This page is a plain account of how we look after your information: where it is held, how it is protected, who else is involved, and what we have not done yet. It is written so that you can check it rather than take our word for it, and where a claim can be verified from outside we have given you the link.
Anything we are still working on is kept in its own section at the bottom rather than written up here as though it were already true. If something you expected to find is not on this page, that is usually why.
Every claim below was last checked against our running systems on 13 August 2026.
Who we are
Vitalife Clinic Ltd is a company registered in England and Wales, company number 16777077, with its registered office at 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ. The clinic is delivered online and has no consulting premises. We are the data controller for everything described here.
We are registered with the Information Commissioner’s Office as a data controller under reference ZC220213. That registration was made on 11 August 2026 and runs until 10 August 2027. The ICO’s register is public, so you do not have to believe us: look the reference up yourself.
Our data protection contact is privacy@vitalifeclinic.co.uk, which is the same address filed with the ICO.
Where your information lives
This website and our client portal run on servers rented from Clook Internet, a Lancashire hosting company trading as Sub 6 Limited. Clook publishes that its hosting platform runs in United Kingdom data centres, in Manchester, and the range of internet addresses our servers use is registered in the United Kingdom to that same company. Your record is stored there and nowhere else.
How those buildings are powered. Clook states that its data centres run entirely on renewable energy, that it works only with data centre partners holding ISO 50001 accreditation for energy management, and that those partners have used renewable energy since 2013. We are repeating that on their authority, in their own words, rather than presenting it as something we have audited. Clook is itself still applying for ISO 14001 and ISO 50001 and does not hold either yet.
The computers that do our AI work are a separate matter. Those are machines Vitalife owns outright, standing on our own premises in the United Kingdom. They are not rented, not shared with anybody, and not in somebody else’s cloud.
Some of the companies that help us run the clinic do work outside the United Kingdom. They are named below, because a page that said “everything is in the UK” and left them out would not be honest.
How your information is protected
In transit. Everything between your device and us travels over an encrypted connection. Both this website and the client portal answer only over HTTPS, using TLS 1.3.
At rest. The sensitive parts of a client record are encrypted field by field inside our database, with AES-256. That covers health check-ins, journals and private writing, goals, form answers, messages, a coach’s notes, contact details, and any enquiry sent to us before an account existed. A copy of the database taken on its own does not read as text.
What is not encrypted, and why. Names and dates of birth are held in ordinary form, so that a coach can search for a client and so client lists sort properly. We judged that a fair trade against the health record itself, which is the part that matters, and we would rather tell you than let you assume otherwise.
We do not describe this as end to end encryption, because it is not. End to end would mean nobody but you could ever read it, us included, and that would make coaching impossible. What is true is that a record is unreadable to anyone who gets hold of the storage, and inside the clinic it is readable only by the people whose job needs it. A coach sees their side of a privacy line we set out in the privacy policy, administrative access is restricted, and a client’s private writing stays private unless they choose to share it.
Card details never reach us. Payments go straight to Stripe. We never see or store a card number.
Backups. The portal database is backed up every night, and again before every software update. Those backups are encrypted before they are written to disk rather than afterwards, so there is never a moment when a readable copy of a client record exists as a file. Old ones are deleted automatically rather than piling up.
Our AI runs on our own computers
This is the part most people ask about, so it is worth being exact. Every AI assisted feature we offer runs on hardware Vitalife owns and controls in the United Kingdom. Nothing about you is sent to OpenAI, to Google, to Anthropic or to any other AI company. Nothing about you is used to train anybody’s model, ours included.
That covers all of it: a coach’s draft progress notes, the written summary a client can ask for about their own progress, programme content drafted before a coach reviews it, and the illustrations on our articles.
It is worth saying why this is more than a setting somebody could change. The client portal contains no code capable of calling an outside AI service. The parts that used to do so were removed rather than switched off, so there is nothing to re-enable by accident, and the machines the work is handed to are configured to answer only from models that run on them.
Who else is involved
A short list, each one under contract as our processor and each used for one thing only:
- Stripe: taking payments.
- Zoom: live programme sessions and appointments, where a programme includes them.
- Brevo: delivering our emails.
- Meta (WhatsApp Business): coach messaging over WhatsApp, and only where a client has opted in and given us their number.
- Clook Internet: the servers this website and the portal run on.
Some of these process data outside the United Kingdom. Where they do, the transfer is covered by the safeguards UK law requires, such as the UK Addendum to the EU Standard Contractual Clauses. Beyond this list, we disclose your information only where the law requires it.
How we measure visitors
We count visits to this website and to the portal, and we do it ourselves on our own servers. There is no Google Analytics and no other third party measurement service, so nothing about your visit leaves Vitalife.
It sets no cookies and stores nothing at all on your device. Your IP address is never written to disk: it is combined with a secret that changes daily, turned into an anonymous code, and that secret is destroyed after two days, at which point nobody can work backwards from the code, us included. If your browser sends “Do Not Track” or “Global Privacy Control”, we do not count you at all. There is more detail in our privacy policy.
Your rights
Under UK GDPR you can ask for a copy of your data, have it corrected, have it erased, restrict or object to how we use it, take it elsewhere, and withdraw consent at any time. Email privacy@vitalifeclinic.co.uk and we will answer within one month. Today a request is handled by a person rather than by a button, which is one of the things listed below as unfinished.
If you are not satisfied with how we have handled something, you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We would rather have the chance to put it right first, but that route is yours and we will not stand in the way of it.
What we are working towards
Nothing in this section is true yet. It is here because a trust page that lists only the good news is not worth reading.
ISO 27001. We are not certified to ISO 27001 and we are not currently compliant with it. We have chosen it as the standard we are organising ourselves towards. Some of what it asks for is already in place: encryption of the sensitive record, access limited by role, an inventory of what data we hold and where, encrypted backups on a schedule, and the short supplier list above. What is missing is the formal half, and it is the larger half: a documented management system, a risk register somebody has signed off, internal audit, and an independent certification body. We will say so on this page when any of that changes, and we will not call ourselves compliant before it does.
Asking for your data, and asking us to delete it. Both rights are real today and both are answered by a person. We are building them into the portal so a client can do it themselves and watch it happen.
Written confirmation from our hosting company. What we say above about UK data centres and renewable energy is Clook’s published statement about their platform in general. It is not a confirmation given to us in writing about the particular servers we rent, and nobody has audited it on our behalf. Getting that in writing is on this list. Until it arrives, that paragraph stands on their authority rather than ours, which is why it is worded the way it is.
Making the in-house AI rule structural. Our AI machines answer only from local models today, and that is currently a matter of how they are configured. We want it to be a rule the software enforces rather than a setting somebody could change, so that the promise above holds without anybody having to remember it.
How this page is checked
On 13 August 2026 every statement above was checked against the systems that were actually running, not against our own documents. That distinction matters more than it sounds: a security document describes what somebody intended, and only the running system says what is so.
The date near the top of this page is when that was last done. If you think something here is wrong, tell us at privacy@vitalifeclinic.co.uk. We will either show you the check or correct the page.
