Privacy Policy

Welcome to the AXA Health App privacy policy

While you’re using the AXA Health App (‘the App’), your personal information will be processed by two different companies that act as separate ‘Data Controllers’. These Data Controllers are each responsible for their processing of your personal information in compliance with data protection laws.

AXA Health Services Limited (‘AXA Health’, ‘we’) is the Data Controller for processing your personal information when:

  • you set up the App
  • you’re on the homepage
  • you click on a service
  • you update your Personal Details in My Account
  • you make requests through the Privacy Centre
  • you view the Help section
  • you speak to us about issues you may have with the App.

This AXA Health App privacy policy tells you what personal information AXA Health collects within the App, what we do with it, and why. It also explains the rights that you have over your information.

Sectrum Wellness UK Ltd (‘Spectrum.Life’) is the Data Controller for processing your personal information when you use the following services within the App (depending on your entitlement, you may not see all of these on your homepage): EAP, Events, Learn, Health coaching, Mental Wellbeing coaching, Cancer coaching, Health assessments (Know your numbers, glucose and cholesterol, wellbeing consultation, DIY checkpoint) and Health score.

For information about what Spectrum.Life does with your personal information, please access the privacy policy

External websites: Depending on your entitlement, you may be able to see links within the App which take you to external sites, where more services are available. The companies providing these sites and services are Data Controllers and process your personal data independently of AXA Health. For information about what these companies do with your personal information, please consult their privacy policies.

External AXA Health branded websites: You can click on links within the App which take you to AXA Health sites hosted outside of the App. For information about how AXA Health processes the personal data we collect through these sites, please click on the sites’ own Privacy Policy links.

The rest of this privacy policy relates only to the personal data processing done by AXA Health Services Limited in connection with the AXA Health App.

From time to time, we may make changes to this privacy policy; you should check back periodically to view the most up-to-date version. We may also provide you with further notices highlighting certain uses we wish to make of your personal data.

Last updated: 01 April 2025

1. Our Privacy Principles

When we collect and use your personal information, we look after it properly and use it in accordance with our privacy principles: 

  1. Your personal information is processed fairly, lawfully and in a transparent manner
  2. Your personal information is collected for a specific purpose and is not processed in a way which is incompatible with the purpose for which we collected it
  3. Your personal information is adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed
  4. Your personal information is kept accurate and, where necessary kept up to date
  5. Your personal information is kept no longer than is necessary for the purposes for which the personal information is processed
  6. We take appropriate steps to keep your personal information secure
  7. Your personal information is processed in accordance with your rights
  8. We only transfer your personal information to another country or an international organisation outside the United Kingdom and European Economic Area when we have taken steps to ensure that it is protected. Such steps may include placing the party we are transferring information to under contractual obligations to protect it to adequate standards
  9. AXA UK and AXA Group companies do not sell your personal information and we do not permit the selling of customer data by any companies who provide a service to us

2. Why do we process your personal information and what are our legal bases for doing so?

Within the App, AXA Health collects personal information about you when:

  • you set up the App
  • you’re on the homepage
  • you click on a service
  • you update your Personal Details in My Account
  • you make requests through the Privacy Centre
  • you view the Help section
  • you speak to us about issues you may have with the App.

 

We process this personal information for different reasons and to do so we must rely on ‘legal bases’ set out in data protection law. There’s detailed information about this below.  

 

A. To set up and manage your account and access to app services, and to manage the security of the App, we may collect: 

  • Your name, email address, date of birth, who your employer is and your login details.
  • Information about any issues you’re having with the App or details of any complaint about it. If you call us, your phone call may be recorded.
  • Information about how you use the App including your IP address, User ID and details of the pages, objects and external links you click on (see also Section 3 on Cookies).

 

Complaints management here refers to resolving issues with using the App itself (e.g. technical bugs or design). For information about how AXA Health uses your personal information if you make a complaint about the health and wellbeing services themselves, please see AXA Health Services Ltd company privacy policy.

  • Our legal basis for using your personal information to set up and manage your account is that this is in our, your and your employer’s legitimate interests.
  •  Our legal basis for processing your personal information to manage the security of the App is that we have a legitimate interest in doing so and we are under a legal obligation to secure your personal information.  

 

B. For research, analytical, service improvement, marketing and product development purposes, we may process:

  • Information about how you use the App including your IP address, User ID and details of the pages, objects and external links you click on (see also Section 3 on Cookies)
  • Demographic information, which may include information obtained from third parties (for example companies like Experian and LexisNexis who provide consumer classification, market segmentation and lifestyle data).
  • Information about the products you hold from other AXA UK companies.

 

For information on how to object to our use of your personal information for marketing purposes, please see section 6 (What are your rights in relation to your personal information?).

  • Our legal basis is that we have a legitimate interest to monitor and understand how people are using the App and improve it, and to process it for marketing purposes.  

 

C. Anonymising your personal information

When required, we anonymise personal information so that individuals cannot be identified before we use it for management information and analysis of our products and services. Analysis of anonymous information provides us with insights about our business, and with opportunities to improve our products and services and the health and wellbeing of the people who use them. The way that we anonymise personal information aligns with regulatory guidance and is achieved using different techniques, for example removing identifying data or overwriting it with randomised non-identifiable data.

  • Anonymisation still constitutes use of your personal information; we rely on the legal bases that we relied on when your data was originally collected.  

3. Storing and collecting information from your device

The App uses technology similar to cookies (‘similar technologies’) to store and collect information from your device. Like cookies, these similar technologies can be used in numerous ways, including to recognise a device and store information about users’ preferences and interactions during a single visit or across multiple visits.  

Within the App, AXA Health may use similar technologies to collect usage information about you when: 

  • you set up the App 
  • you’re on the homepage 
  • you click on a service 
  • you update your Personal Details in My Account 
  • you make requests through the Privacy Centre 
  • you view the Help section  
  • you speak to us about issues you may have with the App. 

For information about the use of cookies when you interact with EAP, Events, Learn, Health coaching, Mental Wellbeing coaching, Cancer coaching, Health assessments (Know your numbers, glucose and cholesterol, wellbeing consultation, DIY checkpoint) and Health score, please consult: https://app.spectrum.life/privacy-policy  

For information about the use of cookies when you interact with external sites, please consult the relevant third-party provider’s cookie policy.  

For information about the use of cookies when you interact with AXA Health branded sites external to the App, please consult the cookies policy link for that site.  

The rest of this section describes the use of similar technologies in the AXA Health App.   

Strictly necessary similar technologies: Some of the similar technologies that we use are ‘strictly necessary’. They are required for the App to work properly (including accessing information about how you’ve interacted with the App so that we can investigate and fix any defects or code issues).  

Strictly necessary similar technologies cannot be disabled.   

Analytics similar technologies: These enable us to understand how users interact with the App. For instance, they measure visits to the App and show us how users navigate around it (excluding when you are using the health and wellbeing services and external sites). We compile this usage information into management reports so that we can improve and develop the App’s user experience – the reports are aggregated, anonymous and you cannot be identified from them.   

Collection of analytics data can be disabled when you register and in the App’s Privacy Centre.  

4. Who do we share your personal information with?

AXA Health may share your personal information with AXA Group companies, and other third parties outside the AXA Group. We share information for the purposes described in this privacy policy. 

 Disclosures within our Group 

To provide the App, your personal information may be shared with other companies in the AXA Group. Your personal information might be shared for our general business administration, efficiency, and accuracy purposes. 

 Disclosures to third parties outside our Group  

We also disclose your information to the types of third parties listed below for the purposes described in this privacy policy. They might include: 

  • Your relatives, guardians, or someone else acting on your behalf where we have your consent or where Data Protection law allows this. 
  • Our third-party services providers and their sub-contractors such as IT suppliers, auditors, lawyers, consultants and marketing agencies. 
  • Partner businesses so that they can provide their products or services to you via the App, for example:   
    • Medical professionals, including providers of health assessment services and counselling services 
    • Providers of complimentary therapies such as meditation and mindfulness. 
  • Regulatory authorities such as the Care Quality Commission and the Information Commissioner’s Office. 
  • Third parties in connection with the sale, transfer, or disposal of our business. 

We may also disclose your personal information to other third parties where: 

  • we are required or permitted to do so by law or by regulatory bodies, for instance where there is a court order, statutory obligation or regulatory request.   
  • we believe that such disclosure is necessary to assist in the prevention or detection of any criminal action or is otherwise in the overriding public interest; or 
  • where exemptions under the data protection legislation allow us to do so. 

 

Transfer of your data outside of the UK 

If we transfer personal information outside the UK to a country which is deemed not to have the same standards of data protection as the UK, we will ensure that appropriate safeguards have been implemented to protect your personal information. Such steps may include imposing contractual obligations on third parties to adequately protect your personal information. 

5. How long do we keep your records for?

We keep your personal information for as long as reasonably necessary to fulfil the relevant purposes set out in this privacy policy or to comply with our legal and regulatory obligations. In most cases, we will keep your information for up to seven years after our relationship with you ends, but this varies depending on the nature of the personal information and our purposes for processing it.  

6. What are your rights in relation to your personal information?

The rights that you have over your personal information are described below. If you make a rights request, we’ll either do what you’ve asked, or explain why we can’t - usually for legal or regulatory reasons. In some circumstances exercising some of these rights may mean that we are unable to continue providing you with the App.  

We may ask you for information to confirm your identity. 

Within the App, AXA Health collects limited personal information about you because the App acts only as a gateway/access point to services provided by Spectrum.Life, or as signposting to sites outside the App.  

For rights requests relating to the use of EAP, Events, Learn, Health coaching, Mental Wellbeing coaching, Cancer coaching, Health assessments (Know your numbers, glucose and cholesterol, wellbeing consultation, DIY checkpoint) and Health score within the App, please consult https://app.spectrum.life/privacy-policy 

For rights requests relating to the use of services accessed via external sites, please consult the relevant third-party provider’s privacy policy.  

For rights requests relating to the use of AXA Health services accessed via AXA Health sites external to the App, please click the privacy policy links on those sites to access relevant privacy information.   

The right to access your personal information

You are entitled to a copy of the personal information we hold about you and information about how we use it. Please email data.protection@axahealth.co.uk with the subject line: AXA Health App - Data Subject Access Request.  

The right to rectification

We take steps to ensure that the personal information we hold about you is accurate and to the extent necessary, complete. If needed, you can update your personal information in the App in the ‘Personal Details’ page. If you can’t access the App, please email data.protection@axahealth.co.uk with the subject line: AXA Health App – Rectification Request. 

The right to erasure

You can request an account deletion from the Privacy Centre within the App and we’ll delete your account and the personal information that’s connected to your App use. If we can’t for any reason, we’ll advise you at the time. If you can’t access the App, email data.protection@axahealth.co.uk with the subject line: AXA Health App – Account Deletion. 

The right to restriction of processing

You can ask us to suspend using your personal information for a period. For example, if you need us to retain your personal information beyond our retention periods, you can ask us not to delete it. Please email data.protection@axahealth.co.uk with the subject line: AXA Health App – Restriction Request.  

The right to data portability

In certain circumstances, you have the right to the personal information that you have provided to us in a machine-readable format. Please email data.protection@axahealth.co.uk with the subject line: AXA Health App – Portability Request. 

The right to object

You can ask us to stop processing all or some of your personal information. If we are doing this for marketing purposes, we will stop in line with your request. Otherwise, depending on the (non-marketing) purpose and our legal basis for processing, we may not always be able to fulfil your request but as a first step, please email data.protection@axahealth.co.uk with the subject line: AXA Health App – Objection Request.  

The right to withdraw consent

We ask for your consent to process your personal information for certain purposes, and you can withdraw this consent at any point in the Privacy Centre. If you can’t access the App to do this, please email data.protection@axahealth.co.uk with the subject line: AXA Health App – Consent Withdrawal. 

The right to lodge a complaint:

You have the right to complain to the Information Commissioner’s Office (ICO) if you consider that we have not complied with data protection law. The ICO will usually expect you to have given us the opportunity to resolve your complaint before interceding, so please do bring any concerns to us in the first instance at data.protection@axahealth.co.uk or by using our postal address (see Section 7)More information can be found on the Information Commissioner’s Office website: https://ico.org.uk/.

7. How to contact the Data Protection Officer (DPO)

You can contact the AXA Health DPO by email or post:

The Data Protection Officer 
International House, 
Forest Road, 
Tunbridge Wells, 
TN2 5FE

Email address: data.protection@axahealth.co.uk