Privacy Policy
Introduction
Rayonex Biomedical UK Ltd (“we”, “our”, “us”) is committed to protecting and respecting your privacy in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR). This privacy policy sets out how Rayonex Biomedical UK Ltd uses and protects your personal data. This privacy policy is provided in a layered format so that you can click through to the specific areas set out below.
- Important Information and Who We Are
- The Personal Data We Collect
- How We Collect Data
- Lawful Basis for Processing
- Marketing Communications
- Cookies and Tracking Technologies
- Data Sharing
- International Transfers
- Data Security
- Data Retention
- Automated Decision-Making
- Your Data Protection Rights
- Complaints
- Changes to This Policy
- Contact Us
1. Important Information and Who We Are
This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you visit www.rayonex.co.uk (the “Website”), including any data you may provide when you purchase products, attend courses, register as a practitioner, participate in a scan, subscribe to marketing communications, or otherwise interact with us.
Children’s Data
This Website and our services are not intended for children under the age of 18. We do not knowingly collect personal data from children without appropriate parental or guardian consent.
Data Controller
For the purposes of UK data protection law, the Data Controller responsible for your personal data is: Rayonex Biomedical UK Ltd
Correspondence address:
Rayonex Biomedical UK Ltd
9 Reform Street
Blairgowrie
Perthshire
PH10 6BD
Email: contact@rayonex.co.uk
Telephone: 0204 586 1876
If you have any questions about this privacy policy, including any requests to exercise your legal rights (Section 12), please contact us using the information set out above.
2. The Personal Data We Collect
Personal data means any information about an individual from which that person can be identified.
We may collect, use, store and process the following categories of personal data:
A. Customer and Order Data
- Full name
- Billing and delivery address
- Email address
- Telephone number
- Order history
- Payment transaction confirmation details (we do not store full card details)
B. Course and Training Records
- Name and contact details
- Courses attended
- Certification status
- Attendance records
- Assessment outcomes (where applicable)
C. Certified Practitioner Information
Where individuals are listed as certified practitioners, we may process:
- Name
- Practice name
- Professional contact details
- Certification status
- Practice location
Practitioner details are published either:
- With the practitioner’s consent; or
- Under our legitimate interests in promoting certified practitioners and supporting customers in locating trained professionals.
D. Marketing Data
- Email address
- Mobile number
- Marketing preferences
- Interaction data (e.g. email opens, clicks)
We use Mailchimp as our email marketing platform.
E. Technical and Usage Data
- IP address
- Browser type and version
- Time zone setting
- Device type
- Website usage data (via cookies and similar technologies)
F. Scan and Check-Up Data (Including Special Category Data)
We offer scan services that generate a Check-Up Report and a Detailed Report.
When you participate in a scan, we may collect:
- Your name and contact details (for delivery of results)
- Scan reference information
- Scan result data
In this policy, references to “scan data”, ”scan result data”, “scan-related data” or similar terms refer to information that may relate to health or wellbeing and may constitute special category data under Article 9 UK GDPR.
Identifiable scan data is processed only:
With your explicit consent; and/or
For the provision of a service you have requested.
Where scan result data constitutes special category (health) data, we process it only with your explicit consent in accordance with Article 6(1)(a) and Article 9(2)(a) UK GDPR.
You will be asked to provide clear and explicit consent for the processing of your scan‑related health data at the point of booking or request. You may withdraw your consent at any time by contacting us using the details set out in Section 12. Please note that if you withdraw your consent, we may no longer be able to provide the scan service or related results.
Scan data used for internal analysis and service improvement is anonymised. This means:
- Identifiers are removed or stored separately;
- The data cannot reasonably be used to identify you;
- It is no longer personal data once anonymised.
G. Identity Verification Data (Rental Products)
Where products are rented, we may request proof of identity and address for verification purposes. This may include:
- Passport
- Driving licence
- Utility bill or bank statement
This information is processed for the purposes of fraud prevention, asset protection, and contractual security.
Our lawful basis for processing this data is:
- Article 6(1)(b) UK GDPR – performance of a contract; and/or
- Article 6(1)(f) UK GDPR – legitimate interests in preventing fraud and protecting company property.
We retain identity verification data only for as long as necessary in connection with the rental agreement and in accordance with legal limitation periods.
H. Identity Verification Data (Collective Practitioners Support Services)
Where individuals register with our Collective Practitioners Support Services, we request proof of identity and address for verification purposes. This may include Photo ID such as:
- Passport
- Driving licence
This information is processed for the purposes of identity verification, safeguarding of services, fraud prevention, and ensuring the integrity and security of practitioner and client interactions.
Our lawful basis for processing this data is:
- Article 6(1)(b) UK GDPR – performance of a contract; and/or
- Article 6(1)(f) UK GDPR – legitimate interests in maintaining secure and trusted service provision, preventing fraud, and protecting participants.
We retain identity verification data only for as long as necessary to confirm the identity of the Practitioner and for a reasonable period thereafter in accordance with legal limitation periods.
3. How We Collect Data
We use different methods to collect personal data from and about you including through:
- Your interactions with us. You may give us your personal data by filling in online forms or by corresponding with us by post, phone, email or otherwise. This includes personal data you provide when you:
- place orders;
- create an account on our Website;
- complete forms;
- register for courses;
- participate in events;
- request marketing to be sent to you; or
- give us feedback or contact us.
-
Automated technologies or interactions. As you interact with our Website, we will automatically collect Technical and Usage Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies, server logs and other similar technologies.
- Third parties or publicly available sources. We will receive personal data about you from various third parties as set out below:
- Technical Data is collected from analytics providers, search information providers and marketing platforms (Mailchimp).
- Contact, Financial and Transaction Data is collected from providers of technical, payment and delivery services.
4. Lawful Basis for Processing
The law requires us to have a legal basis for collecting and using your personal data. We have set out below an explanation of the legal bases we rely on, together with examples of how we plan to use the various categories of your personal data.
Performance of a contract with you: Where we need to perform the contract we are about to enter into or have entered into with you.
This includes processing orders, delivering products, administering courses, issuing certifications, providing scan reports and verifying identity.
Legitimate interests: We may use your personal data where it is necessary to conduct our business and pursue our legitimate interests. We make sure we consider and balance any potential impact on you and your rights (both positive and negative) before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law).
This includes personal data processed to operate and improve our business, maintain practitioner records, promote certified practitioners, verify customer identity, prevent fraud, and ensure the security of our systems and Website.
Legal obligation: We may use your personal data where it is necessary for compliance with a legal obligation that we are subject to, including tax, accounting and regulatory requirements.
This includes processing personal data to comply with tax, accounting and other regulatory or statutory requirements.
Consent: We rely on consent only where we have obtained your active agreement to use your personal data for a specified purpose, for example if you subscribe to an email newsletter.
This includes sending email marketing communications, processing identifiable scan-related health data, sharing scan results with a named practitioner, and placing certain cookies where required under PECR. Where we rely on consent, you may withdraw it at any time.
5. Marketing Communications
We use Mailchimp to send newsletters and updates about products, services, training, and events.
Marketing emails are sent only where:
- You have provided consent; or
- You are an existing customer, and marketing relates to similar products/services, and you have not opted out.
You may unsubscribe at any time via the link in any email.
If you opt out of receiving marketing communications, you will still receive service-related communications that are essential for administrative or customer service purposes.
6. Cookies and Tracking Technologies
Our Website uses cookies and similar technologies in accordance with PECR.
These may include:
- Strictly necessary cookies
- Analytics cookies
- Marketing cookies (where applicable)
Non-essential cookies are used only with your consent. You can manage cookie preferences via our cookie banner or browser settings.
7. Data Sharing
We may share your personal data where necessary with the parties set out below:
- Payment processors
- Delivery and logistics providers
- IT hosting and support providers
- Mailchimp (email marketing platform)
- Professional advisers (accountants, legal advisers)
- Regulatory authorities where required by law
Health data (such as scan results) is only shared with third parties (such as a named practitioner) where you have provided explicit consent for this specific disclosure, or where we are otherwise permitted or required to do so by law.
We ensure that all third-party processors provide appropriate safeguards and process data in accordance with UK data protection law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
8. International Transfers
Personal data may be transferred outside the UK in limited circumstances (for example where equipment requires repair or servicing). Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, such as:
- UK-approved International Data Transfer Agreements (IDTAs); or
- Adequacy regulations issued by the UK Government.
Where special category (health) data is transferred outside the UK, we ensure that appropriate safeguards are applied in accordance with UK data protection law.
9. Data Security
We implement appropriate technical and organisational measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorised way, altered or disclosed, including:
- Secure servers
- Access controls
- Encryption where appropriate
- Regular system monitoring
10. Data Retention
We retain personal data only for as long as is reasonably necessary to fulfil the purposes for which we collected it, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements.
We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.
We retain personal data as follows:
- Order and financial records: typically for six years (for HMRC compliance purposes).
- Course and certification records: for as long as certification remains valid and for a reasonable period thereafter.
- Marketing data: until you unsubscribe or withdraw consent.
- Identifiable scan data: only for as long as necessary to provide results and comply with legal obligations.
- Identity verification data (rental products): only for as long as necessary in connection with the rental agreement and in accordance with legal limitation periods.
- Identity verification data (Collective Practitioners): only for as long as necessary to confirm the identity of the Practitioner and for a reasonable period thereafter in accordance with legal limitation periods.
- Anonymised data: may be retained indefinitely for analytical or research purposes, as it can no longer be associated with you and cannot be traced back to you in any way.
In some circumstances you can ask us to delete your data. Please see Section 12 (Your Data Protection Rights) for further information.
11. Automated Decision-Making
We do not carry out solely automated decision-making that produces legal or similarly significant effects in relation to our services.
12. Your Data Protection Rights
Under UK data protection laws, you have a number of rights in relation to your personal data. You have the right to:
- Request access to your personal data (commonly known as a “subject access request”)
- Request correction of the personal data that we hold about you.
- Request erasure of your personal data. Note, however, that we may not always be able to comply with your request for erasure for specific legal reasons
- Restrict processing of your personal data
- Object to processing of your personal data
- You also have the absolute right to object at any time to the processing of your personal data for direct marketing purposes
- Request the transfer of your personal data to you or to a third party.
- Withdraw consent at any time where we are relying on consent to process your personal data
You have the same rights in respect of your health and special category data as with any other data, including the right to request deletion, access, or restriction of your scan data. However, in some cases, legal obligations may mean we cannot immediately erase certain health data, and we will inform you if this is the case.
If you wish to exercise any of the rights set out above, requests can be made by contacting us at contact@rayonex.co.uk
No Fee Usually Required
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we could refuse to comply with your request in these circumstances.
What We May Need from You
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
Time Limit to Respond
We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
13. Complaints
If you are dissatisfied with how we process your data, you have the right to make a complaint to the Information Commissioner’s Office (ICO), the UK regulator for data protection issues (www.ico.org.uk).
Before contacting the ICO, please make sure you have first made your complaint to us or asked us for clarification if there is something you do not understand. The ICO will expect you to have done this before reviewing your complaint.
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline: 0303 123 1113
Online: www.ico.org.uk/concerns
14. Changes to This Policy
We may update this Privacy Policy periodically. The latest version will always be published on our Website, and any material changes will be communicated to you where appropriate.
Current Version 5th May 2026
15. Contact Us
If you have any questions regarding this privacy policy or about the use of your personal data or you want to exercise your privacy rights, please contact us in the following ways:
Correspondence address:
Rayonex Biomedical UK Ltd
9 Reform Street
Blairgowrie
Perthshire
PH10 6BD
Email: contact@rayonex.co.uk
Telephone: 0204 586 1876
By using our Website and services, you acknowledge that you have read and understood this Privacy Policy.