Enurgy
Privacy Policy
Last updated: 7 August 2026
This Privacy Policy explains how Enurgy Lab Ltd ("Enurgy", "we", "us") collects, uses and protects your information when you use the Enurgy mobile application (the "App"), this website, and our in-café membership services.
Who we are (data controller)
- Controller: Enurgy Lab Ltd, a private limited company registered in England and Wales, company number 17096126.
- Registered office and trading address: London, United Kingdom.
- Data protection contact: developer@enurgylab.com.
- Applicable law: the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR).
We have not appointed a statutory Data Protection Officer as we are not required to; the contact above is responsible for data protection matters.
1. Information we collect
We collect only what we need to run the service:
- Account information: your name, email address, password (stored hashed), and optional phone number and date of birth.
- Membership and transaction information: your membership tier, billing status, order history and in-café purchases. Card details are handled by our payment provider and are never stored on our servers.
- Health and wellbeing data: with your explicit permission, sleep, recovery, readiness, heart-rate, activity and related metrics from Apple Health, WHOOP, Oura and similar sources, plus wellbeing goals and preferences you enter yourself.
- Usage data: app screens viewed, features used, crash reports, device model, operating system version and app version.
- Communications: messages you send to our support address and your responses to surveys or event sign-ups.
2. How we use your information
- To create and manage your account and membership.
- To generate personalised drink recommendations and bespoke blends based on your wellbeing profile.
- To process payments, subscriptions and event bookings.
- To provide customer support and respond to your enquiries.
- To improve the App and our menu through aggregated, de-identified analysis.
- To send service messages, and — only where you have opted in — marketing about events and offers.
- To meet our legal, accounting and regulatory obligations.
3. Health data — specific commitments
Health and fitness data is special category data and we treat it accordingly. Health data is collected only with your explicit, separate consent, and is used solely to provide you with personalised recommendations and features inside the App.
- We never use health data for advertising or marketing.
- We never sell, rent or trade health data, and we never share it with data brokers.
- We do not use health data for any purpose unrelated to your own health, wellbeing and personalisation experience.
- You can disconnect a wearable or health source at any time in the App; we stop receiving new data immediately.
- Data read from Apple Health is handled in accordance with Apple's HealthKit requirements and is not stored in iCloud alongside third-party analytics.
4. Legal bases for processing
- Contract: to provide the App, your account and your membership.
- Consent: for health and wearable data, marketing communications and optional analytics. You may withdraw consent at any time.
- Legitimate interests: to secure our systems, prevent fraud and improve our services, balanced against your rights.
- Legal obligation: to keep tax, accounting and compliance records.
5. Sharing your information
We do not sell your personal data. We share it only with service providers who process it on our instructions under written contracts: cloud hosting and database providers, payment processors, email and notification providers, and error-reporting and analytics providers. We may also disclose information where required by law or to establish or defend legal claims.
Where data is transferred outside the UK or EEA, we rely on adequacy decisions or the UK International Data Transfer Addendum to Standard Contractual Clauses.
6. Retention
We keep account and membership data for as long as your account is active. If you delete your account, we delete or irreversibly anonymise your personal and health data within 30 days, except records we must keep for legal, tax or fraud-prevention reasons (typically up to 6 years for transaction records). Backups are purged on a rolling 35-day cycle.
7. Security
Data is encrypted in transit using TLS and encrypted at rest by our hosting provider. Access to production data is restricted to authorised personnel who need it, and is logged. No system is completely secure, so we also ask you to use a strong, unique password and to tell us promptly about any suspected unauthorised access.
8. Cookies, tracking and marketing (PECR)
This website uses only cookies that are strictly necessary to serve the pages securely. We do not run advertising cookies or third-party tracking pixels on this site. If we later add analytics or marketing cookies, we will ask for your consent through a cookie banner first, and you will be able to change or withdraw that choice at any time.
In the App, optional analytics and crash reporting run only if you allow them, and on iOS we ask separately through Apple's App Tracking Transparency prompt. Marketing emails are sent only with your consent, or to existing customers about similar services under the PECR soft opt-in; every message has a one-click unsubscribe.
9. Automated decision-making
Personalised recommendations are generated automatically from the wellbeing data you share. They are suggestions only, have no legal or similarly significant effect on you, and you can ignore them, order anything else, or turn personalisation off in the App.
10. Your rights under the UK GDPR
- Access — a copy of the personal data we hold about you.
- Rectification — correction of inaccurate or incomplete data.
- Erasure — deletion of your data where we no longer need it or you withdraw consent.
- Restriction — pausing our use of your data while a concern is resolved.
- Objection — objecting to processing based on our legitimate interests, and to direct marketing at any time.
- Portability — your data in a structured, commonly used, machine-readable format.
- Withdraw consent — at any time, without affecting processing carried out beforehand.
To exercise any right, email developer@enurgylab.com. We respond within one month, free of charge, and may ask for proof of identity first. If you are unhappy with our response you can complain to the UK Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, 0303 123 1113, ico.org.uk.
11. Data breaches
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the ICO within 72 hours of becoming aware of it, and tell affected users directly where the risk is high.
12. Children
The App is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.
13. Changes and contact
We will post any changes to this policy on this page and update the date above. Material changes will also be notified in the App. Questions about this policy or our data practices can be sent to developer@enurgylab.com, Enurgy Lab Ltd (company number 17096126), London, United Kingdom.