← Back to PARTICULAR

Privacy Policy

Effective 7 April 2026 · Astra Castra Ltd

Introduction

Astra Castra Ltd (company number 17077201), trading as PARTICULAR (“PARTICULAR”, “we”, “us”, “our”), operates the website particular.health and provides personalised food supplement products and related services (the “Services”). This Privacy Policy describes how we collect, use, disclose and protect your personal information when you visit our website, use our Services, make a purchase, or otherwise communicate with us.

We are committed to protecting and respecting your privacy. This policy outlines the basis on which any personal data we collect will be processed by us. By visiting our website, using our Services, or otherwise providing us with your personal information, it will be processed as described in this policy.

Please read this Privacy Policy carefully. If there is a conflict between our Terms & Conditions and this Privacy Policy, this Privacy Policy controls with respect to the collection, processing and disclosure of your personal information.

1. Who we are

Astra Castra Ltd, trading as PARTICULAR, is the data controller for personal data collected through particular.health for the purposes of the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018 (“DPA 2018”).

Registered office: 128 City Road, London EC1V 2NX.
Company number: 17077201.
Contact us with privacy questions at privacy@particular.health.

2. Personal information we collect

When we use the term “personal information”, we are referring to information that identifies or can reasonably be linked to you. Personal information does not include information that has been anonymised or aggregated so that it cannot identify you. We may collect the following categories of personal information depending on how you interact with our Services:

CategoryExamples
IdentityFirst name, last name, date of birth, biological sex
ContactEmail address, phone number, shipping address
Health & lifestyleSelf-reported questionnaire answers including health goals, diet, lifestyle factors, medical conditions, current medications, allergies, pregnancy and menopause status. Used solely for formula personalisation.
BiometricHeight and weight (self-reported)
FinancialStripe payment token, billing address. We never store or have access to your full card number.
AccountAuthentication ID, account creation date, formula history, order history
TechnicalIP address, browser type, device information, pages visited
CommunicationsInformation you include in messages to our customer support
Consent recordsIP address and timestamp when you agree to our privacy policy, terms, and marketing preferences

3. How we collect your information

We collect personal information from the following sources:

  • Directly from you — when you complete our health questionnaire, create an account, place an order, sign up for our email list, contact customer support, or otherwise provide information to us.
  • Automatically — when you visit our website, we collect technical information such as your IP address, browser type and pages visited through server logs and anonymised analytics tools.
  • From our service providers — our payment processor (Stripe) and authentication provider (Clerk) may provide us with information necessary to deliver our Services.
  • From clinic partners — if your account is created by a clinic partner on your behalf, they may provide us with your identity and contact information.

We may also collect, use and share aggregated data such as statistical or demographic data for any purpose. Aggregated data could be derived from your personal data but is not considered personal data in law as it will not directly or indirectly reveal your identity. For example, we may aggregate questionnaire responses to understand what health goals are most common among our users. However, if we combine aggregated data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data in accordance with this policy.

4. How we use your data

Depending on how you interact with us, we may use your personal data for the following purposes:

  • Provide and deliver our Services — generate your personalised supplement formula based on your questionnaire answers, process your order, arrange manufacturing and shipping, manage your subscription, and maintain your account and formula history so you can re-order.
  • Transactional communications — send order confirmations, dispatch notifications, subscription renewal reminders, and payment failure alerts. These are essential to delivering our Services and cannot be opted out of.
  • Lifecycle communications — send onboarding guidance, formula reviews, reorder reminders, and post-purchase follow-ups. You can unsubscribe from these at any time via the one-click link in each email.
  • Marketing — with your explicit consent, send promotional offers and product updates. You can withdraw consent at any time by clicking the unsubscribe link in any email or contacting us.
  • Security and fraud prevention — detect, investigate and prevent fraudulent, illegal or malicious activity, and protect the security of our Services.
  • Service improvement — monitor anonymised site performance and page views to improve our website and Services.
  • Legal compliance — comply with applicable law, including financial record-keeping requirements, and respond to lawful requests from authorities.

Clinic-created accounts: If your account was created by a clinic partner on your behalf, you will receive a notice explaining how your data is processed, in accordance with Article 14 of the UK GDPR.

5. Legal bases for processing

We process your personal data under the following legal bases:

  • Performance of a contract — to provide personalised supplement products and services tailored to you, process your payments, fulfil your orders, and manage your subscription.
  • Explicit consent (Article 9(2)(a)) — your health and lifestyle questionnaire answers may constitute special category data under the UK GDPR. By completing the questionnaire, you give explicit consent to our processing of this data solely for the purpose of generating your personalised formula. This data is never shared with third parties in identifiable form; our manufacturer receives only ingredient codes and doses, not your health information.
  • Consent — for marketing communications and any non-essential cookies (where required).
  • Legitimate interests — fraud prevention, service improvement, anonymised performance monitoring, and security. We balance our interests against your rights and do not process where your interests override ours.
  • Legal obligation — maintaining financial records as required by HMRC and complying with other regulatory requirements.

6. How we disclose your information

In certain circumstances, we may disclose your personal information to third parties for legitimate purposes subject to this Privacy Policy. Such circumstances include:

  • Service providers — third-party processors who assist us with payment processing, manufacturing, shipping, email delivery, authentication, hosting and analytics (see Section 7 for full list).
  • Legal requirements — we may disclose your data to comply with legal obligations, respond to lawful requests by public authorities (including law enforcement), or protect our rights, privacy, safety or property.
  • Business transfers — if we undergo a merger, acquisition, reorganisation, sale of assets, or bankruptcy, your personal data may be transferred as part of that transaction. We will notify you of any such change and any choices you may have.
  • With your consent — where you direct or request us to share your information with a third party.

We do not sell your personal data to any third party. We do not share your data with third parties for their own marketing purposes.

7. Third-party processors

We share data with the following processors only to the extent necessary to deliver our Services:

ProcessorPurpose & location
StripePayment processing & subscription management (UK/US)
ClerkUser authentication & session management (US, SCCs in place)
SupabaseDatabase hosting — EU region (AWS Frankfurt)
VercelWebsite hosting & cookieless performance analytics — EU edge (GDPR DPA in place)
Shift Management GmbHSupplement manufacturing & fulfilment (Germany, DPA in place). Receives: customer name, shipping address, anonymised order code, ingredient formula. Does not receive questionnaire answers or health data.
ResendTransactional & lifecycle email delivery (US, DPA in place)
ShippoShipping label generation & parcel tracking (US)
Google AnalyticsAggregated website analytics with anonymised IP addresses (US, SCCs in place). Only loaded if you opt in via our cookie banner.
Microsoft ClarityAnonymised session recordings and heatmaps for improving site usability (US, SCCs in place). Only loaded if you opt in via our cookie banner.
Meta (Facebook)Conversion tracking and audience matching for advertising campaigns (US, SCCs in place). Only loaded if you opt in to marketing cookies via our cookie banner.

Each processor is contractually bound to process your data only on our instructions and in accordance with applicable data protection law. We conduct due diligence on all processors before engaging them and review their practices periodically.

8. International transfers

Some of our processors are based outside the United Kingdom (see Section 7). Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the ICO, or reliance on the processor’s compliance with an adequate data protection framework as recognised by the UK Government.

You can contact us at privacy@particular.health for more information about the specific safeguards applied to the transfer of your personal data.

9. Automated decision-making

Your personalised formula is generated by an automated system based on your questionnaire answers. This automated processing determines which ingredients and doses are included in your supplement blend. All formulas are produced within UK Expert Group on Vitamins and Minerals (EVM) and SACN safe upper level guidelines.

You can review and adjust any ingredient dose before purchasing. You have the right to request human review of your formula at any time by contacting us at hello@particular.health.

10. Data retention

How long we retain your personal information depends on different factors, including whether we need the information to maintain your account, provide our Services, comply with legal obligations, or resolve disputes:

  • Account and formula data — retained for as long as your account is active, so you can re-order the same formula in the future.
  • Financial records — retained for 6 years after the relevant transaction, as required by HMRC.
  • Marketing preferences — retained until you withdraw consent or request deletion.
  • Technical logs — retained for up to 90 days for security and debugging purposes.

You may request deletion of your account and associated data at any time (subject to legal retention obligations) by emailing privacy@particular.health.

11. Your rights under UK GDPR

Depending on the circumstances, you have the following rights with respect to your personal data. These rights are not absolute and may be subject to limitations:

  • Access — request a copy of the personal data we hold about you.
  • Correction — request that we correct any inaccuracies in your personal data.
  • Deletion — request the deletion of your personal data under certain circumstances (“right to be forgotten”).
  • Restriction — request that we limit how we use your data while a concern is being resolved.
  • Portability — request the transfer of your personal data to another service provider in a structured, commonly used, machine-readable format.
  • Objection — object to certain types of processing, including processing based on legitimate interests and direct marketing.
  • Withdrawal of consent — where we rely on consent to process your personal data, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, email us at privacy@particular.health. We will respond within 30 days. We may need to verify your identity before processing your request.

12. Children’s data

Our Services are not intended to be used by children. We do not knowingly collect personal information from anyone under the age of 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@particular.health and we will take steps to delete that information.

13. Cookies and analytics

We use cookies in three categories: strictly necessary (always on, required for authentication via Clerk and secure payments via Stripe), analytics (Google Analytics and Microsoft Clarity, only loaded if you opt in), and marketing (Meta Pixel and similar advertising tools, only loaded if you opt in).

Google Analytics is configured to anonymise IP addresses. Microsoft Clarity records anonymised session replays and heatmaps. Vercel Analytics and Speed Insights provide cookieless performance monitoring and are always on. You can change your preferences at any time via the “Cookie preferences” link in our footer. For full details, see our Cookie Policy.

14. Third-party links

Our website may contain links to websites or online platforms operated by third parties. If you follow links to sites not affiliated or controlled by us, you should review their privacy and security policies and other terms and conditions. We do not guarantee and are not responsible for the privacy or security of such sites, including the accuracy, completeness or reliability of information found on them.

Our inclusion of such links does not, by itself, imply any endorsement of the content on such platforms or of their owners or operators.

15. Security

We implement technical and organisational measures to ensure your data is secure. All data in transit is encrypted via TLS. Our database is hosted in the EU with encryption at rest. Authentication tokens are managed by Clerk and never stored in our database. Payment card data is handled entirely by Stripe and never passes through our servers.

However, please be aware that no security measures are perfect or impenetrable, and we cannot guarantee “perfect security.” We recommend that you do not use unsecure channels to communicate sensitive or confidential information to us.

16. Complaints

If you have complaints about how we process your personal information, please contact us using the details in Section 1. We will endeavour to resolve your concern promptly.

You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO). You can contact the ICO at ico.org.uk or by calling 0303 123 1113.

17. Changes to this policy

We may update this Privacy Policy from time to time, including to reflect changes to our practices or for other operational, legal or regulatory reasons. We will post the revised Privacy Policy on this page, update the “Effective” date above, and notify registered users of material changes by email. Continued use of our Services after the effective date constitutes acceptance of the updated policy.

18. Contact

Should you have any questions about our privacy practices or this Privacy Policy, or if you would like to exercise any of the rights available to you, please email us at privacy@particular.health or write to us at Astra Castra Ltd, 128 City Road, London EC1V 2NX.

For the purpose of applicable data protection laws, we are the data controller of your personal information.