Privacy Policy

Version 2.0 – Effective date: 07/07/2026
This version replaces the policy dated 10/10/2023 (last updated 17/12/2025).

This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You. We process Personal Data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who We Are

PreActiv is a trading name of Snow Squared Ltd ("the Company", "We", "Us" or "Our"), a company registered in England and Wales. Registered address: Brunel House, 11 The Promenade, Clifton, Bristol, United Kingdom, BS8 3NG. ICO registration number: ZB292222.

Questions about this policy or about your Personal Data should be directed to our Data Protection Lead, contactable via our contact form.

2. The Two Ways We Handle Your Data

We handle Personal Data in two distinct capacities, and your rights are exercised slightly differently depending on which applies to you:

  • If you are an NHS patient referred to the PreActiv programme, or a member of NHS Trust staff with a PreActiv account, your NHS Trust is the Data Controller and PreActiv is the Data Processor, acting only on the Trust's documented instructions. Section A below applies to you.
  • If you are visiting our website or contacting us with an enquiry, PreActiv is the Data Controller. Section B below applies to you.
3. Interpretation and Definitions

The words of which the initial letter is capitalised have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.

  • Account means a unique account created for You to access our Service or parts of our Service.
  • Website refers to PreActiv and is accessible from https://www.preactiv.co.uk and any client specific domain e.g. trust.preactiv.co.uk
  • Service refers to the PreActiv's perihabilitation programme.
  • Country refers to: United Kingdom
  • UK GDPR means the UK General Data Protection Regulation, as supplemented by the Data Protection Act 2018.
  • Trust / Your NHS Trust means the NHS organisation responsible for your care that has referred you to the PreActiv programme.
  • Data Controller means the legal person which, alone or jointly with others, determines the purposes and means of the processing of Personal Data. For NHS patients referred to PreActiv and for NHS Trust staff users, the Data Controller is Your NHS Trust. For website visitors and enquirers, the Data Controller is the Company.
  • Data Processor means a person or organisation which processes Personal Data on behalf of, and on the instructions of, a Data Controller. PreActiv acts as Data Processor in respect of referred NHS patients.
  • Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analysing how the Service is used. For the purpose of the UK GDPR, Service Providers are considered Data Processors (or sub-processors, where PreActiv itself acts as Data Processor).
  • Personal Data is any information that relates to an identified or identifiable individual, such as a name, an identification number, location data, an online identifier or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that individual.
  • Special Category Data means Personal Data requiring additional protection under Article 9 UK GDPR, including data concerning health and racial or ethnic origin.
  • Cookies are small files that are placed on Your computer, mobile device or any other device by a website, containing the details of Your browsing history on that website among its many uses.
  • Device means any device that can access the Service such as a computer, a cellphone or a digital tablet.
  • Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
Section A: NHS Patients and Trust Staff Using the PreActiv Platform

This Section applies to you if you have been referred to the PreActiv digital perihabilitation programme by your NHS Trust, or if you are a member of NHS Trust staff with a PreActiv account.

A1. Who is responsible for your data

Your NHS Trust is the Data Controller for the Personal Data processed in connection with your PreActiv programme. PreActiv (Snow Squared Ltd) is the Data Processor and processes your data only on the Trust's documented instructions, under a written data processing contract that complies with Article 28 UK GDPR. Your Trust's own privacy notice also applies to this processing.

A2. What data we process

On the instructions of your Trust, we process:

  • Identity and contact details: first name and last name, date of birth, gender, postcode, NHS number, mobile number and/or email address.
  • Health information (Special Category Data): your diagnosis, information relevant to screening for contraindications, your responses to health and wellbeing questionnaires, and your activity and exercise data generated through the programme.
  • Equality information (Special Category Data): racial or ethnic origin, where collected by your Trust to help ensure equitable access to care.
  • Usage Data generated when you use the platform, as described in Section B3.
A3. Why your data is processed and the lawful basis

Your data is processed to deliver a personalised perihabilitation programme as part of your NHS care: to create your account, tailor your programme safely, monitor your progress, allow your clinical team to review that progress, and contact you about the programme by SMS and/or email.

The lawful bases, which are determined by your Trust as Data Controller, are: Article 6(1)(e) UK GDPR – processing necessary for the performance of a task carried out in the public interest (the provision of NHS healthcare); and, for health and equality data, Article 9(2)(h) UK GDPR – processing necessary for the provision of health care, carried out under the responsibility of professionals subject to a duty of confidentiality.

Taking part in PreActiv is voluntary. Your clinical team will explain the programme and ask for your agreement before referring you, and you may opt out at any time by informing Trust staff or contacting PreActiv directly. This agreement is how the NHS ensures your participation is informed and voluntary; it is separate from the lawful basis for data processing described above.

A4. Where your data is stored

All patient Personal Data is stored on servers located in the United Kingdom. We do not transfer patient Personal Data outside the UK.

A5. Who we share your data with

We share your data with your NHS clinical team through the secure clinician dashboard, so that they can review your progress and support your care. We also use a small number of carefully selected sub-processors to run the platform, each bound by contract to protect your data:

  • Google Cloud Platform – primary cloud infrastructure for all platform data (hosted in London, UK; NHSE-approved supplier)
  • Kinsta – managed web hosting and content delivery (UK (London) data centres)
  • Bunny.net – content delivery network
  • ClickSend – SMS delivery of registration links and programme messages
  • Google Workspace (Gmail) – email delivery of registration links and programme messages (UK (London) data region)

We do not sell patient data, share it with advertisers, or use it for marketing. Messages you receive from PreActiv as a patient relate to your programme and are not marketing communications.

A6. How long your data is kept

Your Personal Data is anonymised 12 months after the end of the programme. If you opt out before completing the programme, your opt-out is treated as the end of your programme for this purpose. After anonymisation, data is used only within aggregated (averaged) data sets from which neither you nor your Trust can be identified, for the purposes of evaluating and improving the programme.

A7. Your rights

You have the rights described in Section 5 of this policy. Because your Trust is the Data Controller, requests (including requests for deletion of your data) are managed jointly by your Trust's Information Governance team and PreActiv. You can raise a request either with your clinical team or with us using our contact form, and we will make sure it reaches the right place.

A8. NHS Trust staff users

Where you hold a PreActiv account as a member of NHS Trust staff, we process your full name, date of birth, postcode, and mobile number and/or email address on your Trust's behalf, in order to create and secure your individual account (including one-time password authentication), enable role-based access, and maintain an audit trail of platform activity. The lawful basis, determined by your Trust, is Article 6(1)(e) UK GDPR (public task). Staff accounts are reviewed every three months and accounts that are no longer required are deleted. Your rights are exercised as described in Section A7.

Section B: Website Visitors and Enquiries
B1. Types of Data Collected

While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You. Personally identifiable information may include, but is not limited to:

  • Email address
  • First name and last name
  • Phone number
  • Address and postcode
B2. Usage Data

Usage Data is collected automatically when using the Service. Usage Data may include information such as Your Device's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data.

When You access the Service by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data.

B3. Tracking Technologies and Cookies

We use Cookies to operate Our Service and remember Your preferences. We do not use third-party advertising or analytics cookies.

Cookies can be “Persistent” or “Session” Cookies. Persistent Cookies remain on Your personal computer or mobile device when You go offline, while Session Cookies are deleted as soon as You close Your web browser. We use both Session and Persistent Cookies for the purposes set out below:

  • Cookie Notice Acceptance Cookies – Type: Persistent Cookies. Administered by: Us. Purpose: These Cookies identify if users have accepted the use of cookies on the Website.
  • Functionality Cookies – Type: Persistent Cookies. Administered by: Us. Purpose: These Cookies allow us to remember choices You make when You use the Website, such as remembering your login details or language preference. The purpose of these Cookies is to provide You with a more personal experience and to avoid You having to re-enter your preferences every time You use the Website.
B4. Use of Your Personal Data

The Company may use Personal Data for the following purposes:

  • To provide and maintain our Service, including to monitor the usage of our Service.
  • To manage Your Account: to manage Your registration as a user of the Service. The Personal Data You provide can give You access to different functionalities of the Service that are available to You as a registered user.
  • To contact You: To contact You by email, telephone calls, SMS, or other equivalent forms of electronic communication, such as a mobile application's push notifications regarding updates or informative communications related to the functionalities, products or contracted services, including the security updates, when necessary or reasonable for their implementation.
  • To provide You with news, special offers and general information about other goods, services and events which we offer that are similar to those that you have already purchased or enquired about unless You have opted not to receive such information. We do not send marketing communications to NHS patients.
  • To manage Your requests: To attend and manage Your requests to Us.
B5. Lawful basis for this processing

We rely on the following lawful bases under Article 6 UK GDPR: performance of a contract (Article 6(1)(b)) for managing accounts and delivering contracted services; legitimate interests (Article 6(1)(f)) for operating, securing and improving our website and Service and responding to enquiries; consent (Article 6(1)(a)) for marketing communications and non-essential cookies, which You may withdraw at any time; and legal obligation (Article 6(1)(c)) where processing is required by law.

B6. Email Marketing

We may use Your Personal Data to contact You with newsletters, marketing or promotional materials and other information that may be of interest to You. You may opt-out of receiving any, or all, of these communications from Us by following the unsubscribe link or instructions provided in any email We send or by contacting Us. Marketing is sent only to business contacts and enquirers, never to NHS patients referred to the programme.

B7. Sharing Your Personal Data

We may share Your personal information in the following situations:

  • With Service Providers: We may share Your personal information with Service Providers to operate the Service, to contact You, and to monitor and analyse the use of our Service. Our Service Providers are listed in Section A5 and are bound by contract to protect Your data.
  • With Your consent: We may disclose Your personal information for any other purpose with Your consent.
B8. Legal disclosures

Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency). The Company may disclose Your Personal Data in the good faith belief that such action is necessary to:

  • Comply with a legal obligation
  • Protect and defend the rights or property of the Company
  • Prevent or investigate possible wrongdoing in connection with the Service
  • Protect the personal safety of Users of the Service or the public
  • Protect against legal liability
B9. Retention of Your Personal Data

The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use Your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.

The Company will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of Our Service, or We are legally obligated to retain this data for longer time periods. Retention of NHS patient data is described in Section A6.

B10. Where your data is stored

Our Service is hosted on servers located in the United Kingdom and Personal Data is not transferred outside the UK. If that ever changes for website or business data, we will only transfer Personal Data where UK GDPR transfer safeguards are in place, and we will update this policy first.

5. Your Rights Under UK GDPR

The Company undertakes to respect the confidentiality of Your Personal Data and to guarantee You can exercise Your rights. You have the right under UK GDPR to:

  • Request access to Your Personal Data. The right to access, update or delete the information We have on You. Whenever made possible, you can access, update or request deletion of Your Personal Data directly within Your account settings section. If you are unable to perform these actions yourself, please contact Us to assist You. This also enables You to receive a copy of the Personal Data We hold about You.
  • Request correction (rectification) of the Personal Data that We hold about You. You have the right to have any incomplete or inaccurate information We hold about You corrected.
  • Request erasure of Your Personal Data. You have the right to ask Us to delete or remove Personal Data when there is no good reason for Us to continue processing it.
  • Request restriction of processing of Your Personal Data in certain circumstances, for example while a query about accuracy is resolved.
  • Object to processing of Your Personal Data. This right exists where We are relying on a legitimate interest as the legal basis for Our processing and there is something about Your particular situation, which makes You want to object to our processing of Your Personal Data on this ground. You also have the right to object where We are processing Your Personal Data for direct marketing purposes.
  • Request the transfer (portability) of Your Personal Data. We will provide to You, or to a third-party You have chosen, Your Personal Data in a structured, commonly used, machine-readable format. Please note that this right only applies to automated information which You initially provided consent for Us to use or where We used the information to perform a contract with You.
  • Withdraw Your consent. You have the right to withdraw Your consent on using your Personal Data where consent is the lawful basis (for example, marketing). If You withdraw Your consent, We may not be able to provide You with access to certain specific functionalities of the Service.

If you are an NHS patient, these rights apply to the processing carried out on behalf of your Trust and are managed jointly with your Trust, as described in Section A7.

You may exercise Your rights by contacting Us. Please note that we may ask You to verify Your identity before responding to such requests. If You make a request, We will try our best to respond to You within one month, as required by UK GDPR.

You have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection: www.ico.org.uk, or by telephone on 0303 123 1113. NHS patients may also complain via their Trust's Data Protection Officer.

6. Security of Your Personal Data

The security of Your Personal Data is important to Us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While We strive to use commercially acceptable means to protect Your Personal Data, We cannot guarantee its absolute security.

Our security measures include encryption of data at rest and in transit, role-based access controls, one-time password (two-factor) authentication, regular independent penetration testing, and daily backups. PreActiv is registered with the NHS Data Security and Protection Toolkit (DSPT) and is Cyber Essentials certified.

7. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the “last updated” date above. Material changes affecting NHS patient data will be communicated to the relevant NHS Trusts before taking effect.

8. Contact Us

If you have any questions about this Privacy Policy, You can contact us by using our contact form.