Walk-A-Cise
Privacy Policy
Last updated: 12 August 2026
This Privacy Policy explains what information Walk-A-Cise ("the App", "we", "us") collects, why we collect it, how it is used and protected, and how you can request that your data be deleted. Walk-A-Cise is a digital exercise therapy app that delivers a prescribed walking exercise programme to people with Peripheral Arterial Disease (PAD).
1. Who We Are
Walk-A-Cise is a digital health service designed to support people with Peripheral Arterial Disease (PAD) and intermittent claudication through a prescribed, structured walking exercise programme. The service is intended to extend the principles of supervised exercise therapy into a digital format by providing patient-facing walking guidance, progress tracking, educational content and, where enabled, a clinician dashboard for reviewing adherence and outcomes.
Supervised exercise therapy is a recommended first-line treatment for people with intermittent claudication because structured walking programmes can improve pain-free walking distance, overall walking ability and quality of life. Walk-A-Cise supports this care model by helping users follow their prescribed programme safely, record activity, complete walking assessments and share relevant progress information with their clinical team where this forms part of their care pathway.
If you have any questions about this Privacy Policy or how your data is handled, contact us at:
Privacy contact: Support@granite.health
For UK data protection purposes, the organisation that determines why and how Walk-A-Cise processes personal data is the data controller. Where Walk-A-Cise is provided through an NHS organisation or another healthcare provider, that organisation is expected to be the controller for patient care records and clinical decision-making. Walk-A-Cise is expected to act as a processor for that healthcare organisation under a written data processing agreement. Where Walk-A-Cise provides the App directly to users outside a healthcare-provider pathway, Walk-A-Cise may act as the controller for account, support, technical and App-use data.
For UK data protection purposes, Walk-A-Cise Ltd is the data controller for personal data processed where the App is provided directly to users. Where Walk-A-Cise is provided through an NHS organisation or another healthcare provider, that organisation is expected to be the controller for patient care records and clinical decision-making, and Walk-A-Cise is expected to act as a processor under a written data processing agreement unless otherwise agreed in writing.
2. Information We Collect
2.1 Account Information
When you register for Walk-A-Cise, we collect information such as your name, email address, and any details needed to link your account to your prescribed exercise programme, which may include information provided by your referring clinician or NHS service.
2.2 Health and Fitness Data
To deliver and track your prescribed exercise programme, Walk-A-Cise collects and processes the following health and fitness data, either entered directly by you or read from Health Connect (Android) or Apple Health (iOS), where you have granted permission:
Steps taken
Walking distance
Walking speed and pace
Exercise session duration and frequency
Heart rate (where a connected device provides this)
Calories burned
Any other activity or exercise data made available through Health Connect or Apple Health that you choose to share with the App, where this is needed to support your prescribed walking programme and help your clinician assess your progress in more detail.
We only request the specific Health Connect or Apple Health data types needed to deliver and monitor your prescribed walking programme. You control which data types the App can access through your device's Health Connect or Apple Health permission settings at any time, and you can withdraw permission without losing access to the App's core features, although this may limit our ability to track your progress accurately.
The App may use your device's GPS/location services during walking sessions to help measure activity accurately and support your walking programme. We do not store GPS location data, retain route maps, or show walking routes in the App. Location access is used only while needed for walking-session functionality, and you can manage or withdraw location permission through your device settings.
Where the App accesses Health Connect or Apple Health data, it does so only after you grant permission through your device. We request permission only for data types needed to deliver the walking programme, explain the purpose of each requested data type in the App, and do not use Health Connect or Apple Health data for advertising, profiling, sale, data brokering, or purposes unrelated to providing the health and fitness features you have chosen to use.
2.3 Device and Usage Information
We collect limited technical information such as device type, operating system version, and app usage/crash data, used only to keep the App working reliably and to diagnose technical issues.
If we use analytics or crash-reporting tools, we configure them to collect the minimum information needed to diagnose faults, monitor service performance, and improve safety and reliability. We do not permit analytics or crash-reporting providers to use Walk-A-Cise health data for their own advertising or unrelated commercial purposes.
Assumption for publication draft: Walk-A-Cise does not use advertising analytics, behavioural advertising SDKs or data-brokering tools. If crash reporting is enabled, it is used only to diagnose faults and improve service reliability. The specific crash-reporting provider, if any, must be confirmed before publication and listed in this policy.
3. Health Data — Why We Collect It, How It Is Used, and How It Is Protected
Why we collect it
Your health and activity data is collected to deliver the core purpose of Walk-A-Cise: providing a personalised, prescribed walking exercise programme for the management of Peripheral Arterial Disease, tracking your progress against that programme, and giving you and, where applicable, your prescribing clinician visibility of your adherence and outcomes.
How we use it
To build and adjust your personalised exercise plan
To track your progress and show you your activity history within the App
To share progress and adherence information with your prescribing clinician or NHS service, where your care pathway requires this
To support clinical audit and service improvement, using de-identified or aggregated data wherever possible
We do not use your health data for advertising, and we do not sell your health data to any third party.
We apply data minimisation and purpose limitation: we collect the least amount of personal and health data required for the service, use it only for the purposes described in this policy, and keep privacy settings under regular review.
Whether it is shared with third parties
Your health data may be shared with:
Your prescribing clinician or the NHS service that referred you to Walk-A-Cise, where relevant to your ongoing care
Cloud hosting and infrastructure providers who store data on our behalf under contract, and who are not permitted to use it for their own purposes
Health Connect (Android) or Apple Health (iOS) itself, as the platform through which certain data is read, subject to the permissions you grant at device level
Walk-A-Cise uses a contracted cloud hosting provider with data hosted in the UK or EEA, and the provider acts only as a processor under written contract. The specific hosting provider, support tools, email tools and any subprocessors is GraniteXS whom we ahve a data Processing agreement.
We do not share your health data with any third party for marketing purposes, and we do not sell it.
How it is protected
Health data is encrypted in transit and at rest
Access to identifiable health data is restricted to staff and systems that need it to provide or support the service, on a role-based, least-privilege basis
All access to health data is logged and auditable
Data is held on servers located in the UK / EEA
Data is hosted in the UK or EEA and is protected using encryption, access controls, audit logs and least-privilege access. Do not state Cyber Essentials Plus, ISO 27001 or any other certification unless it has been verified.
4. Our Lawful Basis for Processing
Health data is 'special category data' under UK GDPR. We process it on the basis of:
Article 9(2)(h) — provision of health or social care, where your use of the App forms part of a prescribed care pathway; and/or
Article 9(2)(a) — your explicit consent, where you use the App outside of a formal NHS referral pathway.
Other personal data is processed using the lawful basis that best fits the activity: Article 6(1)(b) where processing is necessary to provide the App to you; Article 6(1)(c) where we must comply with a legal obligation; Article 6(1)(e) where processing is carried out in the public task of an NHS or public-sector healthcare organisation; and/or Article 6(1)(f) where we have a legitimate interest in operating, securing and improving the service and that interest is not overridden by your rights and freedoms.
Where we rely on consent or explicit consent, you can withdraw that consent at any time through the App permissions, your device health-data settings, or by contacting us. Withdrawal of consent does not affect processing already carried out before withdrawal, but it may limit our ability to provide some App features.
Assumption for publication draft: where Walk-A-Cise is used as part of a healthcare-provider pathway, special category health data is processed for the provision of health or social care under Article 9(2)(h), with the relevant Data Protection Act 2018 Schedule 1 condition and appropriate policy documentation maintained by the controller where required. Where Walk-A-Cise is used directly by a user outside such a pathway, explicit consent may be relied on for relevant optional health-data processing.
5. How Long We Keep Your Data
We retain personal data only for as long as necessary for the purpose for which it was collected, including providing the App, supporting clinical care, meeting legal and regulatory obligations, resolving disputes, maintaining security, and keeping appropriate audit records. Where Walk-A-Cise data forms part of a healthcare record, retention should follow the applicable NHS Records Management Code of Practice or the retention policy of the relevant healthcare controller.
Active account, profile and App activity data is retained while the account remains active. After account deletion or confirmed account closure, personal data is deleted from active systems within one month unless a longer retention period is required by law, clinical governance, audit, dispute resolution or the relevant healthcare controller's records policy. Encrypted backups may retain deleted data for up to 90 days before permanent purge through the normal backup cycle. De-identified or aggregated analytics may be retained for service evaluation and improvement where individuals can no longer reasonably be identified. Where Walk-A-Cise is used by an NHS organisation, retention will also follow that organisation's applicable records-management requirements.
6. Deleting Your Account and Data (right to be forgotten)
You can request deletion of your Walk-A-Cise account and the personal and health data associated with it at any time.
How to request deletion
In the App: go to Settings > Account > Delete My Account, and follow the on-screen instructions.
By email: contact us at support@granite.health with the subject line “Account Deletion Request”, including the email address associated with your account so we can verify your identity.
What happens when you request deletion
We will verify your identity before actioning the request, to prevent someone else deleting your account.
Your account, profile information, and health and exercise data will be permanently deleted from our active systems.
Where we are required by law or NHS clinical record-keeping obligations to retain certain records, we will retain only what is legally required, for no longer than necessary, and will tell you if this applies to your request.
Data may remain in encrypted backups for a limited period after deletion, after which it is permanently purged as part of our normal backup cycle.
Timeframe
We normally respond to deletion and other data-rights requests without undue delay and within one month of verifying your identity. If a request is complex or we receive multiple requests, we may extend this by up to two further months where permitted by law, and we will explain the reason for any extension.
7. Data Security
We use appropriate technical and organisational measures to protect your data, including encryption, access controls, audit logging, and regular security testing. No system can be guaranteed 100% secure, but we work to identify and address risks on an ongoing basis.
We maintain technical and organisational safeguards appropriate to the sensitivity of health data, including staff confidentiality obligations, supplier due diligence, data processing agreements with processors, regular access reviews, secure development practices, incident response procedures, and breach assessment and notification processes. Where a personal data breach is likely to result in a risk to individuals' rights and freedoms, we will notify the Information Commissioner's Office within the required timeframe and inform affected individuals where required by law.
Before launching or materially changing Walk-A-Cise, we assess privacy risks, including whether a Data Protection Impact Assessment is required, particularly because the service processes special category health data and may involve monitoring of exercise behaviour over time.
A Data Protection Impact Assessment, clinical safety assessment, NHS DTAC evidence pack, Data Security and Protection Toolkit assessment and any medical-device regulatory assessment should be completed or explicitly documented as not applicable before live deployment. This policy should not be treated as evidence that those assessments have already been completed.
8. Your Rights
Under UK GDPR, you have the right to:
Access the personal data we hold about you
Have inaccurate data corrected
Request erasure of your data (see Section 6)
Restrict or object to certain processing
Receive your data in a portable format
Withdraw consent at any time, where consent is our lawful basis for processing
Complain to the Information Commissioner's Office (ICO) if you believe your data has been handled improperly
To exercise any of these rights, contact us using the details in Section 1.
You also have the right to complain to the Information Commissioner's Office, the UK's supervisory authority for data protection. We encourage you to contact us first so we can try to resolve your concern, but you may contact the ICO at any time.
9. International Transfers
We aim to store and process Walk-A-Cise personal data in the UK or EEA. If any personal data is transferred outside the UK or EEA, we will ensure that appropriate safeguards are in place, such as an adequacy decision, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism. We currently do not do this.
Walk-A-Cise stores and processes personal data in the UK or EEA and does not intentionally transfer personal data outside the UK or EEA. If any supplier or subprocessor processes data outside the UK or EEA, Walk-A-Cise will document the transfer and use an appropriate lawful transfer safeguard before that processing begins.
10. Children's Privacy
Walk-A-Cise is intended for adults using a clinically prescribed walking exercise programme. It is not directed at children and should not be used by anyone under 18 unless a healthcare organisation has specifically approved that use and the required parental responsibility, consent, safeguarding and clinical governance arrangements are in place. If you believe a child's data has been provided to us, please contact us so we can review and remove it where appropriate.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Where changes are significant, we will notify you in the App or by email before they take effect. The "Last updated" date at the top of this policy shows when it was last revised.
12. Contact Us
If you have any questions about this Privacy Policy, or wish to exercise any of your rights, please contact:
Privacy contact: Support@granite.health FAO WAC. ICO Registration
Registration reference
ZB249064
Date registered
22 October 2021
Registration expires
21 October 2026
Payment tier
Tier 1
Data controller
Walk-A-Cise Ltd
Final Verification
Walk-A-Cise project team is named as the interim service operator until the legal entity, company or charity number, registered address and ICO registration number are confirmed.
Drafted assumption: NHS or healthcare providers are controllers for patient care records and clinical decision-making; Walk-A-Cise acts as processor under written data processing agreement for provider deployments; Walk-A-Cise may act as controller for direct-to-user account, support, technical and App-use data.
no advertising analytics, behavioural advertising SDKs, data-brokering tools or marketing use of health data are used.
Crash reporting, if enabled, is limited to fault diagnosis and service reliability, and the provider must be named before publication.
Cloud hosting is in the UK or EEA under a processor contract; the exact hosting provider, support tools, email tools and subprocessors must be confirmed before publication.
Active account data is retained while the account is active; deletion from active systems occurs within one month after verified deletion request or closure, subject to legal, audit or clinical-record obligations; encrypted backups are purged within up to 90 days.
Health Connect and Apple Health permissions are used only for the walking programme and must match the App Store, Google Play and in-app disclosure wording before release.
DPIA, clinical safety, NHS DTAC, DSPT and any medical-device/regulatory assessment Has been completed and we comply