AIDA is built for people living with autoimmune conditions, so we handle health information. That deserves a clear explanation rather than a wall of legalese. This policy tells you what we collect, why, who sees it, and what you can ask us to do about it.
1. Who we are
AIDA operates myaida.app and is the data controller for the personal data described here. You can reach us through our contact page.
Practitioners who list on AIDA are separate, independent data controllers for any information you give them directly or that they collect while working with you. Their own privacy notices apply to that.
2. What we collect
When you create an account
- Your name and email address, and a password (stored encrypted — we never see it)
- The conditions you tell us you live with
- Optional detail you choose to give: why you joined, which pillars you want help with, your day-to-day challenges, age band and gender
- Whether you opted in to email updates
When you apply as a practitioner
- Contact details, practice name, professional title, website, address and postcode
- Your biography, qualifications, years of experience, languages and delivery formats
- The conditions and pillars you work with
- Profile photo and logo
When you buy something
- Order details and billing information. Card details go straight to our payment provider — they never touch our servers.
Automatically
- Standard technical data: IP address, browser and device type, pages viewed, and how you arrived. See our Cookie Policy.
3. Health information
The conditions you select are special category data under UK GDPR, which gets extra protection. We ask for it for one reason: so the site can show you practitioners, services and articles that are actually relevant to you.
- We rely on your explicit consent, given when you tick the box at sign-up.
- It is never displayed on your public profile and is not visible to other members.
- Telling us is entirely optional — every question after the account step can be skipped, and you can change or clear your answers at any time.
- You can withdraw consent whenever you like by clearing your conditions or asking us to delete your account.
4. Why we use your data
| What for | Lawful basis |
|---|---|
| Creating and running your account | Performance of a contract |
| Tailoring what you see to your conditions and goals | Explicit consent |
| Processing orders and payments | Performance of a contract |
| Reviewing practitioner applications | Legitimate interests — keeping the directory trustworthy |
| Sending you service emails (password resets, order confirmations) | Performance of a contract |
| Sending marketing emails | Consent — you can unsubscribe from any of them |
| Keeping the site secure and preventing abuse | Legitimate interests |
| Meeting our legal and accounting obligations | Legal obligation |
5. Who we share it with
We do not sell your data. We never have and we will not. We share it only with:
- Practitioners you book with — the details needed to deliver your service
- Our payment provider — to take payment securely
- Our hosting, email and analytics providers — who process data on our instructions only
- Authorities — where the law requires it
6. How long we keep it
- Account data: while your account is open, then deleted or anonymised within 12 months of closure
- Order and payment records: 6 years, because tax law requires it
- Marketing preferences: until you unsubscribe, plus a suppression record so we do not email you again by mistake
- Website logs: usually 12 months
7. Your rights
Under UK GDPR you can ask us to:
- Give you a copy of the data we hold about you
- Correct anything that is wrong
- Delete your data (“right to be forgotten”)
- Restrict or object to how we use it
- Send your data to another service in a portable format
- Withdraw consent at any time, including for health data and marketing
Just contact us and we will respond within one month. There is no charge.
8. Where your data is stored
Our servers are in the UK/EU. Some of our providers may process data outside the UK; where that happens we rely on UK adequacy regulations or standard contractual clauses to keep the same level of protection.
9. Security
The site runs over HTTPS, passwords are hashed, and access to member data is limited to people who need it to run AIDA. No system is perfectly secure, but if a breach ever affects your rights we will tell you and the regulator promptly.
10. Children
AIDA is not intended for under-18s and we do not knowingly collect their data. If you believe a child has given us information, tell us and we will remove it.
11. Changes
If we change this policy we will update the date at the top of the page, and tell you directly if the change is significant.
12. Complaints
Please come to us first — we would rather fix it. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113.
AIDA is operated by [company name], [registered address]. Company number [number]. ICO registration [number].
Questions about anything on this page? Email us at Jess@myaida.co.uk or use the contact form.