Privacy policy
This page contains PEAK4's current policies. Select a policy below to jump to the relevant section.
- Store Privacy Policy — how we collect and use your information when you shop with us
- App Privacy Policy — how we handle your data within the PEAK4 mobile application
- Data Protection & Information Security Policy — how PEAK4 protects information across all services
Store Privacy Policy
Last updated: June 23, 2026
PEAK4 Products operates this store and website, including all related information, content, features, tools, products and services, in order to provide you, the customer, with a curated shopping experience (the "Services"). PEAK4 Products is powered by Shopify, which enables us to provide the Services to you. This Privacy Policy describes how we collect, use, and disclose your personal information when you visit, use, or make a purchase or other transaction using the Services or otherwise communicate with us. If there is a conflict between our Terms of Service and this Privacy Policy, this Privacy Policy controls with respect to the collection, processing, and disclosure of your personal information.
Please read this Privacy Policy carefully. By using and accessing any of the Services, you acknowledge that you have read this Privacy Policy and understand the collection, use, and disclosure of your information as described in this Privacy Policy.
Personal Information We Collect or Process
When we use the term "personal information," we are referring to information that identifies or can reasonably be linked to you or another person. Personal information does not include information that is collected anonymously or that has been de-identified so that it cannot identify or be reasonably linked to you. We may collect or process the following categories of personal information, depending on how you interact with the Services, where you live, and as permitted or required by applicable law:
- Contact details including your name, address, billing address, shipping address, phone number, and email address.
- Financial information including credit card, debit card, and financial account numbers, payment card information, transaction details, form of payment and other payment details.
- Account information including your username, password, security questions, preferences and settings.
- Transaction information including the items you view, put in your cart, add to your wishlist, or purchase, return, exchange or cancel, and your past transactions.
- Communications with us including the information you include in communications with us, for example when sending a customer support inquiry.
- Device information including information about your device, browser, or network connection, your IP address, and other unique identifiers.
- Usage information including information regarding your interaction with the Services, including how and when you interact with or navigate the Services.
Personal Information Sources
We may collect personal information from the following sources:
- Directly from you including when you create an account, visit or use the Services, communicate with us, or otherwise provide us with your personal information.
- Automatically through the Services including from your device when you use our products or services or visit our websites, and through the use of cookies and similar technologies.
- From our service providers including when we engage them to enable certain technology and when they collect or process your personal information on our behalf.
- From our partners or other third parties.
How We Use Your Personal Information
Depending on how you interact with us or which of the Services you use, we may use personal information for the following purposes:
- Provide, Tailor, and Improve the Services. We use your personal information to provide you with the Services, including to process your payments, fulfil your orders, remember your preferences, send account notifications, process purchases, returns and exchanges, manage your account, arrange for shipping, and create a customised shopping experience for you.
- Marketing and Advertising. We use your personal information for marketing and promotional purposes, such as to send marketing communications by email, text message or postal mail, and to show you online advertisements on the Services or other websites, including based on items you have previously purchased or added to your cart.
- Security and Fraud Prevention. We use your personal information to authenticate your account, provide a secure payment and shopping experience, detect and investigate possible fraudulent or illegal activity, and secure our services.
- Communicating with You. We use your personal information to provide customer support and maintain our business relationship with you.
- Legal Reasons. We use your personal information to comply with applicable law or respond to valid legal process, and to enforce or investigate potential violations of our terms or policies.
How We Disclose Personal Information
In certain circumstances, we may disclose your personal information to third parties for legitimate purposes subject to this Privacy Policy. Such circumstances may include:
- With Shopify, vendors and other third parties who perform services on our behalf (e.g. IT management, payment processing, data analytics, customer support, cloud storage, fulfilment and shipping).
- With business and marketing partners to provide marketing services and advertise to you. Our business and marketing partners will use your information in accordance with their own privacy notices.
- When you direct, request or otherwise consent to our disclosure of certain information to third parties, such as to ship you products or through your use of social media widgets or login integrations.
- With our affiliates or otherwise within our corporate group.
- In connection with a business transaction such as a merger or bankruptcy, to comply with applicable legal obligations, to enforce applicable terms of service, or to protect or defend the Services and our rights.
Relationship with Shopify
The Services are hosted by Shopify, which collects and processes personal information about your access to and use of the Services in order to provide and improve the Services for you. Information you submit to the Services will be transmitted to and shared with Shopify as well as third parties that may be located in countries other than where you reside. To learn more about how Shopify uses your personal information and any rights you may have, you can visit the Shopify Consumer Privacy Policy. Depending on where you live, you may exercise certain rights with respect to your personal information via the Shopify Privacy Portal.
Third Party Websites and Links
The Services may provide links to websites or other online platforms operated by third parties. We do not guarantee and are not responsible for the privacy or security of such sites, including the accuracy, completeness, or reliability of information found on these sites. Our inclusion of such links does not imply any endorsement of the content on such platforms or of their owners or operators.
Children's Data
The Services are not intended to be used by children, and we do not knowingly collect any personal information about children under the age of majority in your jurisdiction. If you are the parent or guardian of a child who has provided us with their personal information, you may contact us using the contact details below to request that it be deleted.
Security and Retention of Your Information
Please be aware that no security measures are perfect or impenetrable, and we cannot guarantee perfect security. We recommend that you do not use unsecure channels to communicate sensitive or confidential information to us. How long we retain your personal information depends on different factors, such as whether we need the information to maintain your account, to provide you with Services, comply with legal obligations, resolve disputes or enforce applicable contracts and policies.
Your Rights and Choices
Depending on where you live, you may have some or all of the following rights in relation to your personal information. These rights are not absolute, may apply only in certain circumstances and, in certain cases, we may decline your request as permitted by law.
- Right to Access / Know. You may have a right to request access to personal information that we hold about you.
- Right to Delete. You may have a right to request that we delete personal information we maintain about you.
- Right to Correct. You may have a right to request that we correct inaccurate personal information we maintain about you.
- Right of Portability. You may have a right to receive a copy of the personal information we hold about you and to request that we transfer it to a third party, in certain circumstances.
- Managing Communication Preferences. You may opt out of receiving promotional emails at any time by using the unsubscribe option displayed in our emails. If you opt out, we may still send you non-promotional emails, such as those about your account or orders.
If you reside in the UK or European Economic Area, you may also have the right to object to or restrict processing of your personal information, and the right to withdraw consent where we rely on consent to process your personal information.
You may exercise any of these rights by contacting us using the contact details provided below. We may need to verify your identity before we can process your requests. You may designate an authorised agent to make requests on your behalf, subject to verification.
Complaints
If you have complaints about how we process your personal information, please contact us using the contact details provided below. Depending on where you live, you may have the right to lodge your complaint with your local data protection authority.
International Transfers
Please note that we may transfer, store and process your personal information outside the country you live in. If we transfer your personal information out of the European Economic Area or the United Kingdom, we will rely on recognised transfer mechanisms like the European Commission's Standard Contractual Clauses, or any equivalent contracts issued by the relevant competent authority of the UK, unless the data transfer is to a country that has been determined to provide an adequate level of protection.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time, including to reflect changes to our practices or for other operational, legal, or regulatory reasons. We will post the revised Privacy Policy on this website and update the "Last updated" date.
Contact
Should you have any questions about our privacy practices or this Privacy Policy, or if you would like to exercise any of the rights available to you, please email us at store@PEAK4.co.uk or write to us at 5 Parr Lane, Eccleston, PR7 5SL, GB. For the purpose of applicable data protection laws, we are the data controller of your personal information.
App Privacy Policy
Effective Date: 01/02/2026 | Version: 1.0
1. Introduction
PEAK4 Ltd ("PEAK4", "we", "us", "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and protect personal data when you use the PEAK4 Mobile Application, access related digital services, participate in PEAK4 wellbeing programmes, visit our website, or communicate with us. This policy is issued in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Who We Are
PEAK4 Ltd is the data controller in relation to personal data processed through the App, except where we act as a data processor on behalf of a Sponsoring Organisation.
- Registered Address: Avon View Offices, 90 High Street, Bidford-On-Avon, Alcester, England, B50 4AF
- Contact Email: hello@PEAK4.co.uk
- Data Protection Contact: helpdesk@PEAK4.co.uk
3. Scope of This Policy
This Privacy Policy applies to individual users of the PEAK4 Mobile App, participants in employer-sponsored wellbeing programmes, visitors to our website, and individuals who contact us.
4. Controller and Processor Roles
Depending on the deployment model, PEAK4 may act as a data controller, where we determine the purposes and means of processing personal data, or as a data processor, where we process personal data strictly on behalf of a Sponsoring Organisation under a written data processing agreement. Where PEAK4 acts as a processor, your Sponsoring Organisation is the primary data controller and determines how and why your data is used.
5. What Personal Data We Collect
5.1 Identity and Contact Data
- Full name
- Email address
- Organisation or employer details
- Job role (where relevant)
5.2 Account and Authentication Data
- Username
- Encrypted passwords
- Login timestamps
- Account status information
5.3 Technical and Device Data
- Device type and model
- Operating system
- App version
- IP address
- Device identifiers
- Log files, crash reports and usage analytics
5.4 Wellbeing Programme Data
- Programme participation records
- Goal setting information
- Activity logs
- Engagement metrics
5.5 Wearable Device Data (If Connected)
Where you choose to connect a wearable device or third-party platform, we may receive step counts, heart rate data, activity levels, sleep metrics, calorie expenditure and other physiological or activity-related data. This data may constitute special category data (health-related data) under UK GDPR.
5.6 Communication Data
- Support enquiries
- Feedback
- Messages submitted through the App
6. Special Category Data
Certain information processed via the App, particularly wearable-derived physiological metrics, may qualify as special category data under Article 9 UK GDPR. We process such data only where you have provided explicit consent, where processing is necessary for employment or occupational health purposes, or where another lawful Article 9 condition applies.
7. How We Collect Your Data
We collect data directly from you through account registration, App use and wearable connection; from your Sponsoring Organisation; from integrated third-party platforms such as wearable providers; and automatically via device and usage tracking technologies.
8. Why We Use Your Data
We use personal data to provide and maintain the App, authenticate users, deliver wellbeing programmes, facilitate occupational health services, enable wearable integrations, monitor engagement and programme effectiveness, improve App functionality, maintain system security, and comply with legal and regulatory obligations. We do not sell personal data.
9. Lawful Bases for Processing
Under UK GDPR, we rely on contractual necessity, legitimate interests balanced against user rights, legal obligations, and explicit consent where required. Where processing is based on consent, you may withdraw that consent at any time.
10. Sharing of Personal Data
We may share personal data with Sponsoring Organisations in accordance with programme terms, IT service providers and cloud hosting providers, analytics providers, wearable platform providers where connected, professional advisers, and regulators or authorities where legally required. All third-party service providers are subject to appropriate contractual safeguards.
11. International Transfers
Where personal data is transferred outside the United Kingdom, we ensure appropriate safeguards are in place, such as UK International Data Transfer Agreements, adequacy regulations, or standard contractual clauses.
12. Data Security
We implement appropriate technical and organisational security measures, including encryption in transit, access controls, authentication safeguards, secure hosting environments, and monitoring and logging. No digital system can be guaranteed to be completely secure.
13. Data Retention
We retain personal data only for as long as necessary to deliver services, fulfil contractual obligations, and meet legal and regulatory requirements. Retention periods vary depending on the nature of the data and service. Where employer-sponsored access ends, data may be archived or deleted in accordance with contractual and regulatory requirements.
14. Your Rights Under UK GDPR
You have the right to access your personal data, correct inaccurate data, request erasure where applicable, restrict processing, object to processing, request data portability where applicable, and withdraw consent. Requests may be submitted to helpdesk@PEAK4.co.uk. You also have the right to complain to the Information Commissioner's Office (ICO).
15. Wearable Technology Disclaimer
If you connect a wearable device, data is generated and initially processed by the wearable provider. Accuracy depends on device technology. Data is used for wellbeing purposes only and is not medical advice. PEAK4 does not control device hardware or firmware. Participation in wearable programmes is voluntary unless otherwise defined by your Sponsoring Organisation.
16. Children's Data
The App is not intended for individuals under the age of 18 unless expressly authorised under a sponsoring programme. We do not knowingly collect children's personal data without appropriate authority.
17. Automated Decision-Making
PEAK4 does not conduct automated decision-making or profiling that produces legal or similarly significant effects on individuals.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The latest version will always be available within the App and on our website. Continued use of the App constitutes acceptance of updates.
19. Contact Us
If you have questions about this Privacy Policy or your personal data, please contact PEAK4 Ltd at hello@PEAK4.co.uk or our privacy contact at helpdesk@PEAK4.co.uk.
Data Protection & Information Security Policy
Policy Version: V1 | Issued: 12/12/2025 | Valid Until: 12/12/2026 | Document Owner: Director | Reference: PKT-0020-E
Who this applies to: All PEAK4 employees, contractors, temporary staff, and relevant third parties where applicable.
How to raise a concern: Unless otherwise stated, raise concerns confidentially to the Director as soon as possible.
Policy exceptions: Any exception must be approved by the Director and documented (including scope, risk and compensating controls).
1. Purpose
PEAK4 exists to improve health, wellbeing and performance through data-led insight, technology and expert delivery. We work with people, organisations and communities in environments where trust, care and integrity matter. Protecting information and personal data is fundamental to how we operate and how we earn and retain the confidence of our clients, partners and programme participants.
This policy sets out how PEAK4 protects information and personal data, supporting confidentiality, integrity and availability across all PEAK4 services. It defines the principles, governance arrangements and responsibilities that apply to employees, contractors and relevant third parties.
This policy is practical and proportionate to PEAK4's cloud-based operating model and the sensitive nature of wellbeing and performance data. It supports compliance with UK GDPR, the Data Protection Act 2018, contractual obligations and client information security expectations.
2. Scope
This policy applies to:
- All PEAK4 employees, contractors and temporary staff
- All information assets owned, managed or processed by PEAK4
- All systems, platforms and tools used to deliver PEAK4 services (including supplier-managed cloud services)
- All personal data, wellbeing/performance data and confidential business information processed in the course of PEAK4 activities
- Information relating to employees, clients, programme participants, partners and suppliers
3. Definitions
- Personal data: Any information relating to an identified or identifiable individual.
- Special category data: Personal data revealing racial/ethnic origin, political opinions, religious beliefs, trade union membership, genetic/biometric data, health data, or sex life/sexual orientation.
- Wellbeing/performance data: Data PEAK4 processes in relation to wellbeing and performance programmes (may include health-related data depending on context).
- Controller / Processor: As defined under UK GDPR. PEAK4 may act as controller or processor depending on the service and contract.
- Incident: An actual or suspected event that compromises confidentiality, integrity or availability of information.
- Personal data breach: A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.
4. Policy Principles
PEAK4 applies the following principles to all information and personal data processing:
- Lawfulness, fairness and transparency. We process data lawfully and explain clearly how it is used.
- Purpose limitation. We use data only for legitimate service, operational, legal or contractual purposes.
- Data minimisation. We collect and use only what is necessary.
- Accuracy. We take reasonable steps to ensure data is accurate and up to date.
- Storage limitation. We retain data only as long as necessary and dispose of it securely.
- Integrity and confidentiality. We apply appropriate security measures to prevent unauthorised access, loss or misuse.
- Accountability. We maintain governance, records and evidence of compliance.
5. Legal Basis, Participant Trust and Ethical Use
PEAK4 processes personal data only where a lawful basis applies under UK GDPR, including contractual necessity, legitimate interests, legal obligation, and consent where required or appropriate.
PEAK4 recognises that programme participants place a high level of trust in the organisation. Participant wellbeing and performance data is treated with particular care. Participation in PEAK4 programmes is supported by clear information at sign-up and onboarding about how data will be collected, used and protected. PEAK4 does not use participant data in ways that are unexpected, intrusive or not aligned to the programme purpose.
Where special category data is processed, PEAK4 applies additional safeguards and ensures appropriate UK GDPR conditions are met.
6. Data Subject Rights
Individuals have rights under UK GDPR, including the right of access, right to rectification, right to erasure where applicable, right to restrict processing, right to object, and right to data portability where applicable. PEAK4 will respond to valid requests within statutory timeframes and will verify identity where appropriate. Requests and outcomes are recorded in line with PEAK4 governance practices.
7. Governance and Responsibilities
7.1 Director (Senior Management Accountability)
Overall accountability sits with the Director, who is responsible for:
- Approving this policy and ensuring it is reviewed at least annually
- Providing oversight of information security and data protection risk
- Ensuring appropriate controls are in place across PEAK4
- Ensuring suppliers and partners meet appropriate security and data protection standards
- Ensuring security and privacy are embedded into service planning, delivery and change
- Ensuring PEAK4 maintains appropriate records (including Records of Processing Activities, incident logs and training logs)
7.2 Employees and Contractors
All employees and contractors are responsible for:
- Complying with this policy and related contractual obligations
- Handling PEAK4, client and participant information responsibly
- Applying good judgement when accessing, using or sharing information
- Completing required onboarding and awareness activities
- Promptly reporting suspected or actual data protection or information security incidents
A breach of this policy may result in disciplinary action and/or termination of contract engagement.
8. Information Classification and Handling
PEAK4 information may include personal data, wellbeing and performance data, client confidential information, and commercially sensitive business information. Information must be:
- Accessed only where there is a legitimate business need
- Stored securely using PEAK4-approved systems and platforms
- Shared only with authorised individuals or organisations
- Protected from unauthorised access, disclosure, loss or damage
PEAK4 applies data minimisation and retention controls. Information must not be copied into unapproved locations, personal accounts, or unmanaged devices.
9. Access Control and Least Privilege
PEAK4 applies least privilege. Access is granted on a role-based basis, approved by senior management or delegated role owners, reviewed and adjusted when roles change or engagements end, and removed promptly when no longer required. Access controls are primarily enforced through core cloud platforms and supplier-managed systems. Elevated and administrator access is restricted and granted only where required.
10. Acceptable Use of Systems
PEAK4 systems, devices and information must be used for legitimate business purposes, in a lawful, professional and responsible manner, and in line with confidentiality, data protection and contractual obligations. Unauthorised or inappropriate use that could compromise security, confidentiality or PEAK4's reputation is not permitted. This includes attempting to bypass security controls, sharing accounts, or introducing unapproved software or tools that may increase risk.
11. Mobile Devices and Remote Working
PEAK4 operates a flexible, cloud-based working model. When working remotely or using mobile devices, individuals must:
- Take reasonable steps to prevent unauthorised access
- Secure devices when unattended (including screen locks)
- Use PEAK4-approved platforms and systems where possible
- Avoid accessing sensitive information in public or shared environments where risk is increased
- Not leave devices visible or unsecured in vehicles or public places
- Report loss or theft promptly to the Director
12. Passwords and Authentication
Authentication controls are enforced through PEAK4's core platforms and supplier-managed systems. Controls include minimum password requirements, protection against repeated failed login attempts, and account lockout or similar safeguards. Where supported and appropriate to risk, PEAK4 uses additional authentication measures such as multi-factor authentication. Users must never share passwords, reuse passwords across sensitive services, or store passwords insecurely.
13. Cloud Services and Suppliers
PEAK4 uses third-party cloud services and specialist technology partners. PEAK4 takes a risk-based approach to supplier assurance, which includes proportionate due diligence and supplier selection, contractual confidentiality and data protection obligations including processor terms where applicable, role-based access control and secure handling of data, governance oversight of supplier-managed services, and secure handling of information throughout the service lifecycle including exit and termination. Where services are supplier-managed, PEAK4 relies on supplier controls and certifications supported by contractual protections and ongoing governance.
14. Data Lifecycle Management
14.1 Onboarding
- Access is granted appropriately based on role
- Data collected aligns with programme and service requirements
- Individuals are provided with clear information on data use where applicable
14.2 Service Delivery
- Information is used, stored and shared securely to support delivery, insight and reporting
- Client reporting and dashboards are managed through approved platforms
- Any change that may affect data protection or security is assessed proportionately for risk and contractual impact
14.3 Offboarding and Exit
- Access is removed promptly when no longer required
- Data is deleted or lawfully retained in line with contractual, regulatory and business need
- Offboarding actions are supported by PEAK4 operational checklists (including the Leaver IT Asset & Access Checklist)
Further detail is defined in the Client Contract Termination & Data Handling Procedure.
15. Backup, Resilience and Recovery
Service resilience is supported through supplier-managed backup and recovery arrangements and PEAK4's Disaster Recovery and System Testing approach where applicable. PEAK4 maintains proportionate oversight of resilience based on service criticality and supplier assurance.
16. Clear Desk and Clear Screen
PEAK4 expects sensible steps to prevent unauthorised access, including locking screens when unattended, keeping physical information secure and out of view in shared environments, avoiding unnecessary exposure of information in public or shared spaces, and minimising printing and physical records where digital controls are stronger.
17. Removable Media
Use of removable media is discouraged in favour of approved cloud systems. Where removable media is used, individuals must follow acceptable use and confidentiality requirements, encrypt and handle information securely where possible, minimise the information stored, and ensure secure deletion or disposal when no longer required.
18. Data Retention and Secure Disposal
PEAK4 retains records only for lawful, contractual or legitimate business need and disposes of them securely at the end of the retention period. Retention periods are defined within PEAK4's Records Retention Policy and Retention Schedule. Where PEAK4 acts as a processor, retention follows the controller's written instructions unless legal obligations require otherwise. Secure disposal includes secure deletion for digital records and secure disposal of physical records where applicable.
19. Incident Management and Breach Response
19.1 Reporting
All suspected or actual incidents must be reported immediately to the Director.
19.2 Response
PEAK4 will assess scope and severity, take proportionate containment and remediation actions, preserve evidence where appropriate, and determine whether the incident constitutes a personal data breach.
19.3 Notification
Where required, PEAK4 will notify the ICO within 72 hours of becoming aware of a notifiable personal data breach. PEAK4 will notify affected clients and individuals where there is a high risk to rights and freedoms. Incident handling is managed in line with the Incident Response Plan.
20. Contract Termination and Data Handling
When a client contract ends, PEAK4 ensures access is removed where no longer required, data is deleted or lawfully retained in line with contractual, regulatory and business requirements, and data within supplier-managed platforms is handled securely and in line with supplier terms and contractual obligations. Detailed steps are defined in the Client Contract Termination & Data Handling Procedure.
21. Artificial Intelligence (AI) Use
PEAK4 may use AI-enabled functionality in a limited, controlled and transparent manner within PEAK4's management dashboards ("Peakie AI"), delivered by PEAK4's technology partner, to support insight and interpretation. AI outputs are advisory and do not replace human judgement. PEAK4 does not use AI to make automated decisions about individuals that would have a material impact (e.g., employment, disciplinary or health eligibility decisions) without appropriate governance, assessment and explicit client agreement. AI use is governed by PEAK4's Artificial Intelligence (AI) Policy and is subject to this Data Protection & Information Security Policy.
22. Training and Awareness
PEAK4 embeds responsibilities through onboarding and day-to-day working practices. All employees and contractors must understand this policy and follow it, complete required training appropriate to their role, and request support or clarification if unsure. Policy acceptance and key training activity are recorded within PEAK4's Training Log.
23. Monitoring, Assurance and Continuous Improvement
PEAK4 maintains proportionate monitoring and assurance through access reviews and leaver controls, supplier oversight and governance, incident logging and post-incident review, periodic review of policies and procedures, and continuous improvement based on lessons learned, client expectations and organisational growth.
24. Exceptions and Non-Compliance
Any exception to this policy must be approved by the Director in advance, documented with rationale, duration and compensating controls, and reviewed periodically and removed where possible. Non-compliance may result in disciplinary action, termination of contract engagement, and/or contractual consequences.
25. Review and Approval
This policy is reviewed and approved at least annually and updated following material changes, significant incidents, or changes to PEAK4 services, suppliers, legal obligations or client requirements. Approved by the Director. Date: 10/12/2025.
Related Documents
This policy is supported by separate operational procedures and registers maintained within PEAK4's Compliance Framework, including the Incident Response Plan, Records Retention Policy, Client Contract Termination & Data Handling Procedure, and Artificial Intelligence (AI) Policy. These documents are version-controlled and reviewed periodically.