AìNGEL

Privacy Policy

Privacy Policy

Effective Date: May 27, 2025

Your privacy matters to us. This policy explains in plain English how we collect, use, and protect your personal information when you use AìNGEL, your voice-first AI health companion for home health care.

1. Who We Are

AìNGEL is operated by AiNGEL Limited, a company registered in England and Wales.

Company Name: AiNGEL Limited

Company Registration Number: 14749115

Registered Office: London, United Kingdom

ICO Registration: [Application pending/Number to be inserted when available]

We are the "data controller" for the personal information we collect about you. This means we decide how and why your information is processed, and we're responsible for keeping it safe.

2. What is AiNGEL?

AìNGEL is an artificial intelligence (AI) health companion designed to support you with health monitoring, daily care, and healthy ageing at home. Our platform uses advanced AI technology, including voice recognition and analysis, to provide personalised health support.

Important to know:

  • AìNGEL is a support tool, not a replacement for medical professionals
  • We use AI to analyze your voice and health patterns
  • Your interactions help us provide personalised care recommendations
  • We may detect health concerns and alert you or your chosen contacts

3. Information We Collect

To provide our services, we need to collect different types of information about you. Here's what we collect and why:

3.1 Account Information

What we collect:

  • Full name
  • Email address
  • Phone number
  • Date of birth
  • Home address
  • Password (encrypted - we never see your actual password)

Why we need it: To create and manage your account, verify your identity, and communicate with you about the service.

3.2 Health Information

What we collect:

  • Current health conditions and medical history
  • Medications you're taking
  • Allergies and dietary requirements
  • Mobility aids or assistive devices you use
  • Vision, hearing, or cognitive support needs
  • Health measurements (blood pressure, heart rate, weight, etc.)
  • Symptoms or concerns you report
  • Emergency contact details

Why we need it: To personalize your care, provide appropriate health reminders and monitoring, and alert emergency contacts if needed. We only collect this with your explicit consent.

3.3 Voice Interactions and Analysis

What we collect:

  • Voice recordings of your conversations with AiLycia (our AI companion)
  • Voice patterns and characteristics (pitch, tone, speed, breath patterns)
  • Transcripts of conversations
  • Voice biomarker data (indicators of health or wellbeing in your voice)
  • Timestamps of when you use voice features

Why we need it: Voice is the primary way you interact with AìNGEL. Analyzing your voice helps us understand your instructions, monitor your wellbeing, detect early signs of health changes, and improve how AiLycia responds to you.

3.4 Device and Technical Information

What we collect:

  • Device type (smartphone, tablet, smart speaker)
  • Operating system and version
  • Internet connection type
  • IP address and approximate location (for service delivery)
  • Browser type and settings
  • App version
  • Connected health devices (smartwatch, blood pressure monitor, etc.)

Why we need it: To ensure AìNGEL works properly on your devices, troubleshoot technical issues, and improve compatibility.

3.5 Usage and Analytics

What we collect:

  • How often you use the service
  • Which features you use most
  • Time of day you typically interact with AiLycia
  • Length of conversations
  • Error messages or technical problems
  • Response times and performance data

Why we need it: To understand how AìNGEL is being used, identify and fix problems, and continuously improve our service.

5. How We Use Your Information

Here's exactly what we do with the information we collect:

Providing the AiNGEL Service

  • Creating and managing your account
  • Enabling voice interactions with AiLycia
  • Providing medication reminders
  • Offering health tips and guidance
  • Facilitating communication with your care circle (if you choose)
  • Managing appointments and schedules
  • Responding to your questions and requests

Personalization (With Your Consent)

  • Tailoring health recommendations to your specific needs
  • Adjusting AiLycia's responses based on your preferences
  • Remembering your routines and patterns
  • Suggesting relevant content and features
  • Adapting to your communication style

Health Monitoring (With Your Consent)

  • Tracking health metrics you choose to share
  • Analyzing voice patterns for health indicators
  • Identifying potential health concerns
  • Monitoring changes in wellbeing over time
  • Providing proactive health alerts
  • Creating health summaries and reports

Important: We never diagnose conditions or prescribe treatments. We provide information to support conversations with your healthcare professionals.

Emergency Response

  • Detecting potential emergencies (falls, distress, unusual patterns)
  • Contacting your designated emergency contacts
  • Alerting emergency services if necessary and authorized
  • Providing relevant medical information to first responders (only essential information)

Service Improvement and Development

  • Improving AI accuracy and responses
  • Developing new features and services
  • Fixing bugs and technical issues
  • Training our AI models (using anonymized data)
  • Conducting research to improve health support
  • Testing new technologies

Communication

  • Sending important service updates
  • Responding to your questions and support requests
  • Providing health and safety notifications
  • Sending technical updates about the service
  • Marketing communications (only if you've opted in)

You can opt out of marketing emails at any time by clicking "unsubscribe" or through your account settings.

Security and Legal Compliance

  • Protecting against fraud and misuse
  • Ensuring platform security
  • Complying with legal obligations
  • Responding to legal requests
  • Protecting our legal rights

6. Sharing Your Information

Your privacy is paramount. We do not sell your data to anyone, ever. Period.

We only share your information in these specific circumstances:

With Your Explicit Consent

We may share information with people and organizations you specifically authorize:

  • Your chosen care circle: Family members, carers, or friends you designate
  • Healthcare professionals: Your GP, specialists, or other medical professionals (only what you authorize)
  • Care providers: Home care agencies or facilities (only what you authorize)

You control exactly what information is shared and with whom. You can change or revoke these permissions at any time.

Emergency Services

If we detect a potential emergency or you request emergency help:

  • We may contact emergency services (999/111)
  • We'll alert your designated emergency contacts
  • We'll share only essential medical information needed for your care
  • This includes critical health data, medications, and allergies

This happens only in genuine emergencies to protect your health and safety.

Service Providers (With Strict Safeguards)

We work with carefully selected companies that help us provide AìNGEL:

  • Cloud hosting providers (to store data securely)
  • AI and voice analysis technology providers
  • Communication service providers (email, SMS)
  • Payment processors (when we introduce paid services)
  • Technical support and maintenance providers

Important safeguards:

  • All service providers sign data processing agreements
  • They can only use data for the specific purposes we authorize
  • They must maintain the same security standards we use
  • They cannot use your data for their own purposes
  • We regularly audit their security and compliance

Legal Requirements

We may share information if required by law or to protect rights:

  • To comply with legal obligations or court orders
  • To respond to valid requests from law enforcement or regulators
  • To protect against fraud or security threats
  • To protect our legal rights or those of others
  • To prevent harm to you or others

We'll notify you if legally permitted, and we'll only share the minimum necessary information.

Business Transfers

If AìNGEL is involved in a merger, acquisition, or sale:

  • We'll notify you before your information is transferred
  • The new owner must honor this privacy policy
  • You'll have the option to delete your data before transfer

Anonymized Data for Research

We may use anonymized, aggregated data for research purposes:

  • All personal identifiers are permanently removed
  • The data cannot be traced back to you
  • Used to improve health outcomes and AI technologies
  • May be shared with research institutions or published

This anonymized data helps improve care for everyone but cannot identify you personally.

7. International Data Transfers

Your data is primarily stored and processed in the United Kingdom. However, some of our service providers may process data outside the UK, including in countries that may not have equivalent data protection laws.

How We Protect Your Data Internationally

When we transfer data outside the UK, we ensure appropriate safeguards are in place:

  • Adequacy decisions: We only transfer to countries the UK government has deemed to have adequate data protection
  • Standard Contractual Clauses: We use UK-approved contracts that require equivalent protection
  • Additional security measures: Encryption, access controls, and security audits
  • Binding Corporate Rules: For transfers within service provider organizations

Your right to information: You can request details about international transfers and the safeguards in place by contacting us at ark@aingel.life.

8. How Long We Keep Your Data

We only keep your personal information for as long as necessary. Here's our approach:

While You're Using AiNGEL

We keep your account and health information for as long as your account is active, so we can continue to provide personalized service.

After Account Closure

  • Health data: Deleted within 30 days unless you request otherwise
  • Voice recordings: Deleted within 90 days
  • Account information: Retained for 12 months for legal/accounting purposes, then deleted
  • Anonymized data: May be retained indefinitely for research (cannot identify you)

Legal Requirements

We may need to keep certain information longer if:

  • Required by UK law (e.g., tax records for 6 years)
  • Necessary for legal claims or disputes
  • Needed for regulatory compliance

Your Control

You can request deletion of your data at any time by:

  • Using the delete account option in your settings
  • Emailing us at ark@aingel.life
  • Calling us on +44 (0) 7443 719 521

We'll confirm deletion within 30 days, except for data we're legally required to keep.

9. Keeping Your Data Safe

We take data security extremely seriously. Here's how we protect your information:

Encryption

  • In transit: All data sent between your device and our servers is encrypted using industry-standard TLS/SSL
  • At rest: Data stored on our servers is encrypted using AES-256 encryption
  • Voice data: Encrypted immediately upon recording
  • Backups: All backups are encrypted and stored securely

Access Controls

  • Multi-factor authentication for all staff accessing systems
  • Strict role-based access - staff can only access what they need for their job
  • Regular access reviews and audits
  • Immediate access revocation when staff leave
  • Logged and monitored access to sensitive data

Technical Security

  • Firewalls and intrusion detection systems
  • Regular security patches and updates
  • Secure development practices
  • Vulnerability scanning and penetration testing
  • DDoS protection
  • 24/7 security monitoring

Staff Training and Policies

  • Mandatory data protection training for all staff
  • Confidentiality agreements
  • Clear security policies and procedures
  • Regular security awareness training
  • Incident response procedures

Regular Audits

  • Annual independent security audits
  • Regular penetration testing
  • ISO 27001 compliance processes (certification in progress)
  • NHS Data Security and Protection Toolkit compliance (where applicable)

In Case of a Data Breach

If a security breach occurs that may affect your data:

  • We'll notify the ICO within 72 hours if required
  • We'll inform you directly if there's a high risk to your rights
  • We'll explain what happened, what data was affected, and what we're doing about it
  • We'll provide advice on steps you can take to protect yourself

Your Responsibility

You can help keep your account secure by:

  • Using a strong, unique password
  • Not sharing your login details
  • Logging out on shared devices
  • Keeping your devices secure with passwords/biometrics
  • Being cautious of phishing attempts
  • Reporting suspicious activity immediately

10. Your Rights Under UK GDPR

UK data protection law gives you important rights over your personal information. Here's what you can do:

Right to Access (Subject Access Request)

What this means: You can ask us for a copy of your personal data.

What you'll get:

  • Confirmation that we hold your data
  • A copy of your personal information
  • Details about how we use it
  • Who we share it with
  • How long we'll keep it

Timeline: We'll respond within one month, free of charge.

Right to Rectification

What this means: You can ask us to correct inaccurate or incomplete information.

Examples:

  • Updating your address or phone number
  • Correcting health information
  • Adding missing information

How: Update in your account settings or contact us directly.

Right to Erasure ("Right to be Forgotten")

What this means: You can ask us to delete your personal data in certain circumstances.

You can ask for deletion if:

  • The data is no longer needed for the original purpose
  • You withdraw consent (where consent was the legal basis)
  • You object to processing and there's no overriding reason to keep it
  • The data was processed unlawfully
  • It must be deleted to comply with a legal obligation

Limitations: We may need to keep some data for legal obligations or to establish legal claims.

Right to Restrict Processing

What this means: You can ask us to limit how we use your data in certain situations.

You can restrict processing when:

  • You're challenging the accuracy of the data
  • The processing is unlawful but you don't want deletion
  • We no longer need the data but you need it for a legal claim
  • You've objected to processing pending verification

What happens: We'll store the data but not use it (except with your consent or for legal claims).

Right to Data Portability

What this means: You can get your data in a commonly used, machine-readable format and transfer it to another service.

This applies to:

  • Data you've provided to us
  • Data processed based on consent or contract
  • Data processed by automated means

Format: We'll provide data in CSV, JSON, or another standard format.

Right to Object

What this means: You can object to certain types of processing.

You can object to:

  • Processing based on legitimate interests
  • Direct marketing (we'll stop immediately)
  • Processing for research purposes (unless there's a compelling reason)

What happens: We'll stop processing unless we can show compelling legitimate grounds that override your interests.

Right to Withdraw Consent

What this means: If we're processing your data based on consent, you can withdraw it at any time.

Important points:

  • Withdrawal doesn't affect processing done before withdrawal
  • Must be as easy to withdraw as to give consent
  • You can withdraw consent for specific purposes while keeping others active
  • Some services may not work properly without certain consents

How: Through account settings or by contacting us.

Rights Related to Automated Decision-Making

What this means: You have rights regarding decisions made solely by AI without human involvement.

At AiNGEL:

  • We use AI to support decisions, not make them automatically
  • Important decisions (like health concerns) involve human review
  • You can request human review of AI-influenced decisions
  • You can challenge decisions you believe are unfair

11. How to Exercise Your Rights

Exercising your rights is straightforward. Here's how:

Contact Methods

What to Include in Your Request

  • Your full name and email address associated with your account
  • Clear description of your request and which right you're exercising
  • Any specific details that will help us process your request
  • Proof of identity (we may need this to protect your data)

Our Response Timeline

  • Initial acknowledgement: Within 48 hours
  • Full response: Within one month
  • Complex requests: May take up to two additional months (we'll explain why)
  • Urgent requests: We'll prioritize based on circumstances

Free of Charge

Exercising your rights is generally free. We may charge a reasonable fee only if:

  • Your request is clearly unfounded or excessive
  • You request multiple copies of the same information

We'll explain any charges before processing your request.

Verification

To protect your privacy, we may need to verify your identity before processing certain requests. This might involve:

  • Confirming details from your account
  • Requesting additional identification
  • Using two-factor authentication

12. Making a Complaint

We're committed to protecting your privacy. If you're unhappy with how we've handled your data, here's what to do:

Step 1: Contact Us First

Please let us know about your concerns. We'll do our best to resolve the issue quickly:

  • Email: ark@aingel.life
  • Phone: +44 (0) 7443 719 521
  • We'll acknowledge your complaint within 48 hours
  • We'll aim to resolve it within 10 working days

Step 2: Contact the ICO

You have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator:

Website: ico.org.uk/make-a-complaint/

Phone: 0303 123 1113

Address:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Important: You can complain to the ICO at any time, but they usually encourage you to speak to us first to give us the chance to resolve your concerns.

13. Changes to This Privacy Policy

We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

How We'll Notify You

  • Minor changes: We'll update the "Effective Date" at the top and post the new policy on our website
  • Significant changes: We'll:
    • Email you at least 30 days before the changes take effect
    • Show a prominent notice when you log in
    • Highlight what's changed
    • Give you the option to review and accept the changes

Your Choices

If you don't agree with significant changes to how we handle your data:

  • You can withdraw your consent for affected processing
  • You can request deletion of your data
  • You can close your account

We'll process your request before the new policy takes effect.

14. Contact Us

We're here to help with any questions or concerns about your privacy and data protection.

AìNGEL Privacy Team

Email (Recommended)

ark@aingel.life

For privacy inquiries, data requests, or general questions

Phone

+44 (0) 7443 719 521

Monday - Friday: 9:00 AM - 6:00 PM (UK time)

Postal Address

AiNGEL Limited
Data Protection Officer
London, United Kingdom

Response time: We aim to respond to all privacy inquiries within 48 hours, with full responses within one month as required by UK GDPR.

In Summary

At AìNGEL, your privacy isn't just a legal requirement—it's fundamental to everything we do. We:

  • ✓ Only collect data we genuinely need to provide your care
  • ✓ Never sell your data to anyone
  • ✓ Give you complete control over your information
  • ✓ Use industry-leading security to protect your data
  • ✓ Are transparent about how we use your information
  • ✓ Respect all your rights under UK law

Questions? We're here to help. Contact us anytime at ark@aingel.life