iFALL PRIVACY POLICY

UK PRIVACY NOTICE

Last updated: 11 September 2025

1. WHO WE ARE

iFall is operated by:

iFall UK
trading as iFall
Email for privacy enquiries: support@ifall.co.uk
Website: https://www.ifall.co.uk

For the purposes of UK data protection law, iFall UK is the controller of the personal information described in this Privacy Policy, except where another organisation acts as an independent controller for its own purposes.

2. WHAT THIS POLICY COVERS

This Privacy Policy explains how we collect and use personal information when you:

  • visit ifall.co.uk;
  • contact us;
  • buy an iFall X1;
  • complete pre-delivery setup;
  • create or use an iFall account;
  • use the iFall X1 device or emergency service;
  • ask for support or device reconfiguration; or
  • otherwise deal with us.

Where a purchaser buys an iFall X1 for another person, some information may relate to the wearer rather than the purchaser. The purchaser should ensure the wearer is given this Privacy Policy and has appropriate authority to provide information about the wearer.

3. PERSONAL INFORMATION WE MAY COLLECT

Depending on how you use iFall, we may collect:

Identity and contact information

  • name;
  • email address;
  • telephone number;
  • postal and delivery address;
  • account or customer reference information.

Order and payment information

  • products ordered;
  • quantity and colour;
  • order value;
  • delivery information;
  • payment status;
  • refund or dispute information; and
  • transaction identifiers.

Payment card details are normally collected and processed by our payment provider rather than stored directly by iFall.

Account and setup information

  • login/account information;
  • device serial number or identifier;
  • configuration choices;
  • emergency contacts;
  • support preferences; and
  • information required to configure the device.

Device and technical information

  • device identifiers;
  • connectivity or diagnostic information;
  • alarm status;
  • service logs;
  • timestamps;
  • IP address and browser/device information where applicable.

Location information

  • GPS or other location information generated or supplied in connection with an alarm or locating function, where the service is configured to process it.

Emergency-event information

  • alarm activations;
  • time and date of an event;
  • available location;
  • communications or actions associated with the event;
  • information supplied to emergency services or emergency contacts.

Health and medical information

Where you choose or are required to provide relevant health or medical information for emergency use, we may process information.

Health information is special category personal data and receives additional protection under data protection law.

Contact and support information

  • messages sent through our contact form;
  • emails and other correspondence;
  • support requests;
  • complaint records; and
  • records of device reconfiguration requests.

Website information

  • pages viewed;
  • basic security logs;
  • cookie choices; and
  • other information collected through cookies or similar technologies where used.

4. HOW WE COLLECT INFORMATION

We may collect information:

  • directly from you when you order, contact us or complete setup;
  • from the purchaser where the purchaser is arranging the service for the wearer;
  • from the iFall X1 device and connected systems;
  • from payment, delivery, hosting, communications and support providers;
  • from emergency contacts where they contact us;
  • from emergency services where necessary in connection with an incident; and
  • automatically from the website through necessary cookies, server logs or other permitted technologies.

5. WHY WE USE PERSONAL INFORMATION AND OUR LAWFUL BASES

We must have a lawful basis under UK data protection law for each use of personal information.

We may use personal information for the following purposes.

A. To process orders, take payment, deliver devices and manage refunds

Lawful basis: necessary to enter into or perform a contract with you; and, where relevant, compliance with legal obligations.

B. To create and administer your account and complete device setup

Lawful basis: necessary to enter into or perform a contract with you.

C. To configure and operate the iFall service

Lawful basis: necessary to perform our contract with you.

D. To process an alarm and provide relevant information to emergency services or configured emergency contacts

Lawful basis: performance of our contract where the processing is necessary to provide the service; and, in a genuine emergency, vital interests may also apply where processing is necessary to protect someone's life or physical safety.

E. To process health or medical information

Health information is special category data.

Our intended Article 9 condition for health information supplied during setup is explicit consent where that is the appropriate condition. We will request that consent separately and clearly.

In a genuine emergency, where a person is physically or legally incapable of giving consent and the processing is necessary to protect life, the vital-interests condition may apply.

We will not rely on "vital interests" merely because it is convenient, and it is not a substitute for obtaining explicit consent where consent can reasonably be obtained.

F. To provide customer support, respond to enquiries and handle complaints

Lawful basis: performance of a contract where the enquiry concerns an existing customer or service; and our legitimate interests in responding to enquiries, administering our business and resolving issues.

G. To protect the website, service and customers from fraud, misuse and security threats

Lawful basis: our legitimate interests in maintaining security and preventing fraud, and compliance with legal obligations where applicable.

H. To keep accounting, tax, consumer-law and transaction records

Lawful basis: compliance with legal obligations and our legitimate interests in establishing, exercising or defending legal claims.

I. To improve the service using non-sensitive operational information

Lawful basis: our legitimate interests in understanding service performance and improving reliability, provided those interests are not overridden by your rights and freedoms.

We do not use health information for general advertising or unrelated marketing.

J. Marketing

If we send electronic marketing that requires consent, we will ask for consent or use another lawful route only where permitted by law. You can opt out of marketing at any time.

6. EMERGENCY CONTACTS AND INFORMATION ABOUT OTHER PEOPLE

You may be able to provide information about emergency contacts or another wearer.

You should only provide another person's information where you have a proper reason and authority to do so.

Where appropriate, please tell that person that their information has been provided to iFall and direct them to this Privacy Policy.

We will use emergency-contact information only for purposes connected with the iFall service, safety, support or other purposes explained at the time, unless the law allows or requires otherwise.

7. WHO WE SHARE PERSONAL INFORMATION WITH

We may share personal information where necessary with:

Payment providers

We use Stripe to process payments. Stripe may process payment, transaction, device and fraud-prevention information in accordance with its own privacy information and its role in providing payment services.

Delivery providers

We may provide names, addresses and contact details to couriers or postal providers so they can deliver orders.

Hosting, IT and security providers

We may use providers that host our website, systems, databases, email or security services.

Communications providers

Where the service uses SMS, telephone, internet, mobile-network or other communications services, relevant data may be processed by those providers to transmit communications.

Support and service providers

We may use carefully selected suppliers or contractors to provide technical support, customer support, device services or other operational services.

Emergency services

When an alarm is activated, we may disclose information that is reasonably necessary to assist emergency response, which may include the wearer's identity, location, emergency-event information and relevant medical information.

Emergency contacts

Where configured and appropriate, we may provide relevant alarm or location information to nominated emergency contacts.

Professional advisers and authorities

We may share information with lawyers, accountants, insurers, auditors, regulators, courts, law-enforcement bodies or other authorities where reasonably necessary or legally required.

Business transfers

If our business or relevant assets are sold, reorganised or transferred, personal information may be disclosed to advisers and potential or actual acquirers subject to appropriate protections.

We do not sell personal information to advertisers.

8. STRIPE

We use Stripe for payment processing and related fraud-prevention and payment services.

Stripe may collect information such as your name, email address, billing or shipping address, transaction details, payment-method information, device information and IP address, depending on the payment method and Stripe services used.

Stripe may act as a processor for some activities and as a controller for other activities.

You can read Stripe's privacy information at:

https://stripe.com/gb/privacy

iFall does not need to receive or store your full card number in order to process a standard Stripe payment.

9. APPLE FIND MY

The Apple Find My feature is provided by Apple and is subject to Apple's own terms and privacy practices.

Use of Apple Find My may require a compatible Apple device, account and permissions.

Describe here whether iFall itself receives any location or account data from Apple Find My. Do not state that iFall receives Apple Find My data unless the technical implementation confirms this.

We will never ask you to send your Apple ID password through the iFall website contact form.

10. INTERNATIONAL TRANSFERS

Some suppliers we use may process personal information outside the United Kingdom.

Where UK data protection law treats this as a restricted international transfer, we will use an applicable lawful transfer mechanism, such as:

  • UK adequacy regulations; or
  • an approved safeguard such as the UK International Data Transfer Agreement or UK Addendum, where appropriate.

We will take reasonable steps to ensure that transferred personal information receives an appropriate level of protection.

You may contact us at support@ifall.co.uk for more information about relevant transfer safeguards.

11. HOW LONG WE KEEP INFORMATION

We keep personal information only for as long as reasonably necessary for the purposes described in this Policy, including legal, regulatory, tax, accounting, security and claims requirements.

Our intended retention approach is:

Contact-form and pre-sales enquiries

Normally up to 12 months after the enquiry is closed, unless a longer period is reasonably required.

Order, payment and accounting records

Normally up to 6 years after the end of the relevant financial year or customer relationship where needed for tax, accounting or legal-claims purposes.

Customer account records

For as long as the account or service is active, followed by a limited period where reasonably necessary for support, fraud prevention, legal obligations or claims.

Device configuration records

For as long as the configuration is needed to provide the service, followed by 30 days.

Emergency-event records

3 months

Health and medical information

We aim to keep this only for as long as it is necessary for the emergency service for which it was supplied.

Security logs

Normally for 3 months, unless required for investigation of a security incident or legal claim.

We may retain information for longer where required by law, a court, regulator or a genuine legal claim. Where possible, information no longer needed will be deleted or anonymised.

12. SECURITY

We use reasonable technical and organisational measures designed to protect personal information against unauthorised access, alteration, disclosure, loss or destruction.

Measures may include access controls, authentication, encryption where appropriate, supplier controls, secure payment processing, logging and staff/contractor access restrictions.

No internet-connected service can guarantee absolute security. You should protect your login credentials and tell us promptly if you suspect unauthorised access.

13. YOUR DATA PROTECTION RIGHTS

Depending on the circumstances, UK data protection law may give you the right to:

  • ask for access to your personal information;
  • ask us to correct inaccurate or incomplete information;
  • ask us to erase information in certain circumstances;
  • ask us to restrict processing in certain circumstances;
  • object to certain processing;
  • receive certain information in a portable format;
  • withdraw consent where we rely on consent; and
  • complain about how we use your personal information.

These rights are not absolute and may depend on our lawful basis and the circumstances.

If you withdraw consent, this does not affect the lawfulness of processing carried out before withdrawal.

To exercise a right, contact: support@ifall.co.uk

We may need to verify your identity before acting on a request.

14. YOUR RIGHT TO OBJECT

Where we rely on legitimate interests, you have the right to object to processing in certain circumstances.

You also have an absolute right to object to the use of your personal information for direct marketing.

To object, contact support@ifall.co.uk or use the unsubscribe method provided in a marketing message.

15. COMPLAINTS

Please contact us first if you have a concern about how we use personal information: support@ifall.co.uk

You also have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator.

Information Commissioner's Office:

https://ico.org.uk/

If you are in the Republic of Ireland, separate EU/Irish data-protection rules may apply and you may also have rights involving the Irish Data Protection Commission. Obtain Irish/EU privacy advice before publishing this notice for an actively marketed Irish service.

16. COOKIES AND SIMILAR TECHNOLOGIES

We may use cookies or similar technologies for:

  • essential website operation;
  • security;
  • checkout and payment functionality;
  • remembering user choices; and
  • analytics or other optional purposes if introduced.

Strictly necessary technologies may be used without consent where the law permits.

Where consent is required for non-essential cookies or similar technologies, we will not use them until the required consent has been obtained.

17. ELECTRONIC MARKETING

We will send direct electronic marketing only where permitted by law.

Where consent is required, we will seek a clear opt-in.

You can opt out at any time using the unsubscribe method in the message or by contacting support@ifall.co.uk.

Service messages about your order, account, safety, device or support are not marketing merely because they identify iFall.

18. AUTOMATED DECISION-MAKING

iFall does not currently make decisions about customers based solely on automated processing that produce legal or similarly significant effects.

If this changes, we will update this Policy and provide the information and safeguards required by law.

This statement must be removed or amended if the service later uses automated decision-making of that kind.

19. CHILDREN

Online ordering is intended for adults aged 18 or over.

20. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy when our services, suppliers or legal obligations change.

We will publish the updated version on this page and change the "Last updated" date.

Where a change materially affects how we use existing personal information, we will provide additional notice where required.

21. CONTACT US

For privacy questions, rights requests or complaints, contact:

iFall UK