Privacy Policy

Effective date: 14 July 2026 Last updated: 14 July 2026

1. Who we are

Remy is a healthcare CRM operated by Armada Labs Studio Ltd ("Remy", "we", "us"), a company registered in England and Wales (company number 16782069) with registered office at 45 Colebrooke Avenue, London, England, W13 8JZ, United Kingdom.

We are registered with the UK Information Commissioner's Office (ICO) under registration number ZC143978.

For any privacy question, or to exercise your rights, contact our data protection team at privacy@remy.health (or write to us at the address above, marked "Data Protection").

2. Which "hat" we are wearing

Remy plays two roles under data protection law, and this policy is mainly about the first:

  • As a controller — for the personal data of our website visitors and the staff who create and use Remy accounts (for example, their name, work email, and billing details). This policy explains that processing.
  • As a processor — for patient and practice data that our customers (the healthcare practices) put into Remy. There, the practice is the controller and decides how the data is used; we only process it on their instructions under a Data Processing Agreement. If you are a patient of a practice that uses Remy, please contact that practice about your data in the first instance; we will assist them as their processor.

3. The personal data we collect (as a controller)

CategoryExamplesSource
Account dataName, work email, role, organisation, password/credentialsYou, or your practice admin
Contact & profilePhone number, avatar, address (staff profiles)You
Billing dataSubscription plan, billing contact, card details (held by our payment processor), invoicesYou / Stripe
Usage & device dataLog-ins, feature usage, IP address, browser/device, cookiesAutomatically
CommunicationsSupport requests, emails and messages you send usYou
Marketing dataEmail, preferences, engagement with our emails (if you opt in)You

We do not seek to collect special category data about you as a website visitor or account holder. (Health data belonging to patients is processed under our processor role — see section 2 and the DPA.)

4. Why we process it, and our lawful basis

PurposeLawful basis (UK GDPR Art 6)
Provide, operate and secure the Remy service to your practicePerformance of a contract
Authenticate users and manage accountsPerformance of a contract
Take payment and manage subscriptionsPerformance of a contract
Support, service messages and important noticesLegitimate interests (running the service) / contract
Improve, troubleshoot and secure the platform; prevent fraud/abuseLegitimate interests (a secure, working product)
Marketing emails about RemyConsent, or soft opt-in legitimate interests where permitted — always with an unsubscribe
Comply with legal and regulatory obligationsLegal obligation

Where we rely on legitimate interests, we have balanced those interests against your rights and can provide our assessment on request.

5. Cookies and analytics

We use cookies and similar technologies. Non-essential cookies are only set with your consent. See our Cookie Policy for the full list and to change your preferences at any time.

6. Who we share it with

We share personal data with trusted service providers ("sub-processors") who help us run Remy — for example hosting, communications, payments and analytics. Each is bound by a contract that requires appropriate security and permits them to use the data only to provide their service to us. Our current list, including what each does and where it processes data, is published at /legal/subprocessors.

We may also disclose data where required by law, to protect our rights, or in connection with a business sale or reorganisation (with appropriate safeguards).

We do not sell your personal data.

7. International transfers

Some of our sub-processors process data outside the UK/EEA (for example in the United States). Where they do, we rely on an appropriate safeguard — the UK Addendum to the EU Standard Contractual Clauses (SCCs) and/or the provider's certification under the EU-US Data Privacy Framework (and UK extension) — so your data receives an equivalent level of protection. Details of each provider's location and safeguard are in the Sub-processor list.

8. How long we keep it

We keep personal data only as long as necessary for the purposes above:

  • Account data — for the life of your account and up to 90 days after closure, unless we must keep it longer.
  • Billing and transaction records6 years to meet tax/accounting law.
  • Support communications — up to 24 months.
  • Marketing data — until you unsubscribe, then suppressed to honour your choice.
  • Logs and usage data — up to 12 months.

When no longer needed, data is securely deleted or anonymised.

9. How we protect it

We use technical and organisational measures appropriate to the risk, including encryption in transit and at rest, role-based and row-level access controls, UK/EU data hosting for core systems, audit logging, and staff access on a need-to-know basis. See our Security page for more.

10. Your rights

Under UK GDPR you have the right to: access your data; have it corrected; have it erased; restrict or object to processing; data portability; and to withdraw consent at any time (without affecting prior processing). You also have the right to complain to the ICO (ico.org.uk), though we'd appreciate the chance to help first.

To exercise any right, contact privacy@remy.health. We will respond within one month. If your request concerns patient data held in a practice's account, we will direct it to that practice as the controller.

11. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Some product features use AI (e.g. to transcribe or summarise calls) but these support, and do not replace, human judgement.

12. Changes to this policy

We may update this policy from time to time. We will post the new version here with a revised "Last updated" date and, for material changes, notify account holders directly.

13. Contact

Armada Labs Studio Ltd, 45 Colebrooke Avenue, London, England, W13 8JZ, United Kingdom Data protection: privacy@remy.health ICO registration: ZC143978