Privacy Policy & Data Protection Notice

Document Version: 1.3.0 (Effective Date: 24 July 2026) | Compliant with UK GDPR, Data Protection Act 2018 & PECR

Official DWP Non-Affiliation Disclaimer

MyPIPApp is an independent digital application guidance platform. We are not affiliated with, endorsed by, or associated with the Department for Work and Pensions (DWP), the UK Government, or any government agency. All decision guidance, points estimation tools, and draft application statement generators are for educational and self-advocacy purposes only.

1. Information We Collect

In Plain English:

We only collect the contact details, questionnaire answers, symptom diary logs, and medical evidence letters you choose to provide to help build your PIP claim.

We collect personal information directly from you when you register, complete questionnaire modules, log symptoms, or upload medical documents:

  • Account & Contact Credentials: Your full name, email address, password hash, and optional National Insurance Number (NINO) if provided for form drafting.
  • Special Category Data (Health & Medical Records): Clinical condition descriptions, symptom severity logs, mobility scores, daily living impact details, GP letters, and uploaded medical evidence files.
  • Technical & Usage Analytics: Anonymised browser data, interaction timestamps, and consent records. Non-essential analytics (such as Google Analytics 4) are strictly opt-in and consent-gated.
In Plain English:

Under UK data protection law (UK GDPR), we only process your sensitive health data because you have given explicit consent to use our PIP guidance tools.

We process your personal information under the following lawful bases set out in the UK General Data Protection Regulation (UK GDPR):

  • Contractual Performance (Article 6(1)(b)): Processing is necessary to deliver the MyPIPApp service, generate your PIP claim drafts, and maintain your private account workspace.
  • Explicit Consent (Article 9(2)(a)): Special Category Data concerning your health, medical conditions, and disability impact is processed only with your explicit opt-in consent provided during signup and profile creation.
  • Legitimate Interests (Article 6(1)(f)): Maintaining site security, preventing fraudulent auth attempts, and implementing edge rate limiting.

3. Data Sharing & Third-Party Processors

Zero Data Sale Guarantee: We never sell, monetise, or share your personal or medical data with advertisers, third-party data brokers, or marketing agencies.

Data is shared strictly with trusted enterprise infrastructure providers operating under binding data protection agreements:

Google Cloud / Firebase

Encrypted database and storage hosted in europe-west4 (EU/UK residency).

Stripe Payments

PCI-DSS Level 1 payment processor. Card credentials never touch our servers.

Sentry Diagnostics

Aggregated application error diagnostics with de-identified stack traces.

4. Data Security & Storage Controls

In Plain English:

Your health data is protected by enterprise-grade encryption both in transit and at rest. Strict access rules ensure only you can access your records.

We enforce multi-layered security controls to protect your medical details:

  • Strict App Check validation on all Firestore and Storage read/write queries.
  • TLS 1.3 encryption for all data in transit and AES-256 encryption at rest.
  • Role-based access rules ensuring users can read and write only their own records.

5. Data Retention & International Transfers

In Plain English:

We keep your records only while your account is active. You can delete your account and all stored documents whenever you choose.

Your personal and medical records are retained for as long as your account remains active. All primary databases are located within the europe-west4 region, satisfying UK GDPR international transfer safeguards under Standard Contractual Clauses (SCCs) where applicable.

6. Your Statutory Rights & Account Deletion

In Plain English:

You have full ownership of your data. You can download a complete export or instantly purge your account with zero remaining traces.

Under the UK GDPR and Data Protection Act 2018, you possess full statutory rights over your personal data:

  1. Right of Access: Request a complete export archive of all profile information, questionnaire responses, and symptom logs.
  2. Right to Erasure (Zero-Touch Account Purge): You can trigger an instant, irreversible purge of your entire account, medical documents, and profile data via your Account Settings workspace.
  3. Right to Rectification: Edit or correct any inaccurate personal details or clinical information directly in your profile settings.
  4. Right to Revoke Consent: You can withdraw consent for optional analytics or health data processing at any time.

7. Data Controller & Registered Corporate Disclosures

In Plain English:

If you have any privacy questions or wish to raise an enquiry to exercise your rights, our Data Protection Lead and UK compliance team are here to help.

Data Controller & Contact Details

  • Data Controller: MyPIPApp (UK operations)
  • Platform Website: https://mypipapp.co.uk
  • Data Protection Lead: [email protected]
  • Support & Account Enquiries: [email protected]
  • Governing Law: United Kingdom General Data Protection Regulation (UK GDPR) & Data Protection Act 2018 (England and Wales)
  • Supervisory Authority: You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk or by telephone at 0303 123 1113.