Privacy policy

Privacy Policy

Last updated: 20 April 2026

This Privacy Policy describes how RJC Health UK Limited trading as HLTH Code ("we", "us", or "our") collects, uses, and shares your personal data when you visit or make a purchase from gethlth.co.uk (the "Site"). We are the data controller of the personal data we hold about you.

Personal Data We Collect

When you visit the Site, we automatically collect certain information about your device, including information about your web browser, IP address, time zone, and some of the cookies that are installed on your device. Additionally, as you browse the Site, we collect information about the individual web pages or products that you view, what websites or search terms referred you to the Site, and information about how you interact with the Site. We refer to this automatically collected information as "Device Information".

We collect Device Information using the following technologies:

  • "Cookies" are data files that are placed on your device or computer and often include an anonymous unique identifier. For more information about cookies and how to disable them, visit www.allaboutcookies.org. You can manage your cookie preferences at any time via the cookie banner on the Site.
  • "Log files" track actions occurring on the Site and collect data including your IP address, browser type, Internet service provider, referring/exit pages, and date/time stamps.
  • "Web beacons", "tags", and "pixels" are electronic files used to record information about how you browse the Site.

When you make a purchase or attempt to make a purchase through the Site, we collect certain information from you, including your name, billing address, delivery address, payment information (including card numbers), email address, and phone number. We refer to this information as "Order Information".

When you subscribe to our email or SMS communications, we collect your email address, phone number, and marketing preferences. We refer to this as "Marketing Information".

When we talk about "Personal Data" in this Privacy Policy, we are referring to Device Information, Order Information, and Marketing Information collectively.

How We Use Your Personal Data

We use the Order Information that we collect generally to fulfil any orders placed through the Site, including processing your payment information, arranging for delivery, and providing you with invoices and order confirmations. Additionally, we use this Order Information to:

  • Communicate with you about your order or account;
  • Screen our orders for potential risk or fraud; and
  • Where you have consented, provide you with information or advertising relating to our products or services.

We use the Device Information that we collect to help us screen for potential risk and fraud (in particular, your IP address), and more generally to improve and optimise our Site — for example, by generating analytics about how our customers browse and interact with the Site and to assess the success of our marketing and advertising campaigns.

We use Marketing Information to send you promotional emails, SMS messages, and other communications about our products, where you have consented to receive them. You can opt out of these communications at any time using the unsubscribe link in any email or by replying STOP to any SMS.

Legal Bases for Processing

Under UK GDPR, we rely on the following lawful bases to process your Personal Data:

  • Contract — to fulfil our contract with you when you place an order (processing Order Information to take payment, arrange delivery, and handle returns).
  • Legitimate interests — to protect our business against fraud, to improve and secure the Site, and to send service communications about orders you have placed.
  • Consent — for direct marketing emails and SMS, and for non-essential cookies. You may withdraw consent at any time.
  • Legal obligation — to retain tax and accounting records, and to respond to lawful requests from regulators or law enforcement.

Sharing Your Personal Data

We share your Personal Data with third parties to help us use your Personal Data as described above. These include:

We may also share your Personal Data to comply with applicable laws and regulations, to respond to a court order, subpoena, or other lawful request for information we receive, or to otherwise protect our rights.

International Data Transfers

Some of the service providers we use (including Shopify, Klaviyo, and Google) are based outside the United Kingdom. Where we transfer your Personal Data outside the UK, we ensure appropriate safeguards are in place — such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or reliance on adequacy regulations made by the UK Government. Your Personal Data may also be shared with our affiliated company, RJC Health Pty Ltd, in Australia, in which case the transfer will be made under an appropriate safeguard recognised under UK GDPR. You may request a copy of the safeguard used by contacting us at the details below.

Behavioural Advertising

We use your Personal Data to provide you with targeted advertisements or marketing communications we believe may be of interest to you, where you have consented. For more information about how targeted advertising works, you can visit the Network Advertising Initiative's educational page at https://www.networkadvertising.org/understanding-online-advertising/how-does-it-work.

You can opt out of targeted advertising through:

You can also opt out of interest-based advertising in the UK and EU via the Your Online Choices portal at https://www.youronlinechoices.com/uk/.

Do Not Track

Please note that we do not alter our Site's data collection and use practices when we see a Do Not Track signal from your browser, as there is currently no industry standard for how to respond to such signals.

Your Rights

Under UK GDPR and the Data Protection Act 2018, you have the following rights in relation to your Personal Data:

  • The right to be informed about how we use your Personal Data (this Privacy Policy).
  • The right of access — to request a copy of the Personal Data we hold about you.
  • The right to rectification — to ask us to correct inaccurate or incomplete Personal Data.
  • The right to erasure — to ask us to delete your Personal Data in certain circumstances.
  • The right to restrict processing — to ask us to limit how we use your Personal Data in certain circumstances.
  • The right to data portability — to receive your Personal Data in a structured, commonly used, machine-readable format.
  • The right to object — to object to processing based on legitimate interests, including direct marketing.
  • Rights in relation to automated decision-making and profiling.
  • The right to withdraw consent at any time, where we rely on consent to process your Personal Data.

To exercise any of these rights, please contact us using the details below. We will respond within one month, as required by UK GDPR. You will not have to pay a fee unless your request is clearly unfounded, repetitive, or excessive.

If you are not satisfied with how we have handled your Personal Data or a request to exercise your rights, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's data protection regulator, at ico.org.uk or by calling 0303 123 1113. We would appreciate the chance to address your concerns before you approach the ICO, so please contact us first.

Data Security

We take appropriate technical and organisational measures to protect your Personal Data from misuse, interference, loss, unauthorised access, modification, and disclosure. Payment transactions are processed through Shopify's secure, PCI-compliant payment infrastructure. However, no method of transmission over the Internet or method of electronic storage is completely secure.

Children's Privacy

Our Site is not intended for individuals under the age of 16, and we do not knowingly collect Personal Data from children. If you believe we have inadvertently collected information from a child, please contact us so we can promptly delete it.

Data Retention

We retain your Order Information for as long as your account remains active, and thereafter for the period required to meet our legal, tax, and accounting obligations (typically six years from the end of the relevant financial year, in line with HMRC requirements). Marketing data is retained until you withdraw consent or we determine that the data is no longer accurate. Device Information collected via analytics and advertising cookies is retained for the periods set by the relevant provider.

Changes

We may update this Privacy Policy from time to time to reflect changes to our practices or for other operational, legal, or regulatory reasons. We encourage you to review this page periodically.

Contact Us

For more information about our privacy practices, if you have questions, or if you would like to make a complaint or exercise any of your rights, please contact us by email at info@gethlth.co.uk or by post at:

RJC Health UK Limited trading as HLTH Code
Company No. 13922983
Registered in England and Wales
Registered office: C/O Buzzacott LLP, 130 Wood Street, London, United Kingdom, EC2V 6DL