Privacy Notice

Wait Less Time · operated by EYEV Limited · Effective 2 August 2026 · Version 2026-08-02

Wait Less Time is a progressive web app for comparing general NHS and private-care information and arranging remote GP, physiotherapy and dietitian consultations. This notice explains how EyeV handles personal data about account holders, dependants, waitlist members and people who contact us.

1. Who is responsible for your data

EYEV Limited is the controller of the Wait Less Time app and membership data. EyeV is registered in England and Wales under company number 12614372, with registered office at 29 Bridgford Road, West Bridgford, Nottingham, NG2 6AU. Our ICO registration reference is ZB264788.

Our privacy contact is Adam Holliday at adam@eyev.health. You may also email support.waitlesstime@eyev.health. We do not describe this role as a statutory Data Protection Officer unless and until a compliant appointment and independence assessment are documented.

HealthHero Solutions Limited (company number 03766413) provides the clinical services. EyeV sends it the information needed to create or update a patient record, arrange consultations and return appointment information. HealthHero is responsible for clinical decisions and handles clinical records under its applicable clinical and legal duties; EyeV handles the app and membership data. EyeV will route relevant rights requests to HealthHero.

2. Personal data we collect

Optional Google Health connection: the PWA may offer a read-only Google Health connection for compatible Fitbit, Pixel Watch and other data associated with your Google Account. It is off by default. Immediately before Google is opened, the app identifies the exact data requested, explains the dashboard-only purpose and asks for a separate affirmative choice. You can decline individual Google permissions, disconnect at any time, or delete your Wait Less Time account. EyeV does not use Google Health data for advertising, sell it, use it for research, make clinical decisions from it, or automatically disclose it to HealthHero or a clinician.

EyeV's use of information received from the Google Health API will adhere to the Google Health API Developer and User Data Policy, including its Limited Use requirements.

3. Where the data comes from

Most data comes from you. An adult account holder supplies dependant information. Auth0 supplies verified sign-in identity; Stripe supplies subscription and payment status; HealthHero supplies appointment and consultation records; Google Health supplies only the optional metrics and permission state you separately authorise; public NHS organisation data supplies GP-practice information; and the app and its infrastructure create technical, security, audit and delivery records automatically.

Profile and care information needed to arrange a consultation is contractual or clinically required. If you do not provide mandatory identity, contact, eligibility, authority or clinical-safety information, EyeV or HealthHero may be unable to create the correct record or arrange care. Waitlist participation is optional.

4. Why we use data and the lawful bases

PurposePersonal-data basis under UK GDPRHealth/special-category condition
Create and secure the account; provide the profile, membership and appContract, Article 6(1)(b); legitimate interests in account security where appropriate, Article 6(1)(f)Not normally applicable unless the information reveals health or another special category
Create/update a patient record, assess booking requirements and arrange careContract, Article 6(1)(b); legal obligation where one applies, Article 6(1)(c)Article 9(2)(h) where processing is necessary for health care under appropriate professional responsibility. Article 9(2)(a) explicit consent is used only for genuinely optional processing where applicable.
Show optional Google Health readings in your private dashboardYour consent, Article 6(1)(a)Your explicit consent, Article 9(2)(a). The connection is optional and is not needed for membership or clinical care. You can withdraw it in the Health tab.
Process membership payments, tax, refunds and financial recordsContract, Article 6(1)(b); legal obligation, Article 6(1)(c); legitimate interests in preventing duplicate or fraudulent billing, Article 6(1)(f)Not intended to use health data
Provide support, transactional messages and service notificationsContract, Article 6(1)(b); legitimate interests in operating and supporting the service, Article 6(1)(f)Where a support message contains health information, access is minimised and the information is used only to provide support or arrange care; Article 9(2)(h) applies where necessary for health care and Article 9(2)(f) where strictly necessary for legal claims.
Keep the service secure, investigate incidents, maintain audit trails and establish or defend legal claimsLegal obligation, Article 6(1)(c), and legitimate interests in security, service integrity and legal claims, Article 6(1)(f)Article 9(2)(f) where special-category data is strictly necessary for legal claims; any other condition must be documented
Send the single launch email requested through the waitlistConsent, Article 6(1)(a), and PECR consentNot applicable
Process an account-deletion or rights request and prevent a deleted identity being silently recreatedLegal obligation, Article 6(1)(c), and legitimate interests in proving and enforcing deletion, Article 6(1)(f)Article 9(2)(f) where necessary for legal claims; retained records are minimised and pseudonymised

Our legitimate interests do not override your rights. The approved DPIA and legitimate-interests assessments record the necessity, balancing and safeguards for the service. We do not use health data for advertising, sell it, or make solely automated decisions that have legal or similarly significant effects.

5. Who receives data

Processors must act under contract and only on documented instructions. We do not share data with advertisers, data brokers or analytics resellers.

6. International transfers

Auth0/Okta, Cloudflare, Google, Stripe, Twilio SendGrid and Slack may process some data outside the UK, including in the United States, depending on the contracted service and support location. EyeV's transfer register records the relevant destinations and the applicable UK adequacy regulation or approved transfer mechanism, such as the UK International Data Transfer Agreement or UK Addendum, together with the required transfer-risk assessment and supplementary safeguards.

You may ask our privacy contact for a copy of, or information about, the safeguards that apply.

7. How long we keep data

DataCurrent PWA retention approach
Account, profile, dependant, membership, booking and support data held by EyeVKept while the account is active and needed to provide and protect the service. Account deletion closes access immediately and starts asynchronous local and provider deletion, subject to the exceptions below.
Financial, contract and transaction recordsMembership state is kept while needed for billing and support. The exact accepted membership terms and pseudonymous contract evidence are retained until six calendar years after the latest paid service period ends; each paid renewal moves that bounded date forward. EyeV, Stripe and professional advisers may retain invoices, tax and transaction evidence for the corresponding legal period, or longer where a live legal dispute or another legal duty requires it.
WaitlistKept until the requested single launch email is queued and the waitlist entry is removed, or removed earlier if consent is withdrawn.
Transactional emailEncrypted pending email content is normally kept between one hour and 30 days for delivery/retry. EyeV delivery records are normally kept 90 days and may be refreshed to 180 days by provider webhook events; EyeV's separate provider-event status records are also kept up to 180 days. A pseudonymous suppression reference has no current automatic expiry and is kept while needed to avoid sending to an address that bounced, was dropped, generated a spam report, unsubscribed or was otherwise suppressed.
Google Health connectionEyeV does not persist the retrieved step, activity, calorie, sleep or resting-heart-rate readings; a short-lived in-memory dashboard response may be reused for up to one minute. Encrypted OAuth credentials and the connection-consent record are kept while the connection remains active. If the connection is not used or refreshed for 90 days, EyeV attempts to revoke the Google grant before removing the local credentials and consent record. A failed revocation leaves only the encrypted recovery reference needed for a later retry. Successful disconnection and account deletion also revoke access and remove the local records. Google may retain its own account, permission and activity records under its privacy notice.
Account deletionProvider identifiers remain encrypted only while deletion and verification are pending. After completion, EyeV keeps a redacted deletion case for 90 days and a permanent pseudonymous tombstone and minimal audit outcome. These do not contain the deleted profile or message content.
Security, payment and provider-operation audit recordsKept only for the period set in the approved operational retention schedule. Some pseudonymous event identifiers are retained long term to prevent replay, duplicate billing or unsafe recreation.
HealthHero clinical recordsHealthHero retains clinical records under its own applicable clinical and legal duties. EyeV cannot promise their deletion where retention is required.

HealthHero clinical records and recording: HealthHero's privacy policy explains how its electronic health record may include calls, video, images and documents, the retention that applies to clinical records, and the relevant rights route. Where consultation recording applies, the relevant notice is provided before recording begins.

8. Account deletion

Profile → Delete my account immediately closes app access, tombstones the identity and starts stopping future billing. EyeV then works through local records and Auth0, Google Health, Stripe and HealthHero references, with repeat verification and operational follow-up if a provider is unavailable. You may receive status and completion emails.

Erasure is not absolute. EyeV or a provider may retain limited data for legal obligations, legal claims, fraud/security controls or clinical record-keeping. Deleting the app account is separate from stopping renewal and from exercising a statutory cooling-off or refund right.

9. Children and dependants

Wait Less Time accounts are for adults. The adult member supplies a dependant's information and must confirm parental responsibility or authority and consent to arrange care where required. A dependant retains their own data-protection rights. Contact our privacy contact if a dependant wants to understand, correct or exercise rights over their information.

Safeguards for dependant care: the service applies age and consent rules, provides Article 14 information where required, maintains a safeguarding route and uses a child-accessible privacy explanation where appropriate.

10. Cookies and on-device storage

The PWA uses strictly necessary first-party cookies for sign-in, session and security functions and minimal on-device storage so the interface works. These are not used for advertising. We do not use third-party advertising or behavioural-tracking cookies.

11. Security

We use HTTPS/TLS in transit, authenticated access controls, HttpOnly session cookies, encryption for sensitive stored payloads, provider ownership checks, rate limits, audit records and operational monitoring. No system can be guaranteed completely secure. If a personal-data breach creates a reportable risk, we will notify the ICO and affected people as required.

12. Your rights

Depending on the processing and lawful basis, you may have rights to be informed, access a copy, correct inaccurate data, erase data, restrict processing, receive portable data, object to legitimate-interest processing, withdraw consent and complain. Withdrawing consent does not affect earlier lawful processing. These rights can have legal exceptions, particularly for clinical records, legal obligations and legal claims.

Contact adam@eyev.health or support.waitlesstime@eyev.health. We may need to verify identity and normally respond within one month. EyeV handles requests about the app and membership data and will route relevant requests about clinical records to HealthHero.

13. Complaints and changes

You may complain to EyeV through in-app support or the contacts above. You also have the right to complain to the Information Commissioner's Office, telephone 0303 123 1113. For a clinical-care complaint, contact EyeV and we will route it to HealthHero's clinical complaints procedure.

We will update this notice when the service, providers or legal bases change. A material change will be brought to members' attention and, where required, fresh acceptance or consent will be requested.