Privacy Policy
Olly (“Olly”, “we”, “us”) provides health insurance and related health, triage and care-navigation services to members and their employers in the United Kingdom. This policy explains what personal data we collect, why we collect it, how we use and share it, and the rights you have over it.
1. Who we are
Olly is the data controller for the personal data described in this policy. Where an employer arranges cover for its staff, the employer is a separate controller of the employment data it holds; Olly is the controller for the policy, claims and health data it processes to provide the service.
Olly Insurance Ltd
Registered in England and Wales, company number [●]
Registered office: [●]
Data Protection contact: privacy@hiolly.com
2. The data we collect
| Category | Examples |
|---|---|
| Identity and contact | Name, date of birth, email, phone number, postal address, membership number |
| Policy and employment | Employer, scheme, cover level, start and end dates, dependants |
| Financial | Premium and invoice records, payment status. Card details are handled by our payment processor and are not stored by Olly. |
| Health (special category) | Symptoms you describe, triage answers, conditions, medications, appointment and referral records, claims and treatment information, documents you upload (such as GP letters or receipts) |
| Wearable and lifestyle (optional) | Steps, sleep, heart rate and similar readings, only if you connect a wearable or health app and consent to share it |
| Communications | Chat transcripts with Olly, support requests, notification preferences |
| Technical | Device type, app version, IP address, login events, diagnostic logs |
We receive most of this data directly from you, from your employer or broker when your cover is set up, and from healthcare providers and clinics involved in your care.
3. Why we use your data and our lawful basis
| Purpose | Lawful basis (UK GDPR) |
|---|---|
| Setting up and administering your policy, verifying identity, collecting premiums | Contract (Art. 6(1)(b)) |
| Assessing eligibility, handling claims and prior authorisations, paying providers | Contract; and for health data, insurance purposes under the Data Protection Act 2018, Schedule 1, Part 2, para 20 |
| Symptom triage, care navigation and booking appointments | Explicit consent (Art. 9(2)(a)) for health data; contract for the service itself |
| Wearable and lifestyle insights | Explicit consent, which you can withdraw at any time in the app |
| Sending service notifications (email, SMS, push, in-app) | Contract; legitimate interests for non-essential updates, with an opt-out |
| Preventing fraud, securing our systems, keeping audit logs | Legitimate interests; legal obligation |
| Meeting regulatory, tax and insurance-law obligations | Legal obligation |
| Improving our products, including evaluating and testing our triage service | Legitimate interests, using de-identified or pseudonymised data wherever possible |
4. Health data and AI-assisted triage
Olly's symptom checker uses automated systems, including large language models, to ask you questions and suggest the most appropriate next step, such as self-care, a GP appointment, or urgent care. Please note:
- Triage suggestions are guidance, not a diagnosis. A clinician reviews any onward referral or care decision that affects your cover.
- We do not make solely automated decisions about you that have a legal or similarly significant effect. Claims and coverage decisions involve human review.
- Your conversations are stored so that clinicians and support staff can see what you told us, and so that we can review the safety and quality of the triage service.
- Health data is never used for advertising and is never sold.
- If you would rather not use the AI symptom checker, you can contact us directly and we will help you another way.
5. Who we share data with
- Healthcare providers such as GPs, clinics, physiotherapists and hospitals we refer you to or that treat you under your cover.
- Your employer or broker, limited to membership and billing information. We do not share your health data with your employer.
- Service providers who process data on our behalf under contract: cloud hosting, identity and authentication, payment processing, email and notification delivery, customer support tooling, and AI model providers used for triage. These providers act only on our instructions.
- Regulators, auditors and law enforcement where the law requires it, including the FCA, the ICO and HMRC.
- Professional advisers and insurers or reinsurers involved in underwriting or funding your cover.
6. International transfers
We host your data in the United Kingdom or the European Economic Area. Some service providers, including AI model providers, may process data outside the UK. Where that happens we rely on UK adequacy regulations or the International Data Transfer Agreement (or the Addendum to the EU Standard Contractual Clauses), together with additional safeguards such as pseudonymisation and encryption.
7. How long we keep data
| Data | Retention |
|---|---|
| Policy, claims and financial records | 7 years after the policy ends, to meet insurance, tax and complaints obligations |
| Health and triage records | For as long as your policy is active, plus 7 years, in line with insurance and clinical record-keeping guidance |
| Wearable and lifestyle data | Until you disconnect the source or withdraw consent, after which it is deleted within 30 days |
| Technical and security logs | Up to 12 months |
| Marketing preferences | Until you opt out, then a suppression record is kept so we honour your choice |
8. How we protect data
We encrypt data in transit and at rest, restrict access on a need-to-know basis with role-based controls, keep audit logs of access to health records, separate identifying data from clinical data where practical, and test our systems for vulnerabilities. Staff and contractors who handle personal data are trained and bound by confidentiality obligations.
9. Your rights
Under UK data protection law you can ask us to:
- Access the personal data we hold about you and receive a copy.
- Correct data that is inaccurate or incomplete.
- Erase your data where we no longer need it, subject to insurance and legal retention duties.
- Restrict or object to processing based on legitimate interests.
- Port data you gave us to another provider in a machine-readable format.
- Withdraw consent at any time for processing based on consent, such as wearable data or the AI symptom checker.
To exercise a right, email privacy@hiolly.com. We respond within one month and will not charge a fee unless a request is clearly excessive.
10. Cookies and analytics
Our web apps use strictly necessary cookies and local storage to keep you signed in and remember your preferences. We use privacy-respecting product analytics to understand how features are used; these are aggregated and not used to build advertising profiles. We do not use third-party advertising cookies.
11. Children
Dependants under 18 may be covered under a parent's or guardian's policy. In that case the policyholder provides the dependant's data and exercises rights on their behalf, until the dependant is old enough to do so themselves. We do not knowingly collect data directly from children outside a policy.
12. Changes to this policy
We will post any changes here and update the date at the top. If a change materially affects how we use your health data, we will notify you in the app or by email before it takes effect.
13. Contact and complaints
Questions or concerns: privacy@hiolly.com.
If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint or on 0303 123 1113.
