canary

Privacy Policy

Healthy Canary B.V. · Effective 1 May 2026 · Version 1.0 · Data hosted in the European Union (Frankfurt, Germany)

1. Introduction

Healthy Canary B.V. (“Healthy Canary,” “we,” “us,” or “our”) provides a preventive health intelligence platform that helps individuals understand their health and helps employers support workforce wellbeing through aggregated, anonymised insights.

We consider the protection of your personal data — and especially your health data — to be fundamental to our relationship with you. Health data is among the most sensitive categories of personal data, and we treat it accordingly. This Privacy Policy explains what data we process, why, on what legal basis, how we protect it, and the rights you have over it.

This policy applies to all individuals who use the Healthy Canary platform, whether you joined directly or through an employer that offers Healthy Canary as a benefit.

2. Who we are (data controller)

Healthy Canary B.V. is the data controller responsible for the personal data processed through the platform. We are a private limited company registered in the Netherlands.

Registered address: [insert registered address]
Chamber of Commerce (KvK) number: [insert KvK number]
Data Protection Officer: privacy@healthycanary.com

You may contact our Data Protection Officer at any time with questions about this policy, to exercise your rights, or to raise a concern about how your data is handled.

3. The data we process

We process the following categories of personal data.

Account data you provide directly. Your name, email address, and password (stored only in hashed form). This is the information necessary to create and secure your account.

Health data you provide or connect. This is special category data under Article 9 of the GDPR and receives the highest level of protection. It includes: biomarker and laboratory results you upload or that are delivered through our certified laboratory partners; continuous metrics from wearable devices you choose to connect (such as heart rate variability, sleep, and recovery data from WHOOP or other supported devices); responses to weekly wellbeing check-ins; supplement and protocol adherence you log; and records of any interactions with clinicians or psychologists arranged through the platform.

Usage and technical data. Basic operational logs including page views, feature usage, device and browser type, and error logs. This data is used to operate, secure, and improve the platform.

What we do not collect. We do not collect precise geolocation data. We do not track you across other websites or services. We do not purchase personal data about you from data brokers.

4. How we use your data and our legal basis

We only process your personal data where we have a valid legal basis under the GDPR. The table below sets out each purpose and the corresponding basis.

PurposeData usedLegal basis
Create and secure your accountAccount dataContract performance — Art. 6(1)(b)
Provide and personalise your individual health dashboardHealth dataExplicit consent — Art. 9(2)(a)
Arrange clinician or psychologist consultations you requestHealth dataExplicit consent — Art. 9(2)(a)
Generate aggregated, anonymised workforce insights for your employerHealth data, aggregated and anonymisedExplicit consent — Art. 9(2)(a)
Secure the platform and prevent fraud and abuseAccount and technical dataLegitimate interests — Art. 6(1)(f)
Comply with legal and regulatory obligationsAs requiredLegal obligation — Art. 6(1)(c)

Where we rely on your explicit consent to process health data, you may withdraw that consent at any time through your Account Settings or by contacting our Data Protection Officer. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal. Where you withdraw consent for a feature that depends on health data, that feature will no longer be available to you.

5. Employer relationships and data sharing

Where your employer offers Healthy Canary as a workplace benefit, the following principles apply without exception.

Your individual health data is never shared with your employer. Your employer cannot see your biomarker results, your check-in responses, your wellbeing scores, your clinician or psychologist interactions, or any other data that identifies you.

Employers receive only aggregated, anonymised cohort signals. For example, an employer may see that burnout risk indicators are elevated within a team, expressed as a group-level trend. Employers never receive data at the level of an identifiable individual.

Aggregate reporting is subject to a minimum group size. We do not display any cohort signal for a group unless it contains a sufficient number of enrolled individuals to prevent any individual from being identified or inferred. This threshold is enforced technically, not merely as a matter of policy.

You control your consent. Any consent you grant for your data to contribute to anonymised workforce reporting can be reviewed and revoked at any time in your Privacy Settings. Revoking this consent removes your data from future aggregate reporting.

6. Data storage, location, and security

Location. All personal data is stored and processed within the European Union, on servers located in Frankfurt, Germany. We do not transfer your personal data outside the European Economic Area except where a specific processor requires it, in which case appropriate safeguards under Chapter V of the GDPR (such as Standard Contractual Clauses) are applied. Any such transfers are listed in Section 7.

Encryption. Data is encrypted at rest using AES-256 and in transit using TLS 1.3.

Access controls. Access to personal data within Healthy Canary is restricted to authorised personnel on a strict need-to-know basis, protected by multi-factor authentication and logged for audit purposes. Special category health data is subject to additional access restrictions.

Organisational measures. We maintain internal policies governing data handling, breach response, and staff training, and we review our security measures regularly.

7. Third-party processors

We engage a limited number of carefully selected service providers (“processors”) to operate the platform. Each is bound by a data processing agreement that requires them to protect your data to the standard set out in this policy and to process it only on our instructions.

ProcessorFunctionData location
SupabaseDatabase and authentication infrastructureEU (Frankfurt)
WHOOPWearable device data integration (only when you connect your device)United States — Standard Contractual Clauses
AnthropicAI-powered health insights — processed under a data processing agreement and not used to train modelsUnited States — Standard Contractual Clauses
StripePayment processing — no health data is sharedEU / United States

We keep this list current. Where we add or change a material processor, we update this policy in accordance with Section 11.

8. How long we keep your data

We retain your personal data only for as long as necessary for the purposes described in this policy.

Active accounts. We retain your data for as long as your account is active.

After account deletion. Following deletion of your account, we retain your health data for a period of up to five years, solely to allow you to recover and export your longitudinal health history should you wish to return or to provide it to a clinician. You may request immediate and permanent deletion of your data at any time, in which case we will erase it without waiting for this period to elapse, subject only to any overriding legal retention obligation.

Technical logs. Operational and security logs are retained for a shorter period consistent with their purpose.

9. Your rights under the GDPR

You have the following rights in relation to your personal data:

  • Access — obtain confirmation of whether we process your data and a copy of it.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure— request deletion of your account and data (“right to be forgotten”).
  • Portability — receive your data in a structured, commonly used, machine-readable format, and have it transmitted to another provider where technically feasible.
  • Restriction — request that we limit our processing of your data in certain circumstances.
  • Objection — object to processing carried out on the basis of legitimate interests.
  • Withdraw consent — withdraw any consent you have given, at any time.

You may exercise any of these rights through your Account Settings or by contacting privacy@healthycanary.com. We will respond within the timeframes required by the GDPR, ordinarily within one month.

You also have the right to lodge a complaint with a supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens (Dutch Data Protection Authority); you may also contact the supervisory authority in your country of residence.

10. Cookies

We use a single, strictly necessary session cookie to keep you securely signed in during your visit. Because this cookie is essential to providing the service you have requested, it does not require consent under the applicable rules. We do not use advertising, tracking, or analytics cookies that would require your consent.

11. Changes to this policy

We may update this policy from time to time. Where a change is material — for example, a change to the categories of data we process, the purposes of processing, or the processors we use — we will notify you by email at least 30 days before the change takes effect, giving you the opportunity to review it and, where relevant, to withdraw consent.

The current version of this policy is always available at healthycanary.com/privacy. The effective date and version number at the top of this document indicate when it was last updated.

12. Contact

For any question, request, or concern regarding this policy or your personal data, contact our Data Protection Officer at privacy@healthycanary.com.