Privacy
Privacy notice
This notice explains what NutriHub handles, why it is used and the choices available to professional users and clients.
Last updated: 26 August 2026
Who is responsible for your information?
A practice using NutriHub normally decides why and how contact records are used. That practice is the data controller and NutriHub processes the records on its instructions. NutriHub is separately responsible for professional account, security, support and service-administration information that it collects for its own purposes.
Questions about care records should first be sent to the practice that created them.
Public directory enquiries
When you use the public directory to send an enquiry, NutriHub collects the contact and routing details shown in the form so it can protect the service from misuse and securely pass your enquiry to the practice you selected. NutriHub is responsible for that initial collection and routing. Once the selected practice receives and responds to the enquiry, that practice is responsible for how it uses the enquiry and any later care record.
The enquiry form is for contact details and availability questions only. Do not include health conditions, symptoms, diagnoses, medication, medical records or urgent information. Contact emergency services where urgent help is needed.
Information handled through NutriHub
- Professional account, organisation, team, role and security information.
- Contact details, appointments, consultations, notes, plans and progress records entered by a practice.
- Portal messages, forms, food logs, documents and responses submitted by a client.
- Branding, regional settings, email-domain and integration configuration.
- Technical security events, delivery records, support references and limited device or request information.
Why information is used
- To provide the practice workspace and client portal.
- To authenticate users, enforce permissions and protect accounts.
- To deliver plans, recipes, invitations, reminders and service messages.
- To operate requested integrations and provide support.
- To maintain, troubleshoot and improve the reliability and security of the service.
- To meet legal obligations and establish or defend legal claims.
Sensitive and health-related information
Practices may use NutriHub for health-related and other sensitive records. NutriHub does not decide the clinical purpose of those records. Each practice is responsible for identifying an appropriate legal basis, giving required notices and collecting consent where local law requires it.
Sharing and international processing
Information is shared only with authorised practice members, the relevant client and service providers needed to operate NutriHub. Optional integrations receive information only when a practice enables them. The current provider categories are listed on the subprocessor page.
Where a provider processes information outside the relevant country, NutriHub and the practice must use an appropriate transfer mechanism and contractual protection.
Retention
Practices choose retention periods appropriate to their legal and professional duties. Account, security and support information is kept only as long as needed for the service, legal compliance, fraud prevention and dispute handling. A configured retention period is not a substitute for a practice reviewing and lawfully disposing of records.
Your rights
Depending on applicable law, you may have rights to access, correct, delete, restrict, object to or receive a copy of your information. Clients should send care-record requests to their practice. Professional users may contact support@nutrihub.health. You may also complain to your local data-protection authority.
Contact
Privacy and security questions can be sent to support@nutrihub.health. Do not include passwords, authentication codes or full care records in an ordinary email.