FoodFacts CONNECT

Last updated: July 2026

Privacy policy

FoodFacts CONNECT helps you find and book verified Registered Dietitians and Registered Nutritionists. Because that can involve information about your health, we hold ourselves to a high standard. This policy explains, in plain English, what we collect, why, and the rights you have.

1. Who we are

FoodFacts CONNECT is operated by foodfacts.org, a non-profit organisation fighting food misinformation. foodfacts.org is the data controller for the personal data described in this policy. You can contact us about anything in this policy via our contact form— choose the subject “Privacy request”.

The practitioners you book through CONNECT are independent, regulated professionals. Once you engage a practitioner, they act as a separate data controller for the clinical records they keep about your consultations, under their own professional and regulatory obligations (HCPC for Registered Dietitians, AfN for Registered Nutritionists).

2. What we collect

If you use CONNECT as a client

  • Account data — your name, email address, password (stored only as a secure hash) and whether your email is verified.
  • Booking data — the appointments you make: which practitioner, which service, date and time, price paid, and the status of the booking (confirmed, cancelled, completed and so on).
  • Information you choose to share — optional goals or dietary preferences you add to your profile, notes you attach to a booking, and messages you send to practitioners. These may reveal information about your health (see section 4).
  • Reviews — ratings and review text you submit about practitioners you have seen.
  • Technical data — IP address and browser information in security and audit logs, and a session cookie that keeps you signed in (see our cookie policy).

If you use CONNECT as a practitioner

  • Account and profile data — your name, email, public profile (photo, bio, specialisms, location, languages, services and prices).
  • Verification data — your credential type, registration body (HCPC or AfN), registration number, and the outcome of our register checks. Your registration number is checked against the public register and a verification decision is recorded.
  • Insurance and payout data — your professional indemnity insurance details, and a Stripe Connect account reference so you can receive payouts. We never see or store your full bank details — Stripe holds those.
  • Earnings data — records of bookings, fees and the platform commission applied.

If you just get in touch

  • Contact messages — your name, email address, chosen subject and message text when you use the contact form.

We do not collect data for advertising, we do not use third-party analytics or tracking cookies, and we never sell personal data.

3. Why we use your data (lawful bases)

Purposes of processing and their UK GDPR lawful bases
PurposeLawful basis (UK GDPR)
Creating and running your account; taking bookings; processing payments and refunds; enabling messagingArticle 6(1)(b) — performance of a contract
Verifying practitioner registration against the HCPC / AfN registers and displaying verified statusArticle 6(1)(f) — legitimate interests (protecting the public from unverified providers), and Article 6(1)(b) for the practitioner agreement
Keeping appointment and financial records after account deletionArticle 6(1)(c) — legal obligation (tax and accounting law) and Article 6(1)(f) — legitimate interests in professional record-keeping and defending legal claims
Security, fraud prevention and audit loggingArticle 6(1)(f) — legitimate interests in keeping the platform safe
Sending transactional emails (booking confirmations, cancellations, verification decisions)Article 6(1)(b) — performance of a contract
Optional marketing emailsArticle 6(1)(a) — consent, which you can withdraw at any time in your settings
Health-related information you choose to share (goals, booking notes, messages)Article 6(1)(b), plus Article 9(2)(a) — your explicit consent (see section 4)

4. Health information and explicit consent

Information about your health is special category data under UK GDPR and gets extra protection. On CONNECT, health information only exists where you choose to share it — for example, goals you add to your profile, a note you attach to a booking, or something you tell a practitioner in a message.

We ask for your explicit consent (Article 9(2)(a)) before storing goals or dietary information on your profile, and we record when that consent was given. You can withdraw consent at any time by removing the information in your dashboard settings or by asking us to delete it. Withdrawing consent does not affect the lawfulness of processing before withdrawal.

A practical tip: messages you send to a practitioner are shared with that practitioner. Only share what you are comfortable with them knowing, and never use messaging for urgent medical matters — call 999 or NHS 111 instead.

5. Who processes data on our behalf

We use a small number of carefully chosen service providers (processors) to run CONNECT. Each is bound by a data processing agreement.

Processors and sub-processors
ProviderWhat they doWhat they process
NetlifyHosting and content deliveryTechnical request data (IP address, request logs)
NeonDatabase hosting (Postgres)All platform data described in section 2, encrypted at rest
StripePayment processing and practitioner payoutsPayment card details (we never see these), transaction amounts, practitioner payout account details
MailerSendTransactional email deliveryYour email address and the content of emails we send you

We share booking details (your name, the service, date and time, and any note you attach) with the practitioner you book — that is the point of the platform. We do not share your data with anyone else except where the law requires it (for example, a lawful request from a regulator or law enforcement).

6. International transfers

We aim to keep data in the UK and European Economic Area. Some of our providers (for example Stripe, Netlify and MailerSend) are US-headquartered and may process data outside the UK. Where that happens, transfers are protected by safeguards recognised under UK GDPR — the UK Extension to the EU–US Data Privacy Framework, UK International Data Transfer Agreements, or Standard Contractual Clauses with the UK Addendum.

7. How long we keep your data

  • Account and profile data — kept while your account is active, deleted when you delete your account.
  • Appointment and financial records — retained for up to 8 years. This reflects professional record-keeping norms for regulated health professionals, tax and accounting law, and the period in which legal claims can be brought. If you delete your account, these records are anonymised rather than deleted: your name, email and other identifiers are removed, but the record that an appointment happened, its date and its financial details are kept.
  • Messages — deleted when your account is deleted.
  • Contact form messages — kept for up to 2 years so we can handle follow-ups, then deleted.
  • Security and audit logs — kept for up to 2 years.

Practitioners keep their own clinical records about you under their own professional obligations — deleting your CONNECT account does not delete a practitioner's clinical records, which they must retain under their regulator's rules.

8. Your rights

Under UK GDPR you have the right to:

  • Access — get a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data. Most profile data can be edited directly in your dashboard.
  • Erasure — ask us to delete your data (see delete my data for how, and for the 8-year anonymised-records exception described above).
  • Portability — receive the data you gave us in a machine-readable format. You can export your data from your dashboard settings.
  • Restriction — ask us to pause processing of your data in certain circumstances.
  • Objection — object to processing based on legitimate interests, and to any marketing at any time.
  • Withdraw consent — where processing is based on consent (marketing, health information you shared), withdraw it at any time.

To exercise any right, use your dashboard settings (data export and account deletion are self-service), visit delete my data, or send us a privacy request. We respond within one calendar month. We will never charge you for a reasonable request.

Not happy with our answer?You have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk or on 0303 123 1113. We would appreciate the chance to put things right first, but you do not have to give us one.

9. How we protect your data

  • All traffic is encrypted in transit using TLS.
  • Data is encrypted at rest in our database.
  • Passwords are stored only as secure one-way hashes.
  • Access to personal data is restricted by role-based access controls — practitioners see only their own clients' bookings, and administrative access is limited and audit-logged.
  • Payment card details never touch our servers — they go directly to Stripe, a PCI-DSS Level 1 provider.

No internet service can promise perfect security, and we do not claim that platform messages are end-to-end encrypted. If we ever discover a breach that risks your rights, we will notify the ICO within 72 hours and tell you directly where the risk is high.

10. Children

CONNECT is for adults. You must be 18 or over to create an account. We do not knowingly collect data from anyone under 18; if you believe a child has created an account, please contact us and we will remove it.

11. Changes to this policy

If we make material changes we will update the date at the top of this page and, where the change significantly affects you, email account holders before it takes effect.