Olly

Privacy Policy

Last updated: 11 September 2026 · Version 1.0

Olly (“Olly”, “we”, “us”) provides health insurance and related health, triage and care-navigation services to members and their employers in the United Kingdom. This policy explains what personal data we collect, why we collect it, how we use and share it, and the rights you have over it.

1. Who we are

Olly is the data controller for the personal data described in this policy. Where an employer arranges cover for its staff, the employer is a separate controller of the employment data it holds; Olly is the controller for the policy, claims and health data it processes to provide the service.

Olly Insurance Ltd
Registered in England and Wales, company number [●]
Registered office: [●]
Data Protection contact: privacy@hiolly.com

2. The data we collect

CategoryExamples
Identity and contactName, date of birth, email, phone number, postal address, membership number
Policy and employmentEmployer, scheme, cover level, start and end dates, dependants
FinancialPremium and invoice records, payment status. Card details are handled by our payment processor and are not stored by Olly.
Health (special category)Symptoms you describe, triage answers, conditions, medications, appointment and referral records, claims and treatment information, documents you upload (such as GP letters or receipts)
Wearable and lifestyle (optional)Steps, sleep, heart rate and similar readings, only if you connect a wearable or health app and consent to share it
CommunicationsChat transcripts with Olly, support requests, notification preferences
TechnicalDevice type, app version, IP address, login events, diagnostic logs

We receive most of this data directly from you, from your employer or broker when your cover is set up, and from healthcare providers and clinics involved in your care.

3. Why we use your data and our lawful basis

PurposeLawful basis (UK GDPR)
Setting up and administering your policy, verifying identity, collecting premiumsContract (Art. 6(1)(b))
Assessing eligibility, handling claims and prior authorisations, paying providersContract; and for health data, insurance purposes under the Data Protection Act 2018, Schedule 1, Part 2, para 20
Symptom triage, care navigation and booking appointmentsExplicit consent (Art. 9(2)(a)) for health data; contract for the service itself
Wearable and lifestyle insightsExplicit consent, which you can withdraw at any time in the app
Sending service notifications (email, SMS, push, in-app)Contract; legitimate interests for non-essential updates, with an opt-out
Preventing fraud, securing our systems, keeping audit logsLegitimate interests; legal obligation
Meeting regulatory, tax and insurance-law obligationsLegal obligation
Improving our products, including evaluating and testing our triage serviceLegitimate interests, using de-identified or pseudonymised data wherever possible

4. Health data and AI-assisted triage

Olly's symptom checker uses automated systems, including large language models, to ask you questions and suggest the most appropriate next step, such as self-care, a GP appointment, or urgent care. Please note:

5. Who we share data with

6. International transfers

We host your data in the United Kingdom or the European Economic Area. Some service providers, including AI model providers, may process data outside the UK. Where that happens we rely on UK adequacy regulations or the International Data Transfer Agreement (or the Addendum to the EU Standard Contractual Clauses), together with additional safeguards such as pseudonymisation and encryption.

7. How long we keep data

DataRetention
Policy, claims and financial records7 years after the policy ends, to meet insurance, tax and complaints obligations
Health and triage recordsFor as long as your policy is active, plus 7 years, in line with insurance and clinical record-keeping guidance
Wearable and lifestyle dataUntil you disconnect the source or withdraw consent, after which it is deleted within 30 days
Technical and security logsUp to 12 months
Marketing preferencesUntil you opt out, then a suppression record is kept so we honour your choice

8. How we protect data

We encrypt data in transit and at rest, restrict access on a need-to-know basis with role-based controls, keep audit logs of access to health records, separate identifying data from clinical data where practical, and test our systems for vulnerabilities. Staff and contractors who handle personal data are trained and bound by confidentiality obligations.

9. Your rights

Under UK data protection law you can ask us to:

To exercise a right, email privacy@hiolly.com. We respond within one month and will not charge a fee unless a request is clearly excessive.

10. Cookies and analytics

Our web apps use strictly necessary cookies and local storage to keep you signed in and remember your preferences. We use privacy-respecting product analytics to understand how features are used; these are aggregated and not used to build advertising profiles. We do not use third-party advertising cookies.

11. Children

Dependants under 18 may be covered under a parent's or guardian's policy. In that case the policyholder provides the dependant's data and exercises rights on their behalf, until the dependant is old enough to do so themselves. We do not knowingly collect data directly from children outside a policy.

12. Changes to this policy

We will post any changes here and update the date at the top. If a change materially affects how we use your health data, we will notify you in the app or by email before it takes effect.

13. Contact and complaints

Questions or concerns: privacy@hiolly.com.

If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint or on 0303 123 1113.