Skip to main content

    Privacy Policy

    Last updated: July 2026

    1. Introduction

    Gewardz Media Ltd, trading as Gewardz Health ("we," "our," or "us"), operates Viscacare, a healthcare navigation platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

    2. Information We Collect

    We collect information you provide directly to us:

    • Account information (email address, name, phone number)
    • Countries you explore and bookmark
    • Chat conversations with our AI-powered assistance
    • Travel checklist items you create
    • Profile preferences and settings

    For subscription members, our payment processor Stripe additionally provides us with a payment card fingerprint (a one-way identifier that lets us recognise the same card without storing card numbers) and billing name and country. We never see or store your full card number, expiry, or CVC.

    3. How We Use Your Information

    We use the information we collect to:

    • Provide, maintain, and improve our services
    • Personalise your experience with relevant healthcare information
    • Send you technical notices and support messages
    • Respond to your comments and questions
    • Analyse usage patterns to improve our platform
    • Enforce our subscription terms and prevent evasion of the 6-month minimum commitment period — see Section 10 (Anti-Evasion Retention) for detail
    • Detect and record security events (blocked sign-ups, chargebacks, suspected fraud)

    4. Data Sharing

    We do not sell your personal information. We share limited information, only as necessary, with the following categories of recipient and named processors:

    • Payment processing — Stripe Payments Europe, Ltd. (Ireland): handles card payments, subscription billing, and refunds. We receive only tokenised references and a card fingerprint.
    • Platform & database hosting — Supabase (via Lovable Cloud): stores your account data, dashboard content, and application state.
    • Telehealth doctor provider — Health Hero: a regulated digital health service that delivers your online Doctor consultations and holds the clinical record.
    • Transactional email & support: providers used to send account, billing, and support communications.
    • Analytics & error monitoring: providers used to understand aggregate platform usage and detect faults. Non-essential analytics only run with your cookie consent.
    • Legal & regulatory authorities: where disclosure is required by law, court order, or to establish, exercise or defend legal claims.
    • Business partners: only with your explicit consent.

    Each processor is bound by a written data processing agreement and may only process your data on our documented instructions.

    5. Data Security

    We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction.

    6. Your Rights

    You have the right to:

    • Access your personal data
    • Correct inaccurate data
    • Request deletion of your data
    • Object to processing of your data
    • Data portability

    7. Governing Law

    This Privacy Policy shall be governed by and construed in accordance with the laws of Northern Ireland, United Kingdom.

    If you are a consumer resident in the European Union, the European Economic Area, the United Kingdom or Switzerland, this choice of law does not deprive you of the protection afforded by mandatory provisions of the law of the country in which you are habitually resident, and you may bring proceedings in the courts of that country. You may also lodge a complaint with your national data protection authority.

    8. GDPR Compliance

    If you are located in the European Economic Area (EEA) or United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR).

    Data Controller

    The data controller responsible for your personal data is Gewardz Media Ltd, registered in Northern Ireland, United Kingdom.

    Legal Basis for Processing

    We process your personal data on the following legal bases:

    • Contract: Processing necessary to perform our contract with you (e.g. providing your subscription services)
    • Consent: Where you have given explicit consent (e.g. marketing communications, analytics cookies)
    • Legitimate interests: Processing necessary for our legitimate interests (e.g. improving our platform, fraud prevention)
    • Legal obligation: Processing necessary to comply with applicable laws

    Data Retention

    We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected. Account data is retained for the duration of your account plus 12 months after deletion. Chat history is retained for 6 months. Billing records are retained for 7 years as required by law.

    A limited set of hashed identifiers (see Section 10) is retained for 12 months from cancellation to enforce the 6-month minimum subscription term, irrespective of the broader account retention above.

    Cross-Border Data Transfers

    Your data may be transferred to and processed in countries outside the EEA and United Kingdom. Where this occurs we ensure appropriate safeguards are in place, including the European Commission's Standard Contractual Clauses (SCCs) for EU/EEA data subjects and the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the SCCs for UK data subjects, together with any supplementary technical measures required following the Schrems II decision.

    Your GDPR Rights

    In addition to the rights listed in Section 6, under GDPR you have the right to:

    Health and Other Special Category Data

    Some information you choose to give us — details you store in your secure health vault, information shared with an online Doctor, and any wearable or activity data you connect — is special category data concerning health under Article 9 GDPR. We process it only on the basis of your explicit consent (Article 9(2)(a)), or where it is necessary for the provision of health care by or under the responsibility of a health professional (Article 9(2)(h)) in the case of care delivered through our clinical partner. Health vault content is encrypted at rest, is not used for marketing or advertising, and is never sold. You can withdraw consent, disconnect a wearable, or delete vault content at any time; withdrawal does not affect processing carried out before you withdrew.

    Automated Decisions

    We do not make decisions producing legal or similarly significant effects about you by automated means, with one exception: the anti-evasion check described in Section 10, which can automatically refuse a new sign-up or subscription where hashed identifiers match our blocklist. You have the right to obtain human review of that decision, to express your point of view, and to contest it — email privacy@gewardz.com and a person (not a system) will review your case.

    Children

    Viscacare is intended for adults aged 18 or over. We do not knowingly collect personal data from children. Where a Family or Carer membership covers a person under 18, the account holder is responsible for that person's information and confirms they have authority to share it. If you believe a child has given us personal data, contact privacy@gewardz.com and we will delete it.

    Data Protection Officer

    For GDPR-related enquiries, please contact our Data Protection Officer at dpo@gewardz.com.

    9. Contact Us

    If you have questions about this Privacy Policy, please contact us at privacy@gewardz.com

    10. Anti-Evasion Retention

    Subscription memberships carry a 6-month minimum term and a 14-day cooling-off period during which we may charge the standard market rate of €39 for any online Doctor appointment used before cancellation (see our Terms of Service and Subscription Policy). To prevent people from cancelling early and then re-registering under a new email address to escape the commitment or an outstanding balance, we retain the following identifiers for 12 months from the cancellation date:

    • Hashed email address (SHA-256; the original address cannot be recovered from the hash)
    • Hashed phone number in E.164 format (SHA-256)
    • Stripe payment card fingerprint — a one-way identifier issued by Stripe that lets us recognise the same physical card without storing card numbers, expiry dates or CVCs
    • A reference to the original user account, the original Stripe subscription, the reason (early cancellation, chargeback, unpaid balance, fraud, or manual) and any amount owed

    Legal basis: Legitimate interests (Article 6(1)(f) GDPR) — protecting our ability to enforce a contract you entered into and preventing consumer-side fraud — balanced against the fact that we only retain hashed, non-directory identifiers rather than raw personal data. In the case of chargebacks and unpaid balances we also rely on the necessity of processing for the establishment, exercise or defence of legal claims (Article 9(2)(f) where relevant).

    What this list is used for: When someone tries to sign up or start a new subscription, we hash the email and phone they submit and compare them to this list. If Stripe returns the same card fingerprint on a new checkout, we compare that too. On a match we refuse the new subscription and ask the person to contact support so any outstanding balance can be settled. The list is never used for marketing, profiling, credit scoring, or shared with third parties.

    Security events log: We keep a related audit log of blocked sign-up and checkout attempts, chargebacks, and suspected evasion. It records the event type, timestamp, IP address, user agent, and (where available) the associated blocklist entry. This log is retained for 24 months for security and dispute-defence purposes and is accessible only to authorised administrators.

    Your rights: You can ask us at any time to review your record, to be released early (for example if you settle an outstanding balance), or to object to this processing under GDPR. Email privacy@gewardz.com or our Data Protection Officer at dpo@gewardz.com. Where we cannot release you (typically because a balance is still owed), we will tell you why in writing.

    Data & privacy FAQ

    Who sees your records, how they are protected, and how to delete them

    Plain answers on access, encryption, retention and deletion — including wearable data and blood test results.