UK Privacy Policy
UK Privacy Policy
Last Updated: February 2026
Index
Function Health, Inc. and certain of its corporate affiliates (collectively, “Function,” “we,” “us” or “our”) understand that your privacy is important to you and that you care about how your Personal Data is used. We respect your privacy and are committed to protecting your Personal Data.
This Privacy Policy applies to our collection, use and sharing of your Personal Data when making available our UK websites that link to this Privacy Policy (together, the “Site”), as well as associated marketing activities and any other activities described in this Privacy Policy. Under the GDPR, we are a ‘controller’ for the activities covered by this Privacy Policy. This Privacy Policy does not apply to our other websites. For example:
For reference, when we refer to “Personal Data”, we mean any information which identifies you as an individual or which otherwise renders you identifiable. When we use the term “GDPR”, we are referring to the UK General Data Protection Regulation.
The Personal Data we typically collect about you is outlined in the table below.
Category of Personal Data
Contact Data
Technical Data
Communications Data
Analytics Data
Category of Personal Data
What this means
Contact Data
Technical Data
Communications Data
Analytics Data
No obligation to provide Personal Data. You do not have to provide Personal Data to us. However, where we need to process your Personal Data either to comply with applicable law or to deliver our Site, and you fail to provide that Personal Data when requested, we may not be able to provide some or all parts of our Site. We will notify you if this is the case at the time.
Don’t give us sensitive information. We ask that you do not provide us with any sensitive types of Personal Data (e.g., health-related information, information related to racial or ethnic origin, political opinions, religion or other beliefs, criminal convictions information etc) – whether through the Site or otherwise. For example, please do not input any of these types of sensitive information in any free-text ‘message’ fields via which you can communicate with us on the Site (e.g., using any ‘Contact Us’ functionality or similar).
We use your Personal Data for the purposes listed below and any associated sharing of Personal Data (see the section called How we share your Personal Data, below).
In respect of each of the purposes for which we use your Personal Data, the GDPR requires us to establish a ‘legal basis’ for that use. Our legal bases for processing your Personal Data described in this Privacy Policy are listed below.
SITE OPERATION
Purpose: To provide, operate and secure the Site.
Categories of Personal Data:
Legal basis:
BUSINESS ADMINISTRATION
Purpose: Administration and operation of our business and business planning activities, including to analyse, adapt and improve our business.
Categories of Personal Data:
Legal basis:
PERSONALISATION
Purpose: To personalise your experience with the Site (including remembering your selections and preferences as you navigate).
Categories of Personal Data:
Legal basis:
DEALING WITH YOUR CONTACTS WITH US
Purpose: To deal with any contact you might make with us using any 'Contact us' or similar function on the Site or via any other method of communication (e.g., by email), as well as any issues arising from such contacts (including replying to you).
Categories of Personal Data:
Legal basis:
MARKETING AND RELATIONSHIP MANAGEMENT
Purpose: To communicate with you (including to provide updates on our activities, the Site and any other products or services), including as part of our marketing activities and/or for customer, vendor or partner relationship management purposes.
Categories of Personal Data:
Legal basis:
IMPROVEMENT AND ANALYTICS
Purpose: To analyse your usage of our Site, understand user activity, and improve the Site.
Categories of Personal Data:
Legal basis:
PRIVACY PROTECTIVE STEPS
Purpose: We may aggregate, deidentify or anonymise certain Personal Data for our legitimate business purposes. If we aggregate, deidentify or anonymise your Personal Data such that it is no longer Personal Data (i.e., it can no longer be associated with you), we may use this information as non-Personal Data indefinitely without further notice to you.
Categories of Personal Data: Any and all data types relevant in the circumstances
Legal basis:
COMPLIANCE AND PROTECTION
Purpose: To comply with applicable laws, lawful requests, and legal process (such as to respond to disclosure orders or similar, as well as investigations or requests from government authorities); to protect our, your or others’ rights, privacy, safety or property (including by making and defending legal claims); to audit our internal processes for compliance with legal and contractual requirements or our internal policies; to enforce the terms of agreements that govern access to the Site; and to prevent, identify, investigate and deter fraudulent, harmful, unauthorised, unethical or illegal activity, including cyberattacks and identity theft.
Categories of Personal Data: Any and all data types relevant in the circumstances
Legal basis:
CORPORATE EVENTS
Purpose: To facilitate or carry out any corporate events such as in the context of a merger or acquisition, sale or transfer of business or asserts, reorganizations and restructuring, financing, joint ventures and other corporate events (including providing Personal Data to allow third parties to investigate – and, where relevant, to continue to operate – all or relevant part(s) of our operations).
Categories of Personal Data: Any and all data types relevant in the circumstances
Legal basis:
FURTHER USES
Purpose: We may use your Personal Data for further uses beyond those described above, we only do this with your consent or whether those further purposes are compatible with the initial purpose for which Personal Data was collected.
Categories of Personal Data: Any and all data types relevant in the circumstances
Legal basis:
We also use cookies and other similar technologies on our Site. For further information on how and why we use such technologies, please see our UK Cookie Policy.
What are your rights?
The GDPR may give you certain rights regarding your Personal Data and how we process it in certain circumstances, meaning you may ask us to take the following actions in relation to your Personal Data:
Exercising your rights
To exercise any of the rights described above, please contact us using the contact details shown below.
We may request specific information from you to help us confirm your identity and process your request. Whether or not we are required to fulfil any request you make will depend on a number of factors (e.g., why and how we are processing your Personal Data), if we reject any request you may make (whether in whole or in part) we will let you know our grounds for doing so at the time, subject to any legal restrictions. Typically, you will not have to pay a fee to exercise your rights; however, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive.
Timing
We try to respond to all legitimate requests within a month of receipt. It may take us longer than a month if your request is particularly complex or if you have made a number of requests; in this case, we will notify you and keep you updated.
We may share your Personal Data with the following categories of recipient and as otherwise described in this Privacy Policy, in other applicable notices, or at the time of collection.
Affiliates. Such as our corporate parent, subsidiaries and affiliates, including certain members of the Function Health group of companies.
Service providers. Third parties that provide services on our behalf or help us operate parts of the Site or our business (such as our hosting providers, information technology/security providers, customer support, email delivery, marketing, consumer research and website analytics).
Professional advisors. Professional advisors, such as lawyers, auditors, bankers and insurers, where necessary in the course of the professional services that they render to us.
Authorities and others. Law enforcement, government authorities, and private parties, as we believe in good faith to be necessary or appropriate in the circumstances.
Parties to corporate events. We may disclose Personal Data in the context of actual or prospective corporate events (e.g., investments in Function, financing of Function, or the sale, transfer or merger of all or part of our business, assets or shares), for example, we may need to share certain Personal Data with prospective counterparties and their advisers. We may also disclose your Personal Data to an acquirer, successor, or assignee of Function as part of any acquisition, sale of assets, or similar transaction, and/or in the event of an insolvency, bankruptcy, or receivership in which Personal Data is transferred to one or more third parties as one of our business assets.
We may share your Personal Data with third parties who are based outside the UK, including in the European Economic Area (“EEA”), the United States and Canada.
Where we share your Personal Data with third parties who are based outside the UK, we try to ensure a similar degree of protection is afforded to it by implementing one of the following mechanisms:
You may contact us using the details below if you want further information on the specific mechanism used by us when transferring your Personal Data outside of the UK.
We employ technical, organizational and physical safeguards designed to protect the personal information we collect. However, security risk is inherent in all internet and information technologies, and we cannot guarantee the security of your personal information.
We are committed to only keeping your Personal Data for so long as we reasonably need to use it for the purposes set out above. This general rule applies unless a longer retention period is required by law.
To determine the appropriate retention period for Personal Data, we consider the amount, nature, and sensitivity of the Personal Data, the potential risk of harm from unauthorised use or disclosure of your Personal Data, the purposes for which we process your Personal Data and whether we can achieve those purposes through other means, and the applicable legal requirements.
When we no longer require the Personal Data that we have collected about you, we will either delete or anonymise it or, if this is not possible (for example, because your Personal Data has been stored in backup archives), then we will securely store your Personal Data and isolate it from any further processing until deletion is possible.
This Site may include links to third-party websites, platforms, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share your Personal Data.
We do not control these third-party websites and are not responsible for their privacy statements or practices. When you leave our Site, we encourage you to read the privacy policy of every site you visit.
If you would like to make a complaint regarding this Privacy Policy or our practices in relation to your Personal Data, please contact us using the contact details shown below. We will reply to your complaint as soon as we can.
If you feel that your complaint has not been adequately addressed, you have a right to complain to the UK Information Commissioner’s Office (ico.org.uk/make-a-complaint/).
You can contact us by email: privacy@functionhealth.com.
We have also appointed a UK Representative for the purpose of the GDPR:
Name: Ezra AI UK Limited
Address: 3rd Floor 1 Ashley Road, Altrincham, Cheshire, WA14 2DT, United Kingdom
Email: privacy@ezra.ai
Any changes will be made available here (or another page we notify to you at a later date) and where applicable we might also notify you via email and/or in our Site.