Privacy Policy
Last updated: 17 June 2026
Amilis Ltd ("the Company," "we," "us," or "our") takes the handling of personal data seriously. This Privacy Policy explains what personal data we collect through amilisltd.com and our femtech clinical-data platform, how we use it, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Amilis structures the fragmented cycle, lab, and imaging data that fertility clinics hold across multiple systems into a single chronological patient timeline. That core function means we interact with two categories of person: clinic staff who use the platform as practitioners, and visitors to this website. This policy covers both.
1. Data Controller
Amilis Ltd (35 Luke Street, Shoreditch, London EC2A 4NE) is the data controller for personal data processed through amilisltd.com under the UK GDPR and the Data Protection Act 2018. You can contact us at [email protected].
Where a fertility clinic or gynecology practice uses the Amilis platform to process patient records, that clinic is the data controller for patient data and the Company acts as a data processor under a written Data Processing Agreement. This policy does not cover patient data processed on behalf of clinic customers; that processing is governed by the applicable DPA between the Company and the clinic.
2. Personal Data We Process
The personal data we collect through this website and the early-access platform depends on how you interact with us:
- Identity and contact data you submit voluntarily: name, job title, clinic or organisation name, work email address, and telephone number provided through contact or early-access enquiry forms;
- Communications content: the text of messages you send us, including enquiries about the platform, data governance questions, and onboarding correspondence;
- Account data for early-access participants: login credentials (email address and hashed password), user preferences, and audit log entries recording which patient records were accessed and when;
- Technical data collected automatically: IP address, browser type and version, operating system, referring URL, pages visited, and session duration;
- Analytics data with your consent: aggregated, anonymised usage metrics collected only after you accept analytics cookies through our cookie consent banner.
We do not use patient record data submitted by clinic customers to train machine-learning models, build marketing profiles, or for any purpose other than providing the timeline organisation service described in the applicable DPA. Patient data is not personal data for which the Company is a controller under this policy.
3. Lawful Bases (Article 6 UK GDPR)
We rely on the following lawful bases for processing personal data about website visitors and platform users:
- Pre-contract steps or performance of a contract (Article 6(1)(b)): responding to enquiries and onboarding early-access clinic participants who have requested the service;
- Legitimate interests (Article 6(1)(f)): operating and securing the website and platform; communicating with clinic contacts about account matters; fraud prevention. Our interests in maintaining a functional and secure clinical data service are balanced against and do not override the rights of the individuals concerned;
- Legal obligation (Article 6(1)(c)): complying with applicable law, including responding to lawful requests from regulatory authorities;
- Consent (Article 6(1)(a)): setting non-essential analytics cookies; sending marketing communications to individuals who have opted in. You can withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
4. Recipients and International Transfers
We share personal data only with processors acting under written contracts meeting Article 28 UK GDPR requirements. These include cloud hosting providers and productivity tools. We do not sell personal data to third parties.
Where a processor is located outside the United Kingdom, transfers are protected by one of: the UK International Data Transfer Agreement (IDTA); the UK Addendum to the European Commission's Standard Contractual Clauses; or an adequacy regulation made under section 17A of the Data Protection Act 2018. Details of applicable transfer mechanisms are available on request from [email protected].
5. Retention
We retain personal data only as long as necessary for the purpose for which it was collected:
- Enquiry and early-access contact data: 24 months from last meaningful contact;
- Platform account data: for the duration of the active early-access engagement, then deleted within 30 days of account closure unless a longer period is required by law;
- Server access logs: 90 days;
- Audit trail records (which clinician accessed which record): retained for the period specified in the applicable DPA with the clinic, reflecting the clinic's own regulatory record-keeping obligations.
6. Your UK GDPR Rights
Under the UK GDPR you have the following rights in relation to personal data for which the Company is controller:
- Right of access: to obtain a copy of the personal data we hold about you;
- Right to rectification: to have inaccurate data corrected;
- Right to erasure: to request deletion of your personal data where there is no overriding ground for continued processing;
- Right to restriction of processing: to request that we pause processing in certain circumstances while a dispute is resolved;
- Right to data portability: to receive data you have provided to us in a structured, commonly used, machine-readable format;
- Right to object: including the absolute right to object to direct marketing processing at any time and, in other cases, to object on grounds relating to your particular situation;
- Rights related to automated decision-making: we do not engage in solely automated decisions with legal or similarly significant effects.
To exercise any of these rights, email [email protected] with a clear description of your request. We will respond within one calendar month. That period may be extended by a further two months for complex or numerous requests, in which case we will notify you of the extension within the first month.
7. Right to Complain to the ICO
You have the right to lodge a complaint about our processing with the UK Information Commissioner's Office ("ICO"). The ICO's website is ico.org.uk; helpline 0303 123 1113. We would, however, appreciate the opportunity to address your concerns before you contact the ICO, so please reach out to us first.
8. Cookies
See our Cookie Policy. Non-essential cookies are not set without your prior consent under the Privacy and Electronic Communications Regulations (PECR). You can update your cookie preferences at any time using the "Cookie preferences" link in the footer.
9. Security and Changes
We implement technical and organisational measures appropriate to the risk, including encryption of data in transit and at rest, access controls limited to authorised personnel, and audit logging of access to patient records on the platform. These are operational measures; they do not constitute certification under any specific standard.
When we make material changes to this policy, we will update the "Last updated" date at the top of the page. Continued use of our website or platform after a material change constitutes acceptance of the revised policy.
10. Contact
Amilis Ltd35 Luke Street, Shoreditch
London EC2A 4NE
Email: [email protected]
Phone: +44 20 7946 0958