Trust & transparency

The data is only honest if people trust it.

A wellbeing platform lives or dies on one thing: whether an employee believes their honesty is safe. If they don’t, they tell you they’re fine — and your dashboard confidently reports that everything is well right up until someone leaves.

So we don’t treat privacy as a policy. We build it into how the platform works, and we publish exactly where every line sits.

Employers see conditions. Never people.

Every insight an employer receives is aggregated across a group. No individual’s answers, activity, or care is ever visible to their organisation — not to HR, not to their manager, not to anyone above them. That isn’t a setting we offer. It is how the system is built, and it cannot be turned off.

Exactly what your organisation can — and cannot — see

Most platforms bury this in a data-processing agreement. We put it on a public page, because a manager and an employee should be able to read the same thing and both feel safe.

Your organisation sees

Always aggregated, always above minimum group sizes
Condition scores across the organisation and by team
Strain level and bounce-back trends over time
Participation rates
Condition-specific recommendations
Board-ready summary reporting

Your organisation never sees

Not by request, not by escalation, not by admin override
Any individual’s survey answers
Who is using support, or how often
Anything an employee writes, journals, or reflects on
Any therapy or coaching content, ever
Any clinical record or diagnosis
8

The minimum group size rule

No result is ever shown for a group smaller than eight responses. If a team is too small, its data rolls up into a larger group rather than being displayed — so no one can be identified by narrowing the filters. Thresholds can be raised for your organisation, never lowered.

Things we have decided never to do

Some of these are technically possible and would even make the product “smarter”. We don’t do them, because the moment employees suspect we might, the honesty the whole platform depends on disappears.

No individual monitoring

We do not track, score, or flag individual employees. There is no hidden risk profile with someone’s name on it.

No sentiment mining

We do not read, scan, or analyse the content of messages, emails, chat, or calendars. We measure what people choose to tell us, nothing they didn’t.

No surveillance

No keystroke, location, activity, or productivity tracking. This is a wellbeing platform, not a monitoring tool wearing its clothes.

No selling data

Employee data is never sold, shared with advertisers, or used to train external models. It exists to help your people, and for nothing else.

No AI diagnosis

Our digital tools reflect and support. They never diagnose, and they never make a clinical decision. That is a human clinician’s job.

No performance linkage

Nothing on the platform — wellbeing data, manager practice, support usage — is ever connected to reviews, capability processes, or pay.

Clinical governance, not just software

Because real clinicians provide real care through the platform, it is held to clinical standards — not only the standards of a technology product.

Registered clinicians only

Every therapist is BACP, UKCP or HCPC-registered, identity-verified, DBS-checked and covered by professional indemnity insurance.

Clinical supervision

Care is delivered within a supervision framework, so clinicians practising through the platform are themselves supported and accountable.

Clear safeguarding routes

Defined escalation pathways for risk, with a human always in the loop. The AI never handles a crisis — it hands over.

Where the line sits

Every part of the platform makes explicit where self-help ends, where a manager’s role ends, and where clinical support begins.

Data protection and security

The practical safeguards behind the promises above.

UK GDPR compliant

Lawful basis, data minimisation, and clear retention limits. Employees can request access to or deletion of their own data at any time.

Encrypted throughout

Data is encrypted in transit and at rest. Clinical records are held separately from organisational analytics, with stricter access controls.

Privacy by design

Aggregation and minimum group sizes are enforced at the data layer — the separation is structural, not a report-time setting someone could change.

UK-based care

Clinical care is delivered by UK-registered practitioners, within UK professional and safeguarding frameworks.

Optional, self-deleting recordings

Where sessions can be recorded, it is opt-in, auto-deletes after 30 days, and the individual can delete a recording at any time.

Data processing agreement

A full DPA is provided to every employer, setting out roles, responsibilities and safeguards in writing before any data is collected.

We describe our security practices as aligned to ISO 27001 principles. Where formal certifications apply, we share current documentation on request rather than claiming more than we hold.

The questions people really ask

Could a determined HR director find out how one person answered?

No. Because results are only ever shown for groups above the minimum size, narrowing filters to isolate one person simply returns no data. There is no screen, export, or admin mode anywhere in the product that reveals an individual’s responses.

What if my manager is the problem the survey is measuring?

Managers see team-level signals only, above the same thresholds, and never individual answers. If a whole team reports strain on Fairness or Community, that shows — but who said what does not, and cannot.

Does my employer know if I book therapy?

No. Your use of support, the fact that you booked, who you saw, and everything discussed are confidential to you and your clinician. Your employer sees none of it — not even that you logged in.

What happens to my data if the organisation stops using MySafeWellbeing?

Organisational reports belong to the employer. Your personal and clinical data remains governed by UK GDPR and clinical confidentiality regardless, and you can request its deletion at any point.

Is anything shared if someone is at risk?

Safeguarding follows defined clinical pathways with a human in the loop, in line with a clinician’s professional and legal duties — not automated reporting to an employer. We are transparent about these routes rather than making blanket promises we cannot keep.

Bring your toughest privacy question to the review

Works councils, DPOs and sceptical employees all welcome. The Workplace Wellbeing Review is where we answer the hard questions in detail — before anything is signed.