Carea Logo
Back to home

Privacy Policy

Last updated: 31 March 2025

This privacy policy sets out how Carea Group Limited (“Carea”) uses and protects your Personal Data.

1. Important information and who we are

This privacy policy gives you information about how Carea collects and uses your Personal Data through your use of this website, including any data you may provide when you register with us or download the Carea App.

This website and the Carea App are not intended for children.

Controller

Carea Group Limited, registered in England and Wales under company number 16189696 is the controller and responsible for your Personal Data (collectively referred to as “Carea”, “we”, “us” or “our” in this privacy policy). We provide tools to women who are eighteen years of age or older and are pregnant or in postpartum period to monitor their health and well-being during this time, as well as useful information to support their journey (the “Services”).

“You”, “your” are the individuals that access our website available at https://www.careaapp.com/, download and use our app (the “Carea App”) or interact with us in relation to our Services.

If you have any questions about this privacy policy, including any requests to exercise your legal rights (paragraph 9), please contact us using the information set out in the contact details section (paragraph 10).

2. The types of Personal Data we collect about you

Personal Data means any information about an individual from which that person can be identified. We may collect, use, store and transfer different kinds of Personal Data about you which we have grouped together as follows:

  • Identity Data includes first name, last name, any previous names, username or similar identifier, marital status, title, date of birth and gender.
  • Contact Data includes billing address and email address.
  • Health Data includes information that you may choose to input into the Carea App, such as:
    • Pregnancy Outcomes - whether a live birth or pregnancy loss occurred; for live births: baby's name, weight, birth date, and birth experience; for pregnancy loss: date of miscarriage.
    • Journal Entries - weight changes, baby movement patterns, emotional well-being and mood changes, symptoms experienced, dietary habits and cravings, exercise routines and physical activity levels.
    • Medical Information - blood pressure readings, blood sugar levels, ultrasound images and reports, results from prenatal tests, vaccination records, medication and supplement intake.
    • Appointment Tracking - dates and details of prenatal appointments, notes from healthcare providers, reminders for upcoming appointments.
    • Health Insights - personalised health tips and recommendations, risk assessments for conditions like gestational diabetes or preeclampsia, progress tracking against typical pregnancy milestones.
    • Lifestyle Data - sleep patterns and quality, stress levels and coping mechanisms, hydration levels, sexual activity and libido changes.
    • Baby Development - weekly updates on baby's growth and development, visualisations of baby's size.
    • Community and Support - participation in forums or support groups, sharing experiences and advice with other users, access to expert Q&A sessions.
  • Transaction Data includes details about payments to and from you and other details of Services you have purchased from us.
  • Technical Data includes IP address, login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, device ID, and other technology on the devices you use to access our website and/or the Carea App. This also includes device type, screen resolution, language preferences, network information, referring website or application, session duration and interaction data, and error reports and performance data.
  • Profile Data includes your username and password, purchases or orders made by you, your interests, preferences, feedback and survey responses.
  • Usage Data includes information about how you interact with and use our website and/or the Services provided through the Carea App.
  • Marketing and Communications Data includes your preferences in receiving marketing from us and our third parties and your communication preferences.

We also collect, use and share aggregated data such as statistical or demographic data which is not Personal Data as it does not directly (or indirectly) reveal your identity.

3. How is your Personal Data collected?

We use different methods to collect data from and about you including through:

  • Your interactions with us. You may give us your Personal Data by filling in online and/or in-app forms or by corresponding with us by email or otherwise. This includes Personal Data you provide when you visit our website, download and use the Carea App, create an account, subscribe to our service or publications, request marketing, enter a promotion or survey, or give us feedback or contact us.
  • Automated technologies or interactions. As you interact with our website and/or the Carea App, we will automatically collect Technical Data about your device, application usage, equipment, browsing actions and interaction patterns using cookies, server logs, mobile analytics software, and other similar technologies. Please see our cookie policy for further details.
  • Third parties or publicly available sources. Technical Data is collected from analytics providers such as Google (based outside the UK). Contact and Transaction Data is collected from payment service providers such as RevenueCat and Stripe (both based outside the UK), which also enables support for Apple Pay and Google Pay. Our payment providers collect all payment data directly from you and will not share it with us.

4. How we use your Personal Data

Legal basis

The law requires us to have a legal basis for collecting and using your Personal Data. We rely on one or more of the following legal bases:

  • Performance of a contract with you: Where we need to perform the contract we are about to enter into or have entered into with you.
  • Legitimate interests: We may use your Personal Data where it is necessary to conduct our business and pursue our legitimate interests, for example to prevent fraud and enable us to give you the best and most secure customer experience.
  • Legal obligation: We may use your Personal Data where it is necessary for compliance with a legal obligation that we are subject to.
  • Consent: We rely on consent only where we have obtained your active agreement to use your Personal Data for a specified purpose, for example for your Health Data if you subscribe to an email newsletter.

Purposes for which we will use your Personal Data

Purpose / UseType of DataLegal Basis, Conditions for Processing & Retention Period

To register you as a new customer and create your profile, including inputting information about your pregnancy journey and any related health insights. For instance:

a) We collect date of birth to confirm your eligibility for the Carea App. You should be 18+ to register for the Services. We also collect email address so that we can verify your account.

b) We use your email address to send you an invitation where you have been referred to Carea.

c) The Health Data we process enables us to provide the Service to you and our clinical team to provide you with appropriate support or information when you request or need this support.

a) Identity

b) Contact

c) Health (where provided by you, such as pregnancy progress, IVF details, or well-being check-ins)

Art. 6 Lawful Basis for Processing:

a) Performance of a contract with you (to create and manage your account);

b) Legal Obligation; and

c) Legitimate Interest (running our business but excluding Health Data)

Art. 9 Conditions for Processing:

b) Explicit consent (for the processing of health data you provide, such as pregnancy-related tracking or well-being entries). Article 9 - Archiving, research and statistics with a basis in law.

Retention:

Personal Data will be retained for as long as you have an active account. If you delete your account, we will erase your data within 30 days, unless we are required to retain it for legal or regulatory reasons.

To provide the Services to you including personalised tracking and insights (e.g., reminders for IVF medications, milestone tracking, and tailored content based on your pregnancy stage and well-being status).

a) Identity

b) Contact

c) Health (where provided by you, such as IVF treatment details, medication tracking, and mental well-being check-ins)

d) Profile

Art. 6 Lawful Basis for Processing:

a) Performance of a contract with you (to provide App Services tailored to your pregnancy journey);

b) Necessary for our legitimate interests (to improve our Services based on anonymised insights).

Art. 9 Conditions for Processing Health Data:

Explicit consent (for processing Health Data you voluntarily provide).

As outlined in Article 9.2(h) of the GDPR. This processing is carried out by us, where applicable under the responsibility of professionals who are subject to the obligation of professional secrecy.

Retention:

Health data will be retained for as long as you have an active account. Upon deletion of your account, health-related data will be deleted within 30 days. Anonymised data may be retained for research and analytics.

To manage our relationship with you, including:

a) Notifying you about changes to our terms or privacy policy.

b) Dealing with your requests, complaints, and queries.

c) Providing customer support related to the Carea App and website.

We may also use your Personal Data to:

d) Investigate any suspected breaches of, and enforce our Terms.

e) Process and deal with any complaints made by or about you.

f) Investigate usage of the Carea App or the Services that may be inappropriate.

g) Enforce our Carea App End-user Terms.

a) Identity

b) Contact

c) Profile

d) Marketing and Communications

Art. 6 Lawful Basis for Processing:

a) Performance of a contract with you (to provide account support and service updates);

b) Necessary to comply with a legal obligation (to keep records of user interactions and complaints);

c) Necessary for our legitimate interests (to manage customer relationships and service improvements, and to study how you use our Services).

Retention:

Data related to service requests, complaints, and queries will be retained for 6 years after the last interaction, in line with legal limitation periods for potential claims.

To administer and protect our business, the Carea App, and website (including troubleshooting, data analysis, testing, system maintenance, support, reporting, and hosting of data).

a) Identity

b) Contact

c) Technical

Art. 6 Lawful Basis for Processing:

a) Necessary for our legitimate interests (to run and improve our Carea App and website, ensure security, and prevent fraud);

b) Necessary to comply with a legal obligation (to maintain data security).

Retention:

Technical logs and security data will be retained for up to 12 months, unless required for longer retention due to security investigations or legal requirements.

To deliver personalised content and recommendations, including:

a) Suggested articles, podcasts, or mindfulness exercises based on your pregnancy journey.

b) Targeted in-app notifications and emails about relevant topics.

a) Identity

b) Contact

c) Profile

d) Usage

e) Health (where provided by you, to tailor recommendations and insights)

Art. 6 Lawful Basis for Processing:

a) Performance of a contract with you;

b) Necessary for our legitimate Interest (to enhance the user experience by tailoring content to their pregnancy journey and to help refine and improve content offerings);

c) Protection of vital interests: where we are concerned about your safety or the safety of another and a user is physically or legally incapable of giving consent. See the ‘Risk or crisis situations’ section.

Art. 9 Conditions for Processing:

a) Explicit consent (for using Health Data to personalise content); Article 9(2)(i) and (h) To protect Vital Interests and for Health or Social care.

b) To improve user engagement and relevance of content; Art. 6.1 (Lawful Basis).

Retention:

Data used for personalisation will be retained for as long as you have an active account. If you opt out of personalisation, data will be deleted within 30 days.

To carry out market research through your voluntary participation in surveys.

a) Identity

b) Contact

c) Profile

Art. 6 Lawful Basis for Processing:

a) Necessary for our legitimate interests (to understand customers' needs and improve our Services);

b) Consent (where required for optional surveys).

Retention:

Survey responses will be anonymised where possible. Identifiable survey data will be retained for 2 years before deletion.

Purposes, data types, lawful bases and retention

Anonymised Data

We use your Personal Data and Special Category Data to create data sets and reports that contain anonymised data that cannot be used to identify you. We use such reports and data, and may disclose them to external parties, for statistical, analytical and reporting purposes; research; and for evaluating and enhancing the Carea App or our site or improving the Services.

Risk or crisis situations

In the rare situation where we feel that you or someone else is at risk, we may use your Personal Data and Special Category Data to escalate risk to the appropriate external support mechanisms. External support mechanisms may include the appropriate representative from your GP, third party escalation services and/or the emergency services.

Direct marketing

During the registration process you will be asked to indicate your preferences for receiving direct marketing communications from us via email. We may also analyse your Identity, Contact, Technical, Usage and Profile Data to form a view on which Services and offers may be of interest to you.

Third party marketing

We will never sell your Personal Data to any third party. We will only share your Personal Data with any third party for their own direct marketing purposes if we have obtained your express consent.

Opting out of marketing

You can ask us to stop sending you marketing communications at any time by following the opt-out links within any marketing communication sent to you or by contacting us at support@careaapp.com.

Cookies

For more information about the cookies we use and how to change your cookie preferences, please see our cookie policy.

5. Disclosures of your Personal Data

We may share your Personal Data where necessary for the purposes set out above. We may also share your Personal Data with third parties in connection with a sale, transfer or merger of parts of our business or assets.

We require all third parties to respect the security of your Personal Data and to treat it in accordance with the law. We do not allow our third-party service providers to use your Personal Data for their own purposes.

6. International transfers

We do not transfer your Personal Data outside of the EU.

7. Data security

We have put in place appropriate security measures to prevent your Personal Data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. We limit access to your Personal Data to those employees, agents, contractors and other third parties who have a business need to know.

We have put in place procedures to deal with any suspected Personal Data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

8. Data retention

Details of retention periods for different aspects of your Personal Data are set out in the section above covering purposes for which we will use your Personal Data.

9. Your legal rights

You have a number of rights under data protection laws in relation to your Personal Data. You have the right to:

  • Request access to your Personal Data (commonly known as a “subject access request”).
  • Request correction of the Personal Data that we hold about you.
  • Request erasure of your Personal Data in certain circumstances.
  • Object to processing of your Personal Data where we are relying on a legitimate interest as the legal basis, including the absolute right to object to processing for direct marketing purposes.
  • Request the transfer of your Personal Data to you or to a third party in a structured, commonly used, machine-readable format.
  • Withdraw consent at any time where we are relying on consent to process your Personal Data.
  • Request restriction of processing of your Personal Data in certain scenarios, for example where you want us to establish its accuracy or where you have objected to our use of it.

You will not usually have to pay a fee to exercise these rights. We try to respond to all legitimate requests within one month.

10. Contact details

If you have any questions about this privacy policy or about the use of your Personal Data, or if you want to exercise your privacy rights, please contact us at support@careaapp.com.

11. Complaints

You have the right to make a complaint at any time to the Information Commissioner’s Office (“ICO”), the UK regulator for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.

12. Changes to the privacy policy

We keep our privacy policy under regular review. This version was last updated on 31 March 2025. It is important that the Personal Data we hold about you is accurate and current. Please keep us informed if your Personal Data changes during your relationship with us.

13. Third-party links

This website and/or the Carea App may include links to third-party websites, plug-ins and applications. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit.