For patient registration and for the care we provide
This notice explains what we do with your personal data once you register as a patient — what we collect, why, who else sees it, how long we keep it and what you can ask us to do. It is deliberately separate from the notice that covers the website, because registering as a patient means giving us far more, and more sensitive, data.
1. Who is the controller, and who else is involved
The controller is:
MicroBiome Bank Ltd.
2 Brandon Road
Braintree, Essex, CM7 2NL
England
Company number 13656497
Email: privacy@microbiomebank.com
MicroBiome Bank Ltd. is the party you contract with. MicroBiome Bank Kft. (1118 Budapest, Ménesi út 104., company number 13-09-189941) provides the Hungarian care and the laboratory work, and acts as our processor for that purpose, on our documented instructions. Where care is delivered in Hungary, Hungarian healthcare law applies to the medical documentation created about you — see section 6.
2. What we collect at registration
Identification data: family name, given name, sex, date and place of birth, mother's name.
Social security number (TAJ). We ask for it because care delivered in Hungary has to be documented against a healthcare identifier.
Contact and address data: email address, telephone number, street address, city, postcode, country, preferred language.
Health data: the condition you register with, the programme you join, and everything that arises during care — the compatibility test result, LOT numbers, the symptom diary, your treating physician's instructions, and our correspondence about your treatment. This is a special category of personal data under Article 9 of the GDPR.
Your patient identifier, which we generate so that your samples and capsules can be traced without your name travelling with them.
Payment data, where you place an order.
3. Where the data comes from
Mostly from you, through the registration form and in the course of your care. We also receive data from your treating physician and from laboratories involved in your treatment, and we may receive or send data to public health authorities where the law requires it.
4. Why we process it, and on what legal basis
Registering you and performing the service. Legal basis: performance of a contract (Article 6(1)(b)).
Delivering care and documenting it. Legal basis for the health data: Article 9(2)(h) — processing necessary for the provision of health care, carried out under the responsibility of a health professional bound by professional secrecy. Where a specific step goes beyond that, we ask for your explicit consent (Article 9(2)(a)) and tell you so at the time.
Traceability of the product you receive. Every batch is traceable by LOT number, so that if a safety question ever arises we can identify who received what. Legal basis: legal obligation (Article 6(1)(c)) and our legitimate interest in patient safety (Article 6(1)(f)).
Meeting legal, accounting and tax obligations. Legal basis: Article 6(1)(c).
Answering your questions and keeping you informed about your own treatment. Legal basis: Article 6(1)(b).
We do not use patient data for marketing unless you have separately consented, and we do not profile patients or take decisions about them by automated means.
5. Who we share it with
MicroBiome Bank Kft. — as our processor, for the Hungarian care and the laboratory work.
Your treating physician, and other healthcare providers involved in your care.
Laboratories carrying out the analyses.
Zapier Inc. and monday.com Ltd. — our form relay and case-handling systems. A registration submitted through the website reaches our team this way. Both act as processors.
Stripe Payments Europe, Ltd. — card payments. Card details go to Stripe, not to our server.
Regulatory and public health authorities, where the law requires it.
IT and hosting providers, as processors.
We do not sell patient data, and we do not share it with advertisers.
6. How long we keep it
Medical documentation: 30 years from the date it was created, and discharge summaries 50 years, in line with the Hungarian healthcare data legislation that applies to the care delivered in Hungary. This is a legal obligation — we cannot delete this documentation on request before the period expires.
Accounting and tax records: for the period required by the applicable accounting rules.
Registration data that never led to care: deleted after 12 months, like any other enquiry.
Data processed on the basis of consent: until you withdraw that consent, unless one of the periods above applies.
7. International transfers
Some of the processors named above are established outside the European Economic Area and the United Kingdom, or process data there. Where that happens we rely on the safeguards permitted by data protection law — principally the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, and an adequacy decision where one applies. Ask us and we will tell you which safeguard applies in a given case.
8. Security and professional secrecy
Your treatment data is covered by medical professional secrecy. On top of that we apply technical and organisational measures: encryption in transit, access control so that only staff involved in your care can see your record, LOT-level traceability that does not require your name to travel with the product, and protection of our forms against automated abuse.
9. Your rights
You have the right to:
Access your data and your medical documentation, and receive a copy.
Rectify inaccurate or incomplete data. Note that a correction to medical documentation is recorded alongside the original entry rather than overwriting it — that is how medical records work.
Erasure, subject to the retention periods in section 6. We cannot delete documentation the law requires us to keep.
Restrict processing.
Portability — receive your data in a structured, commonly used, machine-readable format.
Object to processing based on our legitimate interests.
Withdraw consent where processing is based on consent. This does not affect what was lawfully done beforehand, and it does not remove documentation we must keep.
Complain to a supervisory authority (Article 77). In the United Kingdom this is the Information Commissioner's Office (ico.org.uk); in Hungary the Nemzeti Adatvédelmi és Információszabadság Hatóság (naih.hu). You may also complain to the authority where you live.
Where the patient is a child, the parent or legal guardian registers on their behalf and exercises these rights for them, until the child is old enough to do so themselves. We ask for a child's data only to the extent the care requires it, and we do not use it for marketing or profiling.
11. Changes to this notice
We may update this notice. Any change is published on this page with a new "Last updated" date, and we will tell you directly if a change materially affects how we use your data.