Privacy Policy

Last Updated:


August 2026

Introduction


Myora Ltd ("Myora", "we", "us", "our") is committed to protecting your privacy. This policy explains what personal information we collect, why we collect it, how we use and protect it, and the rights you have over it.

Myora Ltd is the data controller for the personal information described in this policy. We are a company registered in England and Wales (Company No. 16694154), with our registered office at 128 City Road, London, EC1V 2NX, United Kingdom. We are registered with the UK Information Commissioner's Office (ICO) under registration number ZC119958.

We operate across the United Kingdom and Nigeria. Depending on where you are and how you engage with us, your personal data is protected under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, and under the Nigeria Data Protection Act, 2023 (NDPA), the Nigeria Data Protection Act General Application and Implementation Directive, 2025 (NDPA-GAID) and any guidance issued by the Nigeria Data Protection Commission (NDPC). Where we handle the personal data of individuals in Nigeria, we do so in accordance with the NDPA and, where we are required to register, we maintain registration with the NDPC.

Where we deliver a health or wellness programme in partnership with another organisation (such as an employer, HMO, insurer, health scheme or similar sponsor), that organisation and Myora each act as independent data controllers in respect of the data each of us processes, neither of us processes your data as the other's processor, and each of us is responsible for our own processing under applicable data protection law.

What we collect


Information you provide to us:

  • Name, email address, phone number (including your WhatsApp number) and other contact details when you join our waitlist, enquire about our services, or sign up to our platform.

  • Organisation details if you represent a corporate, HMO, insurer or health scheme.

  • Where required to verify your identity or eligibility for a programme, a government-issued identification number (such as a national ID number) and any member or scheme identifier issued to you by a sponsoring organisation.

  • Date of birth and gender.

  • Health and wellness information you give us or that we generate through assessments, screening, clinical checkpoints, daily check-ins and coaching — including diet and nutrition (including cultural and regional dietary practices), physical activity, sleep, stress, mood, weight, body composition and measurements, blood pressure, blood glucose and other clinical and biometric markers, family and personal medical history, and lifestyle factors.

  • Health scores, risk insights and other indicators we derive from your data (for example a health-age or physiological-age score), together with the underlying inputs used to calculate them.

  • Records relating to any clinical-risk escalation — that is, where a screening or monitoring result indicates a risk to your health or safety that may require urgent attention.

  • Messages and communications you send us, including through WhatsApp, our mobile app, email and web forms.

Information we collect automatically:

  • Device and browser information.

  • IP address and approximate location.

  • Pages visited and how you interact with our website and app.

  • Cookies and similar technologies (see "Cookies" below).

Information from third parties:

  • Where an organisation (such as an employer, HMO or insurer) sponsors your participation, we may receive your name and contact details from them to enrol you.

  • Where you complete clinical screening or a clinical assessment through one of our partner labs, clinics or a sponsoring organisation (or a provider acting on its behalf), we may receive your test results and clinical measurements. We only receive and use this health information where you have given us your explicit consent, or where another lawful condition for processing special category / sensitive data applies.

Special category (health) data


Most of the information above about your health is special category personal data under the UK GDPR and sensitive personal data under the Nigeria Data Protection Act, 2023. This kind of data receives extra protection under the law.

We only collect and use it where you have given us your explicit consent, which you provide when you join a programme and complete your assessment, or where another lawful condition applies (for example, to protect your or another person's vital interests in an emergency, or where processing is carried out by or under the responsibility of a professional owing a duty of confidentiality for the purposes of medical care).

You can withdraw your consent at any time (see "Your rights"). Where any of this sensitive data relates to a person under 18, we process it only on the basis of verified parental or guardian consent (or another lawful basis) and with additional safeguards appropriate to a child.

Why we use your information and our lawful basis


Under the UK GDPR and the Nigeria Data Protection Act, 2023 we must have a lawful basis for using your personal data. Our bases are set out below. We may rely on more than one lawful basis for a given activity, depending on the circumstances.

What we use your data for

Lawful basis

Providing and personalising your wellness coaching, assessments, health scores (such as a health-age or physiological-age score), ThriveScore, risk insights and progress tracking

Performance of our contract with you and/or your consent, and for health data your explicit consent

Sending you coaching messages and programme content over WhatsApp and our app

Consent

Responding to enquiries and providing support

Our legitimate interests in running and supporting our service

Processing rewards and payments, determining and administering any performance-based or outcome-based reward you may be eligible for, including verifying achievement of your goals and processing payment

Consent; Performance of our contract with you

Sending you updates and marketing about Myora

Consent (you can opt out at any time)

Producing anonymised, aggregate insights for sponsoring organisations

Our legitimate interests in operating a B2B2C service, using only anonymised data

Improving and securing our website, app and services

Our legitimate interests

Meeting legal and regulatory obligations

Legal obligation

Delivering wellness and preventive-health programmes we run with a sponsoring organisation — including onboarding, eligibility and identity verification, clinical checkpoints, progress tracking and reporting to that organisation

Consent, and for health data your explicit consent; and, where applicable, performance of our contract and our legitimate interests in delivering the programme

Developing, training, testing, improving and operating our algorithms, artificial intelligence models, health-scoring methodology and other products and services

Consent; Our legitimate interests, using only de-identified, pseudonymised individual-level data and aggregated data from which you cannot reasonably be identified

Producing and publishing de-identified, aggregated research findings and programme outcomes (for example in reports, peer-reviewed journals or professional forums)

Our legitimate interests, using only de-identified and aggregated data

Acting to protect your health or safety, or that of another person, in an urgent situation (clinical-risk escalation)

Protecting your or another person's vital interests; and, where applicable, your explicit consent

We do not sell your personal information to anyone.

WhatsApp messaging: your consent and how to opt out


Myora delivers coaching and programme content through the WhatsApp Business Platform, provided by Meta Platforms Ireland Ltd.

Opt-in. We will only message you on WhatsApp after you have given us your explicit consent — for example by entering your WhatsApp number and confirming that you would like to receive Myora coaching messages when you sign up. We will never message you on WhatsApp without your prior opt-in.

Opt-out. You can stop receiving WhatsApp messages from us at any time by:

  • replying STOP to any of our WhatsApp messages; or

  • emailing us at team@myora.health asking to be unsubscribed.

Once you opt out, we will stop sending you WhatsApp messages promptly. Opting out of messaging does not delete your account or other data — to do that, see "Your rights".

When you communicate with us over WhatsApp, your messages are also processed by Meta in line with WhatsApp's own terms and privacy policy.

Who we share your information with


We share personal data only where necessary, and we require everyone who processes data on our behalf to protect it and use it only on our instructions. We share data with:

  • Service providers (processors) who help us run Myora — including our messaging provider (Meta / WhatsApp), our AI coaching technology provider (Google, for Gemini), our payment providers, our website and cloud hosting providers, and our clinical screening and lab partners. Some of these providers are located outside Nigeria and/or the UK, so using them involves an international transfer of your data (see "International data transfers"); we put appropriate safeguards in place for those transfers.

  • Sponsoring organisations (employers, HMOs, insurers, health schemes and similar sponsors) — where an organisation sponsors your participation in a programme, we share anonymised, aggregate data with them for reporting purposes, and they do not receive your individual, identifiable health information for those reports except where separately described below. Where a sponsoring organisation is itself an independent data controller for a programme (for example an HMO administering your care), we may share the personal data necessary for that programme with it on a need-to-know basis and under an appropriate data sharing or data processing agreement; in that case the organisation is responsible for its own use of your data under its own privacy notice.

  • Clinical and laboratory partners engaged to carry out or analyse your screening or clinical assessments.

  • A treating clinician, a sponsoring organisation and/or a person you have nominated as an emergency contact — but only where a screening or monitoring result indicates a risk to your health or safety that requires urgent attention, and only to the extent necessary to help you receive timely medical attention (clinical-risk escalation).

  • Professional advisers, regulators and authorities (including the ICO and the NDPC) where we are required to by law or to establish, exercise or defend legal claims.

International data transfers


Myora operates across the United Kingdom and Nigeria (and over time other regions). This means your personal data, including health data, may be transferred to and processed in countries outside the country where it was collected — for example, data collected in Nigeria may be transferred to and processed in the United Kingdom (and other jurisdictions in which we operate or host data), and data collected in the United Kingdom may be transferred to and processed in Nigeria, where we work with local clinical and payment partners.

Whenever we transfer your personal data across borders, we make sure it is protected. Where we transfer data out of the United Kingdom to a country without UK "adequacy" status, we put appropriate safeguards in place, such as the ICO's International Data Transfer Agreement or equivalent contractual protections. Where we transfer data out of Nigeria, we do so only where the transfer meets the requirements of the Nigeria Data Protection Act, 2023 and the NDPA-GAID — for example, where the destination country provides an adequate level of protection, or under a lawful transfer mechanism recognised by the NDPC, such as an approved Cross-Border Data Transfer Instrument (CBDTI), binding corporate rules, standard contractual clauses or other contractual safeguards, or with your explicit consent to the transfer. In each case we take steps to ensure your data receives a level of protection consistent with applicable law. You can request a copy of these safeguards by contacting us at team@myora.health.

How we keep your data safe


We use appropriate technical and organisational measures to protect your information, including encryption of health data in transit and at rest, access controls, and secure hosting. No system is completely secure, but we work to protect your data and to limit who can access it.

If a personal data breach occurs that is likely to put your rights and freedoms at risk, we will notify the relevant regulator — the ICO in the United Kingdom and/or the NDPC in Nigeria — within 72 hours of becoming aware of it. Where a breach is likely to result in a high risk to your rights and freedoms, we will also communicate it to you without undue delay, in clear language, together with advice on steps you can take to protect yourself.

Automated processing and profiling


To personalise your programme, Myora uses your assessment and check-in data to calculate health scores and risk insights and to tailor your coaching. This involves automated processing, including profiling. These insights are designed to support you and your coaching; they are not medical advice, diagnosis or treatment and do not replace professional medical care.

We do not make decisions that produce legal effects or similarly significant effects about you based solely on automated processing. Where the law gives you the right not to be subject to a decision based solely on automated processing, we will not make such a decision about you unless a lawful exception applies; and where one does, you can ask us to have a person review the decision, express your point of view and contest it. You can ask us about how these insights are generated by contacting team@myora.health.

How long we keep your data


We keep personal data only for as long as necessary for the purposes set out in this policy, or as required by law. To decide how long to keep it, we consider the amount, nature and sensitivity of the data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it and whether we can achieve those purposes another way, and any legal, regulatory or reporting requirements.

Where you take part in a programme, we keep your wellness and programme data for the duration of your participation (including any period reasonably needed to verify and pay any reward and to complete follow-up, safety monitoring and reporting) and for a defined period afterwards (which will not usually exceed 18 months after the programme ends, unless a longer retention period is required or permitted by applicable law including any medical records or clinical retention requirements), unless you ask us to delete it sooner. After that, we securely delete or anonymise it.

Where we have de-identified and aggregated data so that you can no longer reasonably be identified, that data is no longer personal data, and we may keep and use it indefinitely for the purposes described in this policy (including developing and improving our products, services and models). We do not attempt to re-identify it.

We may also keep a minimal record of your consent, and of any request you make to us, for longer where we need it as evidence of our compliance with the law.

Change of purpose. We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another compatible reason. If we need to use your personal data for an unrelated purpose, we will notify you and explain the lawful basis that allows us to do so. Where the law requires it, we will seek your consent.

Your rights


Under the UK GDPR and the Nigeria Data Protection Act, 2023 you have the right to:

  • Access the personal data we hold about you.

  • Correct inaccurate or incomplete data.

  • Erase your data ("right to be forgotten").

  • Restrict or object to certain processing.

  • Data portability — receive your data in a portable format.

  • Withdraw consent at any time, where we rely on consent (this will not affect processing carried out before you withdrew it but may mean we can no longer provide the relevant service to you).

  • Not be subject to a decision based solely on automated processing (including profiling) that produces legal effects concerning you or similarly significantly affects you, except where the law permits it — in which case you can ask us to review the decision, express your point of view and contest it.

You will not usually have to pay a fee to exercise any of these rights. However, we may charge a reasonable fee, or refuse to act, if your request is clearly unfounded, repetitive or excessive. We may need to ask you for information to confirm your identity before we act, to make sure your data is not disclosed to anyone who has no right to receive it.

To exercise any of these rights, contact us at team@myora.health. We will respond within the timeframes required by law (usually within one month). You also have the right to complain to a data protection regulator if you are unhappy with how we have handled your data. In the United Kingdom, this is the Information Commissioner's Office (ICO), which you can contact at ico.org.uk or on 0303 123 1113. In Nigeria, this is the Nigeria Data Protection Commission (NDPC), which you can contact at info@ndpc.gov.ng or on +234 (0) 916 061 5551. We would, however, appreciate the chance to address your concerns first.

How to delete your data and account


You can ask us to delete your personal data and close your account at any time by emailing team@myora.health with the subject line "Delete my data". We will verify your request and delete or anonymise your data without undue delay, and we will instruct our service providers to do the same. We may keep a minimal record of your request, and a limited amount of data, only where we are required to by law. We will confirm to you once your request has been completed.

Cookies


We use essential cookies to operate our website and analytics cookies to understand how visitors use our site. You can manage or disable cookies through your browser settings. Disabling some cookies may affect how the site works.

Our website and app may include links to third-party websites, plug-ins and applications. We do not control those third parties and are not responsible for their privacy practices. When you leave our website or app, we encourage you to read the privacy policy of every website or service you visit.

Children


Our services are generally intended for adults, and you must normally be 18 or over to use them. We do not knowingly collect data from anyone under 18 through our general website and app. Where a specific programme is open to participants under 18, we will only collect and process their personal data with the verified consent of a parent or legal guardian, and with appropriate safeguards, in line with applicable data protection law.

Changes to this policy


We may update this policy from time to time. Where changes are significant, we will notify you by email or through our platform. The "last updated" date at the top shows when this policy was last revised.

Contact us


If you have any questions about this privacy policy or our privacy practices, please contact our data protection officer via email at team@myora.health.

For any further queries, our data protection officer, may be reached at the following address:

Myora Ltd

Company No. 16694154 (registered in England and Wales)

Registered office: 128 City Road, London, EC1V 2NX, United Kingdom