We and selected partners, use cookies or similar technologies as specified in the cookie policy.

Privacy Policy

Last Updated: 09/2024

Introduction

Gaia Fertility Ltd. (“Gaia”, “we”, “our”) is committed to protecting the privacy and security of the personal data we collect about end customers and users of our services (“you/your”). 

The purpose of this privacy policy is to explain what personal data we collect from our end customers and users about you when you:

  • Create an account on our website;
  • Speak to our advisor;
  • Enquire about our products;
  • Request marketing to be sent to you;
  • Give us feedback or contact us;
  • Provide us with a scan of your document if this is required for “know your customer” or anti-money laundering purposes;
  • Interact with our website;
  • Contact us, including for assistance or sending feedback;
  • Request information about a clinic;
  • Receive treatment at one of Gaia’s partner clinics;
  • Complete our customer surveys, and
  • Browse the internet while on our website.

This notice provides you with information about your rights and obligations and explains how, why and when we collect and process your personal data. 

We take personal data seriously. Anything containing personally identifiable information is kept safe and we have put in place appropriate technical and other security measures to protect it. We need to collect certain types of information to allow us to make a decision on your request for financial and insurance products. We also need to comply with legal and regulatory requirements relating to anti-fraud, anti-money laundering, know your customer and responsible lending obligations. 

We will only collect the information we need to be able to provide you with the service you have requested. You need to make sure that the information you provide is accurate, complete, and not misleading. Your personal information may need to be disclosed when we are obliged to by law, for purposes of national security, taxation, defence of a legal claim or criminal investigations. 

We also collect data from third-parties. When we do this, we are the data controller. Our website may contain hyperlinks to websites that are not operated by us. We urge you to review any privacy policies posted on any site you visit before using the site or providing any personal information about yourself.

Please read this privacy policy carefully as it provides important information about how we handle your personal information and your rights. If you have any questions about any aspect of this privacy policy you can contact us using the information provided below or by emailing us at dataprotection@gaia.family.

Who are we? 

We are Gaia Fertility Ltd. 

Our registered office is at Great Western Studios, 65 Alfred Rd, London W2 5EU, UK. 

We are registered in England and Wales under company number 12009812. 

We are registered on the Information Commissioner’s Office (ICO) Register under number ZA788761. 

We can be contacted: 

  • By post at 65 Alfred Road, London, W2 5EU 

If you want to contact us about anything data privacy related, you can do so at dataprotection@gaia.family

We have also appointed an external data protection officer (DPO) and their details are as follows:

Evalian Limited

West Lodge

Leylands Business Park

Colden Common

Hampshire

SO21 1TH

United Kingdom

Phone: +44 (0)333 050 0111

Website: www.evalian.co.uk 

Email: dataprotection@gaia.family (Please mark your communications ‘FAO the Data Protection Officer’)

This privacy policy covers our processing of personal data which relates to the following categories of data subjects. 

  • Visitor is a person who has visited Gaia website
  • Member is a person who has signed a Gaia membership agreement
  • Applicant is a person who has applied for a Gaia Plan 

What is personal data?

Personal data’ is any information from which you can be identified, either directly or indirectly. For example, your name or an online identifier.

Special category personal data’ is more sensitive personal data and includes information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purposes of uniquely identifying someone, data concerning physical or mental health or data concerning someone’s sex life or sexual orientation. 

What personal data do we collect? 

We collect, use and are responsible for certain personal data about you. When we do so we are subject to the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

The personal data we collect about you depends on the purpose for which you engage with us. We may collect and use the following data about you:

  1. Identity - full name, marital status, title, date of birth, and partner details if applicable.
  2. Contact - address, email address, telephone number(s), Gaia profile data.
  3. Financial - bank account and payment card details.
  4. Transaction - details about payments to and from you.
  5. Usage - details about how you use our website.
  6. Marketing and Communications - your preferences in receiving marketing from us and your communication preferences.
  7. Technical - internet protocol (IP) address, Gaia log in details, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this website.
  8. Medical - Health and Lifestyle data, see “Special Category Personal Data” below.

Special Category Personal Data

Sometimes we will request or receive Personal Information that is sensitive due to its nature, and we call this “Special Category of Personal Data”. The types of Special Categories of Personal Data Information that we hold, and process include: 

  • Health and lifestyle data – including details of pre-existing or past medical conditions, your family medical history, details regarding appointments and consultations with medical professionals, diagnoses, medical records, whether you do or have ever smoked, details regarding alcohol consumption.

Conditions for processing special category data

We will only process this data with explicit consent from the user. We may collect this data and your explicit consent, either before or after entering a contract and providing The Gaia Plan. Additionally, where we collect additional sensitive health and lifestyle data throughout the course of your engagement with us, we will always ensure that we have your explicit consent to do so.

Purposes for which we use personal data and the legal basis

When providing services to you, we may use your personal data for the following purposes and on the following lawful bases:

Purpose Type of Data Lawful Basis for Processing
To register you as a new customer (a) Identity
(b) Contact
Performance of a contract with you
To provide The Gaia Plan to you, including:
(a) To manage payments, fees and charges
(b) To collect and recover money owed to us
(a) Identity
(b) Contact
(c) Financial
(d) Health & Lifestyle
(a) Performance of a contract with you
(b) Explicit consent (in relation to any Health & Lifestyle Data we need to process in order to provide the Gaia Plan to you)
To manage our relationship with you (a) Identity
(b) Contact
(c) Marketing and Communications
Performance of a contract with you
To enable you to leave a review, complete a survey or provide us with feedback (a) Identity
(b) Contact
(c) Usage
(d) Marketing and Communications
(e) Health & Lifestyle
Explicit consent (completing surveys will always be optional)
To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) (a) Identity
(b) Contact
(c) Technical
Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise)
To deliver relevant website content and marketing materials to you and to measure and understand the effectiveness of the marketing we send you (a) Identity
(b) Contact
(c) Usage
(d) Marketing and Communications
(e) Technical
Consent (subscribing to our marketing emails & communications will always be optional)
To carry out data analysis: including to ensure data accuracy and quality and for insurance risk modelling and product and pricing refinement (a) Technical
(b)Usage
(c) Health & Lifestyle
(a) Necessary for our legitimate interests (to define types of customers for The Gaia Plan, to keep our website updated and relevant and to develop our business)
(b) Explicit consent (in relation to any Health & Lifestyle Data we need to process in order to provide the Gaia Plan to you)
To make suggestions and recommendations to you about The Gaia Plan that may be of interest to you (a) Identity
(b) Contact
(c) Technical
(d) Usage
(e) Health & Lifestyle
(a) Necessary for our legitimate interests (to develop The Gaia Plan and grow our business)
(b) Explicit consent (in relation to any Health & Lifestyle Data we need to process in order to provide the Gaia Plan to you)
To carry out scientific and statistical research about fertility and IVF treatments (a) Identity
(b) Contact
(c) Health & Lifestyle
(a) Archiving, research and statistics
(b) Explicit consent (in relation to any Health & Lifestyle Data we need to process in order to carry out research)
To perform credit and affordability checks in order to grant you credit and monitor your ability to repay your loan (a) Identity
(b) Contact
(c) Financial
(a) Explicit consent (conditional to the services provided by Gaia)
(b) Necessary for our legitimate interests (in relation to ongoing monitoring which we need to do to proactively comply with our regulatory obligations)
To introduce you to Fintern for the purpose of you applying for a loan (a) Identity
(b) Contact
(c) Financial
(a) Performance of a contract with you
To gather insights from customers about Gaia and the effectiveness of our marketing campaigns and engagement (a) Identity
(b) Usage
(c) Technical
Consent
To check whether you are registered with your chosen clinic and to refer you to one of our partner clinics if you have not chosen a clinic (a) Identity
(b) Contact
(a) Performance of a contract with you
(b) Necessary for our legitimate interests (to confirm the information you have provided is accurate and to confirm how you heard about Gaia)
(c) Consent (we will only share your contact details with a clinic with your consent).

Where personal data is processed because it is necessary for the performance of a contract to which you are a party, we will be unable to provide our services without the required information.

Profiling and automated decision-making

We rely on automated decision-making, including profiling, to work out whether we are able to provide you with a Gaia Plan and to calculate the amount of premium and interest rate that you will need to pay. This will be based on the health information and medical history that you provide us, including details of your BMI (which is calculated using your height and weight), age and any fertility conditions and your credit score and financial history. 

This means that our systems could decide that you don't meet the acceptance criteria that we use to offer you a Gaia Plan. If we notify you that we are not able to offer you a Gaia Plan and you believe that this decision should be contested, please contact us at hello@gaia.family. If you would like us to, we can explain how we reached the decision and, if we deem it appropriate, we can manually check any automated decision.

Sharing your data and third parties

Third parties assist us in our marketing efforts, to deliver our products to you and in the provision of our services. The type of information shared will depend on the third party: it can be identity, contact, financial, transaction, usage, marketing & communications, technical and health & lifestyle, but will be limited to what is strictly necessary.

We only allow third parties to handle your personal data if we are satisfied, they take appropriate measures to protect your personal data. We also impose contractual obligations on our service providers, to ensure they can only use your personal data to provide services to us and to you.

We may disclose your personal data to law enforcement agencies and regulatory bodies to comply with our legal and regulatory obligations.

We may also need to share some personal data with other parties, such as potential buyers of some or all of our business or during a restructuring. Usually, data will be anonymised but this may not always be possible. The recipient of the data will be bound by confidentiality obligations.

The third parties we currently rely on or with whom we share personal data 

Accounting services

Gaia uses the accounting service Xero. You can read more about how Xero uses your Personal Information in their privacy notice: https://www.xero.com/uk/legal/privacy/

Aircall

Aircall is a telecom company offering a cloud-based phone system which we use for communicating with our customers. You can read more about how Aircall uses your Personal Information in their privacy notice: https://aircall.io/privacy/

Amazon Web Services (AWS)

AWS is an industry-standard cloud service provider which we build our platform on and provide our web services through. You can read more about how AWS uses your Personal Information here: https://aws.amazon.com/privacy/

Insurance Brokers

We use the Llyod’s brokers Guy Carpenter and Aon UK Limited to distribute our insurance product. You can read more about how Guy Carpenter and Aon uses your Personal Information in their privacy notices: https://www.guycarp.com/company/about/privacy-policy.html and https://www.aon.com/unitedkingdom/privacy.jsp

Calendly

Calendly is a meeting scheduling automation platform. You can read more about how Calendly uses your Personal Information and Calendly’s activities in their privacy notice: https://calendly.com/privacy

Docusign

We use Docusign for sending and signing our membership agreements and other legal contracts. You can read more about how Docusign uses your Personal Information in their privacy notice: https://www.docusign.com/privacy/

Experian

We collect financial information and results of “politically exposed persons” or sanction checks received from the credit bureau Experian. Our sanctions check, credit check and affordability check processes include sharing and obtaining data from Experian.

You can read more about how Experian uses your Personal Information here and Experian’s activities in their privacy notice: https://www.experian.co.uk/privacy/privacy-policies.

Fintern

Fintern underwrites your loan and, in certain cases, provides you with the loan for your treatment costs. You can read more about how Fintern uses your Personal Information and Fintern’s activities in their privacy notice: https://fintern.ai/privacy

Fivetran

Fivetran is a data ingestion tool that connects with multiple sources of data. You can read more about how Fivetran uses your Personal Information in their privacy notice: https://www.fivetran.com/legal/privacy

Google Analytics 

Google Analytics allows us to see how users are finding out about Gaia and if our use of social or paid campaigns are working to draw users to sign up to our platform. 

You can read more about how Google uses your Personal Information here: https://www.google.com/intl/en/policies/privacy/. You can also opt-out of Google Analytics here: https://tools.google.com/dlpage/gaoptout.

Google Cloud Services 

Google Cloud Services is a suite of cloud computing services that provides a series of modular cloud services including computing, data storage, data analytics and machine learning. You can read more about how GCS uses your Personal Information here: https://cloud.google.com/security/privacy

Hex

Hex is a tool used for data science analysis. You can read more about how Hex uses your Personal Information in their privacy notice:https://learn.hex.tech/docs/security/privacy-policy

Hotjar

We use Hotjar in order to better understand our users’ needs and to optimise this service and experience. Hotjar is a technology service that helps us better understand our users’ experience (e.g. how much time they spend on which pages, which links they choose to click, what users do and don’t like, etc.) and this enables us to build and maintain our service with user feedback. Hotjar uses cookies and other technologies to collect data on our users’ behaviour and their devices. This includes a device's IP address (processed during your session and stored in a de-identified form), device screen size, device type (unique device identifiers), browser information, geographic location (country only), and the preferred language used to display our website. Hotjar stores this information on our behalf in a pseudonymized user profile. Hotjar is contractually forbidden to sell any of the data collected on our behalf. You can read more about Hotjar’s use of personal information here: https://www.hotjar.com/legal/policies/privacy/

Hubspot

We use Hubspot to manage all communication with our potential and existing members. You can read more about how Hubspot uses your Personal Information in their privacy notice: https://legal.hubspot.com/privacy-policy

Insurers

Chaucer Group, Beazley Furlonge Ltd and other insurance market participants help us provide you an insurance cover. When you give us your consent to the use of your personal information and your partner’s, if applicable, we might share data with the insurers to issue you an insurance policy in connection with your Gaia Plan. You do not have to give your consent and you may withdraw your consent at any time. However, if you do not give your consent, or you withdraw your consent, this may affect our ability to provide the insurance cover from which you benefit and may prevent the provision of cover for you or handling your claims. You can read more about how Chaucer and Beazley use your Personal Information in their privacy notices: https://www.chaucergroup.com/privacy-cookie-policy and https://www.beazley.com/en-001/privacy-and-cookies-statements.

Mixpanel

Mixpanel allows us to see what pages visitors on our website and app visit. You can read more about how Mixpanel uses your Personal Information in their privacy notice: https://mixpanel.com/legal/privacy-policy/

Meta

We use Meta for advertising and marketing purposes. We may share certain personal data, such as your contact information and website usage data, with Meta to target and deliver relevant advertisements to you. Please note that the collection and use of your personal data by Meta is governed by Meta's privacy policy. You can learn more about how Meta uses your personal information by reviewing their privacy policy https://www.facebook.com/privacy/policy/.

We may also use WhatsApp to contact you and provide you with details about your Treatment Plan. WhatsApp is owned by Meta. You can learn more about how WhatsApp uses your data by reviewing their privacy policy: https://www.whatsapp.com/legal/privacy-policy

Money services providers

Gaia uses different banks, money services providers and payment processors: GoCardLess, HSBC, Revolut, Stripe and Wise. You can read more about how they use your Personal Information in their privacy notices:

  • GoCardLess: https://gocardless.com/privacy/
  • HSBC: https://www.hsbc.co.uk/content/dam/hsbc/gb/pdf/privacy-notice-full.pdf
  • Revolut: https://www.revolut.com/legal/privacy/
  • Stripe: https://stripe.com/fr-gb/privacy
  • Wise: https://wise.com/gb/legal/global-privacy-policy-en

Omni

Omni Analytics is a data visualisation tool used to analyse Gaia’s business. You can read more about how Omni uses your Personal Information in their privacy notice: https://omni.co/privacy

Partner Clinics

If you have chosen a clinic, we may share your identity with the clinic to confirm you are registered with the clinic. If you haven’t chosen a clinic, we might share your contact details with a partner clinic so that they can arrange an initial consultation with you. We will check with you before we do this. We will also share data with the clinic where you have treatment. This data might include medical data, identity and contact information. We will only share medical data with your treatment clinic where we have your explicit consent to do so. 

Prefect

Prefect is a data orchestration tool used for data pipelines. You can read more about how Prefect uses your Personal Information in their privacy notice: https://www.prefect.io/legal/privacy-policy/

Remote

Remote is an employer of record that acts as the legal employer for some of our employees located outside of the UK. You can read more about how Remote uses your Personal Information in their privacy policy: https://remote.com/en-gb/privacy-policy

Snowflake

Snowflake is a cloud based database, used for storing data. You can read more about how Snowflake uses your Personal Information in their privacy notice: https://www.snowflake.com/privacy-policy/

TransUnion

We collect financial information and results of “politically exposed persons” or sanction checks received from the credit bureau TransUnion. Our sanctions check, credit check and affordability check processes include sharing and obtaining data from TransUnion. 

You can read more about how TransUnion uses your Personal Information here and TransUnion’s activities in their privacy notice: https://www.transunion.co.uk/legal-information/bureau-privacy-notice

Typeform

Typeform is an online software service that specialises in online form and survey building. 

You can read more about how Typeform uses your Personal Information here: https://admin.typeform.com/to/dwk6gt/

Vercel

Vercel provides infrastructure to easily deploy, distribute and host web applications. You can read more about how Vercel uses your Personal Information in their privacy notice: https://vercel.com/legal/privacy-policy

Webflow

Webflow hosts our marketing website. You can read more about how Webflow uses your Personal Information in their privacy notice: https://webflow.com/legal/privacy

Zapier

Zapier is a service that integrates various web applications into one platform. 

You can read more about how Zapier uses your Personal Information here: 

https://zapier.com/privacy

International Transfers of Personal Data

To provide products and services to you, it is sometimes necessary for us to share your personal data outside the UK and EEA, for example, with our service providers located outside the UK.

We may also send your data outside of the UK and EEA upon your data portability request, to comply with legal and regulatory duties, and to work with our agents and advisers that runs your accounts and services.

We have taken appropriate steps to ensure that the Personal Data processed outside the UK has an essentially equivalent level of protection to that guaranteed in the UK. We do this by ensuring that:

  • Your Personal Data is only processed in a country which the Secretary of State has confirmed has an adequate level of protection (an adequacy regulation), or
  • We enter into an International Data Transfer Agreement (“IDTA”) with the receiving organisation and adopt supplementary measures, where necessary.

Cookies and Analytical Tools

We collect personal data by using cookies, server logs, visit statistics such as Google Analytics and other similar technologies. Please see our Cookie Policy for further details.

How long we keep your data

We will retain your personal data for as long as is necessary to provide you with our services and for a reasonable period thereafter to enable us to meet our contractual and legal obligations and to deal with complaints, litigation and claims. 

After your relationship with Gaia ends, we may keep your data for the following scenarios:

  • To respond to any queries or complaints;
  • To show that we have acted and treated you fairly;
  • To maintain records according to rules and regulations that apply to us.

At the end of the retention period, we may also retain data for a longer period, and your personal data will be securely deleted or anonymised, for example by aggregation with other data, so that it can be used in a non-identifiable way for statistical analysis and business planning. The retention period of your personal data may need to be extended where we require this to bring or defend legal claims.

Data Analysis and Research 

Gaia will anonymise your information for health-related studies, or research or evaluation in which Gaia will participate. The types of data which may be used for analysis and research purposes include details about a patient (e.g. age, cause of infertility, lifestyle), lab results (e.g. blood test results, hormonal levels), information about cycle planning, the cycle itself, the stimulation phase and egg collection (e.g. stimulation treatment, number of follicles, number of collected eggs), information about embryology and the embryo transfer, results of ultrasound scans, and details about the success or otherwise of a pregnancy. 

Once information is truly anonymised, it does not relate to a person and it is impossible to identify a person from that data. As a result this type of information falls outside data protection laws. 

The purposes for which Gaia will use this analysis and research information are:

  • To report on Gaia’s performance based on statistical studies (e.g., pregnancy rate, birth rate, etc.). Any reporting information will be aggregated, and it will never be possible to identify you from this.  
  • Improve Gaia’s services to you.

Marketing preferences

Both when you enter our site or sign up as a user, we will confirm that you have opted into our services. Any electronic marketing communications we send you will include clear instructions to follow should you wish to unsubscribe at any time.

You may also amend your contact preferences by emailing us at dataprotection@gaia.family.

How we protect your data

We are committed to ensuring that your information is secure. Appropriate security measures are in place to protect against loss, misuse, unauthorised disclosure, destruction, or alteration of information collected from you, including measures to prevent, as far as possible, access to our databases by parties other than Gaia.

We adopt the following technical and organisational measures to protect your personal data:

  1. Limit access to your personal information to those who have a genuine business need to know it. Those accessing and processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.
  2. Have policies and procedures in place regarding treating personal data lawfully and appropriately, including a procedure to deal with any suspected data security breach. We will also notify you and the ICO of a suspected data breach where we are legally required to do so.
  3. Backups of information.
  4. Data protection training for staff.
  5. Encryption of personal data.
  6. Anonymisation of personal data.

Secure Online Services

You can easily identify secure websites by looking at the address in the top of your browser which will begin https:// rather than http://.

Your rights and options

You have certain rights in relation to the processing of your personal data, including to: 

  • Request access to your personal data (commonly known as a “Subject Access Request”). This enables you to receive a copy of the personal data we hold about you.
  • Request rectification of the personal data that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
  • Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have exercised your right to object to processing (see below).
  • Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. If you object to us using your personal data for marketing purposes we will stop sending you marketing material. 
  • Request the restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data, for example if you want us to establish its accuracy or the reason for processing it.
  • Request the transfer of your personal data to another party (data portability).
  • Automated decision-making. You have the right not to be subject to a decision based solely on automated processing which will significantly affect you.

Right to withdraw consent

In the circumstances where you may have provided your consent to the processing of your personal data for a specific purpose, you have the right to withdraw your consent for that specific processing at any time. Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose or purposes you originally agreed to, unless we are permitted by law to do so.

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.

If you wish to exercise your rights, please contact us at dataprotection@gaia.family and we’ll respond within 30 days.  We will assess your request and if we decide not to act upon it or place certain restrictions on it, we will inform you of our reasons for this.

We may need to request specific information from you to help us confirm your identity before we can process a request from you to exercise any of the above rights.  This is another appropriate security measure to ensure that personal information is not disclosed to any person who has no right to receive it.

You can also lodge a complaint with the Information Commissioner’s Office. They can be contacted using the information provided at: https://ico.org.uk/concerns/. Their address is: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. They can be contacted by phone on 0303 123 1113 (local rate) or 01625 545745 if you prefer to use a national rate number. 

For further information on each of those rights, including the circumstances in which they apply, see the Guidance from the UK Information Commissioner’s Office (ICO) on individuals rights under the General Data Protection Regulation. You can find details on how to report a concern at: https://ico.org.uk/make-a-complaint/.

Contact Us

For more information about our privacy practices, if you have questions, or if you would like to make a complaint, please contact us by e-mail at: dataprotection@gaia.family.

If you would like this website privacy policy in another format (for example: audio, large print, braille) please contact us at: dataprotection@gaia.family

Changes to this privacy notice

We may update this notice (and any supplemental privacy notice), from time to time in order to reflect, for example, changes to our practices or for other operational, legal or regulatory reasons. Updated versions of this policy will be posted on our website. We will notify you by email if there are significant changes to this policy.

We've arrived in your state!

Head over to our American site to get to know us and request a quote.

We can’t wait to meet you.

We’re on our way to your state

Find out more about our expansion throughout the US.

We can’t wait to meet you.