Privacy Policy
Last updated: [DATE — set on publication]
1. Who is responsible for your data
Seradiag Ltd (company number 14428934), registered office 128 City Road, London,EC1V 2NX, is the data controller for personal data collected through this website. Contact us about privacy at info@seradiag.co.uk.
[IF REGISTERED: Our ICO registration number is .]
2. Why what you buy here is treated as health data
This is the most important section of this policy, so we have put it near the top.
The tests you buy can reveal information about your health — for example ordering a pregnancy test, an HIV test or a bowel screening test. Under the UK GDPR this is special category data (data concerning health), which is given stronger legal protection than ordinary personal data.
We therefore apply extra safeguards. In particular:
- Your order history is visible only to you when signed in to your account.
- Marketing and reminder emails never name the tests you have bought, unless you have separately and explicitly asked us to allow that. A reminder will say it has been a while since your last order — nothing more. This protects you if other people can see your inbox.
- Your card statement and payment receipt show “Seradiag” and an order number only — never a product name.
- Orders are dispatched in plain outer packaging that does not indicate the contents.
- When you sign in, we give the same message whether or not an email address is registered with us, so nobody can use the login form to work out whether a particular person has bought from us.
We do not receive or store your test results. Tests are read by you at home, and results stay with you.
3. What we collect
- Account details — name, email address, and a password (stored only as a secure cryptographic hash, never in readable form).
- Contact and delivery details — delivery and billing address, phone number if you give one.
- Order information — what you ordered, when, the amount paid, and delivery status.
- Payment information — handled by Stripe. We receive confirmation of payment and a payment reference; we never see or store your full card number.
- Communication preferences — what you have agreed to receive, and when and how you agreed.
- Technical data — strictly necessary cookies for keeping you signed in and holding your basket during checkout, and, only if you consent, Google Analytics 4 cookies to understand how the site is used. See the Cookies section below.
4. Our lawful bases
| Taking and fulfilling your order | Performance of a contract (Art. 6(1)(b)) |
|---|---|
| Handling health-related purchase data | Your explicit consent (Art. 9(2)(a)), given when you place an order or create an account |
| Marketing and reminder emails | Your consent (Art. 6(1)(a)), which you can withdraw at any time |
| Keeping accounting and tax records | Legal obligation (Art. 6(1)(c)) |
| Fraud prevention and site security | Legitimate interests (Art. 6(1)(f)) |
| Medical device safety reporting | Legal obligation, where a reportable incident arises |
5. Marketing — you decide
We only send marketing if you have opted in. Consent boxes are never pre-ticked, and the options are separate so you can accept one and refuse another:
- Reorder reminders — a prompt that it has been a while since your last order. Never names a product.
- Offers and new products — occasional general news.
- Product-specific content — off by default. Only if you switch this on may our emails mention the specific tests you have ordered.
You can change these at any time in your account, or unsubscribe from any email. We record when and how you gave consent, as the ICO expects. Order confirmations and dispatch notices are service messages, not marketing, and are always sent.
6. Who we share data with
We do not sell your data, and we never share what you have bought with advertisers. We share only with:
- A payment processor — to handle your card payment securely.
- A postal courier — name and delivery address only, to deliver your order.
- Our database and authentication provider — hosted in the UK.
- Our website hosting provider.
- A transactional email service — sending order and, where consented, marketing emails.
- Regulators or authorities where we are legally required to do so, including the MHRA for medical device safety.
Three of these — the payment processor, the website hosting provider, and the transactional email service — may transfer data outside the UK as part of how their infrastructure works. Where this happens, it is safeguarded by the UK International Data Transfer Addendum together with the EU Standard Contractual Clauses (and, for some, participation in the EU-US Data Privacy Framework’s UK Extension) — the standard, ICO-recognised mechanisms for this. Our database and authentication provider stores your data in the UK, and the postal courier is a UK company, so neither transfers your data outside the UK. The specific companies we use are confidential business information, available on request — contact info@seradiag.co.uk.
7. How long we keep it
- Order and transaction records — six years after the end of the relevant tax year, as required for UK tax purposes.
- Account details — until you ask us to delete your account.
- Marketing preferences — for as long as we keep a record of your consent or objection, so we can honour it.
- Any other personal data we hold — 5 years from your last interaction with us.
If you ask us to delete your account, we remove your saved details and disconnect your order history from your login. We retain the minimum transaction record the law requires us to keep.
8. How we protect it
- All traffic is encrypted in transit (HTTPS/TLS), and data is encrypted at rest by our hosting providers.
- Passwords are stored only as salted cryptographic hashes and cannot be read by us or recovered — only reset.
- Database access controls mean your records are readable only by your own signed-in account and by authorised staff who need access.
- Our consumer store runs on infrastructure kept separate from our other business systems.
9. Your rights
You have the right to:
- ask for a copy of the data we hold about you;
- have inaccurate data corrected;
- ask us to delete your data (subject to records we must keep by law);
- object to, or ask us to restrict, certain processing;
- withdraw consent at any time, including for marketing;
- receive your data in a portable format;
- complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113.
To exercise any of these, email info@seradiag.co.uk. We will respond within one month.
10. Cookies
We use two kinds of cookies. Strictly necessary cookies keep you signed in and hold your basket during checkout — these are set automatically and don’t require consent, as the site can’t function without them. Analytics cookies(Google Analytics 4) help us understand how the site is used, and are only set if you actively agree via the cookie banner. You can change your choice at any time using the “Cookie preferences” link in the footer.
We do not use advertising or marketing cookies.
Your basket is held in your browser for the current session only, rather than stored long-term, so a shared or family device does not keep a record of what you were looking at.
11. Changes
We will post any changes here and update the date at the top. If a change materially affects how we use your data, we will tell you directly.
