A wellbeing platform lives or dies on one thing: whether an employee believes their honesty is safe. If they don’t, they tell you they’re fine — and your dashboard confidently reports that everything is well right up until someone leaves.
So we don’t treat privacy as a policy. We build it into how the platform works, and we publish exactly where every line sits.
Every insight an employer receives is aggregated across a group. No individual’s answers, activity, or care is ever visible to their organisation — not to HR, not to their manager, not to anyone above them. That isn’t a setting we offer. It is how the system is built, and it cannot be turned off.
Most platforms bury this in a data-processing agreement. We put it on a public page, because a manager and an employee should be able to read the same thing and both feel safe.
No result is ever shown for a group smaller than eight responses. If a team is too small, its data rolls up into a larger group rather than being displayed — so no one can be identified by narrowing the filters. Thresholds can be raised for your organisation, never lowered.
Some of these are technically possible and would even make the product “smarter”. We don’t do them, because the moment employees suspect we might, the honesty the whole platform depends on disappears.
We do not track, score, or flag individual employees. There is no hidden risk profile with someone’s name on it.
We do not read, scan, or analyse the content of messages, emails, chat, or calendars. We measure what people choose to tell us, nothing they didn’t.
No keystroke, location, activity, or productivity tracking. This is a wellbeing platform, not a monitoring tool wearing its clothes.
Employee data is never sold, shared with advertisers, or used to train external models. It exists to help your people, and for nothing else.
Our digital tools reflect and support. They never diagnose, and they never make a clinical decision. That is a human clinician’s job.
Nothing on the platform — wellbeing data, manager practice, support usage — is ever connected to reviews, capability processes, or pay.
Because real clinicians provide real care through the platform, it is held to clinical standards — not only the standards of a technology product.
Every therapist is BACP, UKCP or HCPC-registered, identity-verified, DBS-checked and covered by professional indemnity insurance.
Care is delivered within a supervision framework, so clinicians practising through the platform are themselves supported and accountable.
Defined escalation pathways for risk, with a human always in the loop. The AI never handles a crisis — it hands over.
Every part of the platform makes explicit where self-help ends, where a manager’s role ends, and where clinical support begins.
The practical safeguards behind the promises above.
Lawful basis, data minimisation, and clear retention limits. Employees can request access to or deletion of their own data at any time.
Data is encrypted in transit and at rest. Clinical records are held separately from organisational analytics, with stricter access controls.
Aggregation and minimum group sizes are enforced at the data layer — the separation is structural, not a report-time setting someone could change.
Clinical care is delivered by UK-registered practitioners, within UK professional and safeguarding frameworks.
Where sessions can be recorded, it is opt-in, auto-deletes after 30 days, and the individual can delete a recording at any time.
A full DPA is provided to every employer, setting out roles, responsibilities and safeguards in writing before any data is collected.
We describe our security practices as aligned to ISO 27001 principles. Where formal certifications apply, we share current documentation on request rather than claiming more than we hold.
No. Because results are only ever shown for groups above the minimum size, narrowing filters to isolate one person simply returns no data. There is no screen, export, or admin mode anywhere in the product that reveals an individual’s responses.
Managers see team-level signals only, above the same thresholds, and never individual answers. If a whole team reports strain on Fairness or Community, that shows — but who said what does not, and cannot.
No. Your use of support, the fact that you booked, who you saw, and everything discussed are confidential to you and your clinician. Your employer sees none of it — not even that you logged in.
Organisational reports belong to the employer. Your personal and clinical data remains governed by UK GDPR and clinical confidentiality regardless, and you can request its deletion at any point.
Safeguarding follows defined clinical pathways with a human in the loop, in line with a clinician’s professional and legal duties — not automated reporting to an employer. We are transparent about these routes rather than making blanket promises we cannot keep.
Works councils, DPOs and sceptical employees all welcome. The Workplace Wellbeing Review is where we answer the hard questions in detail — before anything is signed.