Legal
Oncera Ltd customer privacy policy
Last updated: 1 October 2026
This privacy policy tells you what to expect us to do with your personal information.
Who this policy applies to
This policy covers anyone who visits the OnceraPlus website, fills in an assessment (whether or not you've created an account), or creates an account.
Who we are
OnceraPlus is operated by Oncera Ltd.
Contact details
Post: Health Foundry, Canterbury House, 1 Royal St, London, Greater London, SE1 7LL, GB
Email: info@onceraplus.com
What information we collect, use, and why
We collect or use the following information to run OnceraPlus’s patient-facing service:
- Account information – Name, email, phone number, sex, and password credentials. Passwords are never stored in plain text and are protected using industry-standard salted password hashing. We use your account information to operate your account, process payment, and communicate with you about your assessments, subscription, and account activity. We do not sell your data.
- Health information entered for an assessment – Age, sex, treatment intent, immunotherapy drug, tumour staging (T/N/M), and histological type, together with any optional metadata you choose to provide, such as date, patient ID, clinician, hospital and department. We use your clinical information to generate your assessment result and a downloadable PDF report of it. You can enter this before creating an account; if you don't complete registration, it is held only for the duration of your session and is not attached to any account.
- Payment information – Handled entirely by Stripe. We never see or store your card number.
- Usage data – Standard technical information, such as IP address, browser type and pages visited, collected automatically as described in our Cookies Policy.
We also collect or use relevant information for scientific research, validation and development of the AI underlying the OnceraPlus service:
- Health information entered for an assessment, where it is used for scientific research, model validation, testing and the development of the AI underlying the OnceraPlus service.
Some of the information we collect or use is special category data because it concerns your health. This includes:
- Health information entered for an assessment; and
- Health information used for scientific research, validation and development of the AI underlying the OnceraPlus service.
Because health information is particularly sensitive, it is subject to additional protections under UK data protection law.
Data protection rights
Under UK data protection law, we must have a “lawful basis” for collecting and using your personal information. There is a list of possible lawful bases in the UK GDPR. You can find out more about lawful bases on the ICO’s website.
Which lawful basis we rely on may affect your data protection rights which are set out in brief below. You can find out more about your data protection rights and the exemptions which may apply on the ICO’s website:
- Your right of access – You have the right to ask us for copies of your personal information. You can request other information such as details about where we get personal information from and who we share personal information with. There are some exemptions which mean you may not receive all the information you ask for.
- Your right to rectification – You have the right to ask us to correct or delete personal information you think is inaccurate or incomplete.
- Your right to erasure – You have the right to ask us to delete your personal information.
- Your right to restriction of processing – You have the right to ask us to limit how we can use your personal information.
- Your right to object to processing – You have the right to object to the processing of your personal data.
- Your right to data portability – You have the right to ask that we transfer the personal information you gave us to another organisation, or to you.
- Your right to withdraw consent – When we use consent as our lawful basis, you have the right to withdraw your consent at any time.
If you make a request, we must respond to you without undue delay and in any event within one month.
To make a data protection rights request, please contact us at info@onceraplus.com.
Our lawful bases for the collection and use of your data
Our lawful basis for collecting or using personal information to run OnceraPlus’s patient-facing service is:
- Contract – We have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
Where we process health information, a form of special category data, we also rely on Article 9(2)(a) of the UK GDPR – Explicit consent.
Our lawful basis for collecting or using personal information for scientific research, validation and development of the AI underlying the OnceraPlus service is:
- Legitimate interests – We collect or use the information because we have a legitimate interest in conducting scientific research, validating and improving the AI underlying the OnceraPlus service. All of your data protection rights may apply except the right to data portability.
Where we process health information, a form of special category data, we also rely on Article 9(2)(j) of the UK GDPR – Scientific research purposes, together with paragraph 4 of Schedule 1 to the Data Protection Act 2018.
You have the right to object to us using your personal information for these purposes. To object, please email info@onceraplus.com. We will consider your objection in accordance with applicable data protection law.
Where we get personal information from
- Directly from you
- From a family member, carer or other person authorised to provide information on your behalf
How long we keep your information
We keep personal information only for as long as necessary for the purpose for which it was collected.
For the OnceraPlus patient service, we retain account information until your account is closed. We retain health and assessment information until you delete your account or request deletion, unless we are required to retain particular information for longer to comply with a legal or regulatory obligation. We periodically review retained information and delete or anonymise it when it is no longer needed for the purposes for which it was collected. Clinical information entered during an assessment but not attached to a completed account is retained only for the duration of the active session.
For scientific research, validation and development of the AI underlying the OnceraPlus service, personal information may be retained for as long as it remains necessary solely for that scientific research purpose, subject to periodic review and appropriate safeguards. We will review whether continued retention remains necessary and will update our retention practices as appropriate.
How we protect information
Clinical information, assessment results and reports are encrypted (AES-256) at rest, and all data is encrypted in transit. Access is restricted by strict access controls, and we operate a single-account model specifically to reduce how much personal or clinical data can be linked to or accessed through any one login.
Duty of confidentiality
We are subject to a common law duty of confidentiality. However, there are circumstances where we will share relevant health and care information. These are where:
- You’ve provided us with your consent (we have taken it as implied to provide you with care, or you have given it explicitly for other uses);
- We have a legal requirement (including court orders) to collect, share or use the data;
- On a case-by-case basis, the public interest to collect, share and use the data overrides the public interest served by protecting the duty of confidentiality (for example sharing information with the police to support the detection or prevention of serious crime);
- If in England or Wales – the requirements of The Health Service (Control of Patient Information) Regulations 2002 are satisfied.
Sharing information outside the UK
Personal information may be processed outside the UK where necessary to provide hosting, payment and email services, including in the United States and the European Economic Area. Where transfers take place, we rely on safeguards permitted under UK data protection law, including the UK Extension to the EU-US Data Privacy Framework for eligible US organisations, UK adequacy regulations for transfers to the EEA, and, where required, the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
For further information about the safeguards applying to international transfers, or to request a copy of the relevant safeguards where applicable, please contact us at info@onceraplus.com.
Changes to this policy
We may update this policy as the Service evolves. Material changes will be reflected in the "Last updated" date above.
How to complain
If you have any concerns about our use of your personal information, you can make a data protection complaint to us:
Email: info@onceraplus.com
If you remain unhappy with how we’ve used your data after raising a complaint with us, you can also complain to the ICO.
The ICO’s address
Information Commissioner’s OfficeWycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113
Website: www.ico.org.uk/make-a-complaint