Elixir
Legal

Privacy Policy

Last updated 31 August 2026. This notice replaces the shorter version published on 26 July 2026, which described only a fraction of what we actually collect. Revised the same day to remove three things we had stopped doing: the founding list, the programme question on this site, and holding your height.

Who we are

Elixir is a trading name of Elixir Supplements Ltd (Company No. 17385572), registered in England & Wales, registered office 1 Allied Business Centre, Coldharbour Lane, Harpenden AL5 4UT. We are the data controller for the personal data described here. Email info@elixirnad.com.

If you are unhappy with how we handle your data you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We would rather you told us first, but you do not have to.

The short version

  • If you join a list, we hold your email — and your name, phone number and stated interests if you gave them.
  • We do not add you to our marketing list until you click a confirmation link in an email. Submitting a form is not enough.
  • The eligibility check on the programme page runs entirely in your browser. Your health answers are never sent to us, to a clinic, or to anyone else. We never see them.
  • We hold no health data at all — no conditions, no medicines, no weight, no BMI, no allergies. This is a deliberate design decision, enforced in code.
  • We do not sell personal data, and we do not share it for anyone else’s marketing.

What we collect, and when

1. When you join a list or use a form on this site

The launch-news box, the newsletter box in the footer, and the “notify me” prompt all send the same thing to our CRM: your email address, plus your name and phone number if you gave them. We also record the page you were on, the date and time, and the exact consent wording shown to you, so that we can demonstrate consent if we are ever asked to. We no longer ask on this site whether you would consider a prescriber-supervised programme; that question now sits inside your account, behind its own separate permission, and is described in section 4.

2. When you use the contact form

Your name, email address, the subject you picked, and your message. The message is stored against your contact record in our CRM so that whoever replies can see it. If you tick the optional marketing box, that is recorded separately as its own consent — it is never ticked for you.

3. When you take the eligibility check

Nothing. The questions and the result run in your browser and are discarded when you close the page. No health answer is transmitted to us or to any clinic, and no clinic receives anything about you. If you then choose to leave your name and email so we can tell you when a prescriber partnership opens, only that name and email reach us — never the answers.

The same is true of the BMI calculator in the member area: it does the arithmetic in your browser, shows you the number, and stores nothing.

4. When you create a member account

The member area holds your email address, and your first name, phone number and postcode if you gave them. Signing in uses a one-time code emailed to you rather than a password. Beyond that, everything in your account is there because you put it there:

  • the Elixir pieces you own, with serial numbers and dates if you added them;
  • the supplements, CBD or other non-medicinal items in your routine, and the days you ticked them off;
  • your strap size and the interest tags you picked, if you filled in your profile — we used to hold your height as well, and stopped: it was doing nothing the strap size was not already doing, so the stored values were deleted;
  • which waiting lists you joined, and your answers to a small set of fixed-choice profile questions;
  • your marketing and channel consents, each with the date it changed.

We also keep a security log of account events — sign-in requests, successful and failed sign-ins, consent changes, exports and deletions — and a coarse record of the device and network your sessions were opened from, so that you can recognise your own sessions.

What the member area deliberately does not hold: height, weight, BMI, waist or any body measurement, blood pressure, glucose or any physiological reading, medicines, conditions, allergies, diagnoses or appointments. The database rejects those fields outright. If that ever changes, it will only be after a data protection impact assessment, with separate explicit consent and encryption, and this notice will say so before it happens.

5. Automatically, when you visit

Our host processes your IP address and request details to serve the site and keep it secure, and we use Cloudflare Web Analytics, which counts page views without cookies and without tracking you across sites. Your browser fetches our typefaces from Google Fonts, which discloses your IP address to Google. Your browser also keeps a small offline cache of the site, and if a form submission fails to reach us it is held in your own browser’s local storage so it is not lost — that copy stays on your device and is never read by us.

We do not currently run Google Analytics, the Meta pixel, or any advertising tag. If we ever switch one on, it will load only after you have chosen “Accept all” in the cookie banner, and this notice will be updated first.

Why we are allowed to hold it

WhatWhy we hold itLawful basis (UK GDPR Art 6)
Marketing emailsTo send you the launch and weekly emails you asked forConsent — Art 6(1)(a), plus PECR reg 22
Evidence of your consentSo we can show when and how you agreedLegal obligation — Art 6(1)(c), Art 7(1)
Answering your messageTo reply to an enquiry you sent usLegitimate interests — Art 6(1)(f): responding to someone who contacted us
Your member accountTo run the account you asked us to createContract — Art 6(1)(b)
Security logs, rate limiting, anti-bot checksTo keep accounts and the site safeLegitimate interests — Art 6(1)(f): security
How you use your member accountTo improve the app and make what we show you relevantLegitimate interests — Art 6(1)(f): improving a service you asked for. You can object at any time in Settings, and we stop.
Site analytics without cookiesTo see which pages are readLegitimate interests — Art 6(1)(f): understanding our own site

Where we rely on legitimate interests you can object at any time, and we will stop unless we have a compelling reason not to. Where we rely on consent you can withdraw it at any time, and withdrawing it is as easy as giving it.

How marketing consent actually works here

Under PECR reg 22 we may only send you marketing email if you have consented. We take that literally:

  • No box on this site is ticked for you. If a marketing box is offered alongside something else, you tick it or it stays unticked.
  • Submitting a form does not subscribe you. It records an intention, and we email you a confirmation link.
  • You are only added to the list when you click that link. If you never click it, the sign-up is cancelled after 30 days — the record is switched off for marketing immediately and deleted at our next monthly clean-up.
  • Every marketing email carries an unsubscribe link that works in one click, and we act on it immediately.

Enquiries are not marketing. Using the contact form, or leaving your details on the programme page, does not put you on the list — only the separate, unticked box does.

How your account activity is used

If you have an Elixir account, we keep a record of how you use it: when you sign in, which screens you open, when you tick something off your routine, which pieces of kit you register, and which lists you join. We use it for two things — working out which parts of the app are worth building on, and making what we show you relevant rather than generic.

What we do not record. We never record anything you type. Not the names you give things in your routine, and not what you ask Ask Elixir — that is matched on your own device and never reaches us at all. Nothing you told us about the supervised programmes is ever used this way; it sits in its own place, under its own permission. And nothing you told us about your diet is used to decide what to advertise to you, because working backwards from that to a conclusion about your body is not something a shop should be doing.

Where it goes. Nowhere. It is recorded on our own servers, against your own account. No advertising network, analytics company or data broker is given any of it, and there are no tracking scripts in the member area — which is also why you have never seen a cookie banner there. The only cookie the account uses is the one that keeps you signed in.

Turning it off. Settings, under “How this app is improved”. Turn it off and we stop recording, and we delete what has already been collected. Nothing else about your account changes. You have an absolute right to object to processing for direct marketing (Art 21), so this is a switch rather than a request — we do not weigh it against our own interests.

How long we keep it. Thirteen months, then it is deleted automatically. It is included in your data download, and it is deleted with your account.

Who else sees it

We do not sell personal data and we do not share it for anyone else’s marketing. We use a small number of suppliers who process data on our instructions, under contract:

SupplierWhat they do for usWhere
Cloudflare, Inc.Hosts the website and member area, stores the member database, provides cookieless analytics and anti-bot checksUS company; data processed in its global network including the UK/EU
HighLevel Inc. (GoHighLevel / LeadConnector)Our CRM — holds contact records, tags, consent notes and contact-form messages, and sends marketing emailUnited States
Resend, Inc.Sends account emails such as sign-in codesUnited States
Google (Google Fonts)Delivers the typefaces; receives your IP address as part of that requestIreland / United States

We will also disclose data where the law requires it, and if the business is ever sold the buyer would receive it on the same terms.

Sending data outside the UK

Some of those suppliers are based in the United States. Where personal data is transferred outside the UK we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or on UK adequacy regulations where they apply, together with the supplier’s own security commitments. You can ask us for details of the safeguards used for any particular supplier.

How long we keep it

WhatHow long
Sign-ups that were never confirmedCancelled at 30 days; deleted at the next monthly clean-up
Marketing contactsUntil you unsubscribe, and then deleted after two years of no activity
Evidence of consentTwo years after that consent ends
Contact-form enquiriesTwo years from your last message
Member accounts and their contentsWhile the account is open; deleted within 30 days of you asking us to close it
One-time sign-in codes10 minutes
Sign-in sessions30 days
Account activity records13 months, then deleted — or immediately, if you turn it off
Account security log12 months
Host and security logsAs set by Cloudflare’s own retention periods

Your rights

Under UK GDPR you can ask us for a copy of your data, to correct it, to delete it, to restrict or object to what we do with it, and to receive it in a portable form. Where we rely on consent you can withdraw it. You can exercise any of these by emailing info@elixirnad.com, and members can export or delete an account from within the member area. We will respond within one month. There is no charge, and we will not treat you differently for asking.

Cookies and similar technologies

Essential cookies keep the site and your sign-in working — a session cookie for the member area, a cookie remembering your cookie choice, and Cloudflare’s security cookies. These do not need consent because the site cannot work without them. Anything else loads only if you choose “Accept all”. You can change your mind at any time via cookie settings. Our analytics uses no cookies at all.

Children

This site and the member area are for adults. We do not knowingly collect data from anyone under 18, and accounts are 18+ only. If you believe a child has given us their details, email us and we will delete them.

Elixir Health: your blood test results

If you have an Elixir Health test and you choose to keep the results in your account, we hold them: the measurements, the units and reference ranges printed for that test, the day-of-test context you gave us (whether you had eaten; whether it was before midday), the clinician who reviewed the panel, their note, and when it was released and first opened. This is special-category health data. We hold it only with your explicit consent (Article 9(2)(a) UK GDPR), given by a separate tick in your account and recorded with the wording you saw; the clinician's own review sits under their professional duty of confidentiality, not ours. Every value and note is encrypted before it is stored. Results are never used to select marketing, never shared with our marketing systems, and never passed to a clinic or any third party; the only message we send about them is a service email saying they are ready, which carries no results. You can delete any result, or withdraw the consent — which deletes them all — from your account at any time, and they are included in your data export.

Your results never reach our marketing system, our analytics, or any third party. They are never used to decide what you are shown or sent. The only message you will receive about a retest is a reminder of an appointment you booked yourself. Employer-paid testing produces aggregate figures with a suppression floor; an employer never sees an individual result. You can export or delete everything, behind fresh re-authentication, from your account.

The clinic finder

When you use our trusted clinic pages and click through to book, call or get directions, we record the clinic, the action, the time, and — if you searched by postcode — its outward part only (for example CM1). We do not record your name, your IP address or your device. A daily hash lets us count unique clicks and cannot be reversed. We use this to show each clinic what we send them. No cookie is set and no consent banner is needed for it.

Changes to this notice

If we change what we collect or why, we will update this page and change the date at the top. Where the change is significant — particularly anything that would mean holding health data — we will tell people on the list before it takes effect, not after.