aingel.life.
8. How Long We Keep Your Data
We only keep your personal information for as long as necessary. Here's our approach:
While You're Using AiNGEL
We keep your account and health information for as long as your account is active, so we can continue to provide personalized service.
After Account Closure
- Health data: Deleted within 30 days unless you request otherwise
- Voice recordings: Deleted within 90 days
- Account information: Retained for 12 months for legal/accounting purposes, then deleted
- Anonymized data: May be retained indefinitely for research (cannot identify you)
Legal Requirements
We may need to keep certain information longer if:
- Required by UK law (e.g., tax records for 6 years)
- Necessary for legal claims or disputes
- Needed for regulatory compliance
Your Control
You can request deletion of your data at any time by:
- Using the delete account option in your settings
- Emailing us at ark@aingel.life
- Calling us on +44 (0) 7443 719 521
We'll confirm deletion within 30 days, except for data we're legally required to keep.
9. Keeping Your Data Safe
We take data security extremely seriously. Here's how we protect your information:
Encryption
- In transit: All data sent between your device and our servers is encrypted using industry-standard TLS/SSL
- At rest: Data stored on our servers is encrypted using AES-256 encryption
- Voice data: Encrypted immediately upon recording
- Backups: All backups are encrypted and stored securely
Access Controls
- Multi-factor authentication for all staff accessing systems
- Strict role-based access - staff can only access what they need for their job
- Regular access reviews and audits
- Immediate access revocation when staff leave
- Logged and monitored access to sensitive data
Technical Security
- Firewalls and intrusion detection systems
- Regular security patches and updates
- Secure development practices
- Vulnerability scanning and penetration testing
- DDoS protection
- 24/7 security monitoring
Staff Training and Policies
- Mandatory data protection training for all staff
- Confidentiality agreements
- Clear security policies and procedures
- Regular security awareness training
- Incident response procedures
Regular Audits
- Annual independent security audits
- Regular penetration testing
- ISO 27001 compliance processes (certification in progress)
- NHS Data Security and Protection Toolkit compliance (where applicable)
In Case of a Data Breach
If a security breach occurs that may affect your data:
- We'll notify the ICO within 72 hours if required
- We'll inform you directly if there's a high risk to your rights
- We'll explain what happened, what data was affected, and what we're doing about it
- We'll provide advice on steps you can take to protect yourself
Your Responsibility
You can help keep your account secure by:
- Using a strong, unique password
- Not sharing your login details
- Logging out on shared devices
- Keeping your devices secure with passwords/biometrics
- Being cautious of phishing attempts
- Reporting suspicious activity immediately
10. Your Rights Under UK GDPR
UK data protection law gives you important rights over your personal information. Here's what you can do:
Right to Access (Subject Access Request)
What this means: You can ask us for a copy of your personal data.
What you'll get:
- Confirmation that we hold your data
- A copy of your personal information
- Details about how we use it
- Who we share it with
- How long we'll keep it
Timeline: We'll respond within one month, free of charge.
Right to Rectification
What this means: You can ask us to correct inaccurate or incomplete information.
Examples:
- Updating your address or phone number
- Correcting health information
- Adding missing information
How: Update in your account settings or contact us directly.
Right to Erasure ("Right to be Forgotten")
What this means: You can ask us to delete your personal data in certain circumstances.
You can ask for deletion if:
- The data is no longer needed for the original purpose
- You withdraw consent (where consent was the legal basis)
- You object to processing and there's no overriding reason to keep it
- The data was processed unlawfully
- It must be deleted to comply with a legal obligation
Limitations: We may need to keep some data for legal obligations or to establish legal claims.
Right to Restrict Processing
What this means: You can ask us to limit how we use your data in certain situations.
You can restrict processing when:
- You're challenging the accuracy of the data
- The processing is unlawful but you don't want deletion
- We no longer need the data but you need it for a legal claim
- You've objected to processing pending verification
What happens: We'll store the data but not use it (except with your consent or for legal claims).
Right to Data Portability
What this means: You can get your data in a commonly used, machine-readable format and transfer it to another service.
This applies to:
- Data you've provided to us
- Data processed based on consent or contract
- Data processed by automated means
Format: We'll provide data in CSV, JSON, or another standard format.
Right to Object
What this means: You can object to certain types of processing.
You can object to:
- Processing based on legitimate interests
- Direct marketing (we'll stop immediately)
- Processing for research purposes (unless there's a compelling reason)
What happens: We'll stop processing unless we can show compelling legitimate grounds that override your interests.
Right to Withdraw Consent
What this means: If we're processing your data based on consent, you can withdraw it at any time.
Important points:
- Withdrawal doesn't affect processing done before withdrawal
- Must be as easy to withdraw as to give consent
- You can withdraw consent for specific purposes while keeping others active
- Some services may not work properly without certain consents
How: Through account settings or by contacting us.
Rights Related to Automated Decision-Making
What this means: You have rights regarding decisions made solely by AI without human involvement.
At AiNGEL:
- We use AI to support decisions, not make them automatically
- Important decisions (like health concerns) involve human review
- You can request human review of AI-influenced decisions
- You can challenge decisions you believe are unfair
11. How to Exercise Your Rights
Exercising your rights is straightforward. Here's how:
Contact Methods
Email (fastest):
ark@aingel.lifePhone:
+44 (0) 7443 719 521What to Include in Your Request
- Your full name and email address associated with your account
- Clear description of your request and which right you're exercising
- Any specific details that will help us process your request
- Proof of identity (we may need this to protect your data)
Our Response Timeline
- Initial acknowledgement: Within 48 hours
- Full response: Within one month
- Complex requests: May take up to two additional months (we'll explain why)
- Urgent requests: We'll prioritize based on circumstances
Free of Charge
Exercising your rights is generally free. We may charge a reasonable fee only if:
- Your request is clearly unfounded or excessive
- You request multiple copies of the same information
We'll explain any charges before processing your request.
Verification
To protect your privacy, we may need to verify your identity before processing certain requests. This might involve:
- Confirming details from your account
- Requesting additional identification
- Using two-factor authentication
12. Making a Complaint
We're committed to protecting your privacy. If you're unhappy with how we've handled your data, here's what to do:
Step 1: Contact Us First
Please let us know about your concerns. We'll do our best to resolve the issue quickly:
- Email: ark@aingel.life
- Phone: +44 (0) 7443 719 521
- We'll acknowledge your complaint within 48 hours
- We'll aim to resolve it within 10 working days
Step 2: Contact the ICO
You have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator:
Website: ico.org.uk/make-a-complaint/
Phone: 0303 123 1113
Address:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Important: You can complain to the ICO at any time, but they usually encourage you to speak to us first to give us the chance to resolve your concerns.
13. Changes to This Privacy Policy
We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
How We'll Notify You
- Minor changes: We'll update the "Effective Date" at the top and post the new policy on our website
- Significant changes: We'll:
- Email you at least 30 days before the changes take effect
- Show a prominent notice when you log in
- Highlight what's changed
- Give you the option to review and accept the changes
Your Choices
If you don't agree with significant changes to how we handle your data:
- You can withdraw your consent for affected processing
- You can request deletion of your data
- You can close your account
We'll process your request before the new policy takes effect.
14. Contact Us
We're here to help with any questions or concerns about your privacy and data protection.
AìNGEL Privacy Team
Postal Address
AiNGEL LimitedData Protection Officer
London, United Kingdom
Response time: We aim to respond to all privacy inquiries within 48 hours, with full responses within one month as required by UK GDPR.
In Summary
At AìNGEL, your privacy isn't just a legal requirement—it's fundamental to everything we do. We:
- ✓ Only collect data we genuinely need to provide your care
- ✓ Never sell your data to anyone
- ✓ Give you complete control over your information
- ✓ Use industry-leading security to protect your data
- ✓ Are transparent about how we use your information
- ✓ Respect all your rights under UK law
Questions? We're here to help. Contact us anytime at ark@aingel.life