Data Protection Policy

Last Updated: September 11, 2026

1. Introduction

This Data Protection Policy provides a detailed overview of how EverRhythm adheres to data protection laws and frameworks, including the General Data Protection Regulation (GDPR), the Health Insurance Portability and Accountability Act (HIPAA), and the Personal Information Protection and Electronic Documents Act (PIPEDA). Our Privacy Notice provides a user-facing summary of these practices.

2. GDPR Compliance

For users in the European Economic Area (EEA), we are committed to full compliance with GDPR. Our framework includes:

  • Lawful Basis for Processing: We process personal data based on explicit consent (especially for health data), contractual necessity, and legitimate interests.
  • Data Subject Rights: We have established procedures to facilitate user rights, including the right to access, rectify, erase, restrict processing, and data portability.
  • Data Protection by Design and by Default: We integrate data protection into our development processes and ensure that, by default, only necessary data is processed.
  • Data Protection Impact Assessments (DPIAs): We conduct DPIAs for high-risk processing activities involving health data.

3. HIPAA Compliance

For users in the United States, we treat all health-related information as Protected Health Information (PHI) and comply with the HIPAA Privacy and Security Rules. Our measures include:

  • Technical Safeguards: Including encryption of data at rest and in transit, access controls, and audit logs.
  • Administrative Safeguards: Including security policies, employee training, and a designated Privacy Officer.
  • Physical Safeguards: Our hosting providers maintain secure facilities with restricted access.
  • Business Associate Agreements (BAAs): We enter into BAAs with all third-party service providers who may come into contact with PHI.

4. PIPEDA Compliance

For our Canadian users, we adhere to the principles of PIPEDA, which include accountability, identifying purposes, consent, limiting collection, limiting use, disclosure, and retention, accuracy, safeguards, openness, individual access, and challenging compliance.

5. Data Retention and Deletion

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. Users can request the deletion of their account and associated data at any time. Upon deletion, personal data is permanently removed from our production systems, with backups being deleted in accordance with our backup cycle.

6. International Data Transfers

Your information may be transferred to — and maintained on — computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ. For transfers of data from the EEA, we rely on Standard Contractual Clauses (SCCs) and other appropriate safeguards to ensure your data is protected.

7. Data Breach Notification

In the event of a data breach that is likely to result in a high risk to the rights and freedoms of individuals, we will notify the relevant supervisory authorities and affected users without undue delay, in accordance with our legal obligations under GDPR, HIPAA, and other applicable laws.

8. Policy Management and Versioning

We maintain a comprehensive policy management system to ensure our data protection policies remain current and compliant with evolving regulations. All policies undergo regular review and version control to track changes and maintain transparency.

Our policies are systematically managed through:

  • Version Control: Each policy update is versioned and tracked with detailed change logs
  • Regular Reviews: Policies are reviewed at least annually or when regulatory changes occur
  • Approval Process: All policy changes undergo formal review and approval before publication
  • Transparency: Users are notified of significant policy changes and provided with clear information about updates

9. Contact and DPO

If you have any questions about this Data Protection Policy, please contact our Data Protection Officer at dpo@everrhythm.health.