Last updated: July 2026
FoodFacts CONNECT helps you find and book verified Registered Dietitians and Registered Nutritionists. Because that can involve information about your health, we hold ourselves to a high standard. This policy explains, in plain English, what we collect, why, and the rights you have.
FoodFacts CONNECT is operated by foodfacts.org, a non-profit organisation fighting food misinformation. foodfacts.org is the data controller for the personal data described in this policy. You can contact us about anything in this policy via our contact form— choose the subject “Privacy request”.
The practitioners you book through CONNECT are independent, regulated professionals. Once you engage a practitioner, they act as a separate data controller for the clinical records they keep about your consultations, under their own professional and regulatory obligations (HCPC for Registered Dietitians, AfN for Registered Nutritionists).
We do not collect data for advertising, we do not use third-party analytics or tracking cookies, and we never sell personal data.
| Purpose | Lawful basis (UK GDPR) |
|---|---|
| Creating and running your account; taking bookings; processing payments and refunds; enabling messaging | Article 6(1)(b) — performance of a contract |
| Verifying practitioner registration against the HCPC / AfN registers and displaying verified status | Article 6(1)(f) — legitimate interests (protecting the public from unverified providers), and Article 6(1)(b) for the practitioner agreement |
| Keeping appointment and financial records after account deletion | Article 6(1)(c) — legal obligation (tax and accounting law) and Article 6(1)(f) — legitimate interests in professional record-keeping and defending legal claims |
| Security, fraud prevention and audit logging | Article 6(1)(f) — legitimate interests in keeping the platform safe |
| Sending transactional emails (booking confirmations, cancellations, verification decisions) | Article 6(1)(b) — performance of a contract |
| Optional marketing emails | Article 6(1)(a) — consent, which you can withdraw at any time in your settings |
| Health-related information you choose to share (goals, booking notes, messages) | Article 6(1)(b), plus Article 9(2)(a) — your explicit consent (see section 4) |
Information about your health is special category data under UK GDPR and gets extra protection. On CONNECT, health information only exists where you choose to share it — for example, goals you add to your profile, a note you attach to a booking, or something you tell a practitioner in a message.
We ask for your explicit consent (Article 9(2)(a)) before storing goals or dietary information on your profile, and we record when that consent was given. You can withdraw consent at any time by removing the information in your dashboard settings or by asking us to delete it. Withdrawing consent does not affect the lawfulness of processing before withdrawal.
A practical tip: messages you send to a practitioner are shared with that practitioner. Only share what you are comfortable with them knowing, and never use messaging for urgent medical matters — call 999 or NHS 111 instead.
We use a small number of carefully chosen service providers (processors) to run CONNECT. Each is bound by a data processing agreement.
| Provider | What they do | What they process |
|---|---|---|
| Netlify | Hosting and content delivery | Technical request data (IP address, request logs) |
| Neon | Database hosting (Postgres) | All platform data described in section 2, encrypted at rest |
| Stripe | Payment processing and practitioner payouts | Payment card details (we never see these), transaction amounts, practitioner payout account details |
| MailerSend | Transactional email delivery | Your email address and the content of emails we send you |
We share booking details (your name, the service, date and time, and any note you attach) with the practitioner you book — that is the point of the platform. We do not share your data with anyone else except where the law requires it (for example, a lawful request from a regulator or law enforcement).
We aim to keep data in the UK and European Economic Area. Some of our providers (for example Stripe, Netlify and MailerSend) are US-headquartered and may process data outside the UK. Where that happens, transfers are protected by safeguards recognised under UK GDPR — the UK Extension to the EU–US Data Privacy Framework, UK International Data Transfer Agreements, or Standard Contractual Clauses with the UK Addendum.
Practitioners keep their own clinical records about you under their own professional obligations — deleting your CONNECT account does not delete a practitioner's clinical records, which they must retain under their regulator's rules.
Under UK GDPR you have the right to:
To exercise any right, use your dashboard settings (data export and account deletion are self-service), visit delete my data, or send us a privacy request. We respond within one calendar month. We will never charge you for a reasonable request.
Not happy with our answer?You have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk or on 0303 123 1113. We would appreciate the chance to put things right first, but you do not have to give us one.
No internet service can promise perfect security, and we do not claim that platform messages are end-to-end encrypted. If we ever discover a breach that risks your rights, we will notify the ICO within 72 hours and tell you directly where the risk is high.
CONNECT is for adults. You must be 18 or over to create an account. We do not knowingly collect data from anyone under 18; if you believe a child has created an account, please contact us and we will remove it.
If we make material changes we will update the date at the top of this page and, where the change significantly affects you, email account holders before it takes effect.