Managed Self Ltd ("we", "us", "our", "Klarity") is a company registered in England and Wales with company number 10696687. Our registered office is Alum House, 5 Alum Chine Road, Westbourne, Bournemouth, BH4 8DT, United Kingdom.
We are committed to protecting your privacy and ensuring fair and transparent processing of your information. This Policy explains how we collect, use, share and protect your information in connection with Klarity's screening programmes and related services.
They never see your individual results, and they never see any figure drawn from a group smaller than 25 people.
Where your employer or another organisation has arranged for you to take part in a Klarity programme, section 5 explains exactly what that organisation, and any adviser acting for it, can and cannot see.
Information we collect
We collect information through our online questionnaire and related services, including:
- Personal health information, such as your medical history, symptoms, family history of disease and any test results arranged through the programme
- Demographic information, such as your age, sex and ethnicity
- Lifestyle information, such as diet, exercise habits, sleep, alcohol and smoking status
- Data from wearable devices and from optional facial-scan features, where you choose to connect or use them
- Device-related data, such as IP address and device type
Where your participation is arranged through your employer, we also hold the work location your employer has assigned to you, so that programme reporting can be broken down by site.
We do not carry out genetic testing and we do not collect genetic data. Where we refer to family history, we mean information you tell us about conditions in your family.
Health data and ethnicity are special category data under UK GDPR. We process them on the basis of your explicit consent under Article 9(2)(a), or where another Article 9 condition applies, as set out in section 4 of our Privacy Policy.
Purposes of processing
We use your information for the following purposes:
- Cancer screening: to assess your eligibility and facilitate screening procedures
- Risk prediction models: to analyse your information using proprietary AI models to assess risk for different types of cancer
- Personalised recommendations: to provide tailored screening recommendations
- Service delivery: to arrange screening services, including at-home sample collection kits and clinic appointments
- Programme reporting: to produce aggregated and anonymised reports for the organisation funding the programme, as described in section 5
Third-party suppliers
To deliver comprehensive cancer screening services, we work with trusted partners. These include:
These suppliers are contractually bound to confidentiality, to process information only as required to deliver services, and to comply with applicable data protection law.
The organisations described in section 5.3 are not suppliers and do not act on our behalf. They receive only the aggregated and anonymised reports described in that section, and they receive no personal information about you.
Use of AI
We do use AI, and we want to be precise about how.
Our own proprietary risk models process your health, lifestyle and demographic data to produce your risk indicators and recommendations. This is core to the service and is carried out under the lawful bases set out in our Privacy Policy. These models run within our own secured environment.
We also use third-party generative AI services to help produce written content such as personalised health plans. Where we do, we do not send those services information that directly identifies you, including your name, contact details, date of birth or any account identifier. Data sent to those services is pseudonymised, and they are contractually prohibited from using it to train their own models.
AI-generated content is intended to support, not replace, professional advice. No decision with a legal or similarly significant effect on you is made solely by automated means. By using Klarity services you acknowledge this use of AI.
How we share information
We may share your information only as follows.
5.1To deliver your care
- With authorised healthcare professionals: to review your results and provide guidance
- With third-party service providers: such as our phlebotomy and laboratory partners, as listed in section 3
5.2Where the law requires it, or where you ask us to
- Where we are legally obliged to do so, or to establish, exercise or defend legal claims
- With anyone else you specifically ask us to share with, such as your GP
5.3Aggregated and anonymised programme reporting
Where an organisation funds or arranges a Klarity programme, we provide that organisation with reports on how the programme is running and on the general health trends of the participating population. These reports are aggregated and anonymised. They contain no information that identifies you, and they cannot be used to work out anything about you as an individual.
Who receives these reports
- The organisation funding or arranging the programme, which is usually your employer
- That organisation's appointed benefits adviser or insurance broker, where the organisation has instructed us in writing to share the reports with them. Advisers and brokers receive the reports only on that instruction, and only in the same form as the funding organisation receives them.
- Participation figures, such as the number of people invited, the number who started an assessment and the number who completed one
- Aggregate distributions of assessed risk across the participating population
- Aggregate patterns in modifiable health factors, such as physical activity, diet, alcohol and smoking, and in the health goals participants have chosen
- Aggregate uptake of screening tests arranged through the programme
- Comparisons against published population benchmarks
- Your name, contact details, date of birth, staff number, job title or any other identifier
- Your individual assessment answers, risk score, results, screening outcomes or clinical history
- Any indication of whether you personally took part, declined to take part or withdrew
- Any free-text you have written
- Any figure, count, percentage or chart derived from a group of fewer than 25 people who completed an assessment
The minimum group size
We apply a minimum group size of 25 completed assessments to every figure in every report. If a site, team, age band, or any other grouping has fewer than 25 completed assessments, no figure for that grouping is shown at all. It is not shown with a caveat, and it is not shown rounded. It is withheld.
The floor applies to every figure for a grouping, not only to figures about results. If a site has 40 people invited but 12 completed assessments, we withhold its participation counts as well as its health figures.
It also applies after any breakdown. A site with 60 completed assessments broken down by age band has each band tested against the floor separately, because that is where small groups actually appear.
We also apply further statistical controls so that withheld figures cannot be recovered indirectly, including rounding of counts, withholding percentages where the underlying numbers are small, and preventing figures from being calculated by comparing one report against another. These controls are set out in our internal disclosure-control standard, which we review at least annually and which we will describe to you on request.
Taken together, these controls are designed so that no individual can be identified from a report, whether from the report on its own or in combination with other information that the recipient is reasonably likely to have. On that basis the reports are anonymous information rather than personal data, and UK GDPR does not apply to them. We assess and document that judgement against ICO anonymisation guidance before any new report format is released, and we reassess it at least annually.
How the reports may and may not be used
Recipients of these reports are contractually required to:
- use the reports only to evaluate and improve the programme and to plan workplace health and wellbeing support
- not use the reports, or anything derived from them, to set, negotiate or justify insurance premiums, to underwrite any policy, or to price any product or service
- not use the reports to make, inform or support any decision about any individual, including any decision about employment, role, pay, benefits, insurance cover or continued engagement
- not attempt to identify any individual from the reports, and not combine the reports with any other information for that purpose
- not pass the reports on to anyone else without our written agreement
Where you can find out more
You can ask us at any time what reports have been provided in connection with your programme, and to whom. We will tell you. Contact us using the details in section 11.
5.4International transfers
We store your personal information in the United Kingdom, and our teams outside the UK do not have access to it. The one exception is website analytics data, which is described in our Cookie Policy and in section 7 of our Privacy Policy. If any other transfer outside the UK ever becomes necessary, we will put appropriate safeguards in place, such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, and we will update this Policy.
5.5What we never do
We do not sell or share your information for marketing or promotional purposes.
We do not share your individual health information with your employer, with your employer's adviser or broker, or with any insurer. The only exception is where you personally instruct us in writing to share your information with a named recipient, as described in section 5.2. We will never do this on the instruction of your employer, its adviser, its broker or an insurer, and we will never do it because a contract with them requires it.
Security
We implement strict security measures to protect your information against unauthorised access, disclosure, alteration or destruction, including:
- Encryption during transmission and storage
- Access controls limiting access to authorised personnel only
- Secure storage in line with industry standards and GDPR
- Data lifecycle management to ensure secure disposal when no longer needed
- Controls governing the production and release of the reports described in section 5.3, including access logging
Retention
We retain information only for as long as necessary to fulfil the purposes described in this Policy, or to meet legal, regulatory or contractual obligations. When determining retention periods, we consider:
- our contractual obligations to you
- applicable legal requirements
- our legitimate interests (such as maintaining records and improving services)
- the need to resolve potential disputes
In most cases we retain your information for 7 years after our last contact with you, matching the period stated in section 9 of our Privacy Policy. Once the retention period has expired, information is securely deleted or anonymised.
Reports produced under section 5.3 are anonymised and are not personal information. They are therefore not deleted when your information is deleted, and they are not affected if you withdraw your consent or ask us to erase your data. This is because they contain nothing that relates to you as an identifiable person.
Your rights
You have the following rights under data protection law:
- Right to be informed: about how your information is used
- Right of access: to your information
- Right to rectification: of inaccurate or incomplete information
- Right to erasure: in some circumstances
- Right to restriction of processing: in some circumstances
- Right to data portability: to obtain and reuse your information
- Right to object to certain processing, including processing based on legitimate interests
- Right to withdraw consent at any time where we rely on consent, without affecting processing carried out lawfully before withdrawal
- Right to lodge a complaint with a supervisory authority
You can exercise your rights by contacting us at info@getklarity.io. We will respond within one month. You also have the right to complain to the Information Commissioner's Office, where our registration reference is ZA748065.
Data breach notification
If a data breach may pose a risk to your rights and freedoms, we will notify you and the ICO without undue delay, and within 72 hours where feasible, in line with GDPR requirements.
Changes to this Policy
We may update this Policy from time to time to reflect changes in our processing practices or legal requirements. We will publish the updated Policy on our website and notify you of material changes.
Where a change materially affects how your information is shared, we will notify you directly and, where the change relies on your consent, we will ask for your consent again before the change applies to you.
Contact
If you have questions, concerns or wish to exercise your data rights, contact us. Data protection is overseen by our Privacy and Security Officer, who you can reach at info@getklarity.io — mark your message for their attention. Our ICO registration reference is ZA748065.
Alum House, 5 Alum Chine Road
Westbourne, Bournemouth
BH4 8DT
United Kingdom
Wycliffe House, Water Lane
Wilmslow, Cheshire
SK9 5AF
Our ICO registration reference is ZA748065.
ico.org.uk/concerns/casework@ico.org.ukIf you are not satisfied with our response, you can complain to the UK Information Commissioner's Office.