SmartPDT Privacy Policy

We are siHealth Ltd.

We are a digital healthcare company based in Harwell Campus, Oxfordshire, United Kingdom ( Our address is Building R104, Rutherford Appleton Laboratory, Harwell Campus, Didcot, Oxfordshire, United Kingdom and our company registration number is 9176652. We are registered with the UK Information Commissioner’s Office (ICO) with number ZA834797.

siHealth is a company of the Flyby Group (the ”group”), a corporate group controlled by Flyby S.r.l. ( – Livorno, Italy). The group operates worldwide, providing digital systems and services for supporting human decision-making in different sectors, such as Space, Energy, Security and Health & Wellness. s

iHealth has a direct subsidiary inside the group, siHealth Photonics S.r.l. ( . – Livorno, Italy). siHealth Photonics develops digital innovations for healthcare, with particular focus on the smart management of medical conditions through Image Processing and Artificial Intelligence techniques.

The siHealth’s SmartPDT solution (“SmartPDT” or the “solution” or the “service”) is composed by the SmartPDT-D Web-Portal (the “Web-Portal”) for healthcare professionals and the SmartPDT-P App (the “App”) for patients. The SmartPDT solution is provided by siHealth who is the only responsible for the processing of your personal data (“Controller”) in accordance with the General Data Protection Regulation (“GDPR”) and any Data Protection laws applicable.

We do update this Policy from time to time, so please do review this Policy regularly. You can access this Privacy Policy at any time at


Our App is designed to enable you, the patient, to share data (including photographs and videos) and progress of your medical treatment with your healthcare professional, in a way that respects your privacy. Before you can use our App:

1. Your healthcare professional will need to create and share your login details with you, which will include your User ID.

2. You will be asked to provide 4 different consents. You are under no obligation to provide any of these consents and you can withdraw any of them at any time. But as explained on the registration page, you need at least to provide your consent to your data being shared for the purpose of providing the treatment (“medical records”) and of monitoring/improving the service (“service quality”) before you can use our App.

  • A record of your consent
  • Your login details (your User ID and an/or encrypted version of your Password)
  • Photographs and videos you take which you add to the App for your healthcare professional
  • Your approximate location and data collected by the sensors of your mobile device (e.g. GPS). This is to ascertain the approximate light levels where you are receiving treatment and will have a random radius added to enhance your privacy
  • Information you add to the App related to your skin features and treatment
  • Environment type (e.g. park, beach), clothes, indoor/outdoor.

The lawful basis to process your personal data is your explicit consent, in accordance with Art. 6 Par. 1 of the GDPR. We do not know your name, address or other contact details. Your healthcare provider has their own independent records enabling them to link your User ID to your contact details, but we cannot make this link. Some of these information (e.g. type and nature of your skin) constitutes a special category of personal data in accordance with Article 9 of the GDPR. The data processing of the personal data is carried out in compliance with the provisions of the GDPR and other relevant laws.


If you are a healthcare professional using our web-portal to assist with your patients’ treatment, then we will collect your registration information as well as the data about patients and patients’ treatments, using it in accordance with the services contract in place between us. The only other data we collect from visitors using the SmartPDT web-portal ( is via the cookies we use. We use the following cookies on our web-portal:

Cookie provider Cookie name Purpose of the Cookie Duration
siHealth Ltd user This is to verify the signed-in user Expires as soon as user signs out of the system or when user session expires


You have various other rights under applicable data protection laws, including the right to:

  • Access your personal data (also known as a “subject access request”);
  • Correct incomplete or inaccurate data we hold about you;
  • Ask us to erase the personal data we hold about you;
  • Ask us to restrict our handling of your personal data;
  • Ask us to transfer your personal data to a third party
  • Object to how we are using your personal data;
  • Withdraw your consent to us handling your personal data.

You can exercise any of these rights by contacting us. You also have the right to lodge a complaint with us or the Information Commissioner’s Office, the supervisory authority for data protection issues in England and Wales. If you are based outside of England and Wales, you can find your relevant supervisory authority here. Please keep in mind that privacy law is complicated, and these rights will not always be available to you all of the time.


We securely store your personal data in Amazon Web Services (AWS) and Microsoft Azure cloud data centres within:

  • United Kingdom (UK)
  • European Union (EU)
  • United States (US)
  • Brazil
  • South Korea
  • South Africa
  • Brazil


If you withdraw your consent or delete your account with us, we will delete the personal data that we hold about you in the service. If you haven’t used our service for 12 months, then we will delete your account. More generally, we will only retain your personal information for as long as we need it and for the purposes we initially collected it for, unless we are required to keep it for longer to comply with our legal, accounting or regulatory requirements. We also carefully anonymise your personal data so that it can no longer be associated with you, and we use this anonymised data for purposes including research and development, commercialisation, improving outcomes for patients and developing medical treatments. In addition to this, we perform research & development activities for improving the siHealth’s services also by using some of your personal data in pseudonymised way, that are anyway deleted by 12 months since the deletion of your account or your withdrawal of the consent to do so.


According to Art. 37 of the General Data Protection Regulation (GDPR), siHealth has a Data Protection Officer (DPO) which is appointed for the entire corporate group siHealth belongs to (Flyby Group, Italy – Considering that the protection of personal data is of the outmost importance for siHealth, for any questions or to exercise any data subject’s right the following DPO’s e-mail address is available: .


  • Flyby Group: data analytics and research & development activities aimed to help us and the companies in our group for the improvement and optimisation of our services
  • Analytics and web development companies: to help us with the improvement and optimisation of our services. Our service can include analytics like Google Firebase, which we only use to improve the quality and usability of our service.
  • Regulators/ Authorities/ Enforcement Agencies: if we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or in order to enforce or apply our terms of use and other agreements; or to protect the rights, property, or safety of our clients or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection.
  • Prospective buyers of our business: under our legitimate interest to ensure our business can be continued by the buyer.


Your feedback and suggestions on this notice are welcome. We’ve worked hard to create a notice that’s easy to read and clear. But if you feel that we have overlooked an important perspective or used language which you think we could improve, please let us know by email at

For EU-based customers and contacts who have any questions about siHealth’s services and products or about anything related to data protection (GDPR), please contact siHealth Photonics S.r.l., who are siHealth’s representative in the European Union:

  • Address: siHealth Photonics S.r.l., Via A. Lampredi 45, Livorno – 57121, Italy
  • Telephone : +39 0586 090733
  • E-mail:

Last updated on 15th February 2024