Legal

Privacy notice

Mental-health data is among the most sensitive information a person can share. This notice explains what BioTekk collects, why, who can see it, and what you can ask us to do about it.

Version 1.0 · Last updated 27 July 2026 · BIOTEKK LIMITED

1. Scope of this notice

This notice covers personal data processed through the BioTekk website at www.biotekk.com and through business activities such as enquiries, pilot discussions, investor requests and the development briefing.

The BioTekk platform is in active development. Where the platform is made available through an organisation — an NHS or private healthcare provider, a university, or an employer — that deployment will be governed by its own privacy information and a written agreement between BioTekk and that organisation. Where the terms of a specific deployment differ from this notice, the deployment documentation applies to the platform, and this notice continues to apply to the website.

2. Who we are

BIOTEKK LIMITED is a company registered in England & Wales, with its registered office at 2, One Millennium Bridge, London, EC4V 3TT, United Kingdom. For personal data collected through this website, BioTekk is the data controller.

Data protection enquiries: privacy@biotekk.com.

3. Roles, access and organisational reporting

The separation of roles is a deliberate design decision, not a configuration detail. Our recommended organisational model is:

  • The individual can see their own conversations, reflections and wellbeing trends.
  • Authorised professionals — those with a legitimate care or support relationship — may see summaries and prioritisation information appropriate to their role, under access controls and audit logging.
  • Managers and employers do not receive individual conversation content. Organisational reporting is aggregated, and should be configured so that small-group figures cannot be used to identify an individual.
  • BioTekk staff access identifiable content only where strictly necessary — for example to investigate a safety incident or a specific support request — under logged, role-based controls.

Where a deployment proposes access arrangements that differ from this model, that is a matter for the organisation's own governance process, and it must be reflected in the privacy information given to the people affected before they use the platform.

4. What we process, and why

4.1 Website enquiries

When you submit the contact or investor form we process the details you provide — such as name, email address, organisation, role, enquiry type, indicative population size, timescale and the content of your message — together with your consent selections. We use this to respond to you, to assess whether a pilot or investor conversation is appropriate, and to keep a record of the enquiry.

Please do not use website forms to send personal health information about an identifiable individual. If you do, we will handle it in line with this notice and delete it when it is no longer needed for the enquiry.

4.2 Development briefing

If you subscribe, we process your email address and subscription status in order to send occasional updates. Every message includes an unsubscribe route, and you can also unsubscribe by emailing us.

4.3 Technical and security data

Our hosting and form-handling providers process limited technical information as part of delivering the site securely — for example IP address, user agent, request time and spam-filtering signals. This is used for service delivery, abuse prevention and security, not for advertising or profiling.

4.4 Platform data (in development)

Within the platform itself, the categories of data intended to be processed include conversational content you choose to share, reflection and journal entries, wellbeing indicators derived from that content over time, safety-relevant signals, account and authentication data, and — only where separately and explicitly consented to — optional biometric or wearable measurements such as heart-rate variability, electrodermal activity, skin temperature and blood-oxygen saturation. Health data and any biometric data used to infer wellbeing are treated as special-category data.

Optional biometric features remain on the research and development roadmap, are never enabled by default, and can be declined or withdrawn without losing access to the core support features. Individual biometric signals will not be presented as independent evidence of a mental-health condition. Read the position statement.

5. Lawful bases

  • Consent — for the development briefing, for optional biometric and wearable features, and for other optional processing. Consent can be withdrawn at any time.
  • Legitimate interests — for responding to business enquiries, assessing investor requests, protecting the security of our systems, and developing and improving our services. We balance these against your rights and interests.
  • Contract — where processing is necessary to provide a service you or your organisation has entered into.
  • Legal obligation — where we must retain or disclose information to comply with the law.
  • Vital interests and, in a care setting, the health and social-care conditions in data-protection law — relevant to safety escalation where there is a serious risk to life. Any such processing is limited to what is necessary and is documented.

For special-category data such as health information, we rely on explicit consent or another applicable condition under UK GDPR Article 9 and the Data Protection Act 2018, and we maintain the required documentation for that processing.

6. AI processing and automated decisions

The platform uses AI models to interpret language, generate supportive responses, summarise information for authorised professionals and identify defined indicators of concern.

  • Automated outputs are decision support. They are not intended to make a clinical decision about a person without human involvement.
  • Escalation and safeguarding decisions are designed to involve a human — a professional, a responsible person within the organisation, or an appropriate service.
  • Where third-party model providers are used, we require contractual terms restricting use of the data to providing the service, and we do not permit customer content to be used to train third-party foundation models.
  • Where we evaluate or improve our own models, we work with de-identified or minimised data wherever it is technically possible to do so.

Our approach to human oversight is described in more detail on the technology and safety pages.

7. Who we share data with

We share personal data only where there is a clear reason to:

  • Service providers acting as processors under written contract — for example website hosting and form handling, email delivery, cloud infrastructure and AI model inference.
  • Your organisation, where you access the platform through a provider, university or employer, strictly in line with the access model described in section 3.
  • Emergency and safeguarding services, where there is a serious and immediate risk to life and disclosure is necessary and lawful.
  • Professional advisers, auditors and regulators, where required.
  • A successor entity, in the event of a reorganisation or transfer of the business, subject to equivalent protections.

We do not sell personal data, and we do not share it for third-party advertising.

8. International transfers

We prefer UK or EEA processing for platform data. Where a provider processes data outside the UK, we put an approved safeguard in place — UK adequacy regulations, the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses — together with a transfer risk assessment and, where appropriate, additional technical measures.

9. How long we keep data

  • Website enquiries — retained for up to 24 months after our last substantive contact, unless a longer period is needed for a live commercial relationship or a legal obligation.
  • Briefing subscriptions — retained until you unsubscribe, plus a minimal suppression record so we do not contact you again.
  • Investor requests — retained for up to 24 months, or longer where required for regulatory record-keeping.
  • Technical and security logs — typically retained for short periods measured in days or months, according to the provider's configuration.
  • Platform data — retention will be defined per deployment, documented in the relevant agreement, and set to the shortest period consistent with continuity of care and any legal or clinical record-keeping duty.

10. Security

We apply encryption in transit and at rest, role-based access control, least-privilege administration, audit logging of access to sensitive records, environment separation, secure development practices, dependency and vulnerability management, and incident response procedures. Security controls are reviewed as the platform develops.

No system can be guaranteed to be completely secure. If you believe you have found a vulnerability, please contact security@biotekk.com and do not include personal data in your initial report.

11. Your rights

Under UK data-protection law you have the right to:

  • be informed about how your data is used;
  • request access to a copy of your personal data;
  • have inaccurate data corrected;
  • request erasure, where an exception does not apply;
  • restrict processing in certain circumstances;
  • object to processing based on legitimate interests, and to direct marketing at any time;
  • request portability of data you have provided, where applicable;
  • withdraw consent at any time, where processing is based on consent; and
  • not be subject to a decision based solely on automated processing that has a legal or similarly significant effect on you.

To exercise a right, email privacy@biotekk.com. We will respond within one month and will tell you if we need longer because the request is complex. We may ask you to verify your identity before we disclose information.

If you access the platform through an organisation, you may also be able to raise a request with that organisation, and we will support them in responding.

You have the right to complain to the Information Commissioner's Office (ico.org.uk, helpline 0303 123 1113). We would appreciate the chance to address your concern first.

12. Children and young people

The website is intended for adults. Any deployment involving children or young people will only proceed with an age-appropriate design assessment, an appropriate consent or parental responsibility model, safeguarding arrangements agreed with the organisation, and privacy information written in language the intended users can understand.

13. Changes to this notice

We will update this notice as the platform develops. The version number and date at the top of this page indicate the current version. Where a change materially affects how we use your data, we will take reasonable steps to tell you directly.

14. Contact

BIOTEKK LIMITED, 2, One Millennium Bridge, London, EC4V 3TT, United Kingdom.
Privacy: privacy@biotekk.com
Clinical safety: safety@biotekk.com
General: info@biotekk.com

This notice provides information about our data-protection practices. It is not legal advice, and it does not replace the privacy information provided by an organisation that deploys the platform.

Questions about
your data?

Data-protection enquiries are routed to a named owner, not a shared queue. Ask us anything about how the platform handles information.