EverRhythm logo

EverRhythm for Work — Privacy Policy

Last updated: October 2025

At EverRhythm, privacy is not a feature—it is the foundation of our platform. This Privacy Policy outlines how data is collected, processed, and protected within the EverRhythm for Work environment, explicitly detailing the strict boundaries between employer access and employee private medical data.

1. Data Controller & Processor Roles

Due to the hybrid nature of EverRhythm for Work, we operate under dual roles depending on the data type:

  • Data Processor: For organisational data, HR records, leave requests, and corporate communications, the Employer is the Data Controller, and EverRhythm acts as the Data Processor.
  • Data Controller: For personal health tracking, journals, symptom logs, and predictive insights, EverRhythm acts as the Data Controller. This legal separation prevents employers from claiming ownership over employees' private health data.

2. Categories of Data Collected

We collect several categories of data to operate the platform:

  • Organisational Data: Company name, billing details, and administrator contact info.
  • Employment Data: Employee names, work emails, department affiliations, leave balances, and shift schedules.
  • Wellbeing Data: Sleep metrics, mood ratings, heart rate variability, medical conditions, and symptom logs (kept strictly confidential from the employer).
  • Research Data: Anonymised participation data for workplace wellbeing studies (if the employee explicitly opts in).

3. What Employers Can See

Employers have access to specific, limited datasets necessary for HR operations and high-level organisational planning:

  • HR records, contracts, and uploaded compliance documents.
  • Leave requests, approvals, and absence records.
  • Aggregated & Anonymised Analytics: De-identified reports on team wellbeing trends (e.g., "Department A shows a 15% increase in burnout risk"). Minimum group thresholds (k-anonymity = 5) are strictly enforced to prevent re-identification.

4. What Employers CANNOT See

Under no circumstances does an employer have access to an individual employee's private health data. Employers cannot view:

  • Individual mood logs, stress logs, or journal entries.
  • Medication records, prescriptions, or treatment plans.
  • Menstrual cycle data, fertility information, or pregnancy logs.
  • Individual symptom records or chronic illness details.
  • Crisis activity, safeguarding alerts, or counselling usage.
  • Raw wearable device data (e.g., specific heart rate readings).
  • Research decisions, survey responses, or AI health coaching conversations.

5. Data Processing Legal Basis

We process data under the following legal bases as defined by the GDPR and UK DPA:

  • Contract Performance: To provide HR management tools and platform access.
  • Legitimate Interest: To secure the platform and improve the software.
  • Consent: For processing special category (health) data. Employees must explicitly consent to health tracking, and this consent can be withdrawn at any time.
  • Legal Obligation: For compliance with data protection and medical device regulations.

6. Data Retention & Deletion

Organisational data is retained for the duration of the contract and securely deleted 30 days after termination. Employee private health data remains under the employee's control. If an employee leaves the company, their work email association is severed, but they retain full access to their EverRhythm health history via a personal account.

7. GDPR / UK DPA Compliance

EverRhythm is fully compliant with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. We conduct regular Data Protection Impact Assessments (DPIAs) for all AI and health tracking features.

8. Employee Rights

Employees retain full data subject rights over their personal information, including the right to Access, Rectification, Erasure ("Right to be Forgotten"), Portability, Objection, and Restriction of Processing. Requests can be executed directly within the app settings or by contacting our DPO.

9. International Data Transfers

EverRhythm hosts data primarily within the UK and EU. Where data is transferred outside these regions, we rely on Standard Contractual Clauses (SCCs) and robust technical safeguards to ensure equivalent protection.

10. Third-Party Sub-processors

We use vetted sub-processors for infrastructure (e.g., AWS, Stripe). A full list of our current sub-processors is available upon request. We strictly audit sub-processors for security and privacy compliance.

11. Data Breach Response

In the unlikely event of a data breach, EverRhythm operates a 72-hour notification policy to relevant supervisory authorities and affected users, detailing the breach nature, impact, and remediation steps.

12. Contact Information

For questions regarding this policy or to reach our Data Protection Officer (DPO), please contact: privacy@everrhythm.com or write to us at our registered UK headquarters.