How VaxiGo collects, uses, stores, and shares your personal data when you use our website and vaccination booking services, and your rights under UK GDPR.
VaxiGo Ltd (company number 17192717) · Registered office: 1 Chidden Holt, Chandler’s Ford, Eastleigh, SO53 4RJ, England
Registered with the ICO under registration number ZC177441.
Data Protection Officer: dpo@vaxigo.co.uk · General enquiries: support@vaxigo.co.uk
This Privacy Policy explains how VaxiGo Ltd (company number 17192717), whose registered office is at 1 Chidden Holt, Chandler’s Ford, Eastleigh, SO53 4RJ, England (“we”, “us”, “our”, or “VaxiGo”), collects, uses, stores, and shares your personal data when you use our website at vaxigo.co.uk and our vaccination booking services.
VaxiGo is the data controller for the personal data described in this Privacy Policy, except where we act as joint controller with healthcare providers as described in Section 13. We are registered with the Information Commissioner’s Office (ICO) under registration number ZC177441.
We collect personal data in the following ways:
We collect seven categories of personal data. The specific data fields within each category are set out below.
At the time of booking, we ask you three short health questions so that they can be relayed to your chosen healthcare provider for clinical safety screening. These three items constitute special category health data under Article 9 of UK GDPR. The three questions are:
We do not store your answers to these three questions. They are relayed to your provider in real time and no copy is kept by VaxiGo.
Important: VaxiGo does NOT store full payment card details. All card data is processed directly by Stripe Technology Europe Limited through their secure payment interface. VaxiGo only receives a payment reference and confirmation of the card type used.
We only process your personal data where we have a lawful basis to do so under UK GDPR. The legal bases we rely on depend on the category of data and the purpose of processing.
A Legitimate Interests Assessment has been conducted and is available on request by contacting dpo@vaxigo.co.uk.
Your answers to the three health questions asked at booking (pregnancy status, previous vaccination history, and known allergies) constitute special category health data under Article 9 of UK GDPR and require an additional legal basis for processing. Although VaxiGo does not store this information and only relays it to your provider in real time, relaying is itself a form of processing, so an Article 9 condition is required.
Explicit consent (Article 9(2)(a)): At the time of booking, you are asked to give explicit consent for VaxiGo to relay your answers to the three health questions to your chosen healthcare provider. Explicit consent under Article 9(2)(a) is the sole condition we rely on for this processing. Your explicit consent is recorded with a timestamp in our systems.
We share your personal data with the following categories of recipients. We do not sell, rent, or trade your personal data for marketing or commercial purposes.
We share your booking details, name, contact information, and your answers to the three booking-time health questions with the healthcare provider you have selected. This sharing is necessary so that the provider can fulfil your booking and deliver your vaccination safely, using the three health question answers for clinical safety screening. VaxiGo and the relevant healthcare provider act as joint controllers under Article 26 of UK GDPR in respect of the shared booking dataset and the three booking-time health questions (see Section 13).
Stripe processes Platform Fee payments on our behalf. Stripe is an Electronic Money Institution authorised by the Central Bank of Ireland (reference C187865) and regulated by the Financial Conduct Authority in the UK. Stripe acts as a data processor under Article 28 of UK GDPR, and we have a Data Processing Agreement in place. We share your payment transaction data and booking reference with Stripe; full card details are entered by you directly into Stripe’s secure interface and are not shared by VaxiGo.
Supabase provides our database hosting service (PostgreSQL), hosted in Supabase’s eu-west-2 region (London, UK). Supabase acts as a data processor under Article 28, and we have a Data Processing Agreement in place. Supabase hosts your account data, booking records, and consent records. The three booking-time health questions are never stored by VaxiGo and are not hosted in Supabase. Supabase’s US parent company staff may have residual access to infrastructure for support and maintenance, governed by the DPA and the transfer safeguards described in Section 7.
Vercel provides web hosting and CDN services, hosted in Vercel’s lhr1 region (London, UK). Vercel acts as a data processor under Article 28, and we have a Data Processing Agreement in place. Vercel’s US parent company staff may have residual access to infrastructure for support and maintenance, governed by the DPA and the transfer safeguards described in Section 7.
Resend provides our transactional email delivery service and acts as a data processor under Article 28, with a Data Processing Agreement in place. We share your email address, name, booking reference, and transactional content with Resend to send booking confirmations, appointment reminders, account notifications, and complaint acknowledgements. Resend is headquartered in the United States; data may be processed on US-based infrastructure, governed by Resend’s DPA and the transfer safeguards described in Section 7.
GoDaddy provides business email hosting for our support@, complaints@, and dpo@vaxigo.co.uk addresses, and acts as a data processor under Article 28 with a Data Processing Agreement in place. GoDaddy is headquartered in the United States, and email data may be subject to US jurisdiction; VaxiGo relies on GoDaddy’s DPA and the standard contractual transfer safeguards described in Section 7.
We use Google Maps to display provider locations and enable location-based search. When you use map features, your IP address and approximate location (if location services are enabled) are transmitted to Google LLC, which acts as an independent data controller under its own terms. VaxiGo does not control how Google processes this data — see Google’s Privacy Policy. Google LLC is headquartered in the United States; see Section 7.
We may share your personal data with legal or regulatory authorities where required by law, including in response to ICO requests, court orders, or law enforcement requests. The legal basis for such sharing is Article 6(1)(c) (legal obligation).
VaxiGo does not sell, rent, or trade your personal data to any third party for marketing or commercial purposes.
We aim to keep your personal data within the United Kingdom wherever possible. Our database and hosting infrastructure are located in the UK — Supabase in eu-west-2 (London) and Vercel in lhr1 (London).
Some processors have US parent entities whose staff may have residual access to UK-hosted infrastructure for support and maintenance, and GoDaddy, Resend and Google LLC may process certain data on US infrastructure. Stripe Technology Europe Limited processes payments within the EEA and UK under its own regulatory framework as an authorised Electronic Money Institution. We do not make any other intentional international transfers of your personal data.
Where personal data is transferred outside the UK in respect of these processors’ US parent company access, we and those providers rely on appropriate safeguards. Specifically, we rely on the UK Extension to the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on the UK International Data Transfer Agreement (IDTA) or the International Data Transfer Addendum to the EU Standard Contractual Clauses, as set out in each provider’s data processing terms.
Under UK GDPR you have the rights below. To exercise any of them, contact our DPO at dpo@vaxigo.co.uk. We will respond within one calendar month; if your request is complex or numerous, we may extend this by up to two further months and will tell you why within the first month.
You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk or 0303 123 1113. We would appreciate the chance to address your concerns first — please consider contacting dpo@vaxigo.co.uk in the first instance.
We retain your personal data only for as long as necessary for the purposes for which it was collected, or as required by law. Where a statutory period is longer than our general default (5 years from your first login), the statutory period applies.
| Data category | Retention period |
|---|---|
| Booking-time health questions | Not retained — relayed to your provider in real time and never stored by VaxiGo |
| Account data | 5 years from the date of your first login |
| Booking data (non-health) | 7 years from the booking date (Limitation Act 1980 contractual-claims window) |
| Payment records | 7 years from the transaction date (HMRC financial record-keeping) |
| Consent records | 5 years from the date of your first login |
| Communication data | 3 years from the date of the communication (claim duration + 2 years if part of a legal claim) |
| Technical and usage data | 13 months (in line with ICO guidance) |
| Complaint records | 3 years from the date the complaint is resolved |
The three booking-time health questions are never stored on our systems, so there is no VaxiGo retention period for them. Any retention after relay is the responsibility of the healthcare provider under their own privacy policy.
Your answers to the three booking-time health questions constitute special category health data under Article 9 of UK GDPR. Although VaxiGo does not store this information, we apply the following safeguards to the relay of these answers:
Our website uses cookies and similar technologies. For full details of the cookies we use, their purposes, and how to manage your preferences, please see our Cookie Policy. We only use non-essential cookies with your prior consent, obtained through our cookie consent banner when you first visit. You may withdraw your cookie consent at any time via the cookie settings link on our website.
Under Article 26 of UK GDPR, VaxiGo and the healthcare provider you select act as joint controllers in respect of the shared booking dataset and your answers to the three booking-time health questions. Responsibilities are allocated as follows:
VaxiGo is responsible for:
The healthcare provider is responsible for:
You may exercise your rights against either VaxiGo or the healthcare provider, regardless of this allocation. For data held on the VaxiGo platform, contact dpo@vaxigo.co.uk; for clinical records, contact the provider directly. If you are unsure which party to contact, email dpo@vaxigo.co.uk and we will assist you.
The VaxiGo platform is not directed at children under the age of 13. Account creation requires users to be at least 18 years old. Vaccination bookings for minors (persons under 18) must be made by a parent or guardian using their own account. Where a parent or guardian makes a booking on behalf of a minor and answers the three booking-time health questions, they are responsible for the accuracy of the information provided and for giving the explicit consent at booking to relay those answers to the provider on the minor’s behalf.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Where we make material changes, we will notify you by email at least 30 days before they take effect. The current version is always available at vaxigo.co.uk/privacy, and the version number and effective date are shown at the top of this page.
If you have any questions about this Privacy Policy or wish to exercise any of your data protection rights, please contact us:
Data Protection Officer
Email: dpo@vaxigo.co.uk
Post: Data Protection Officer, VaxiGo Ltd, 1 Chidden Holt, Chandler’s Ford, Eastleigh, SO53 4RJ, England
General enquiries: support@vaxigo.co.uk · Complaints: complaints@vaxigo.co.uk
ICO: ico.org.uk · 0303 123 1113