At Rehuman Limited (“Rehuman,” “we,” “us,” or “our”), we are committed to protecting and processing personal data responsibly and in compliance with applicable data protection laws. This Personal Data Processing Statement outlines how we collect, process, store, and protect personal data when providing our health engagement, rewards marketplace, and loyalty program services to insurers, employers, and individual users.This statement operates in parallel with our Privacy Policy and applies to:
For questions regarding this statement, please contact us at info@rehuman.co.uk.
Rehuman may act as either a Data Controller or a Data Processor, depending on the nature of the services provided:
A. When Rehuman Acts as a Data Controller
Rehuman is a Data Controller when we collect and determine the purpose of processing personal data, such as:
B. When Rehuman Acts as a Data ProcessorRehuman acts as a Data Processor when we process data on behalf of insurers, employers, or corporate partners, such as:
When acting as a Data Processor, we only process data according to the instructions of the Data Controller (insurer, employer, or corporate partner) and ensure compliance with contractual obligations, GDPR, CCPA, and other relevant regulations.
The personal data we process may include:
A. Personal Identification Data
B. Health & Engagement Data (if user connects wearables or engages with our platform)
C. Rewards & Loyalty Data
D. Technical & Device Data
E. Payment & Financial Data (only if applicable to the marketplace)
Rehuman does not process sensitive personal data (e.g., racial/ethnic origin, religious beliefs, or biometric data) unless explicitly required for service functionality with user consent.
Rehuman processes personal data for the following purposes:
We process only the minimum amount of data required for these purposes and do not engage in profiling or automated decision-making without human oversight.
We process personal data under the following legal bases:
Rehuman retains personal data only for as long as necessary to fulfill the processing purposes:Data TypeRetention PeriodUser Engagement Data3 years from last interactionRewards Transactions5 years (for auditing & compliance)Health & Activity Data3 years (unless user requests deletion)Corporate Client DataRetained during active contractFinancial Records7 years (per compliance laws)After the retention period, data is securely deleted unless legally required to be retained. Users may request early deletion of their personal data.
We take appropriate technical and organizational measures to protect personal data from unauthorized access, loss, or misuse, including:
Data is stored on secure cloud environments (e.g., Google Firebase, AWS) and access is strictly restricted to authorized personnel.
Rehuman does not sell personal data. However, we may share data in the following circumstances:
Where data is transferred outside of the UK/EU, we ensure compliance via Standard Contractual Clauses (SCCs) or other legally approved mechanisms.
Users have rights under GDPR, CCPA, and other applicable laws to:
To exercise these rights, users can contact us at info@rehuman.co.uk.10. Updates & Contact InformationWe may update this Personal Data Processing Statement periodically. Significant changes will be communicated to users and partners in advance.
📩 For any questions or data requests, contact: Data Protection Officer (DPO) – Rehuman Limited
📧 info@rehuman.co.uk