Healthcount is designed around data minimisation and privacy by design. We collect only what is needed, report only in aggregate, and never share individual health data with employers or insurers.
Healthcount collects the minimum data needed to support maintenance. We don't require detailed food diaries, extensive health questionnaires, or continuous monitoring. The inputs are:
Data collected by Healthcount is used for one purpose: supporting GLP-1 maintenance. It is not used for marketing, profiling, or resold to third parties. Member data drives two outputs — personal maintenance signals for the member and anonymised, aggregated reporting for funders.
Healthcount's data governance role depends on how the service is accessed.
Data processing agreements are available for employer and insurer programmes.
Health data is special category data under UK GDPR. Healthcount processes it carefully and transparently.
Employers do not see individual employee health data. This is a non-negotiable design principle. Specific protections include:
If a cohort is too small for safe reporting, data is withheld until the group size threshold is met.
Reporting for insurers and employers is grouped and de-identified. We use minimum group sizes to reduce re-identification risk. Funders see cohort-level patterns, not individual journeys.
Personal data is retained for as long as a member actively uses Healthcount, plus a reasonable period to allow for pauses in treatment. Aggregated reporting data is retained separately and does not contain personal identifiers. Members can request deletion at any time.
Under UK GDPR, you have the right to access your data, request correction of inaccurate data, request deletion, restrict processing, and data portability. To make a data subject access request (DSAR) or exercise any of these rights, contact us at anna@healthcount.app.
Members can request full deletion of their personal data at any time. Deletion requests are processed promptly. Once deleted, personal data cannot be recovered. Aggregated, anonymised data that has already been included in cohort reporting is retained as it contains no personal identifiers.
Healthcount uses a limited number of subprocessors to deliver the service. All subprocessors are reviewed for data protection compliance and are bound by appropriate contractual terms. A current list is available on request.
Data is hosted on infrastructure within the UK and EU. Where any processing involves transfers outside the UK, appropriate safeguards are in place in line with UK GDPR requirements.
Healthcount is designed so employers can support employee health without accessing personal health data.
For full legal details, see our Privacy Policy and GDPR Compliance pages.
Aggregated insights without individual data exposure. See how a pilot works.