Privacy Policy
Effective date: 14 July 2026 Last updated: 14 July 2026
1. Who we are
Remy is a healthcare CRM operated by Armada Labs Studio Ltd ("Remy", "we", "us"), a company registered in England and Wales (company number 16782069) with registered office at 45 Colebrooke Avenue, London, England, W13 8JZ, United Kingdom.
We are registered with the UK Information Commissioner's Office (ICO) under registration number ZC143978.
For any privacy question, or to exercise your rights, contact our data protection team at privacy@remy.health (or write to us at the address above, marked "Data Protection").
2. Which "hat" we are wearing
Remy plays two roles under data protection law, and this policy is mainly about the first:
- As a controller — for the personal data of our website visitors and the staff who create and use Remy accounts (for example, their name, work email, and billing details). This policy explains that processing.
- As a processor — for patient and practice data that our customers (the healthcare practices) put into Remy. There, the practice is the controller and decides how the data is used; we only process it on their instructions under a Data Processing Agreement. If you are a patient of a practice that uses Remy, please contact that practice about your data in the first instance; we will assist them as their processor.
3. The personal data we collect (as a controller)
| Category | Examples | Source |
|---|---|---|
| Account data | Name, work email, role, organisation, password/credentials | You, or your practice admin |
| Contact & profile | Phone number, avatar, address (staff profiles) | You |
| Billing data | Subscription plan, billing contact, card details (held by our payment processor), invoices | You / Stripe |
| Usage & device data | Log-ins, feature usage, IP address, browser/device, cookies | Automatically |
| Communications | Support requests, emails and messages you send us | You |
| Marketing data | Email, preferences, engagement with our emails (if you opt in) | You |
We do not seek to collect special category data about you as a website visitor or account holder. (Health data belonging to patients is processed under our processor role — see section 2 and the DPA.)
4. Why we process it, and our lawful basis
| Purpose | Lawful basis (UK GDPR Art 6) |
|---|---|
| Provide, operate and secure the Remy service to your practice | Performance of a contract |
| Authenticate users and manage accounts | Performance of a contract |
| Take payment and manage subscriptions | Performance of a contract |
| Support, service messages and important notices | Legitimate interests (running the service) / contract |
| Improve, troubleshoot and secure the platform; prevent fraud/abuse | Legitimate interests (a secure, working product) |
| Marketing emails about Remy | Consent, or soft opt-in legitimate interests where permitted — always with an unsubscribe |
| Comply with legal and regulatory obligations | Legal obligation |
Where we rely on legitimate interests, we have balanced those interests against your rights and can provide our assessment on request.
5. Cookies and analytics
We use cookies and similar technologies. Non-essential cookies are only set with your consent. See our Cookie Policy for the full list and to change your preferences at any time.
6. Who we share it with
We share personal data with trusted service providers ("sub-processors") who help us run Remy — for example hosting, communications, payments and analytics. Each is bound by a contract that requires appropriate security and permits them to use the data only to provide their service to us. Our current list, including what each does and where it processes data, is published at /legal/subprocessors.
We may also disclose data where required by law, to protect our rights, or in connection with a business sale or reorganisation (with appropriate safeguards).
We do not sell your personal data.
7. International transfers
Some of our sub-processors process data outside the UK/EEA (for example in the United States). Where they do, we rely on an appropriate safeguard — the UK Addendum to the EU Standard Contractual Clauses (SCCs) and/or the provider's certification under the EU-US Data Privacy Framework (and UK extension) — so your data receives an equivalent level of protection. Details of each provider's location and safeguard are in the Sub-processor list.
8. How long we keep it
We keep personal data only as long as necessary for the purposes above:
- Account data — for the life of your account and up to 90 days after closure, unless we must keep it longer.
- Billing and transaction records — 6 years to meet tax/accounting law.
- Support communications — up to 24 months.
- Marketing data — until you unsubscribe, then suppressed to honour your choice.
- Logs and usage data — up to 12 months.
When no longer needed, data is securely deleted or anonymised.
9. How we protect it
We use technical and organisational measures appropriate to the risk, including encryption in transit and at rest, role-based and row-level access controls, UK/EU data hosting for core systems, audit logging, and staff access on a need-to-know basis. See our Security page for more.
10. Your rights
Under UK GDPR you have the right to: access your data; have it corrected; have it erased; restrict or object to processing; data portability; and to withdraw consent at any time (without affecting prior processing). You also have the right to complain to the ICO (ico.org.uk), though we'd appreciate the chance to help first.
To exercise any right, contact privacy@remy.health. We will respond within one month. If your request concerns patient data held in a practice's account, we will direct it to that practice as the controller.
11. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Some product features use AI (e.g. to transcribe or summarise calls) but these support, and do not replace, human judgement.
12. Changes to this policy
We may update this policy from time to time. We will post the new version here with a revised "Last updated" date and, for material changes, notify account holders directly.
13. Contact
Armada Labs Studio Ltd, 45 Colebrooke Avenue, London, England, W13 8JZ, United Kingdom Data protection: privacy@remy.health ICO registration: ZC143978