Back to home
    Preventa Health®
    Enterprise security

    Data protection summary

    Your employees' health data deserves the highest level of protection. Here's how Preventa Health safeguards sensitive information at every step — the same content you'll find in the downloadable Security & Data Protection Summary.

    Last updated: September 2026

    Security & privacy features

    Multi-layered controls protect your data at every level.

    Encryption in transit & at rest

    TLS 1.3 for all client and service-to-service traffic. AES-256 for data at rest in primary database, backups, file storage and the report cache.

    Invite-only email OTP sign-in

    Sign-in is invite-only. Users receive a 6-digit one-time code by email — there are no passwords and no public sign-up. Rate limits (5 codes/email/hour, 20/IP/hour) and a 5-attempt lockout protect against brute force. Six-role RBAC is enforced by row-level security in the database and re-validated in every privileged edge function.

    Independent penetration testing

    White-box web application penetration test conducted by Aikido on 04 July 2026, covering the marketing site, app and backend API. Methodology aligned with OWASP Testing Guide v4.2, OWASP ASVS, PTES, NIST SP 800-115 and the OWASP AI Testing Guide (including agentic behaviour).

    EU-only data residency

    Production database, object storage and edge functions run inside the European Union. No personal data is replicated outside the EU.

    Row-level security

    Row-level security policies on every public table isolate data at the database level so users can only reach records their role is authorised to see.

    Role-based access control

    Six roles (Employee, Employer, Nurse, Doctor, Admin, Department Manager) enforced via security-definer database functions and re-validated in every privileged edge function.

    Identity & data separation architecture

    A dual-identity system ensures personal information is never stored alongside clinical results, enabling longitudinal health tracking while preserving strict data isolation.

    Person Identifier (PID)

    Persistent internal identifier

    A system-generated pseudonymous identifier assigned to each individual, stored in the persons table. PII is isolated here and never exposed to employer-role queries. Created when an employee is first invited; links records across multiple testing cycles for longitudinal tracking.

    Unique Test Identifier (UTID)

    Session-specific lab identifier

    A structured, human-readable identifier (format: PH-YYYY-LOC-NNNN) assigned to each test session for clinical traceability without revealing personal identity. Entered on point-of-care testing devices and used to label lab results.

    PII isolation

    Personal information (name, email, department) is stored in a dedicated identity record, completely separate from clinical biomarker results. Test sessions and lab values reference only opaque identifiers — never names or email addresses. Employers have no access to individual-level personal data; they receive only anonymised, aggregate workforce insights with demographic groupings calculated server-side.

    Consent & longitudinal tracking

    Returning employees are asked for explicit consent before past test results are linked to new screening sessions via their PID. Without consent, each testing cycle is treated independently — no historical comparison data is surfaced. Consent decisions are logged with timestamps for full auditability and GDPR compliance.

    Security & Data Protection Summary

    Download the full document — the single source of truth for our security posture, with live platform evidence including RLS policy coverage, audit trail statistics and encryption status.

    Available to administrators

    Health Data Governance Agreement

    Contractual document covering role allocation, lawful basis, confidentiality controls, anonymised reporting safeguards, retention policies and breach notification procedures.

    Sign in to download

    Your data rights

    We respect and uphold the data rights of all individuals. Here's what you and your employees are entitled to.

    Right to access

    Request a copy of all personal data we hold about you

    Right to rectification

    Correct inaccurate or incomplete personal data

    Right to erasure

    Request deletion of your personal data under certain conditions

    Right to portability

    Receive your data in a structured, machine-readable format

    Right to object

    Object to processing of your personal data

    Right to restrict processing

    Request limitation of how we use your data

    Right to consent withdrawal

    Withdraw previously granted consent at any time

    Data handling & retention

    What data we collect, how long we keep it, and where it is stored.

    What we collect

    • Identity data: Name, email address, date of birth, sex
    • Biomarker results: Health markers including lipids, glucose, kidney function, inflammation
    • Survey responses: Lifestyle questions across multiple health domains
    • Organisational data: Employer affiliation, department assignment
    • Pre-testing entries: Blood pressure, glucose, body measurements entered by employees

    Retention periods

    • Biomarker test results: 2 years
    • Audit and access logs: 12 months (extended to 7 years for privileged-action logs)
    • Account data: Duration of contract + 2 years
    • Consent records: Retained for the life of the associated person record for auditability

    In compliance with GDPR Article 5(1)(e) (storage limitation), the platform enforces automated data retention. A scheduled daily job triggers the cleanup-expired-data backend function, which performs bulk deletion of records exceeding their configured retention period.

    Data location & transfers

    All data is stored within the European Economic Area (EEA). In the event that data needs to be transferred outside the EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) and adequacy decisions where applicable.