FREE next-day delivery  ·  Results within 48 hours  

PRIVACY & DATA PROTECTION

Privacy Policy

This Privacy Policy explains how Easy Blood Check Ltd collects, uses, shares and protects your personal information when you use our website, create an account, order a test, provide a sample, book a service or contact us.

Last updated: 26 July 2026 UK customers and website users
i
Health information receives additional protection.

Blood test results, medical questionnaire responses and other health information are special category data under UK data protection law. We only use this information where we have both a lawful basis and an appropriate condition for processing health data.

Who we are

Easy Blood Check Ltd is the controller of personal information where we decide why and how that information is used in connection with our website, customer accounts, orders and services.

Our contact details are:

Easy Blood Check Ltd
21 Deepdene Way
Nottingham
NG8 6BN

Email: info@easybloodcheck.com
Telephone: 0345 060 0600
Website: easybloodcheck.com

Depending on the service, a laboratory, doctor, nurse, phlebotomist or other healthcare provider may also act as a separate controller for information they process for their own clinical, professional or legal purposes. Where required, they are responsible for providing their own privacy information.

Information we collect

We collect the information needed to provide the service you request, keep your account secure, communicate with you and meet our legal obligations. This may include:

Identity and contact detailsName, title, date of birth, postal address, email address, telephone number and, where required for testing, sex or other identifying information.
Account and order informationAccount details, order history, delivery information, booking details, test activation information and customer service records.
Health and test informationThe test ordered, sample information, laboratory results, questionnaire responses, symptoms or medication information you provide, clinical notes and doctor review information where applicable.
Payment and transaction informationPayment status, transaction references, billing details, refunds and fraud-prevention information. Full payment-card details are normally handled by our payment provider rather than stored by Easy Blood Check.
Technical informationIP address, browser and device information, website logs, security events, cookie identifiers and information about how our website is used.
Communications and preferencesEmails, messages, support enquiries, complaints, feedback and your marketing or cookie preferences.

Where a service permits a parent, guardian or authorised representative to act for someone else, we may also collect information needed to verify that authority and administer the service safely.

How we collect information

Most information is provided directly by you when you browse the website, create an account, place an order, activate a kit, complete a questionnaire, book a service, submit a sample or contact us.

We may also receive information from organisations involved in providing your service, including:

  • laboratories that analyse samples and issue results;
  • doctors and other healthcare professionals involved in collection, review or support;
  • payment providers confirming transactions, refunds or fraud checks;
  • delivery and courier providers;
  • website, hosting, security and technical service providers;
  • an authorised representative acting on your behalf.

We also collect limited technical information automatically when you use our website. Further information about cookies and similar technologies is available in our Cookie Policy.

Why we use your information

We only use personal information where data protection law allows us to do so. The basis we rely on depends on what we are doing and the type of information involved.

PurposeTypical lawful basis
Process orders, create and manage accounts, arrange delivery, activate tests, provide results and administer requested services.Necessary to perform our contract with you or take steps at your request before entering into a contract.
Process health information needed for laboratory testing, sample handling or healthcare review.An Article 6 lawful basis plus an appropriate Article 9 condition for special category data, as explained below.
Deal with enquiries, complaints, refunds, failed samples and service issues.Contract, legal obligation and/or our legitimate interests in administering and improving our services.
Prevent fraud, protect accounts, maintain website security and investigate misuse.Our legitimate interests in protecting customers, our systems and our business, and legal obligations where applicable.
Maintain accounting, tax, legal and regulatory records.Compliance with legal obligations and, where appropriate, our legitimate interests in establishing, exercising or defending legal claims.
Send marketing about Easy Blood Check products or services.Consent, or legitimate interests where electronic marketing rules lawfully permit this. You can opt out at any time.
Use non-essential cookies, analytics or advertising technologies.Consent where required by the Privacy and Electronic Communications Regulations.

Where we rely on legitimate interests, we consider whether the use of your information is necessary and balance our interests against your rights and expectations.

Health and special category data

Information about your health, including laboratory results and medical questionnaire responses, is treated as special category data. It receives additional protection under UK data protection law.

We identify both an Article 6 lawful basis and a separate Article 9 condition before processing this information. Depending on the purpose and service arrangement, the relevant condition may include:

  • explicit consent, where this is the appropriate condition and you have been asked to provide it;
  • health or social care, where processing is necessary for healthcare purposes and is carried out by, or under the responsibility of, a professional subject to an obligation of confidentiality;
  • legal claims, where information is necessary to establish, exercise or defend a legal claim;
  • vital interests or public health requirements, in the limited circumstances where the relevant legal conditions are met.

The exact condition depends on why the information is being used. We do not use your test results or other health information for unrelated advertising or profiling simply because you purchased a health test.

Where a laboratory or healthcare professional processes your information as an independent controller, that organisation is responsible for selecting and documenting its own lawful basis and special category condition.

Who we share information with

We only share information where there is a genuine need to do so, where it is lawful and where appropriate safeguards are in place.

Recipients may include:

  • accredited laboratory providers analysing your sample;
  • doctors, nurses, phlebotomists and other healthcare professionals involved in your selected service;
  • payment processors and fraud-prevention providers;
  • postal, courier and delivery companies;
  • website hosting, cloud, email, customer service, security and IT providers;
  • professional advisers, insurers, auditors and legal advisers;
  • regulators, public authorities, courts or law-enforcement bodies where disclosure is required or permitted by law;
  • a purchaser, investor or adviser involved in a genuine business sale, reorganisation or transfer, subject to appropriate confidentiality and data protection safeguards.
We do not sell your personal information or health information to advertisers or data brokers.

Where a supplier acts as our processor, we require appropriate contractual protections governing how it handles personal information.

International transfers

Some technology or service providers may store or process information outside the United Kingdom. When this results in a restricted international transfer, we use a transfer mechanism permitted by UK data protection law.

Depending on the destination and provider, this may include:

  • a UK adequacy regulation;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to the EU Standard Contractual Clauses;
  • another lawful safeguard or permitted exception.

Where required, we also assess whether the transfer provides an appropriate level of protection in practice.

How long we keep information

We do not keep personal information for longer than we reasonably need it. The retention period depends on the type of record, the service provided and any legal, clinical, regulatory, insurance or dispute-resolution requirements.

Order, contract and financial recordsNormally retained for the period needed for accounting, tax, contractual and legal-claims purposes, which may commonly be up to six years after the relevant transaction or relationship.
Health, laboratory and service recordsRetained for the period required to provide the service, maintain an appropriate audit trail and meet applicable clinical, regulatory, insurance or legal requirements. The period may vary by record type and by the laboratory or healthcare provider involved.
Customer service and complaintsKept for as long as reasonably necessary to deal with the matter and any related legal, regulatory or service-quality requirements.
Marketing preferencesKept while marketing remains appropriate. We may retain a limited suppression record after you opt out so that we can respect your preference.
Technical and security recordsGenerally kept for shorter operational periods unless they are needed to investigate a security incident, fraud or legal issue.

When information is no longer required, we delete it, anonymise it or otherwise dispose of it securely, subject to any lawful retention requirement.

How we protect your information

We use appropriate technical and organisational measures designed to protect personal information against unauthorised access, loss, misuse, alteration or disclosure.

Measures may include encrypted website connections, access controls, account security, restricted staff access, supplier due diligence, system monitoring, backups and procedures for responding to security incidents.

Access to health information is limited to people and organisations that need it for an authorised purpose. Where third parties process information for us, we require appropriate confidentiality and data protection commitments.

No internet-based service can guarantee absolute security. If we become aware of a personal data breach, we will assess it and notify affected individuals and the Information Commissioner where the law requires us to do so.

Your data protection rights

Depending on the circumstances, you may have the right to:

AccessAsk for a copy of the personal information we hold about you.
RectificationAsk us to correct inaccurate or incomplete information.
ErasureAsk us to delete information where the law gives you this right.
RestrictionAsk us to restrict how information is used in certain circumstances.
ObjectObject to certain processing based on legitimate interests and object to direct marketing at any time.
PortabilityReceive certain information in a structured, commonly used and machine-readable format where the right applies.
Withdraw consentWithdraw consent at any time where our processing relies on consent. This does not affect processing carried out before withdrawal.
Automated decisionsExercise rights that apply to certain decisions made solely by automated means.

To exercise a right, contact us at info@easybloodcheck.com. We may need to confirm your identity before disclosing or changing personal information.

We will respond without undue delay and, where the statutory time limit applies, normally within one month. Data protection law allows the response period to be extended in certain complex cases and allows the clock to be paused where clarification is reasonably required.

Rights are not absolute. In some cases, an exemption, legal duty, clinical obligation or another person’s rights may affect what we can provide or delete.

Marketing and cookies

Marketing

We may send you service messages about orders, appointments, results, account security or important changes. These are not marketing where their purpose is purely administrative.

We send marketing by email, text or similar electronic means only where this is permitted under data protection law and the Privacy and Electronic Communications Regulations. This may be because you have consented or, for existing customers, because the legal requirements for the customer soft opt-in are met.

You can unsubscribe at any time using the unsubscribe option in a marketing message or by contacting us. We will not use your health information or laboratory results to infer interests for direct marketing unless we have a separate lawful basis and any explicit consent required by law.

Cookies and similar technologies

Our website uses cookies and similar technologies for functions such as security, shopping basket operation and account access. Non-essential technologies, such as certain analytics or advertising tools, are used only where the applicable consent requirements are met.

You can manage your choices through our cookie controls. See our Cookie Policy for further information.

Children's information

Our standard online testing services are intended for adults aged 18 and over unless a particular service expressly permits testing of a minor.

Where a permitted service involves a child or young person, we may need information about the child and the parent, guardian or authorised adult involved. We take additional care to ensure that information is collected lawfully, used only for appropriate purposes and explained in clear language where this is relevant.

If you believe a child has provided personal information to us outside an authorised service, please contact us so that we can review the situation.

Questions and complaints

If you have a question, wish to exercise a data protection right or are unhappy with the way we have handled your information, please contact us first:

Email: info@easybloodcheck.com
Telephone: 0345 060 0600

Post:
Easy Blood Check Ltd
21 Deepdene Way
Nottingham
NG8 6BN

UK data protection law requires organisations to provide a clear route for data protection complaints. We will acknowledge a data protection complaint within 30 days of receiving it, take appropriate steps to investigate it, keep you informed where necessary and communicate the outcome without undue delay.

You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s data protection regulator:

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
ico.org.uk

Changes to this Privacy Policy

We may update this Privacy Policy when our services, suppliers, technology or legal obligations change. The latest version will be published on this page and the date at the top will show when it was last updated.

Where a change materially affects how we use personal information, we will take reasonable steps to bring it to the attention of affected customers where required.

Related documents

These pages explain other parts of your relationship with Easy Blood Check.