Your employees' health data deserves the highest level of protection. Here's how Preventa Health safeguards sensitive information at every step — the same content you'll find in the downloadable Security & Data Protection Summary.
Last updated: September 2026
Multi-layered controls protect your data at every level.
TLS 1.3 for all client and service-to-service traffic. AES-256 for data at rest in primary database, backups, file storage and the report cache.
Sign-in is invite-only. Users receive a 6-digit one-time code by email — there are no passwords and no public sign-up. Rate limits (5 codes/email/hour, 20/IP/hour) and a 5-attempt lockout protect against brute force. Six-role RBAC is enforced by row-level security in the database and re-validated in every privileged edge function.
White-box web application penetration test conducted by Aikido on 04 July 2026, covering the marketing site, app and backend API. Methodology aligned with OWASP Testing Guide v4.2, OWASP ASVS, PTES, NIST SP 800-115 and the OWASP AI Testing Guide (including agentic behaviour).
Production database, object storage and edge functions run inside the European Union. No personal data is replicated outside the EU.
Row-level security policies on every public table isolate data at the database level so users can only reach records their role is authorised to see.
Six roles (Employee, Employer, Nurse, Doctor, Admin, Department Manager) enforced via security-definer database functions and re-validated in every privileged edge function.
A dual-identity system ensures personal information is never stored alongside clinical results, enabling longitudinal health tracking while preserving strict data isolation.
Persistent internal identifier
A system-generated pseudonymous identifier assigned to each individual, stored in the persons table. PII is isolated here and never exposed to employer-role queries. Created when an employee is first invited; links records across multiple testing cycles for longitudinal tracking.
Session-specific lab identifier
A structured, human-readable identifier (format: PH-YYYY-LOC-NNNN) assigned to each test session for clinical traceability without revealing personal identity. Entered on point-of-care testing devices and used to label lab results.
Personal information (name, email, department) is stored in a dedicated identity record, completely separate from clinical biomarker results. Test sessions and lab values reference only opaque identifiers — never names or email addresses. Employers have no access to individual-level personal data; they receive only anonymised, aggregate workforce insights with demographic groupings calculated server-side.
How participant data moves through the platform at each stage.
Returning employees are asked for explicit consent before past test results are linked to new screening sessions via their PID. Without consent, each testing cycle is treated independently — no historical comparison data is surfaced. Consent decisions are logged with timestamps for full auditability and GDPR compliance.
Download the full document — the single source of truth for our security posture, with live platform evidence including RLS policy coverage, audit trail statistics and encryption status.
Available to administrators
Contractual document covering role allocation, lawful basis, confidentiality controls, anonymised reporting safeguards, retention policies and breach notification procedures.
Sign in to download
We respect and uphold the data rights of all individuals. Here's what you and your employees are entitled to.
Request a copy of all personal data we hold about you
Correct inaccurate or incomplete personal data
Request deletion of your personal data under certain conditions
Receive your data in a structured, machine-readable format
Object to processing of your personal data
Request limitation of how we use your data
Withdraw previously granted consent at any time
What data we collect, how long we keep it, and where it is stored.
In compliance with GDPR Article 5(1)(e) (storage limitation), the platform enforces automated data retention. A scheduled daily job triggers the cleanup-expired-data backend function, which performs bulk deletion of records exceeding their configured retention period.
All data is stored within the European Economic Area (EEA). In the event that data needs to be transferred outside the EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) and adequacy decisions where applicable.