This Privacy Policy (“Policy”) is provided for the users of the Website and clients of Habitual. Its purpose is to explain the privacy choices you have when using the Website and informs you about your rights under Data Protection Legislation.
We understand how important it is to keep your personal data safe and secure and we take this very seriously. We have taken steps to make sure your personal data is looked after in the best possible way and we review this regularly.
Please read this Policy carefully, as it contains important information about who we are, your rights and how we use the personal data we collect, store and process on your behalf.
We are Habitual (the trading name for Habitual Healthcare Limited), a company registered in England and Wales with its registered office situated at 25 Eccleston Place, London, England, SW1W 9NF, with company number 15535376.
We are registered with the Information Commissioner’s Office under reference number ZB676724.
"App" means the Habitual health tracking and information mobile application.
“Cookies” means any small text file placed on your computer by the Website when you visit certain parts of the Website and/or when you use certain features of the Website.
“Data Protection Legislation” means (i) the UK GDPR; (ii) the Data Protection Act 2018, to the extent that it relates to processing of personal data and privacy; (iii) all applicable law about the processing of personal data and privacy.
“Habitual”, “our”, “us” and “we” means Habitual Health Ltd.
“personal data” means personal information about an individual that can be used to identify a person.
“Programme” means our weight loss and habit-change programme (which includes total diet replacement food products), expert articles, the App, and virtual social networks with other programme users.
“user”, “you” and “your” means users of the Website and clients of Habitual.
“Website” means www.tryhabitual.com and all associated subdomains, including the App.
“UK GDPR” means the General Data Protection Regulation (Regulation (EU) 2016/679) as incorporated into UK legislation by way of the European Union (Withdrawal Agreement) Act 2020 and as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019.
If you wish to contact us about this Policy, please email dpo@tryhabitual.com and mark for the attention of Pip Young.
When you visit the Website, make a request for us to contact you, request further information about our services and products, register to the Programme, or you contact us for any other reason, we will obtain personal data about you, such as:
We collect personal data from you automatically, as well as when you give us your data.
We will usually collect personal data from you when you:
We automatically collect some information about your visit to the Website. This information helps us to make improvements to Website content and navigation, and includes your IP address, the date, times and frequency with which you access the Website and the way you use and interact with its content.
We will collect your personal data automatically via Cookies, in line with the cookie settings on your browser. For more information about Cookies, and how we use them on the Website, please see the section below, headed ‘Cookies’.
We automatically collect information about your interactions with our email marketing communications and product-related emails, such as whether or not you open the email.
The law says we need a legal basis to collect your personal data. We may collect your personal data when:
Your personal data may be used by us from time to time in order to provide you with the best possible service and experience when using our Website and/or where you wish to register or are a registered user of the Programme. We use your personal data:
We may also share your personal data with a third party called Persona Identities Inc. in order to verify your identity when purchasing medication from us. Any personal data shared by us shall be for the purposes of providing services to you and we have the appropriate documentation in place in order to share your personal data and for it to be processed in accordance with applicable laws. Persona Identities Inc. is certified under the Data Privacy Framework Program. The Data Privacy Framework list can be accessed via the following link: www.dataprivacyframework.gov/s/participant-search
All product-related data, including daily tracking information and health history, will be made anonymous for any internal reviews and for analytics.
For the purposes of Data Protection Legislation, we are the ‘data controller’. This means we control and are responsible for the processing of your personal data.
As well as being the controller of your personal data, sometimes we process the personal data we collect about you meaning we become the “data processor”. We are the processor of your personal data when we use it for the purposes that you have instructed us to, for example, to receive support and advice from us under the Programme. We will always ensure your information is processed fairly and lawfully in accordance with our legal obligations.
At any time, you have the right to ask us to stop processing your personal data for marketing and/or market research purposes.
If you wish to exercise this right, please put your request in writing via email which should be sent to the email address stated under the section above, headed ‘Data Protection’. Please state ‘Unsubscribe’ as the subject and provide us with enough information so we can identify you (e.g. your registration details or any username).
Other than that which is permitted under our contract with you and/or your consent, we will never pass on your personal data to anyone else who does not need it, or has no right to it, unless you give us clear consent to do so.
However, there may be occasions where we may need to pass on your personal data in order to comply with any regulatory or legal obligations.
We may retain your personal data where necessary for a maximum of 7 years or until such time you are no longer a user.
Your personal data may be retained to:
Please be assured that during the period we retain your personal data, we will take the appropriate measures to keep your personal data safe and secure and will only use it for one of the purposes listed here.
When it is no longer necessary to retain your personal data, we will delete it from our system.
The security of your personal data is very important to us so we will use technical and organisational measures to safeguard it.
We take measures to ensure:
Please note that while we will use all reasonable efforts to safeguard your personal data, you acknowledge that the use of the internet is not entirely secure and for this reason we cannot guarantee the security or integrity of any personal data that are transferred from you or to you via the internet.
We also ensure that everyone handling your personal data within Habitual is subject to a duty of confidentiality and understands the importance of safeguarding your information.
We have procedures in place to deal with any suspected security breach and we will notify you and any applicable regulator of any such breach where we are required by law to do so.
You have the right to:
For further information on your rights please go to: https://ico.org.uk/individual-rights.
We do not take any responsibility for any third-party websites which you may access through links from the Website. Please ensure you read the privacy policy of every website you visit.
The Website may place and access certain Cookies on your computer. We use Cookies to improve your experience of using the Website. We have carefully chosen these Cookies and have taken steps to ensure that your privacy is protected and respected at all times.
All Cookies used by the Website are used in accordance with the UK GDPR.
Before any Cookie is placed on your computer, you will be presented with a message bar requesting your consent to set those Cookies. By giving your consent to the placing of Cookies, you are enabling us to provide a better experience and service to you. You have the right to deny consent to the placing of Cookies; however certain features of the Website may not function fully or as intended.
The Website may place the following Cookies:
You can find a list of Cookies that we use in the Cookies Schedule at the end of this Policy.
You can choose to enable or disable Cookies in your internet browser. By default, most internet browsers accept Cookies, but this can be changed. For further details, please consult the help menu in your internet browser.
You can choose to delete Cookies at any time; however, you may lose any information that enables you to access the Website more quickly and efficiently including, but not limited to, personalisation settings.
It is recommended that you ensure that your internet browser is up-to-date and that you consult the help and guidance provided by the developer of your internet browser if you are unsure about adjusting your privacy settings.
For more general information on Cookies, including how to disable and/or delete them, please refer to aboutcookies.org.
If you have a concern about the way we handle your personal data or you have a complaint about what we are doing, or how we have used or handled your personal data, then please email our contact named in the section above, headed ‘Data Protection’, who will try to resolve any query or concern you may have.
You also have a right to raise any concern or complaint with the Information Commissioner’s Office: https://ico.org.uk/.
We may update this Policy from time to time. Please check this Policy each time you access the Website to ensure you are aware of the most recent version that will apply to you.
This Policy was last updated in April 2024.
Below is a list of the Cookies that we use. We have tried to ensure this is complete and up to date, but if you think that we have missed a Cookie or there is any discrepancy, please let us know.
Cookie
Description
Duration
Type
_ga
This Cookie is installed by Google Analytics. The Cookie is used to calculate visitor, session, campaign data and keep track of site usage for the site's analytics report. The Cookies store information anonymously and assign a randomly generated number to identify unique visitors.
2 years
Analytics
_gid
This Cookie is installed by Google Analytics. The Cookie is used to store information of how visitors use a website and helps in creating an analytics report of how the website is doing. The data collected including the number visitors, the source where they have come from, and the pages visited in an anonymous form.
1 day
Analytics
_gat_gtag_UA_148894388_1
Google uses this Cookie to distinguish users.
1 minute
Analytics
mp_*_mixpanel
Mixpanel sets this cookie to determine how users use the website so that a good user experience can be provided.
1 year
Analytics
intercom-id-*
Intercom sets this cookie that allows visitors to see any conversations they've had on Intercom websites.
8 Months
Necessary
intercom-session-*
Intercom sets this cookie that allows visitors to see any conversations they've had on Intercom websites.
7 Days
MUID
Bing sets this cookie to recognise unique web browsers visiting Microsoft sites. This cookie is used for advertising, site analytics, and other operations.
1 Year
Advertisement
IDE
Google DoubleClick IDE cookies store information about how the user uses the website to present them with relevant ads according to the user profile.
1 Year
Advertisement