Summary: We collect only what we need to run the wellness programme. Your private session content is not shared with your employer in identifiable form. We use trusted providers (for example Zoom, WhatsApp) where you choose or where the product requires it. See below for detail.
1. Who is responsible
The data controller for the SafeStories platform is SafeStories (or the entity named in your organisation's agreement). Your employer or sponsoring organisation ("Sponsor") arranges access; some processing may be joint or on the Sponsor's instructions for workforce reporting, as described in your programme materials.
2. Data we collect
- Account and profile: work email, name, phone where provided, department or location if collected, family-member details you add, and similar profile fields.
- Wellness activity: session bookings, workshop registrations, check-in and assessment responses you submit, feedback forms, and in-app actions needed to deliver the Service.
- Communications: messages we send (for example OTP, reminders via email or WhatsApp) and support requests you make.
- Technical data: device type, approximate location from IP, logs, and cookies or similar technologies needed for security and reliability.
3. How we use your data
We use personal data to:
- Provide sessions, workshops, check-ins, and related features
- Authenticate you and keep accounts secure
- Send operational messages (bookings, Zoom links, reminders)
- Improve the Service and, where allowed, produce anonymised or aggregate insights
- Comply with law and respond to valid requests
4. What your employer can see
Private counselling-style sessions and similar confidential interactions are not shared with your employer in a way that reveals what you said. Your Sponsor may receive high-level or aggregated reporting (for example uptake, anonymised wellbeing trends) as agreed in the enterprise contract. If you invite a family member, each person has a separate private account; you do not see their session content unless they choose to share something outside the app.
5. Legal bases (where applicable)
Depending on region (for example GDPR), we rely on bases such as: performance of a contract with you or your Sponsor, legitimate interests (security, product improvement, with balancing tests), consent where we ask for it (for example optional marketing or certain notifications), and legal obligation.
6. Sharing and processors
We share data with service providers who help us run the platform (hosting, email, analytics, support). Video sessions may be delivered via providers such as Zoom; reminders may use WhatsApp or similar channels when you enable them. Those providers process data under contract and only as needed for their service.
7. Retention
We keep data only as long as needed for the purposes above, including legal, tax, and dispute resolution. Retention periods may depend on your Sponsor's programme. You can ask us about deletion subject to exceptions (for example where we must retain by law).
8. Security
We use technical and organisational measures designed to protect personal data. No method of transmission over the internet is 100% secure; we work to reduce risk and to respond to incidents appropriately.
9. Your rights
Where applicable law gives you rights (access, correction, deletion, restriction, portability, objection, withdraw consent), you can exercise them by contacting support in the app or your Sponsor's HR contact. You may also have the right to complain to a supervisory authority.
10. International transfers
If data is processed in countries other than your own, we use appropriate safeguards (for example standard contractual clauses) where required by law.
11. Children
The Service is intended for adults in a workplace context. If you add a dependent, processing is tied to the family benefit your Sponsor provides; we do not knowingly market to children.
12. Changes
We may update this policy. We will post the new version here and change the "Last updated" date. Material changes may be communicated by email or in-app notice where appropriate.
13. Contact
For privacy questions, use in-app support (Settings → Help & Support), or contact your organisation's HR or wellbeing team. HR administrators should use the channels provided in the HR portal agreement.
Template for product and legal review. Have qualified counsel approve final text before production use.