Book a demo
Trust Centre

Privacy by architecture.

Health data at work only works if nobody has to trust anybody. So the organisation cannot see individual data, even if it wanted to.

Three principles.

  • The person owns the data.View, export or delete at any time.
  • The organisation sees groups, never people.Reports exist only for groups of 30 or more, with at least 10 people with data each day and a mix of women and men.
  • Devices are personal.When use ends, the company deletes the account linked to the device. If the device is assigned to another person, a full reset is required at first pairing.

Privacy is a feeling before it is a policy.

How data flows. And where it stops.

What HR can see

Adoption, participation and team averages for readiness, sleep, stress, activity and BMI, by group of 30 or more.

What HR cannot see

The company can never see an individual's data: scores, sleep, heart rate, stress, blood markers, AI conversations and device data stay visible only to that person.

What the person controls

Joining, what to share with the AI, blood-test uploads, and deleting their account at any time.

Security and compliance.

Security.

Encrypted in transit and at rest.
Hosted in the EU.

Compliance.

GDPR (EU) and the revised Swiss Federal Act on Data Protection (nLPD).
EU AI Act: developed in line with the Act; assessment available on request.
Data processing agreement under Art. 28 GDPR (DPA), list of sub-processors and DPIA support available on request.

How we use AI.

  • What it doesExtracts the values from uploaded blood tests. Answers wellbeing questions from the data available: for employees in the app, on their own data; for HR in the dashboard, on aggregated data.
  • What it never doesDiagnose. Report on an individual to the employer. Infer emotions. Make decisions about anyone's employment.
  • Where it runsHosted in the EU.