Privacy and confidentiality
Privacy Policy
This policy explains how Grace Belgravia collects, uses, shares, protects and retains personal information when you visit our website, order a private health test, activate a collection kit, provide a biological sample or receive laboratory results.
Contents
- 1. Who we are and the scope of this policy
- 2. Who is the data controller
- 3. Our privacy commitments
- 4. Personal data we collect
- 5. Where the information comes from
- 6. Why we use personal data
- 7. Lawful bases and special-category conditions
- 8. Health testing, results and urgent-result contact
- 9. Genetic and epigenetic information
- 10. Research, service improvement and artificial intelligence
- 11. Marketing and communications
- 12. Cookies and similar technologies
- 13. Who we share information with
- 14. Laboratories, clinicians and independent controllers
- 15. International transfers
- 16. How long we keep information
- 17. Biological samples
- 18. Security and confidentiality
- 19. Automated calculations and decision-making
- 20. Your data-protection rights
- 21. Children and tests bought for another adult
- 22. Questions and complaints
- 23. Changes to this policy
- 24. Contact details
1. Who we are and the scope of this policy
Grace Belgravia is a trading name of LOXA HOLDINGS LTD, company number 14167113. Our registered office is 71 to 75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom.
This policy applies when you:
- visit or use the Grace Belgravia website;
- contact us or subscribe to communications;
- order or receive an at home blood, saliva, swab, genetic or epigenetic test;
- activate or register a collection kit;
- attend an appointment or use a phlebotomy service arranged through us;
- provide health information or a biological sample;
- receive or discuss laboratory results; or
- make a complaint, exercise a legal right or otherwise interact with us.
This policy should be read with our Terms of Service, Returns, Cancellations and Refunds Policy, Shipping Policy and Cookie Policy.
2. Who is the data controller
LOXA HOLDINGS LTD is the controller of personal data used for the Grace Belgravia website, customer accounts, orders, support, complaints, direct marketing and the coordination of testing services, unless we tell you otherwise.
For some testing activities, an appointed laboratory, clinician, phlebotomy provider or results platform may:
- act as our processor and use information only on our documented instructions;
- act as a separate controller because professional, clinical, regulatory or laboratory obligations require it to decide how particular records are used and retained; or
- act with us under another legally recognised controller arrangement.
Where another organisation acts as a separate controller, its privacy information may be presented during kit activation, appointment booking, sample collection or results access. You may ask us to explain the organisations involved in a particular test.
We have not appointed a statutory data protection officer. Privacy questions and rights requests are handled by our Privacy Lead using the contact details at the end of this policy.
3. Our privacy commitments
We aim to process personal data lawfully, fairly and transparently; collect only what is needed; keep it accurate; retain it for no longer than necessary; and protect it with security appropriate to its sensitivity.
We use health and genetic information only for the stated testing, safety, support, legal or clearly explained optional purposes.
4. Personal data we collect
Some tests or clinical calculations may require limited demographic information for reference intervals, risk calculation or safe interpretation. We collect it only where relevant and explain why it is needed.
5. Where the information comes from
We may receive personal data:
- directly from you when you order, activate a kit, complete a questionnaire, provide a sample or contact us;
- from an adult who buys a kit for you, although that person is not entitled to receive your health results without your authority;
- from laboratories, clinicians, phlebotomists, clinics and results platforms involved in the service;
- from couriers and fulfilment providers concerning dispatch, delivery and sample transport;
- from payment, fraud-prevention and identity-verification providers;
- automatically from your browser, device, cookies and use of the website; and
- from public authorities or professional advisers where lawful and necessary.
We do not obtain your NHS or GP record merely because you purchase a test. Where a service would involve external medical records, this will be explained separately and an appropriate lawful basis will be identified.
6. Why we use personal data
We use information to:
- process payment, fulfil orders and deliver collection kits;
- register kits and link the correct sample to the correct person;
- assess sample suitability and perform laboratory testing;
- calculate derived markers and prepare reports;
- deliver results and provide test-related support;
- contact you about a result where the pathway includes a safety or critical-result process;
- manage appointments, recollections, refunds and complaints;
- keep financial, regulatory, consent and audit records;
- prevent fraud, misuse, cyber incidents and unauthorised access;
- improve website performance and service quality using appropriately minimised or aggregated information;
- send service messages and, where lawful, marketing communications;
- establish, exercise or defend legal claims; and
- comply with court orders, regulators, public-health duties and other legal obligations.
7. Lawful bases and special-category conditions
We must identify an Article 6 lawful basis whenever we process personal data. Health, genetic, biometric and certain other sensitive information also requires an Article 9 special-category condition and, where required, a condition under the Data Protection Act 2018.
| Purpose | Article 6 basis | Special-category condition where relevant |
|---|---|---|
| Orders, fulfilment, testing and results |
Contract Necessary to take steps at your request and perform our contract. |
Health or social care under Article 9(2)(h), with the applicable UK-law safeguards, where processing is carried out by or under the responsibility of a professional subject to confidentiality. Explicit consent under Article 9(2)(a) may be used where appropriate for a specified testing activity. |
| Genetic and epigenetic testing |
Contract To provide the test ordered. |
Explicit consent under Article 9(2)(a), or the health-care condition where the product and professional pathway meet its requirements. Separate consent is required for any optional secondary use that depends on consent. |
| Urgent safety contact | Legitimate interests or Vital interests | Health-care, vital-interests or public-health conditions may apply, depending on the circumstances. |
| Financial, regulatory and public-health duties | Legal obligation | The relevant health-care, public-health or substantial-public-interest condition and Data Protection Act 2018 provision where applicable. |
| Complaints, insurance and legal claims | Legitimate interests or legal obligation. | Article 9(2)(f) where processing is necessary for legal claims. |
| Security, fraud prevention and service administration | Legitimate interests | We avoid using health or genetic data unless necessary and a valid Article 9 condition applies. |
| Marketing and non-essential cookies | , or legitimate interests together with the electronic-marketing soft opt-in where legally available. | We do not use identifiable results or genetic findings for advertising segmentation. |
Where we rely on legitimate interests, we consider the necessity, expected benefit and impact on your rights. You may ask for information about a particular assessment.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not make earlier lawful processing unlawful and may not require deletion where another legal basis or retention duty applies.
8. Health testing, results and urgent-result contact
To provide a test, we may need to share identifiers, relevant questionnaire answers, sample information and order details with the appointed laboratory or clinical provider.
The laboratory may produce:
- measured biomarker values;
- calculated values, ratios, scores or classifications;
- sample-quality and analytical information;
- reference ranges and result flags; and
- clinical comments or recommended follow-up where included in the service.
Where the service includes a critical-result or safeguarding pathway, we or an authorised professional may attempt to contact you using the details supplied. Where necessary and lawful to protect health, information may be shared with an appropriate healthcare professional or emergency service.
Automated systems, contact information and third-party availability can fail. Seek urgent medical help based on symptoms and do not wait for us to contact you.
9. Genetic and epigenetic information
Genetic and epigenetic information is particularly sensitive. It may reveal information about biological relatives as well as the person tested, and interpretations may change as scientific evidence develops.
Where you order such a test:
- we collect only the identity, sample and contextual information needed for the stated product;
- the laboratory may generate raw assay data, variant calls, genotype files, epigenetic markers, scores or model-derived outputs;
- the report may contain probabilistic or informational findings rather than diagnoses;
- we do not contact relatives or disclose your result to a gift purchaser without your authority;
- we do not sell genetic information;
- we do not use identifiable genetic data for advertising; and
- we do not use identifiable genetic data for unrelated research or general-purpose AI training without a separate lawful basis and any explicit consent required.
You should not submit a sample belonging to another person or upload another person's genetic file without lawful authority and the required consent.
Withdrawal of consent cannot reverse laboratory analysis already completed or require destruction of records that must lawfully be retained.
10. Research, service improvement and artificial intelligence
We may use anonymous or properly aggregated information to understand service performance, test uptake, sample failure rates and general trends. Information that has been genuinely anonymised so that no person is identifiable is not personal data.
We do not use identifiable health, laboratory or genetic information for unrelated scientific research, commercial data licensing or training a general-purpose artificial-intelligence model unless:
- the purpose is explained separately;
- an appropriate Article 6 basis and Article 9 condition are identified;
- any explicit consent required is obtained;
- data minimisation and security safeguards are applied; and
- you are told how to withdraw or exercise relevant rights.
We may use secure software, including automated systems, to administer orders, detect errors, calculate values, format reports, identify unusual patterns and support customer service. Human oversight and the limitations of automated outputs are addressed below.
11. Marketing and communications
We send operational messages needed to provide the service, such as order confirmation, dispatch, kit activation, sample status, results availability, security alerts and important policy changes. These are not marketing messages.
We may send marketing by email or text where:
- you have given consent; or
- the electronic-marketing soft opt-in applies because you bought or negotiated to buy a similar product, were offered a clear opt-out when your details were collected and are offered an opt-out in every message.
You may unsubscribe at any time using the message link or by contacting us. We may retain a minimal suppression record so that we continue to respect your choice.
We do not use laboratory results, diagnoses, genetic variants or biological-age outputs to choose advertising audiences.
14. Laboratories, clinicians and independent controllers
A laboratory or clinician may need to keep its own test, quality, professional or medical records and may be legally responsible for deciding how those records are used and retained.
Where a provider is a separate controller:
- its own privacy notice and professional duties apply to its processing;
- it may respond directly to a rights request concerning records it controls;
- it may retain records after Grace Belgravia has deleted corresponding account information; and
- we will help identify or contact the provider where reasonably possible.
Where a provider acts as our processor, we require contractual confidentiality, security, deletion or return provisions and use only on documented instructions, subject to applicable law.
15. International transfers
Some technology, support, cloud or specialist testing providers may process information outside the United Kingdom. We do not permit a restricted transfer unless a lawful transfer mechanism applies.
Depending on the destination and provider, safeguards may include:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to the European Commission Standard Contractual Clauses;
- approved binding corporate rules; or
- a specific legal exception where appropriate.
Where required, a transfer risk assessment is used to consider whether additional contractual, technical or organisational safeguards are needed.
You may contact us for information about the relevant safeguard for a particular transfer.
16. How long we keep information
We keep personal data only for as long as reasonably necessary for the purpose collected, including health safety, laboratory quality, complaints, legal claims, financial obligations and regulatory requirements.
| Record type | Normal retention approach |
|---|---|
| Enquiries without an order | Normally up to 24 months after the last meaningful contact, unless needed for a complaint, safeguarding matter or legal claim. |
| Orders, invoices, refunds and transaction records | Normally up to 7 years after the transaction or end of the customer relationship to meet tax, accounting, contract and claims requirements. |
| Customer-support and complaint records | Normally up to 7 years after closure where needed to evidence the service and resolve claims. |
| Health questionnaires, laboratory results and clinical comments | Normally retained for the period required by the relevant service, laboratory, professional and regulatory framework. Adult testing records may commonly be retained for up to 8 years from the final result or last clinical interaction, and longer where law, safety or an active claim requires it. |
| Genetic and epigenetic test records | Retained only as long as necessary to provide the service and meet applicable laboratory, quality, legal and claims obligations. Test-specific retention information may be given during activation. |
| Security, access and technical logs | Kept for a limited period proportionate to security, fraud investigation and system reliability, commonly up to 24 months unless an incident requires longer preservation. |
| Marketing preferences | Kept while you remain subscribed. A minimal suppression record may be retained after opt-out so that we do not contact you again. |
| Cookie information | According to the duration shown in the Cookie Policy and consent tool. |
We may anonymise data instead of deleting it. A separate laboratory or clinical controller may apply a different lawful retention period.
We suspend routine deletion where records are needed for an active complaint, regulatory investigation, safeguarding matter, litigation hold or legal claim.
17. Biological samples
Blood, saliva and swab samples are sent to the designated laboratory for the test ordered. Samples may be consumed during analysis.
A laboratory may retain a sample or derivative for a limited operational period for analysis, quality control, repeat testing, complaint investigation or a legal requirement. The period varies by sample type and laboratory.
Samples are not returned to customers and are normally disposed of through an appropriate clinical-waste process after the applicable laboratory period.
We do not sell biological samples or authorise their use for unrelated research, commercial biobanking or general-purpose AI development without a separate lawful basis and any explicit consent required.
18. Security and confidentiality
Health and genetic information requires a high level of confidentiality. We and our providers use technical and organisational measures appropriate to the nature, volume and risk of the information.
Measures may include:
- encryption in transit and at rest where appropriate;
- role-based access and least-privilege controls;
- multi-factor authentication for sensitive or privileged access;
- separation or pseudonymisation of sample identifiers and customer details;
- supplier due diligence and data-protection contracts;
- logging, monitoring, backups and vulnerability management;
- staff confidentiality and privacy training;
- secure disposal and retention controls; and
- incident-response and breach-assessment procedures.
No internet or storage system can be guaranteed completely secure. If a personal-data breach creates a risk that requires notification, we will notify the Information Commissioner's Office and affected individuals as required by law.
19. Automated calculations and decision-making
Our service may use software to:
- calculate eGFR, ratios, free androgen index, biological-age estimates or other derived values;
- compare results with laboratory reference intervals;
- assign low, normal, high or other predefined classifications;
- generate standard explanatory text or safety prompts; and
- detect possible sample, identity or fraud issues.
These systems support testing and communication. We do not use test results for solely automated decisions that produce legal or similarly significant effects such as employment, insurance, credit or eligibility decisions.
Where an included clinical review is described, the relevant product information explains the role of the reviewer. You may contact us to question an automated output, request correction of inaccurate source data or ask for an explanation of the calculation used.
20. Your data-protection rights
Send a request to info@gracebelgravia.com with the subject line “Privacy request”. We may ask for information needed to verify identity and protect confidentiality.
We normally respond without undue delay and within one calendar month. A complex request may take longer where the law allows, and we will explain any extension.
A request is normally free. A reasonable fee may apply, or a request may be refused, where it is manifestly unfounded or excessive and the legal requirements are met.
Some rights are limited. For example, we may need to retain medical, laboratory, financial, safety or legal-claim records, and we cannot delete information controlled independently by another organisation.
21. Children and tests bought for another adult
Our standard consumer website and tests are intended for adults aged 18 and over. We do not knowingly provide testing to a child unless a specific product and consent process expressly permits it.
Where an adult purchases a kit as a gift, the adult providing the sample must activate the test in their own name and receive the privacy information. The purchaser does not automatically receive the test recipient's results.
Contact us if you believe a child has provided personal or sample information without the required authority.
22. Questions and complaints
Please contact our Privacy Lead first so that we can investigate and try to resolve a concern.
You also have the right to complain to the Information Commissioner's Office. Its current contact and complaint information is available on the ICO website. We would appreciate the opportunity to address the matter before you approach the regulator, but you are not required to contact us first.
A complaint to the ICO does not prevent you from seeking another legal remedy.
23. Changes to this policy
We may update this policy to reflect changes in law, testing services, laboratories, technology, business operations or data-protection guidance.
The current version and effective date will be published on the website. Where a change materially affects how existing sensitive information is used, we will provide an appropriate additional notice and obtain consent where required.
Privacy contact
24. Contact details
Privacy Lead: Grace Belgravia
Email: info@gracebelgravia.com
Customer correspondence address:
Siddeley House, Room 7, ground floor
50 Canbury Park Road
Kingston upon Thames
KT2 6LX
Legal entity: LOXA HOLDINGS LTD, company number 14167113.
Registered office: 71 to 75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom.
Do not send biological samples, used lancets, sharps or opened test kits to either address.



















