Welcome to the privacy policy for Astron Health (“we”, “us”). Astron Health is a trading name of Astron Health Ltd, a company registered in England and Wales with company registration number 15587830. Astron Health is committed to ensuring that your privacy is protected. This privacy policy sets out how we will collect, store, use, share and protect any information that you provide to us. We also explain your rights and how to contact us. Your personal information will only be used in accordance with this privacy policy.
We have appointed a Data Protection Officer to oversee our handling of personal information. Our Data Protection Officer is Mr. Benjamin Whately, CEO and can be reached at ben@astron.health. We process your information in the ways outlined below.
For the purposes of the data protection law, Astron Health Ltd will be the data controller. Astron Health Ltd is registered with the Information Commissioners’ Office under registration number: C1532868.
We will collect and use different personal information about you for different reasons, depending on our relationship with you. This includes prospective or existing patients, users of the Astron Health website, healthcare professionals, and individuals like business partners, sub-contractors, and suppliers. Each category is discussed in more detail in this privacy policy.
Sometimes we will request or receive “special categories of personal information” (which is information relating to your health, genetic or biometric data, criminal convictions, sex life, sexual orientation, racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership).
Where you provide personal information to us about other individuals (for example, members of your family or other dependents) we will also be data controller of their personal information and we are responsible for protecting their personal information and using it appropriately. This policy will therefore apply to those individuals, and you should refer them to this policy. If you provide us with information relating to other individuals, we are entitled to assume that you have the required authority from that person to provide us with the information and cannot be held responsible if that is not the case.
In order to make this policy as user friendly as possible, we have split it into different sections. Please click on the section below that best describes your relationship with us and the service you receive from us.
This section will apply if you currently participate in a cancer study or receive cancer treatment or if you are looking to participate in a cancer study or receive cancer treatment. Please note that we collect, use, and disclose additional personal information about you if you use our website as described in the section entitled “Users of the Astron Health website.”
We may collect the following categories of personal information:
Please note that sensitive or special categories of personal information may differ from jurisdiction to jurisdiction.
We will collect personal information about you from the following categories of sources in the below contexts:
There are a number of reasons we use your personal information and for each use we need to have a “legal ground” to do so. Some jurisdictions may refer to these as “business” or “commercial” purposes.
We will rely on the following “legal grounds” when we process your “personal information”:
For certain processing purposes, we have outlined alternative legal grounds. We will rely on the following legal grounds when we process your special categories of personal information:
Please read the above section on how we use your personal information for full details.
We will disclose your personal information as reasonably necessary for the purposes set out above with the following categories of parties:
If you reside in California, please read this section for additional disclosures about how we collect, use, and disclose information about you under the California Consumer Privacy Act (or “CCPA”) (California Civil Code Section 1798.100 et seq.).
Please refer to our Health Data Policy for more information about how we process Consumer Health Data about you.
If you are a user of the Astron Health website, this section will be relevant to you and sets out our uses of your personal information.
Please note that sensitive or special categories of personal information may differ from jurisdiction to jurisdiction.
We will collect personal information about you from the following categories of sources in the below contexts:
As well as obtaining information directly from you, we will also collect your personal information from:
We may use your personal information for a number of different purposes. In each case, we must have a “legal ground” to do so. Some jurisdictions may refer to these as “business” or “commercial” purposes. We will rely on the following “legal grounds”, when we process your “personal information”:
If you have filled in contact information, we will contact you to discuss the treatment and our clinical services. This will be based on you having consented to us contacting you.
When the information that we process is classed as “sensitive personal information” or “special categories of personal information”, we may have an additional “legal ground”. We will rely on the following legal grounds when we process your sensitive or special categories of personal information:
Please read the above section on how we use your personal information for full details.
We will disclose your personal information as reasonably necessary for the purposes set out above with the following categories of parties:
If you reside in California, please read this section for additional disclosures about how we collect, use, and disclose information about you under the California Consumer Privacy Act (or “CCPA”) (California Civil Code Section 1798.100 et seq.).
Please refer to our Health Data Policy for more information about how we process Consumer Health Data about you.
If you are a healthcare professional, this section will be relevant to you and sets out our uses of your personal information. Please note that we collect, use, and disclose additional personal information about you if you use our website as described in the section entitled “Users of the Astron Health website.”
For UK and EEA residents, please note that we do not collect any “special categories of personal information”.
We will collect personal information about you from the following categories of sources in the below contexts:
We may use your personal information for a number of different purposes. In each case, we must have a “legal ground” to do so. Some jurisdictions may refer to these as “business” or “commercial” purposes. We will rely on the following “legal ground”, when we process your “personal information”:
Please read the above section on how we use your personal information for full details.
We will disclose your personal information as necessary for the purposes set out above with the following categories of parties:
If you reside in California, please read this section for additional disclosures about how we collect, use, and disclose information about you under the California Consumer Privacy Act (or “CCPA”) (California Civil Code Section 1798.100 et seq.).
If you are a business partner, sub-contractor, or other third-party supplier, this section will be relevant to you and sets out our uses of your personal information. Please note that we collect, use, and disclose additional personal information about you if you use our website as described in the section entitled “Users of the Astron Health website.”
We do not collect any of your special categories of personal information or sensitive personal information. In the event that this changes, we will let you know.
We will collect personal information about you from the following categories of sources in the below contexts:
We may use your personal information for a number of different purposes. In each case, we must have a “legal ground” to do so. Some jurisdictions may refer to these as “business” or “commercial” purposes. We will rely on the following “legal grounds”, when we process your “personal information”:
We will disclose your personal information as reasonably necessary for the purposes set out above with the following categories of parties:
If you reside in California, please read this section for additional disclosures about how we collect, use, and disclose information about you under the California Consumer Privacy Act (or “CCPA”) (California Civil Code Section 1798.100 et seq.).
We may use your personal information to provide you with information about our products or services or which may be of interest to you where you are a website visitor or an existing patient, which are complementary to, or part of, the ongoing services we offer or where you have provided your consent for us to do so.
We may use your personal information to provide you with information about our products, our services or our research which may be of interest to you where you are a healthcare professional who has registered an interest in learning more about our work.
We and our third-party vendors may use a variety of digital technologies over time and across different websites, including this website, to facilitate, deliver, and measure these marketing messages and online targeted ads. For more information, including options you have to manage this data collection, please see our cookie policy. If you wish to opt out of marketing communications, you may do so by clicking on the “unsubscribe” link that appears in all emails or telling us when we call you. Otherwise, you can always contact us at support@astron.health to update your contact preferences.
Please note that, even if you opt out of receiving marketing messages, we may still send you communications which are relevant to the nature of the clinical services we offer you as a patient.
We will retain your personal information for as long as your account is active or as reasonably necessary to provide you services, comply with our legal and regulatory obligations, resolve disputes and/or enforce our agreements.
The exact time period will depend on your relationship with us and the type of personal information we hold.
If you would like further information regarding the periods for which your personal information will be stored, please contact us at support@astron.health.
We take reasonable precautions to help protect the security and privacy of your personal information.
We will store your personal information (including any sensitive or special categories of information) in a specialist I.T. system, hosted in the Microsoft Azure cloud platform. In order to help prevent unauthorised access, loss, misuse or disclosure, we take and maintain reasonable and appropriate technical, organisational and physical safeguards designed to protect your personal information. We have put in place physical, electronic, and managerial procedures to safeguard and secure the information you provide to us including the use of pseudonymisation, encryption generally, a clean desk policy and access controls which we regularly review. Our overall data security policies are documented under our Systems Level Security Policy and reviewed regularly.
We will never knowingly request personal information from anyone under the age of 18. Our website is not targeted to or intended for use by children. Accordingly, we do not have actual knowledge that we sell or share the personal information of consumers under the age of 16 years old. However, if we learn that we have received personal information from a child under the age of 18 without appropriate parental consent, we will delete that information from our database.
There may be some instances where your personal information is transferred to countries outside of the EEA, such as when we transfer information to a patient’s primary healthcare provider based outside the EEA, when we are treating a patient via telemedicine or when a patient elects to travel to a country outside the EEA for their treatment.
Where such a transfer takes place, we will take the appropriate safeguarding measures in accordance with applicable law to ensure that your personal information is adequately protected. We will do so in a number of ways including:
We are also entitled under European data protection laws to transfer your personal information to countries outside the EEA where it is necessary for the performance of the contract we have with you.
If you would like further information regarding our data transfers and the steps we take to safeguard your personal information, please contact us at support@astron.health.
Depending on your place of residency, including certain states in the United States and the UK or EEA, you may have a number of rights in relation to the personal information that we hold about you, which we set out below. If you or your authorized agent would like to exercise your rights, please contact us at any time at support@astron.health. In order to process your request, we may ask you to verify your identity by confirming your name, email address, phone number, or other identifiable information that we have about you in our records, such as your most recent interaction with us, if applicable.
Please note that although we take your rights seriously, there may be some circumstances where we cannot comply with your request such as where complying with it would mean that we couldn’t comply with our own legal or regulatory requirements. However, we will always respond to any request you make and if we can’t comply with your request, we will tell you why. Please note that we reserve the right to honor your request to the extent required by applicable law.
You have the right to access the information that we hold about you. We will not usually charge you in relation to a request. We are happy to provide you with such details but in the interests of confidentiality, we follow strict disclosure procedures which may mean that we will require proof of identify from you prior to disclosing such information. We will usually provide your personal information to you in writing unless you request otherwise. Where your request has been made electronically (e.g., by email), a copy of your personal information will be provided to you by secure electronic means where possible.
We take reasonable efforts to ensure that the personal information we are holding on you is accurate and up to date. However, if you do not believe this is the case, please contact us and we will promptly correct any information found to be incorrect.
In certain circumstances, you have the right to ask us to stop using your personal information, for example where you think that we no longer need to use your personal information. This may also include requests in specific contexts, such as if we process personal information that is considered “sensitive” under certain U.S. states or engage in certain automated decision-making activities.
Where we rely on your consent to process your personal information, you have the right to withdraw such consent to further use of your personal information.
In certain circumstances, you have the right to request that your personal information is deleted such as where we no longer need your personal information for the purpose we originally collected it.
You have a choice about whether or not you wish to receive marketing information from us and you have the right to request that we stop sending you marketing messages at any time. You can do this either by clicking on the “unsubscribe” button in any email that we send to you or by contacting us at support@astron.health. This also includes the right to opt out of targeted advertising, also referred to as “sharing” in some U.S. jurisdictions.
Because we may engage in the practice of online targeted advertising, we may “sell” your personal information as those terms are defined by certain jurisdictions. You may have the right to opt out of “sales” of your personal information.
In certain circumstances, you have the right to request that we transfer any personal information that you have provided to us to a third party of your choice.
We do not carry out any automated decision-making but in the event that this changes in the future, we will notify you.
If we deny your request to exercise the above rights, you may have the right to appeal the decision with us. If you would like to appeal a prior decision, please include information about your prior request to help us review your appeal request.
You have a right to complain to the Information Commissioner’s Office (“ICO”) if you believe that any use of your personal information by us is in breach of applicable data protection laws and regulations. You can visit the ICO’s website at https://ico.org.uk for more information. Please note that lodging a complaint will not affect any other legal rights or remedies that you have. If we deny your appeal to review a prior decision to exercise the above rights, you may also submit a complaint to the relevant supervisory authority, which may include the office of your state attorney general.
We will not discriminate against you for exercising these rights.
Our website may contain links to other websites of interest. However, once you have used these links to leave our site, you should note that we do not have any control over that other website. You should familiarise yourself with the privacy statement applicable to the website in question before use.
If you would like any further information about any of the matters in this policy or if you have any other questions about how we collect, store or use your personal information, you may contact our Data Protection Officer, Mr. Benjamin Whately, by email at support@astron.health or by writing us at Astron Health USA Corporation, 251 Little Falls Drive, Wilmington, Delaware, 19808.
Astron Health, which processes the personal information of individuals in the European Union and European Economic Area, in either role of ‘data controller’ or ‘data processor’, has appointed DataRep as its Data Protection Representative for the purposes of GDPR.
We may need to change this policy from time to time, for example, as the result of changes to law, technologies, or other developments. We will provide you with the most up-to-date notice and you can check this document periodically to view it.
This policy was last updated on 17th December 2024.
We have appointed a Data Protection Officer to oversee our handling of personal information. Our Data Protection Officer is Mr. Benjamin Whately, CEO and can be reached at ben@astron.health. We process your information in the ways outlined below.
For the purposes of the data protection law, Astron Health Ltd will be the data controller. Astron Health Ltd is registered with the Information Commissioners’ Office (ICO) under registration number: C1532868.
We will collect and use different personal information about you for different reasons, depending on our relationship with you.
Sometimes we will request or receive “special categories of personal information” (which is information relating to your health, genetic or biometric data, criminal convictions, sex life, sexual orientation, racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership).
Where you provide personal information to us about other individuals (for example, members of your family or other dependents) we will also be data controller of their personal information and we are responsible for protecting their personal information and using it appropriately. This policy will therefore apply to those individuals, and you should refer them to this policy. If you provide us with information relating to other individuals, we are entitled to assume that you have the required authority from that person to provide us with the information and cannot be held responsible if that is not the case.
In order to make this policy as user friendly as possible, we have split it into different sections. Please click on the section below that best describes your relationship with us and the service you receive from us.
We may share your personal data where necessary with the parties set out below in the relevant sections of this policy. We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
This section will apply if you currently participate in a cancer study or receive cancer treatment or if you are looking to participate in a cancer study or receive cancer treatment.
We may collect the following personal information:
We will collect information directly from you when:
There are a number of reasons we use your personal information and for each purpose we need to have a “legal ground” to do so.
We will rely on the following “legal grounds” when we process your “personal information”:
In each case we assess our need to use this personal information for these purposes against your rights to privacy to ensure we are protecting your rights.
For certain processing purposes, we have outlined alternative legal grounds. We will rely on the following conditions when we process your special categories of personal information:
As per the Data Protection Act 2018, when we process data based on condition in (3) above, this will be processed by or under the responsibility of a professional who is subject to the obligation of professional secrecy under relevant EU or national law.
We will keep your personal information confidential, and we will only share it where necessary for the purposes set out above with the following parties.
If you are a user of the Astron Health website, this section will be relevant to you and sets out our uses of your personal information.
We will collect information directly from you when:
As well as obtaining information directly from you, we will also collect your personal information from:
We may use your personal information for a number of different purposes. In each case, we must have a “legal ground” to do so. We will rely on the following “legal grounds”, when we process your “personal information”:
If you have filled in contact information, we will contact you to discuss the treatment and our clinical services. This will be based on you having consented to us contacting you.
When the information that we process is classed as “special categories of personal information”, we must have an additional “condition”. We will rely on the following conditions when we process your “special categories of personal information”:
If you are a healthcare professional, this section will be relevant to you and sets out our uses of your personal information.
We do not collect any of your special categories of personal information. In the event that this changes, we will let you know.
We may use your personal information for a number of different purposes. In each case, we must have a “legal ground” to do so. We will rely on the following “legal ground”, when we process your “personal information”:
We will keep your personal information confidential, and we will only share it where necessary for the purposes set out above with the following parties:
If you are a business partner, sub-contractor or other third-party supplier, this section will be relevant to you and sets out our uses of your personal information.
We do not collect any of your special categories of personal information. In the event that this changes, we will let you know.
As well as obtaining information directly from you, we will collect information from:
We may use your personal information for a number of different purposes. In each case, we must have a “legal ground” to do so. We will rely on the following “legal grounds”, when we process your “personal information”:
We will keep your personal information confidential, and we will only share it where necessary for the purposes set out above with the following parties:
We may use your personal information to provide you with information about our products or services or which may be of interest to you where you are an existing patient, which are complementary to, or part of, the ongoing services we offer or where you have provided your consent for us to do so.
We may use your personal information to provide you with information about our products, our services or our research which may be of interest to you where you are a healthcare professional who has registered an interest in learning more about our work.
We are committed to only sending you marketing communications that you have clearly expressed an interest in receiving. If you wish to opt out of marketing, you may do so by clicking on the “unsubscribe” link that appears in all emails or telling us when we call you. Otherwise, you can always contact us at support@astron.health to update your contact preferences.
Please note that, even if you opt out of receiving marketing messages, we may still send you communications which are relevant to the nature of the clinical services we offer you as a patient.
We will retain your personal information for as long as your account is active or as reasonably necessary to provide you services, comply with our legal and regulatory obligations, resolve disputes and/or enforce our agreements.
The exact time period will depend on your relationship with us and the type of personal information we hold.
If you would like further information regarding the periods for which your personal information will be stored, please contact us at support@astron.health.
We are committed to ensuring that your information is secure.
We will store your personal information (including the special category information) in a specialist I.T. system, hosted in the Microsoft Azure cloud platform. Azure data storage adheres to all data protection, privacy and security standards. More information can be found here. In order to prevent unauthorised access, loss, misuse or disclosure, we take and maintain appropriate technical, organisational and physical safeguards designed to protect your personal information. We have put in place physical, electronic, and managerial procedures to safeguard and secure the information you provide to us including the use of pseudonymisation, encryption generally, a clean desk policy and access controls which we regularly review. Our overall data security policies are documented under our Systems Level Security Policy and reviewed regularly.
There may be some instances where your personal information is transferred to countries outside of the UK or EEA (as applicable), such as when we transfer information to a patient’s primary healthcare provider based outside the UK or EEA (as applicable), when we are treating a patient via telehealth or when a patient elects to travel to a country outside the UK or EEA (as applicable) for their treatment.
Where such a transfer takes place, we will take the appropriate safeguarding measures to ensure that your personal information is adequately protected. We will do so in a number of ways including where required:
We are also entitled under UK or European data protection laws to transfer your personal information to countries outside the UK or EEA where it is necessary for the performance of the contract we have with you.
If you would like further information regarding our data transfers and the steps we take to safeguard your personal information, please contact us at support@astron.health.
Under data protection law you have a number of rights in relation to the personal information that we hold about you which we set out below. You can exercise your rights by contacting us at any time at support@astron.health.
Please note that although we take your rights seriously, there may be some circumstances where we cannot comply with your request such as where complying with it would mean that we couldn’t comply with our own legal or regulatory requirements. However, we will always respond to any request you make and if we can’t comply with your request, we will tell you why.
You have the right to access the information that we hold about you. We will not usually charge you in relation to a request. We are happy to provide you with such details but in the interests of confidentiality, we follow strict disclosure procedures which may mean that we will require proof of identify from you prior to disclosing such information. We will usually provide your personal information to you in writing unless you request otherwise. Where your request has been made electronically (e.g., by email), a copy of your personal information will be provided to you by secure electronic means where possible.
We take reasonable efforts to ensure that the personal information we are holding on you is accurate and up to date. However, if you do not believe this is the case, please contact us and we will promptly correct any information found to be incorrect.
In certain circumstances, you have the right to ask us to stop using your personal information, for example where you think that we no longer need to use your personal information.
Where we rely on your consent to process your personal information, you have the right to withdraw such consent to further use of your personal information at any time.
In certain circumstances, you have the right to request that your personal information is deleted such as where we no longer need your personal information for the purpose we originally collected it.
You have a choice about whether or not you wish to receive marketing information from us and you have the right to request that we stop sending you marketing messages at any time. You can do this either by clicking on the “unsubscribe” button in any email that we send to you or by contacting us at support@astron.health.
In certain circumstances, you have the right to request that we transfer any personal information that you have provided to us to a third party of your choice.
We do not carry out any automated decision-making but in the event that this changes in the future, we will notify you.
You have a right to complain to the ICO if you believe that any use of your personal information by us is in breach of applicable data protection laws and regulations. You can visit the ICO’s website at https://ico.org.uk for more information. Please note that lodging a complaint will not affect any other legal rights or remedies that you have.
Our website may contain links to other websites of interest. However, once you have used these links to leave our site, you should note that we do not have any control over that other website. You should familiarise yourself with the privacy statement applicable to the website in question before use.
If you would like any further information about any of the matters in this policy or if you have any other questions about how we collect, store or use your personal information, you may contact our Data Protection Officer, Mr. Benjamin Whately, by email at ben@astron.health.
Astron Health, which processes the personal data of individuals in the European Union and European Economic Area, in either role of ‘data controller’ or ‘data processor’, has appointed DataRep as its Data Protection Representative for the purposes of GDPR.
We may need to change this policy from time to time, for example, as the result of changes to law, technologies, or other developments. We will provide you with the most up-to-date notice and you can check this document periodically to view it.
This policy was last updated on 9 January 2025.