About Us

We value your privacy!

At Ikivana, we take your privacy seriously.  Please read on to review our Privacy Policy!

Privacy Policy

Privacy Policy

Effective Date: October 2, 2025

Last Updated: May 04, 2026

VERSION: v1.4

  1. Who We Are

SAENA Ltd (“we,” “us,” or “our”) is a private limited company registered in England and Wales under company number 16734938, with its registered office at 20 Wenlock Road, London, England, N1 7GU United Kingdom. We operate the website at www.ikivana.com and the ‘My Ikivana’ mobile application for Android and iOS (collectively, the ‘Services’). The Site provides lead generation and marketing connecting UK users with international fertility and wellness providers. The mobile app is a secure patient portal used by patients of, and clinical staff working with, IKIVANA Wellness LLP for the delivery of fertility care, including appointment scheduling, secure messaging, document sharing, intake questionnaires, and billing. We are the data controller for personal data processed via the Services, jointly with IKIVANA Wellness LLP for clinical data processed in connection with the patient portal.

You can contact us at:

  • Email: <contact@ikivana.com>
  • Address: DPO/GDPR, 20 Wenlock Road, London, England, N1 7GU United Kingdom

For data protection queries, contact our Data Protection Officer (DPO) at the above details. We are registered with the ICO under reference ZC039535 (Link: https://ico.org.uk/ESDWebPages/Entry/ZC039535).

This privacy policy explains how we collect, use, and protect your personal data when you use the Site. It complies with UK GDPR and applies to all visitors and users.

  1. Personal Data We Collect

We collect minimal personal data directly from you for lead generation purposes only. This includes:

  • Basic contact details: Name, email address, and phone number (if provided).

For the Patient Portal and Mobile App (described in Section 13), we do collect special category health data with your explicit consent. See Section 13 for full details of data collected via the patient portal.

  1. How We Collect Your Personal Data

We obtain your data directly when you:

  • Submit a lead generation form on the Site to request a ‘Fertility Connect Call’.
  • Submit a ‘Ask a Question’ form on the site on the ‘Contact Us’ page.
  • If you email us directly on <contact@ikivana.com>

We do not collect data from third parties or automated tracking beyond essential cookies (see our Cookie Policy).

  1. How We Use Your Personal Data and Our Legal Basis

We use your data solely to:

  • Facilitate lead generation by transferring your details to IKIVANA Wellness LLP for scheduling informational Fertility Connect Calls (general discussions on fertility topics, not medical advice).
  • Send you confirmation emails about your request.
  • Comply with legal obligations (e.g., record-keeping).
  • For patient-portal users only: deliver and coordinate fertility care via IKIVANA Wellness LLP, including scheduling appointments, securely messaging your care team, storing your medical and fertility history, processing payments for treatment, and maintaining clinical records. The full purposes, lawful bases and recipients are set out in Section 13.

Our lawful basis for processing is explicit consent (Article 6(1)(a) UK GDPR), obtained via a clear opt-in checkbox on forms (e.g., “I consent to my data being used for lead generation and shared with IKIVANA Wellness LLP”). You can withdraw consent at any time (see Section 8). We do not rely just based on legitimate interests and consent ensures transparency in this sensitive context.

Processing is necessary and proportionate for our services but does not involve providing any GMC-regulated medical advice or HFEA-licensed activities.

  1. Sharing Your Personal Data

We share your data only with:

  • IKIVANA Wellness LLP (our affiliate in India) to arrange Fertility Connect Calls. This is limited to basic contact details.

We do not sell your data or share it with third parties for marketing. All recipients are bound by data processing agreements ensuring UK GDPR-equivalent protections.

  1. International Data Transfers

Your data may be transferred to IKIVANA Wellness LLP in India (outside the UK/EEA, a non-adequate country). We safeguard transfers using:

  • Standard Contractual Clauses (SCCs) approved by the ICO
    (supplemented by a Transfer Risk Assessment (TRA) to address India’s data protection gaps).
  • Technical measures of encryption during transit.

You have the right to obtain a copy of the SCCs by emailing <contact@ikivana.com>. Transfers are minimized and occur only with your consent. For further details, see ICO guidance on international transfers (ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers).

  1. How Long We Keep Your Personal Data

We retain your data only as long as necessary for the purpose (typically until after the Fertility Connect Call is completed or you withdraw consent, up to 6 months). After this, we securely delete it using industry-standard methods (e.g., overwriting or certified destruction). If a legal obligation applies (e.g., audit), we retain anonymized records.

  1. Your Rights

Under UK GDPR, you have rights regarding your data:

  • Access: Request a copy (free, subject to limits).
  • Rectification: Correct inaccuracies.
  • Erasure (“right to be forgotten”): Delete data (except where legally required).
  • Restriction: Limit processing in certain cases.
  • Portability: Receive data in a structured format.
  • Object: Oppose processing (e.g., on legitimate interests, though we use consent).
  • Withdraw Consent: At any time, without affecting prior processing – email <contact@ikivana.com> or use the unsubscribe link.

To exercise rights, contact us at <contact@ikivana.com>. We respond within one month (extendable to three for complex requests). No fees apply unless requests are excessive. If unsatisfied, complain to the ICO (ico.org.uk/make-a-complaint; helpline: 0303 123 1113).

We may verify your identity before responding to prevent unauthorized access.

  1. Security

We protect your data with appropriate technical (e.g., encryption, firewalls) and organizational measures (e.g., access controls, staff training). As a small business, we conduct regular risk assessments but note no system is 100% secure – report suspected breaches to us immediately.

  1. Children’s Data

The Site is not for children under 18. We do not knowingly collect data from minors. If we discover such data, we delete it promptly. Parents/guardians can contact us for access/erasure.

  1. Changes to This Policy

We may update this policy to reflect legal changes or operations. We notify you via email or Site notice. Continued use constitutes acceptance. Check regularly.

  1. Third-Party Links

The Site may link to external sites (e.g., HFEA or GMC resources). We are not responsible for their privacy practices – review theirs separately.

For questions, contact <contact@ikivana.com>. This policy aligns with ICO best practices for small organizations.

  1. Patient Portal and Mobile App

This section sets out additional information specific to the My Ikivana mobile application and the patient portal at www.ikivana.com/patient-zone (together, the “Patient Portal”). The Patient Portal is used by patients of IKIVANA Wellness LLP and authorised clinical and operational staff for the secure delivery of fertility care.

The Patient Portal processes special category personal data (health data) within the meaning of Article 9 of the UK GDPR. Where this Section 13 conflicts with earlier sections of this Policy in relation to the Patient Portal, this Section 13 prevails.

13.1 Personal Data Collected via the Patient Portal

When you create or use a Patient Portal account, we collect the following categories of data. We collect only what is necessary for the purposes set out in Section 13.3.

Account and identity data:

Name, email address, phone number, password (stored only as a salted hash; never in plain text)
Date of birth, gender, nationality, country of residence, timezone
Address, postal code, emergency contact details
Profile photograph (only if you choose to upload one)
Health and fertility data (UK GDPR Article 9 special category data)

Medical conditions, surgeries, hospitalisations, allergies, current medications, family medical history
Vitals (height, weight, BMI, blood pressure), lifestyle (smoking, alcohol, exercise)
Menstrual cycle history, time trying to conceive, pregnancy history (gravida, para, miscarriages, ectopic, terminations, living children)
Diagnoses, hormone results (AMH, FSH, LH, estradiol, progesterone, AFC), semen analysis results, partner medical information you provide
Previous fertility treatment cycles (IUI, IVF, FET) and outcomes
Documents and uploads

Lab reports, scans, ultrasound images, referral letters, ID copies, and other documents you upload to share with your care team
Payment data

Invoice records, payment status, currency. Card details and bank account numbers are never stored on our servers — they are entered directly on the payment processor’s (Stripe) secure form and we receive only a payment-confirmation token.
Communications

Messages you send to your care team via the in-app messaging feature, support tickets you raise, and the content of those messages and replies
Consent records

Records of consents you provide (UK GDPR consent, telemedicine consent, cross-border data transfer consent, data-processing consent), with timestamps, IP address, and your digital signature
Technical and device data

Authentication tokens (Laravel Sanctum bearer tokens), session timestamps, last sign-in IP address, failed-login counters, account-lock state
Device platform (Android / iOS) and operating-system version
Whether you have enabled biometric unlock — note that fingerprint and face data themselves never leave your device; we only store a flag indicating that biometric unlock is enabled. The biometric template is held by your device’s secure enclave (Android Keystore or iOS Secure Enclave) and is not accessible to us.
HIPAA-aligned audit log entries: which records you accessed, what changes you made, when, and from which IP address (required for clinical record-keeping and audit)

What we do NOT collect:

Location data, contacts, calendar entries, photos other than ones you explicitly upload, advertising identifiers, behavioural-tracking analytics, or third-party data brokers’ data.

13.2 How We Collect Patient Portal Data

Data is collected directly from you when you:

Register for an account (in-app or via the website)
Complete the multi-step intake questionnaire
Send messages, raise tickets, upload documents, or book appointments
Make a payment for treatment via the integrated Stripe checkout
Enable biometric unlock or set a profile photo
Some data is generated automatically as you use the Patient Portal — for example, the audit log, session timestamps, and authentication token records.

Some clinical data may also be entered on your behalf by authorised IKIVANA staff (your assigned doctor or care coordinator), for example clinical notes added after a consultation. You can request a full copy of all data held about you at any time (see Section 8 / 13.7).

13.3 How We Use Patient Portal Data and Our Lawful Bases

We process Patient Portal data for the following purposes:

Purpose Lawful basis (UK GDPR)
Operate your account, authenticate you, secure access Article 6(1)(b) — performance of a contract
Deliver fertility care: schedule appointments, host video consultations, manage clinical records, message your care team, share documents Article 6(1)(b) — performance of a contract; Article 9(2)(h) — health and social care, where the processing is carried out by, or under the responsibility of, a regulated health professional
Process payments for treatment Article 6(1)(b) — performance of a contract; Article 6(1)(c) — legal obligation (financial record-keeping)
Maintain HIPAA-aligned audit logs of who accessed what record Article 6(1)(c) — legal obligation; Article 9(2)(h) — provision of health care
Record explicit GDPR / telemedicine / cross-border consents you provide via the intake questionnaire Article 6(1)(a) — consent; Article 9(2)(a) — explicit consent for special category data
Respond to your support tickets Article 6(1)(b) — performance of a contract
Comply with legal obligations (e.g. HFEA record-keeping requirements, tax records, ICO requests) Article 6(1)(c) — legal obligation
We do not use Patient Portal data for marketing, profiling, automated decision-making, or sharing with third-party advertisers.

13.4 Sharing Your Patient Portal Data

Within the Patient Portal, your data is visible to:

Yourself – you have full read access to all data we hold about you
Your assigned doctor and care coordinator – at IKIVANA Wellness LLP (India), bound by clinical confidentiality and a UK GDPR-equivalent data-processing agreement
IKIVANA administrative staff – for the limited purpose of account, billing and ticket support, role-restricted via least-privilege access controls
We share your data with the following processors / sub-processors:

GoDaddy / Sucuri – UK/EU hosting provider for the website and database (data-processing agreement in place)
Stripe Payments UK Ltd – payment processor (you interact with Stripe directly when paying; we receive only the confirmation token)
Google LLC – calendar synchronisation for appointments, where you have enabled it
Apple Push Notification Service / Firebase Cloud Messaging – when push-notification features are added (advance notice will be given before this is enabled)
We do not sell your data, share it for advertising, or transfer it to third parties for any purpose other than those listed above.

13.5 International Data Transfers

Patient Portal data is processed in the United Kingdom (where IKIVANA’s website and database are hosted) and in India (where IKIVANA Wellness LLP’s clinical staff access the Patient Portal to deliver care). India is not currently designated as an adequate jurisdiction by the UK government for international data transfers.

We safeguard transfers to India using:

The ICO-approved Standard Contractual Clauses (SCCs) and a Transfer Risk Assessment (TRA)
End-to-end encryption in transit (TLS 1.2+)
AES-256 encryption at rest for special category fields including identity numbers, addresses, and clinical notes
Strict role-based access controls limiting Indian staff access to assigned patients only
By using the Patient Portal you provide explicit consent under UK GDPR Article 49(1)(a) for these transfers, in addition to the SCCs. You can withdraw this consent at any time by deleting your account; doing so will end your ability to receive care via IKIVANA Wellness LLP.

13.6 How Long We Keep Patient Portal Data

Health and treatment records have specific retention requirements under UK and Indian healthcare regulations. We retain data as follows:

Active account data: for as long as your account remains active
Clinical and treatment records, consents, audit logs: a minimum of 7 years after the last episode of care (or longer where required by HFEA, NHS, or Indian medical council guidance for fertility records, which can extend to 30 years in some cases)
Payment records: 7 years after the transaction date (UK statutory record-keeping)
Account closure: when you close your account, identifying data (name, email, phone) is deleted; clinical records are retained in pseudonymised form for the periods above to comply with medical record-keeping obligations.

13.7 Your Rights for Patient Portal Data

All UK GDPR rights set out in Section 8 apply to Patient Portal data. In addition:

Right of access: you may export a complete machine-readable copy of all data held about you at any time by contacting us at the address in Section 1
Right to portability: clinical records can be transferred to another healthcare provider on your written request
Right to restrict processing: you may pause processing of your data while a complaint or dispute is investigated
Withdrawal of consent: where processing relies on your consent (Article 9(2)(a)), you may withdraw at any time. This may end our ability to provide care; we will explain consequences before acting on the withdrawal
Note that some clinical and audit-log data must be retained even after a deletion request, to comply with our legal obligations as set out in Section 13.6 and Article 9(2)(h) UK GDPR.

13.8 Security of the Patient Portal

In addition to the measures in Section 9, the Patient Portal applies:

AES-256 encryption at rest for special category fields (medical notes, identifiers, addresses)
TLS 1.2+ encryption for all data in transit
Bearer token authentication (Laravel Sanctum); tokens are device-specific and revocable
Optional biometric unlock — fingerprint or face template never leaves your device’s secure hardware enclave
Configurable session timeout (default 30 minutes of inactivity), automatic account lockout after multiple failed sign-in attempts
HIPAA-aligned audit logging of every access to clinical records
Role-based access control: doctors see only their assigned patients; coordinators see only their assigned patients; administrative staff see only what their role requires
Annual security reviews; suspected breaches notified to the ICO within 72 hours and to affected patients without undue delay where required.

13.9 Mobile App Permissions

The My Ikivana mobile app requests the following device permissions only when needed for a feature you actively use:

  • Internet — to communicate with our secure servers (always required)
  • Files / Photos — only when you tap “Upload” to attach a document or photo
  • Biometric (Fingerprint / Face) — only if you choose to enable biometric unlock; data never leaves your device
  • Storage — to save downloaded reports to your device’s Documents folder when you tap Download

The app does not request access to your camera (uploads use the system file picker), location, contacts, microphone, calendar, SMS, or call logs.

13.10 Children

The Patient Portal is for adults aged 18 or over only. Account creation requires confirmation of age. We do not knowingly process data of anyone under 18; if we discover such data, we will delete it.

13.11 Changes to This Section

Material changes to this Section 13 will be notified to you in-app the next time you sign in, and you may be asked to re-consent. Past consents you have given remain valid for the version of the Policy in effect at the time you gave them.



Schedule your visit online

Take the next step and schedule an appointment today

It just takes a few minutes to book a visit online.