Privacy Policy

Privacy Policy

Last updated: 16 June 2026

This Privacy Policy explains how personal information is handled in the Nexus application and related services (the “Platform”), which is provided by Blüm Health (“Blüm”). It is written to help you understand who is responsible for your data and how it is protected.

1. Who is responsible for your data

Nexus is a multi-organisation platform. The healthcare organisation you are registered with — for example an NHS trust or clinic (your “Organisation”) — decides what data is collected and why.

  • Your Organisation is the data controller for your personal and health information. It is responsible for the lawful basis for processing your data, for the Content it publishes, and for responding to your data protection requests. Your Organisation may also publish its own privacy notice, which applies alongside this policy.
  • Blüm is the data processor. We process data only on your Organisation’s documented instructions to operate and support the Platform. We do not use your personal or health data for our own purposes.

If you want to exercise your data protection rights (see section 7), please contact your Organisation, as the controller.

2. Information we process

On behalf of your Organisation, the Platform processes:

  • Account information — name, email address, phone number, date of birth, and (where collected by your Organisation) identifiers such as an NHS number.
  • Health and care information — responses to forms, questionnaires, and trackers; onboarding answers; and other information you or your care team record.
  • Communications — messages between you and your care team, and any files or images you attach.
  • Community content — posts, comments, and reactions, where your Organisation enables community features (including content you choose to post anonymously).
  • Usage analytics — only where you have given consent, anonymous app-usage data used to improve the Platform. This contains no health data or personal details.
  • Technical data — device and app information, and push-notification tokens used to deliver notifications.

3. How and why your data is used

Your data is used, on your Organisation’s instructions, to:

  • provide the Platform and the services your Organisation offers through it;
  • enable communication between you and your care team;
  • deliver content and recommendations relevant to you;
  • maintain security, prevent misuse, and meet legal and regulatory obligations; and
  • improve the Platform, using anonymous analytics only where you have consented.

4. Lawful basis

The lawful basis for processing your personal and special-category (health) data is determined by your Organisation as controller — typically the provision of healthcare and related public-interest/legal grounds under the UK GDPR and Data Protection Act 2018, and consent for optional usage analytics. Your Organisation can tell you the specific basis it relies on.

5. Storage, security, and where your data is held

  • Data is stored using encryption in transit and at rest, with role-based access controls so that information is only available to those who need it.
  • Access within an Organisation is limited to your designated care team and authorised administrators.
  • Blüm applies industry-standard organisational and technical security measures and complies with UK data protection law, including the UK GDPR and Data Protection Act 2018.

6. Service providers (sub-processors)

Blüm uses a small number of trusted service providers to run the Platform, under contracts that require them to protect your data and process it only as instructed. These currently include providers for: application hosting and database, authentication, file storage, real-time messaging, push notifications, transactional email, and (with consent) anonymous analytics.

  • We do not sell your personal data.
  • Your health information is shared only with your designated care team within the Organisation you are registered with, and with the sub-processors strictly necessary to operate the Platform.
  • An up-to-date list of sub-processors is maintained by Blüm and available to your Organisation on request. (Blüm to maintain the definitive list and processing locations.)

7. Your rights

Under the UK GDPR you have rights to access, rectify, erase, restrict, and object to processing of your personal data, and to data portability. Because your Organisation is the controller, please direct any such request to your Organisation or care team. You also have the right to complain to the Information Commissioner’s Office (ICO).

8. International transfers

Where any processing or storage takes place outside the UK, it is carried out with appropriate safeguards as required by UK data protection law. (Blüm and your Organisation to confirm processing locations and safeguards.)

9. Data retention

Your data is retained for as long as your account is active and as required to provide your care, and thereafter in line with your Organisation’s instructions and applicable healthcare-records retention requirements. Your Organisation determines the specific retention periods.

10. Analytics and cookies

The Platform uses essential cookies/local storage needed for sign-in and security. Optional usage analytics are collected only if you opt in, and you can change this at any time in the app’s settings. Analytics data is anonymous and excludes health information and personal details.

11. Children

Where an Organisation provides services to people under 18, the Organisation is responsible for ensuring an appropriate lawful basis and any required consents are in place.

12. Changes to this policy

We may update this policy from time to time. Where changes are material, we will take reasonable steps to make them available to you.

13. Contact

For questions about how your data is handled, or to exercise your rights, contact your Organisation (the data controller) or its Data Protection Officer. For questions about the Platform itself, contact Blüm Health at [Blüm data protection contact — e.g. privacy@blumhealth.co.uk].


This Privacy Policy is a draft prepared for review. It must be reviewed and approved by Blüm’s legal counsel / Data Protection Officer, the sub-processor list and processing locations confirmed, and bracketed items completed, before it is relied upon.