UK PRIVACY NOTICE
Last updated: 11 September 2025
iFall is operated by:
For the purposes of UK data protection law, iFall UK is the controller of the personal information described in this Privacy Policy, except where another organisation acts as an independent controller for its own purposes.
This Privacy Policy explains how we collect and use personal information when you:
Where a purchaser buys an iFall X1 for another person, some information may relate to the wearer rather than the purchaser. The purchaser should ensure the wearer is given this Privacy Policy and has appropriate authority to provide information about the wearer.
Depending on how you use iFall, we may collect:
Payment card details are normally collected and processed by our payment provider rather than stored directly by iFall.
Where you choose or are required to provide relevant health or medical information for emergency use, we may process information.
Health information is special category personal data and receives additional protection under data protection law.
We may collect information:
We must have a lawful basis under UK data protection law for each use of personal information.
We may use personal information for the following purposes.
Lawful basis: necessary to enter into or perform a contract with you; and, where relevant, compliance with legal obligations.
Lawful basis: necessary to enter into or perform a contract with you.
Lawful basis: necessary to perform our contract with you.
Lawful basis: performance of our contract where the processing is necessary to provide the service; and, in a genuine emergency, vital interests may also apply where processing is necessary to protect someone's life or physical safety.
Health information is special category data.
Our intended Article 9 condition for health information supplied during setup is explicit consent where that is the appropriate condition. We will request that consent separately and clearly.
In a genuine emergency, where a person is physically or legally incapable of giving consent and the processing is necessary to protect life, the vital-interests condition may apply.
We will not rely on "vital interests" merely because it is convenient, and it is not a substitute for obtaining explicit consent where consent can reasonably be obtained.
Lawful basis: performance of a contract where the enquiry concerns an existing customer or service; and our legitimate interests in responding to enquiries, administering our business and resolving issues.
Lawful basis: our legitimate interests in maintaining security and preventing fraud, and compliance with legal obligations where applicable.
Lawful basis: compliance with legal obligations and our legitimate interests in establishing, exercising or defending legal claims.
Lawful basis: our legitimate interests in understanding service performance and improving reliability, provided those interests are not overridden by your rights and freedoms.
We do not use health information for general advertising or unrelated marketing.
If we send electronic marketing that requires consent, we will ask for consent or use another lawful route only where permitted by law. You can opt out of marketing at any time.
You may be able to provide information about emergency contacts or another wearer.
You should only provide another person's information where you have a proper reason and authority to do so.
Where appropriate, please tell that person that their information has been provided to iFall and direct them to this Privacy Policy.
We will use emergency-contact information only for purposes connected with the iFall service, safety, support or other purposes explained at the time, unless the law allows or requires otherwise.
We may share personal information where necessary with:
We use Stripe to process payments. Stripe may process payment, transaction, device and fraud-prevention information in accordance with its own privacy information and its role in providing payment services.
We may provide names, addresses and contact details to couriers or postal providers so they can deliver orders.
We may use providers that host our website, systems, databases, email or security services.
Where the service uses SMS, telephone, internet, mobile-network or other communications services, relevant data may be processed by those providers to transmit communications.
We may use carefully selected suppliers or contractors to provide technical support, customer support, device services or other operational services.
When an alarm is activated, we may disclose information that is reasonably necessary to assist emergency response, which may include the wearer's identity, location, emergency-event information and relevant medical information.
Where configured and appropriate, we may provide relevant alarm or location information to nominated emergency contacts.
We may share information with lawyers, accountants, insurers, auditors, regulators, courts, law-enforcement bodies or other authorities where reasonably necessary or legally required.
If our business or relevant assets are sold, reorganised or transferred, personal information may be disclosed to advisers and potential or actual acquirers subject to appropriate protections.
We do not sell personal information to advertisers.
We use Stripe for payment processing and related fraud-prevention and payment services.
Stripe may collect information such as your name, email address, billing or shipping address, transaction details, payment-method information, device information and IP address, depending on the payment method and Stripe services used.
Stripe may act as a processor for some activities and as a controller for other activities.
You can read Stripe's privacy information at:
iFall does not need to receive or store your full card number in order to process a standard Stripe payment.
The Apple Find My feature is provided by Apple and is subject to Apple's own terms and privacy practices.
Use of Apple Find My may require a compatible Apple device, account and permissions.
Describe here whether iFall itself receives any location or account data from Apple Find My. Do not state that iFall receives Apple Find My data unless the technical implementation confirms this.
We will never ask you to send your Apple ID password through the iFall website contact form.
Some suppliers we use may process personal information outside the United Kingdom.
Where UK data protection law treats this as a restricted international transfer, we will use an applicable lawful transfer mechanism, such as:
We will take reasonable steps to ensure that transferred personal information receives an appropriate level of protection.
You may contact us at support@ifall.co.uk for more information about relevant transfer safeguards.
We keep personal information only for as long as reasonably necessary for the purposes described in this Policy, including legal, regulatory, tax, accounting, security and claims requirements.
Our intended retention approach is:
Normally up to 12 months after the enquiry is closed, unless a longer period is reasonably required.
Normally up to 6 years after the end of the relevant financial year or customer relationship where needed for tax, accounting or legal-claims purposes.
For as long as the account or service is active, followed by a limited period where reasonably necessary for support, fraud prevention, legal obligations or claims.
For as long as the configuration is needed to provide the service, followed by 30 days.
3 months
We aim to keep this only for as long as it is necessary for the emergency service for which it was supplied.
Normally for 3 months, unless required for investigation of a security incident or legal claim.
We may retain information for longer where required by law, a court, regulator or a genuine legal claim. Where possible, information no longer needed will be deleted or anonymised.
We use reasonable technical and organisational measures designed to protect personal information against unauthorised access, alteration, disclosure, loss or destruction.
Measures may include access controls, authentication, encryption where appropriate, supplier controls, secure payment processing, logging and staff/contractor access restrictions.
No internet-connected service can guarantee absolute security. You should protect your login credentials and tell us promptly if you suspect unauthorised access.
Depending on the circumstances, UK data protection law may give you the right to:
These rights are not absolute and may depend on our lawful basis and the circumstances.
If you withdraw consent, this does not affect the lawfulness of processing carried out before withdrawal.
To exercise a right, contact: support@ifall.co.uk
We may need to verify your identity before acting on a request.
Where we rely on legitimate interests, you have the right to object to processing in certain circumstances.
You also have an absolute right to object to the use of your personal information for direct marketing.
To object, contact support@ifall.co.uk or use the unsubscribe method provided in a marketing message.
Please contact us first if you have a concern about how we use personal information: support@ifall.co.uk
You also have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator.
Information Commissioner's Office:
If you are in the Republic of Ireland, separate EU/Irish data-protection rules may apply and you may also have rights involving the Irish Data Protection Commission. Obtain Irish/EU privacy advice before publishing this notice for an actively marketed Irish service.
We may use cookies or similar technologies for:
Strictly necessary technologies may be used without consent where the law permits.
Where consent is required for non-essential cookies or similar technologies, we will not use them until the required consent has been obtained.
We will send direct electronic marketing only where permitted by law.
Where consent is required, we will seek a clear opt-in.
You can opt out at any time using the unsubscribe method in the message or by contacting support@ifall.co.uk.
Service messages about your order, account, safety, device or support are not marketing merely because they identify iFall.
iFall does not currently make decisions about customers based solely on automated processing that produce legal or similarly significant effects.
If this changes, we will update this Policy and provide the information and safeguards required by law.
This statement must be removed or amended if the service later uses automated decision-making of that kind.
Online ordering is intended for adults aged 18 or over.
We may update this Privacy Policy when our services, suppliers or legal obligations change.
We will publish the updated version on this page and change the "Last updated" date.
Where a change materially affects how we use existing personal information, we will provide additional notice where required.
For privacy questions, rights requests or complaints, contact: