Privacy Policy
Last updated: September 2026
Kneu Health
Kneu Health Limited, a company registered in the United Kingdom (no. 14492037) with a registered address at First Floor, 100 Victoria Embankment, London, EC4Y 0DH, United Kingdom (referred to as “Kneu Health,” “we,” “us,” or “our”), provides this privacy policy to inform users of our practices regarding the collection, use, and protection of their personal information.
Kneu Health is subject to the Health Insurance Portability and Accountability Act (HIPAA) as a Business Associate of the healthcare organizations we serve, and to applicable United States federal and state privacy and data security laws. Where we hold protected health information on behalf of a healthcare provider, that information is governed by HIPAA and by our Business Associate Agreement with that provider. Certain state laws, including the California Confidentiality of Medical Information Act, also apply to medical information we handle. The California Consumer Privacy Act contains an exemption for protected health information held by a business associate, and applies to us only in respect of any information falling outside that exemption.
For privacy-related questions, you can contact our Data Protection Officer at:
- Email: privacy@kneu.com
- By visiting the Contact Us page on our website and selecting Data Protection as the subject.
Key Definitions
Personal Data: Any information that identifies, relates to, describes, or can reasonably be linked to an individual.
Data Processing: Any operation on personal data, including collection, storage, use, disclosure, and deletion.
Sensitive Personal Data: Includes health data, financial information, and other categories as defined by laws like HIPAA or state privacy laws.
Protected Health Information (PHI): Individually identifiable health information that we create, receive, maintain or transmit on behalf of a healthcare provider, as defined by HIPAA.
Kneu Health’s Interactions with Personal Data
Data Controller vs. Data Processor
Kneu Health acts as a data controller when determining the purposes and means of processing your data and as a data processor when processing on behalf of other organizations (e.g., healthcare providers).
Our role under HIPAA
When we process protected health information on behalf of a healthcare provider, that provider is the Covered Entity and Kneu Health is its Business Associate. This means:
- Your relationship for the purposes of your health information is with your healthcare provider, not with us. Their Notice of Privacy Practices, not this policy, describes how your health information is used in your care.
- We use and disclose protected health information only as permitted by our Business Associate Agreement with your provider and on their instructions. We do not use it for our own purposes.
- We do not sell protected health information, and we do not use it for advertising or marketing.
- Where we engage a subcontractor that handles protected health information, we require it to accept the same restrictions and conditions that apply to us.
- We report any breach of unsecured protected health information to your healthcare provider, within the timeframes required by the HIPAA Breach Notification Rule and our agreement with them.
- You exercise your HIPAA rights — access to your records, amendment, an accounting of disclosures, and restrictions on use — through your healthcare provider. If you contact us directly with such a request, we will forward it to them without undue delay.
- On termination of our agreement, we return or destroy protected health information as your provider instructs.
Where Kneu Health collects information directly from you and decides how it is used — for example when you contact us through our website — we act as a controller in our own right, and this policy describes what we do.
Personal Data We Collect and Use
1. Website Visitors
We collect non-identifiable data using analytics tools such as Squarespace. Identifiable data may be collected when submitted via forms.
Cookies: We use cookies to enhance user experience. You can manage cookies through your browser settings.
Online advertising
We use online advertising, including Google Ads, to let people know about our services. Our advertising campaigns to date have been run outside the United States. The Google Ads tag is installed across all pages of our website, so it may be active when you visit from the United States even where no campaign is running here. We will update this section if we begin advertising in the United States.
We do not use information from our platform, our app, or patient records for advertising. Protected health information is never used for advertising or marketing, as stated under “Our role under HIPAA” above. We do not upload customer, patient, or registrant contact lists to Google or to any other advertising platform, and we do not use audience matching features that would require us to do so.
Where we do advertise, our advertisements are selected using general criteria such as location, age range, and the search terms a person has typed. An advertisement may therefore appear alongside searches relating to a condition, but it is not directed at any individual on the basis of health information about them, whether held by us or inferred by an advertising platform. We do not use geofencing around hospitals, clinics, or other healthcare facilities to deliver advertising.
The Google Ads tag uses cookies to measure whether a visit to our website followed one of our advertisements. Any reporting we receive from Google is aggregated and does not identify you. You can control these cookies as described under “Cookies” above. Google’s own advertising controls are available at https://myadcenter.google.com and its privacy policy at https://policies.google.com/privacy.
2. Kneu Health App Users
Personal Data Collected:
- Contact Information: Name, email, phone number
- Health Information: Diagnoses, symptom data, app activity logs.
Uses:
- To deliver app functionality and support.
- For healthcare providers to monitor your condition.
- To improve our services (aggregated or de-identified data).
SMS Messaging:
Kneu Health may send SMS (text) messages to patients and caregivers as part of service delivery on the Kneu Health platform. These messages are transactional and directly related to your use of the platform.
Types of SMS messages we send:
- One-time passcode (OTP) messages for identity verification and authentication
- Onboarding notifications to inform you when your care team has added you to the platform and you are able to complete registration
- Service-related notifications directly tied to your use of the Kneu Health app
Message frequency: Message frequency varies. OTP messages are sent when you log in or verify your identity. Onboarding notifications are sent at most once per user. Kneu Health does not send recurring marketing messages via SMS.
Message and data rates may apply. Charges depend on your mobile carrier and service plan. Kneu Health is not responsible for any messaging or data fees charged by your mobile carrier.
Opt-out: You can opt out of SMS messages at any time by replying STOP to any message from Kneu Health. After opting out you will receive a single confirmation message and no further SMS messages will be sent. Please note that opting out of SMS may affect your ability to verify your identity and complete onboarding on the platform.
Help: Reply HELP to any message from Kneu Health for support information, or contact us at privacy@kneu.com.
Consent and data sharing: SMS opt-in data and consent will not be shared with any third parties or affiliates for marketing or promotional purposes. Your phone number and messaging consent information are used solely for the purposes described in this section.
Carrier liability: Carriers are not liable for any delayed or undelivered messages.
Consent collection: SMS consent is collected separately within the Kneu Health mobile application. At the point of phone number entry, users are informed that their number will be used to send a verification code via SMS. Users must separately and explicitly consent to receiving additional SMS communications (such as onboarding notifications) through a dedicated opt-in control during registration.
Email and In-App Notifications: Kneu Health may send emails and in-app notifications to patients and caregivers as part of delivering the Kneu Health platform. Where we provide the platform on behalf of a healthcare provider, these messages are sent as part of that service and on that provider’s behalf. They are transactional and relate to your use of the platform, and may include, for example, messages confirming registration, reminders or prompts relating to activities in the app, information about features or changes that affect your use of the app, and responses to support queries you raise with us.
We limit the information included in these messages to what is necessary for the purpose of the message. We use third-party service providers to deliver them, and where a provider handles protected health information we require it to accept the same obligations that apply to us, as described under Third-Party Processing and Data Transfers below.
Message frequency varies depending on your use of the platform. Emails include an option to unsubscribe where the message is not necessary in order to provide the service, and in-app notifications can be managed in your device settings. As stated under Our role under HIPAA above, we do not use protected health information for advertising or marketing.
Sensitive Data: We handle your health data under strict security and HIPAA-compliant practices.
Privacy Policy: https://www.kneu.com/us/legal/privacy-policy
Terms of Use: https://www.kneu.com/us/legal/terms-of-use
3. Clinical Dashboard Users
Personal Data Collected: Name, email address, and place of work.
Uses: To confirm identity and grant dashboard access.
4. Research Participants
We collect data for approved research projects based on informed consent. Withdrawal of consent is honored at any stage.
Your Privacy Rights (U.S. Residents)
If you are a U.S. resident, you may have the following rights:
- Right to Know: You can request details about the personal information we collect, use, and share.
- Right to Access: Obtain a copy of your personal information.
- Right to Delete: Request deletion of your personal information, subject to legal exceptions.
- Right to Correct: Request corrections to inaccurate or incomplete information.
- Right to Opt-Out: Opt out of the sale or sharing of personal information. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. Where advertising cookies are used on our website, you can decline them as described under “Cookies”.
- Right to Data Portability: Receive a copy of your data in a portable format.
- Rights Under HIPAA: Access your medical records and request amendments or restrictions. These rights are exercised through your healthcare provider, who holds your medical record; if you ask us, we will pass your request to them without undue delay. If you believe your HIPAA privacy rights have been violated, you may file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights at hhs.gov/ocr. Filing a complaint will not result in any retaliation against you.
- Right to Lodge a Complaint: In the event that we refuse your request under the Rights of Access, we will provide you with a reason as to why.
Where the information you are asking about is protected health information we hold for a healthcare provider, we will direct your request to that provider, who is responsible for responding to it.
To exercise these rights, contact us via:
- Email: privacy@kneu.com
- Contact Us form on our website.
Data Security
We implement reasonable safeguards, including encryption and access controls, to protect your data from unauthorized access or disclosure. For health data, we comply with HIPAA’s Security Rule requirements.
Where your data is stored
Personal data relating to our United States customers and their patients is stored and processed in the United States. Personal data relating to our United Kingdom customers is stored and processed in the United Kingdom. We do not transfer United States patient data outside the United States.
Do Not Track
Some browsers include a Do Not Track (DNT) feature that signals to websites that you do not want your online activity tracked. Our website does not currently respond to DNT signals. We will update this section if our practices change.
Where your browser or a browser extension sends an opt-out preference signal such as Global Privacy Control (GPC), we treat that signal as a request to opt out of any sharing of personal information for advertising purposes on that browser.
Data Retention
We retain your personal data only for as long as necessary to provide our services and meet our legal obligations. The following periods apply:
- Account and contact data: for the duration of your relationship with us and 8 years after termination, unless a shorter period is required by an applicable contract, Business Associate Agreement, or applicable law
- Health and assessment data: retained in accordance with our agreement with your healthcare provider. Where we hold protected health information as a Business Associate, we retain it for as long as our agreement with your healthcare provider requires, and return or destroy it on their instruction. Your provider, not Kneu Health, determines how long your health record is kept.
- Financial records: 8 years from collection.
- Marketing and communications data: for the duration of your account, deleted on termination.
Third-Party Processing and Data Transfers
We may share data with trusted third parties (e.g., cloud providers, analytics tools) under binding agreements. If transferring data outside the U.S., we ensure compliance with applicable legal frameworks. Every third party that handles personal data on our behalf does so under a written agreement, and where that party handles protected health information we require it to accept the same obligations that apply to us. If you would like to know which third parties we use and what they do, please contact us at privacy@kneu.com and we will provide the current list.
Children’s Privacy
Our services are not directed to children under 13, and we do not knowingly collect their data without parental consent, as required by the Children’s Online Privacy Protection Act (COPPA).
Other US State Privacy Rights
Depending on the state in which you reside, you may have additional privacy rights under applicable state law, including Virginia (VCDPA), Colorado (CPA), Texas (TDPSA), and other states with active privacy legislation. These rights are broadly consistent with the CCPA rights described above, including rights to access, delete, correct, and port your data, and to opt out of certain data uses. To exercise any state privacy rights, contact us at privacy@kneu.com with the subject line “US State Privacy Request” and include your state of residence. Most state privacy laws contain an exemption for information regulated by HIPAA, so where we hold your information as a Business Associate those laws will generally not apply to it. Separate state laws may still apply to medical information, including the California Confidentiality of Medical Information Act.
Changes to this Policy
We may update this policy from time to time. We will notify you of material changes via the app or by email with at least 30 days’ notice before they take effect. Continued use of our services after that date constitutes acceptance of the updated policy.