Legal

Privacy Policy & Terms of Service

Effective date: 29 June 2026 · NeuroFract LTD
Contents
1. Who we are 2. Data we collect 3. How we use your data 4. Legal basis (UK GDPR) 5. Special category health data 6. Data storage & residency 7. Your rights 8. Who we share data with 9. Cookies & third-party services 10. Children 11. Terms of Service 12. Changes to this policy 13. Contact & complaints

⚠️ NeuroFract is a clinical monitoring tool, not a medical device. It does not provide diagnoses or treatment recommendations. Always discuss your results with your clinician.

1. Who we are

NeuroFract LTD ("NeuroFract", "we", "us") operates the platform at neurofract.com. We are the data controller for all personal data processed through this platform.

Principal Investigator: Dr Antonio Valentin, King's College London.

Contact: privacy@neurofract.com

2. Data we collect

Account data

Health data (patients only)

Usage data

3. How we use your data

We do not use your data for advertising, profiling, or sale to third parties.

We process your data under the following legal bases:

5. Special category health data

Assessment responses (LAEP, SSQ, QOLIE-31, cognitive scores, seizure logs) are special category data under UK GDPR Article 9. By registering and completing assessments, you give explicit consent to us processing this data for the purposes described in this policy.

This data is accessible only to: (a) you, (b) your assigned clinician, and (c) researchers viewing anonymised aggregate data. No individual health data is ever exposed to researchers.

6. Data storage & residency

All data is stored in Google Firebase (Firestore and Firebase Authentication), configured to the europe-west2 (London) region. This means your data is stored within the UK/EEA.

Firebase is operated by Google LLC. Google's data processing terms apply: firebase.google.com/terms/data-processing-terms.

Data is retained for the duration of the clinical pilot and for a minimum of 5 years thereafter, as required by clinical research governance standards.

7. Your rights

Under UK GDPR you have the right to:

We do not offer deletion of health assessment data, as this is required for clinical audit and patient safety. Instead, data is marked as "withdrawn" and excluded from active clinical use. To withdraw, email privacy@neurofract.com.

8. Who we share data with

9. Cookies & third-party services

NeuroFract uses the following third-party services that may process data when you use the platform:

We do not use advertising cookies, tracking pixels, or analytics beyond what Firebase provides by default. The consent banner on our platform allows you to decline non-essential data collection.

10. Children

NeuroFract is not intended for use by anyone under the age of 16 without explicit parental consent and clinician oversight. If you believe a child has registered without consent, contact us immediately at privacy@neurofract.com.

11. Terms of Service

Permitted use

NeuroFract is provided for clinical monitoring and research purposes only. You agree to use the platform only for its intended purpose and in compliance with applicable law.

Not a medical device

NeuroFract is a clinical monitoring and communication tool. It is not a regulated medical device, does not provide diagnoses, and does not replace clinical judgement. All clinical decisions remain the responsibility of the treating clinician.

Accuracy of data

You agree to provide accurate information when completing assessments. Deliberate falsification of health data may compromise patient safety.

Account security

You are responsible for keeping your login credentials secure. Notify us immediately if you suspect unauthorised access to your account.

Availability

We aim for high availability but cannot guarantee uninterrupted service. The platform is provided "as is" during the pilot phase.

Intellectual property

All platform content, design, and code is owned by NeuroFract LTD. The clinical instruments (LAEP, SSQ, QOLIE-31) are used under their respective licences (QOLIE-31 is RAND public domain).

12. Changes to this policy

We will notify registered users by email of any material changes to this policy at least 14 days before they take effect. The effective date at the top of this page will be updated with each revision.

13. Contact & complaints

Data Controller

NeuroFract LTD
King's College London
Email: privacy@neurofract.com

Supervisory Authority

If you are unhappy with how we handle your data, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):
ico.org.uk/make-a-complaint · 0303 123 1113