App Privacy policy

SenLife is committed to protecting the privacy and security of personal data. This policy explains how we collect, use, and protect data when you interact with the SenLife app and outlines your rights regarding data protection.

SenLife Ltd

Company Number: 13812468

Registered office: Fanlings, Croft Lane, Crondall, Farnham, England, GU10 5QG

Email: support@mysenlife.com

Data Protection Officer: Ali Kazmi, ali@kewdata.ai

1. Data Collection and Usage

1.1 Purpose of Data Collection

We collect and process data to:

  • Enable parents and guardians to record and organise behavioural observations about their child.
  • Generate structured reports and AI-assisted insights based on data you provide, for your own use and optional sharing with professionals.
  • Improve app functionality and user experience.
  • Support business management, contracts, and relevant communications.

1.2 Types of Data We Collect and Our Legal Basis for Processing

The table below sets out the categories of data we process and the lawful basis under UK GDPR for each:

 

Data Type

What It Includes

Legal Basis

 

Personal Data

Name, date of birth, and contact details of parents and children

Performance of a contract (to provide App services)

 

Behavioural Data

Daily diary data and behaviour profile provided by parents for AI-assisted analysis

Explicit consent (Article 9(2)(a) UK GDPR — special category data)

 

Medical Information

Details shared by parents to assist with assessments

Explicit consent (Article 9(2)(a) UK GDPR)

 

Non-Personal Data

Device information, IP addresses, and usage data for service improvement

Legitimate interests (service improvement, security, fraud prevention)

2. Our Role: Controller, Not Processor

SenLife Ltd is the data controller for personal data processed through the App, including child profile information, diary entries, questionnaire responses and insight reports. SenLife determines the purposes and means of this processing, including system design, processing logic, security and retention, and therefore acts as controller under UK GDPR.

Parents and guardians are users of the App. Their control over what data they enter and whether they choose to share a report does not change SenLife’s status as controller.

Where a parent chooses to share a report with a third party (such as a school or clinician), that third party becomes an independent controller for its own subsequent use of that information.

3. Anonymised Data and Research Use

Where data is fully and irreversibly anonymised such that no individual can reasonably be re-identified, it no longer constitutes personal data under UK GDPR, and may be used for purposes such as internal research and product improvement.

SenLife is currently assessing whether its anonymisation methods meet the threshold required for use in clinical research, including whether identifying elements are genuinely and irreversibly removed while the data remains useful for that purpose. Until this assessment is complete, anonymised data is not shared with external researchers or used for clinical research purposes.

4. AI Data Processing and Human Review

The SenLife app uses AI-assisted analysis to help identify patterns in behavioural data you provide, generating structured insights for your own understanding and, at your discretion, to support conversations with clinicians or other professionals.

AI-generated insights do not involve automated decision-making that produces legal or similarly significant effects on you or your child. Where AI is used to generate insights, a human remains able to review, question, and if necessary override or disregard any AI-generated output.

AI-generated insights are for informational purposes only and do not replace medical diagnosis, clinical assessment, or professional clinical judgement.If you no longer wish for your data to be used for AI-assisted analysis, you may withdraw your consent at any time by contacting us at support@mysenlife.com. Withdrawing consent will not affect the lawfulness of processing carried out before withdrawal.

5. Data Storage

Personal data is stored securely within the following providers:

  • AWS (UK)
  • Google (UK)
  • Digital Ocean (UK)

These systems use encrypted storage and restricted access. Access is limited to SenLife employees and contractors who require it for their role.

We never store website-derived personal data on local devices unless operationally necessary, with appropriate security measures in place.

6. Data Security and Retention

6.1 Data Security Measures

  • Encryption: All data transmitted between the app and servers is encrypted.
  • Anonymisation/Pseudonymisation: Where possible, data is anonymised or pseudonymised to protect personal identities.
  • Audit Trails: Comprehensive records of data interactions are maintained for regulatory accountability.
  • Access control: Access to user data is limited to users, and to professionals or carers users give permission to. Access within the SenLife team is strictly limited to those who need it.
  • No selling, no sharing without consent: We do not sell user data, and do not share it unless given permission by the user. The user is always in control.

6.2 Data Retention and Deletion

We retain personal data only for as long as necessary to fulfil the purposes described in this policy:

 

Data Type

Retention Period

 

Child diary and behavioural data

Active account, plus up to 12 months after deletion, unless earlier erasure is requested

 

Parent / account data

Up to 6 years after account closure where required for legal or financial purposes

 

Marketing enquiries

24 months from last interaction

 

Operational and system logs

Up to 12 months unless required for security or legal purposes

 

Anonymised data

Retained indefinitely as it no longer constitutes personal data

If your account remains inactive for 12 months, we will email you to check whether you would like to keep it open. If you do not access the SenLife app within 14 days of that email, we will delete your data in line with the schedule above.

7. Parental Consent and User Rights

  • Sharing of data is always optional and controlled by you, either by inviting people to care for your child within the app, or by actively sharing insight reports you have generated.
  • You are in control of your child’s data.
  • The holder of the SenLife account is the data controller for decisions about sharing. SenLife reasonably assumes this person is the parent or guardian of the child, and that any carers have been given permission and access by the parent or guardian to contribute to the account.
  • We believe it is appropriate and realistic for SenLife to assume the account holder has implied or direct consent from a child for their data to be recorded in the App, and that parents/guardians act in the best interests of the child.

7.1 Your Rights Under UK GDPR

If you are a UK or EU resident, you have the right to:

  • Access: Request a copy of your data.
  • Correction: Update inaccurate information.
  • Deletion: Request data removal when no longer needed.
  • Restriction: Limit data processing.
  • Objection: Object to processing based on legitimate interests.
  • Portability: Receive data in a portable format.

To exercise these rights, you can contact us:

  • Email: support@mysenlife.com
  • Post: SenLife Ltd, Fanlings, Croft Lane, Crondall, Farnham, England, GU10 5QG

8. Disclosure and Transfer of Personal Data

We do not sell personal data.

We may share personal data with trusted third-party processors who help us operate our business, including:

  • Trello and ClickUp— customer relationship management
  • Gmail, Slack — communications
  • AWS, Google, Digital Ocean — cloud hosting
  • PostHog, Firebase Analytics, Facebook SDK — usage analytics

A full and current list of our data processors is available on request from support@mysenlife.com.

These providers act under data processing agreements and cannot use your data for their own purposes.

We may also disclose data where required to:

  • Comply with law or regulatory requirements.
  • Enforce our terms or protect rights, safety, or property.
  • Support a business transfer (sale, merger, or funding due diligence).

9. Non-Personal Data Collection

We collect non-personal information, such as device data, to enhance app performance and user experience. This data is anonymised and does not identify individual users.

10. End of Contract Provisions

When you stop using the app, you may delete your data or request its deletion.

11. Third-Party Privacy Policies

The app may contain links to third-party services. We do not control their privacy practices, and recommend reviewing their policies before sharing data with them.

12. Data Breach Notification

If a data breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, as required by UK GDPR. We will also notify the ICO within 72 hours of becoming aware of the breach where required by law.

13. International Data Transfers

Some of our processors and team members (engineering staff in Pakistan, Romania, Bosnia, and South Africa) may access personal data from outside the UK.

To remain compliant with UK GDPR, we ensure:

  • Adequacy decisions are relied on where available.
  • Transfer Risk Assessments (TRAs) are completed for countries without adequacy.
  • Appropriate safeguards are in place (UK Extension to EU Standard Contractual Clauses, or an International Data Transfer Agreement).
  • Technical and organisational security controls, including role-based access controls, are applied.

Specific safeguards by region:

  • United States-based processors: UK Extension to EU Standard Contractual Clauses (Annex 2) + Transfer Risk Assessment.
  • Pakistan, Bosnia, South Africa: International Data Transfer Agreement (IDTA) + Transfer Risk Assessment + additional technical safeguards.
  • Romania, and other EU/EEA-based processors: UK adequacy regulations apply (no additional safeguards required).

Copies of our Transfer Risk Assessments and data processing agreements are available on request from support@mysenlife.com.

14. Data Protection Officer (DPO) Contact Information

SenLife has appointed a Data Protection Officer to oversee compliance with GDPR and ensure that your personal data is handled responsibly and securely. Our DPO can be contacted at: Ali Kazmi, ali@kewdata.ai

15. Contact Us

If you have questions regarding this privacy policy, email us at support@mysenlife.com.

App Privacy Policy updated 20 August 2026. Due for update 12 months from publication.