Politique de confidentialité

Last updated: 26 August 2026

This Privacy Policy explains how HeadX Limited ("HeadX", "we", "us" or "our") collects, uses and shares personal information when you use www.headx.co.uk and its online store (the "Site"), contact us, receive marketing from us, or use the HeadX Duo mobile application and device (together, the "Services").

1. Who we are

HeadX Limited is the controller of the personal information described in this policy, except where another organisation is responsible for its own use of information.

HeadX Limited
Company number: 14057125
The Business Centre
Spring Mill Business Park
Avening Road
Nailsworth
Stroud
Gloucestershire
GL6 0BS
United Kingdom
Email: contact@headx.co.uk

2. Personal information we collect

The information we collect depends on how you interact with HeadX.

Information you provide

  • Identity and contact information: such as your name, billing and delivery address, email address and telephone number.
  • Account information: information used to create and manage a customer account, if you choose to create one.
  • Order and transaction information: products ordered, order history, payment status, delivery details, returns and refunds. Payment card details are handled by Shopify and the relevant payment provider; HeadX does not receive the full card number.
  • Enquiry and support information: messages, product enquiries, organisation, country, professional role, intended use, product or clinical interest, discovery source, relevant page or product selection, support requests, warranty claims, complaints and any files you choose to provide.
  • Marketing information: subscriptions, role and interest selections, preferences, campaign responses and records of consent or objection.
  • Reviews and other content: information you choose to include in a product review, survey or other submission.

Information collected automatically

  • Device and network information: such as IP address, browser and device type, operating system, language, approximate location derived from IP address, and security identifiers.
  • Site activity: pages and products viewed, searches, referral source, interactions with the basket and checkout, purchases, and the date and time of activity.
  • Cookie and privacy choices: consent selections and information collected through cookies, pixels and similar technologies as described below.

Information received from others

We may receive transaction status from Shopify and payment providers, delivery status from delivery providers, referral information from affiliate or campaign partners, and information supplied through services you choose to use. We may combine this with information you provide where necessary for the purposes described in this policy.

3. HeadX Duo App and movement data

When the HeadX Duo App is used with the Duo device, its sensors generate angular movement and related session information. The App automatically calculates measurement summaries for display to the user. Full raw device telemetry is recorded only when Research Mode is enabled; Head Stability also stores a processed movement-sample series for its normal summary and visualisation.

  • Local processing and storage: session and movement data is processed and stored locally on the phone or tablet running the App. It is not automatically transmitted to, accessed by or backed up by HeadX.
  • Export: if a user chooses an export or sharing function, the information is sent only to the destination selected by that user. The App does not send the report to HeadX unless the user separately chooses to send it to us.
  • Permissions: the App uses Bluetooth or Nearby Devices permission to connect to Duo. On Android versions that require location permission for Bluetooth scanning, that permission may also be requested. HeadX does not use it to track or store GPS location.
  • Deletion and local retention: the App does not automatically expire stored sessions. Users can delete individual sessions or use the available clear-all control for assessment records. Generated reports or exported files, copies shared to another service, App settings and device backups may need to be deleted separately.

The person or organisation using the App is responsible for managing access, retention, sharing and any patient or participant information held on its device. Please do not send patient-identifiable or health information to HeadX through ordinary support channels; use anonymised information wherever possible. HeadX does not ask for such information for routine product support. If we receive it inadvertently, we will restrict access and delete or return it as soon as reasonably practicable, unless retention is necessary for the establishment, exercise or defence of legal claims. In that limited case, we rely on the applicable Article 6 lawful basis and the condition in Article 9(2)(f) of the UK GDPR.

4. How and why we use personal information

UK data-protection law requires us to have a lawful basis for each use of personal information. Depending on the circumstances, we use information for the following purposes and bases:

  • To take and fulfil orders: including payment, delivery, order updates, returns and account administration. This is necessary to perform a contract with you or take steps at your request before entering a contract.
  • To provide product support and handle warranty claims, complaints and rights: this may be necessary to perform a contract, comply with legal obligations, or pursue our legitimate interests in supporting customers and keeping appropriate records.
  • To respond to enquiries and arrange demonstrations: this is necessary to take steps at your request and for our legitimate interest in communicating about our products and services.
  • To operate, secure and troubleshoot the Site and Services: we rely on legitimate interests in keeping our services reliable, preventing fraud, protecting users and diagnosing faults, and on legal obligations where applicable.
  • To understand and improve the Site, products and communications: we rely on legitimate interests for proportionate service analysis and improvement, and on consent where non-essential cookies or similar technologies require it.
  • To send marketing: for email or text marketing to individual subscribers, we rely on consent or the products-and-services soft opt-in where all its conditions are met. For corporate subscribers, we may rely on legitimate interests following an appropriate balancing assessment. You may object to direct marketing at any time.
  • To manage reviews, referrals and affiliate activity: we rely on consent where required and otherwise on legitimate interests in operating these programmes, preventing misuse and measuring performance.
  • To comply with law and protect legal rights: including tax, accounting, consumer-protection, product-safety, regulatory and law-enforcement requirements, and the establishment, exercise or defence of legal claims.

Where we rely on legitimate interests, we consider the necessity and proportionality of the use and balance it against your rights and reasonable expectations.

You must provide the identity, contact, payment and order information needed to place and fulfil an order. If you do not provide it, we cannot complete the purchase or deliver the product. Other information is optional unless we explain otherwise when collecting it.

5. Cookies, pixels and similar technologies

We use technologies that are necessary to operate the Site, including the basket, checkout, security and language functions. We also use optional technologies for personalisation, analytics, marketing, advertising measurement, reviews and referral attribution.

Where consent is required, non-essential technologies are used only after you make a choice. When displayed, the Site's cookie controls allow you to accept, decline or manage categories including personalisation, marketing and analytics. You can also use privacy settings provided by your browser or device and contact us for help with a consent choice. Withdrawing consent does not affect processing carried out before withdrawal.

Our current Site integrations include services provided by Shopify, Shopify Forms, Google and YouTube, Meta (Facebook and Instagram), OpenAI Ads, HubSpot, Brevo/PushOwl, Judge.me, Shopify Collabs, BixGrow, UpPromote, ReferrLy and Product Rentals Pro. The services that operate on a particular visit depend on the page, your location and your privacy choices. Providers may change as our services develop; we review this policy and our consent settings when material changes occur.

6. Shopify and enhanced services

The Site and store are hosted by Shopify. Shopify processes information when you visit the Site, use Shopify-powered features or make a purchase. Shopify Network Intelligence is enabled for our store. This allows Shopify to use customer information together with information from interactions with Shopify and other merchants to provide and improve services such as analytics, personalisation, advertising and fraud prevention. Other merchants do not receive access to HeadX customer information through this feature.

Where applicable, Shopify respects consent and opt-out signals submitted through compatible privacy controls. For more information, read Shopify's Consumer Privacy Policy and use the Shopify Privacy Portal to manage choices relating to Shopify's own processing.

7. Who we share information with

We share only the information reasonably necessary for the relevant purpose. Recipients may include:

  • Shopify and providers supporting our store, customer accounts, checkout and platform services;
  • payment, fraud-prevention, delivery and returns providers;
  • hosting, communications, customer-support, security and professional IT providers;
  • analytics, advertising, CRM, review, referral and affiliate providers, subject to applicable consent and opt-out requirements;
  • professional advisers, insurers, auditors and regulators;
  • courts, law-enforcement bodies or public authorities where disclosure is required or permitted by law; and
  • a buyer, investor or adviser in connection with a proposed or completed sale, restructuring or transfer of all or part of our business, subject to appropriate safeguards.

We do not sell personal information for money. Some privacy laws use the terms "sale", "sharing" or "targeted advertising" more broadly for certain advertising or analytics disclosures. Where those laws apply, we honour the relevant consent and opt-out rights. You can contact us to exercise them, and you can use the Shopify Privacy Portal for Shopify's own processing.

8. International transfers

Some providers may process personal information outside the UK. If this involves a restricted transfer under UK data-protection law, we ensure that it is covered by an applicable UK adequacy regulation, an appropriate safeguard such as the UK International Data Transfer Agreement or the UK Addendum to approved contractual clauses, or another mechanism permitted by law. Where required, we also assess whether additional protections are needed.

You may contact us for information about the transfer arrangement relevant to your personal information.

9. Retention

We keep personal information only for as long as it is needed for the purpose for which it was collected, including complying with legal obligations, resolving disputes and establishing, exercising or defending legal claims.

We use the following retention criteria:

  • order and transaction records are retained for the period required by applicable accounting, tax, consumer-protection and product-safety obligations;
  • marketing contact details and preferences are retained until you withdraw consent or object, after which we may retain a minimal suppression record so that we respect your choice;
  • support, rights-request, warranty and complaint correspondence is retained for as long as needed to deal with the matter and demonstrate how it was handled;
  • technical and security information is retained only for as long as required for security, fault diagnosis and service operation; and
  • information stored locally by the App remains under the control of the user or organisation operating the device and can be deleted using the available App or device controls, subject to device backup settings.

We review retained information and delete or anonymise it when it is no longer needed.

10. Security

We use appropriate technical and organisational measures designed to protect personal information against accidental or unlawful loss, alteration, disclosure or access. No internet or storage system can be guaranteed completely secure. Security of information stored locally by the App also depends on the phone or tablet and on the user's or organisation's access, backup and device-security settings. You should protect account and device credentials and contact us if you suspect unauthorised access.

11. Your rights

Depending on the purpose and lawful basis for our use, you may have the right to:

  • be informed about how your personal information is used;
  • request access to it;
  • have inaccurate or incomplete information corrected;
  • request erasure;
  • request restriction of processing;
  • object to processing;
  • receive information you provided in a portable format; and
  • withdraw consent at any time, without affecting processing carried out before withdrawal.

These rights are not absolute and may not apply in every circumstance. To exercise a right, email contact@headx.co.uk or write to the postal address above. We may need to verify your identity before acting on a request.

Your right to object to direct marketing: You may object at any time to our use of your personal information for direct marketing. Use the unsubscribe link in a marketing message or contact us at contact@headx.co.uk. We will stop using your information for that purpose.

12. Automated decisions

We may use consented analytics and marketing information to measure campaigns or personalise advertising. The App calculates and displays measurement summaries. HeadX does not use those outputs to make decisions about users and does not make solely automated decisions that produce legal or similarly significant effects.

13. Children's information

The online store and customer-account features are intended for adults. The HeadX Duo App stores session data locally and does not automatically send children's session information to HeadX.

The clinician, organisation, parent or other responsible adult using the App is responsible for the lawful handling of information on the device. We do not knowingly use children's personal information for direct marketing. If you believe a child has provided personal information directly to HeadX, contact us so that we can take appropriate action.

14. Data-protection complaints

If you believe we have not handled your personal information in accordance with data-protection law, email contact@headx.co.uk with "Data protection complaint" in the subject line, or write to the postal address above.

We will acknowledge your complaint within 30 days, make appropriate enquiries, keep you informed where necessary and tell you the outcome without undue delay.

If you are dissatisfied with our response, you may complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or telephone 0303 123 1113.

15. Changes to this policy

We review this policy regularly. If we materially change how we use personal information, we will take reasonable steps to bring the change to the attention of affected people before the new use begins, where required by law. We will also update the "Last updated" date above.

16. Contact

For privacy questions, rights requests or complaints, email contact@headx.co.uk or write to HeadX Limited at the address in section 1.