mi-SOS

Legal

Privacy Policy

the small print

Last updated: 1 July 2026

1. Who we are

mi‑SOS ("we", "us") provides personal digital identity services for use in an emergency, including QR-coded wristbands, pet tags and the mi‑SOS online portal. We are the data controller for the personal information you provide. You can contact us at [email protected] or on 01670 818 229.

2. What we collect

We collect the information you choose to give us:

3. How your information is used

Your information exists for one purpose: to be available in an emergency, on your terms. When your QR code is scanned, only the information you have chosen to make visible is displayed. We also use your details to run your account, take payments, provide support, and send you essential service messages. We do not sell your personal information, and we do not use your medical information for marketing.

4. Your control over visibility

You decide exactly what a scan reveals. Every field in your profile can be shown or hidden through your privacy settings, and changes take effect immediately. Nothing is made public without your permission. You can also pause a QR code at any time, for example if a band is lost.

5. How your information is protected

Your data is stored on NHS-compatible secure servers in the United Kingdom. We are NHS Digital Technology Assessment Criteria (DTAC) compliant and ISO 27001 certified. Access to your full profile is protected by your password and two-factor authentication.

6. Sharing

We share information only with the service providers who help us run mi‑SOS (such as hosting and payment processing), under contracts that protect your data; with medical staff who request authenticated access to your full profile; and where the law requires it.

7. How long we keep it

We keep your information for as long as your account is active. If your subscription lapses, your data is retained so you can reactivate; if you delete your account, your profiles and documents are permanently removed within 30 days, except where we must keep records to meet legal obligations.

8. Your rights

Under UK GDPR you have the right to access, correct, export and delete your personal information, and to object to or restrict certain processing. Most of this you can do directly in the portal; for anything else, email [email protected]. You also have the right to complain to the Information Commissioner's Office (ICO).

9. Changes to this policy

If we make material changes to this policy, we will notify you by email and in the portal before they take effect.