Back to home
    Preventa Health®
    Legal

    Privacy Statement Preventa Health

    Last updated: September 2026

    Preventa Health B.V. is an organisation that provides preventive medical screening for employees across all sectors.

    In the course of our activities, we process personal data. Below we explain in which situations we process personal data and for what purposes.

    We attach great importance to protecting your privacy when processing personal data. Personal data is processed in accordance with the General Data Protection Regulation (hereinafter: GDPR).

    This privacy statement explains how we handle the processing of your personal data and what your rights are.

    1. Data Controller

    Preventa Health B.V. acts as an independent data controller for all personal data related to health that is collected via our platform, within the meaning of Article 4 GDPR. Preventa Health B.V. is registered with the Dutch Chamber of Commerce (KvK) under number 42162327.

    The employer purchasing our services (the "Organization") acts solely as a data controller for employee contact details and data relating to participation/logistics. Preventa and the Organization are not joint controllers.

    2. What Data We Collect

    We collect the following categories of personal data:

    Identity data:

    Name, email address provided by you or (with your consent) by your employer.

    Health screening data:

    Biomarker test results, pre-test measurements (blood pressure, glucose, body measurements), responses to health questionnaires, and derived health insights. These are special categories of personal data as defined in Article 9 GDPR.

    Engagement survey data:

    Responses to the Preventa Work Engagement Survey (P-PRI), domain scores, and composite risk scores.

    Wearable data (optional):

    If you connect a device: daily values for sleep, activity, heart rate, heart-rate variability and blood oxygen from Google Health (Fitbit, Pixel Watch) or Oura. Section 10 sets this out in full.

    Technical data:

    Authentication session tokens and language preferences stored in your browser's localStorage.

    If you have questions about how we use this data to generate the recommendations sent to you, you can contact us at contact@preventa-health.com.

    3. Whose Personal Data Do We Process?

    We process personal data of the following groups:

    • Participants in our preventive medical screenings
    • Individuals requesting information about our services
    • External parties (such as medical professionals supporting service delivery)

    4. Legal Basis for Processing

    We process your personal data based on the following legal grounds:

    Explicit consent:

    For all health screening data, biomarker results, and responses to health questionnaires. Participation in our services is entirely voluntary.

    You may withdraw your consent at any time without adverse consequences via the Consent Management section of your employee dashboard. Withdrawal does not affect the lawfulness of processing prior to withdrawal. You can withdraw consent by emailing privacy@preventa-health.com.

    Legitimate interest:

    For platform security, fraud prevention, and service improvement using non-medical technical data.

    Personal data collected in the context of our services is never shared with third parties, including your employer. This also applies if the employer terminates its cooperation with us.

    5. Purposes of Processing

    We use your data for the following purposes:

    • Contacting individuals who have shown interest in our services
    • Providing personalized health screening results and scientifically grounded recommendations
    • Generating anonymized, aggregated health reports for your employer (minimum group sizes are applied to prevent re-identification)
    • Complying with applicable laws and regulations

    6. Retention Periods

    We do not retain your data longer than necessary for the purposes of processing and comply with applicable laws and regulations.

    We retain your data for the following periods:

    • Biomarker test results: 2 years
    • Health insights & survey responses: 2 years
    • Audit logs: 7 years
    • Expired survey tokens: 30 days
    • Account data: duration of the contract + 2 years
    • Wearable connections (Google Health / Oura): deleted on disconnect; synced daily values follow the health insights period above

    Automated retention policies ensure timely deletion. Upon withdrawal of consent, your health data will be deleted as soon as possible, unless retention is legally required.

    7. Security

    We have implemented appropriate organizational and technical measures to protect your data. Our servers are protected by a firewall and regularly scanned for malware. Access to personal data is restricted to individuals who require it. Access is logged. These measures aim to prevent unauthorized access to personal data.

    8. Reporting a Data Breach

    We handle your personal data with care. However, a data breach may occur, for example if data reaches the wrong person or is lost due to an error.

    Do you suspect a data breach? Please report it as soon as possible by emailing privacy@preventa-health.com. If necessary, we will contact you within 24 hours.

    9. Service Providers

    As an independent data controller, Preventa uses the following service providers:

    • Cloud infrastructure provider — Database hosting, authentication, and edge computing (EU, Ireland)
    • Email provider — Transactional emails (US, with EU Standard Contractual Clauses)
    • Google (Google Health API) — Source of the wearable data you authorise us to read from Fitbit or Pixel Watch (see section 10)
    • Oura Health Oy — Source of the ring data you authorise us to read (see section 10)

    All service providers are bound by data processing agreements in accordance with Articles 28 and 32 GDPR.

    10. Google user data (Fitbit / Pixel Watch) and Oura

    If you choose to connect a wearable, we process data from that device to enrich your own health report. Connecting is always optional, you start it yourself, and you can undo it at any time.

    What Google data we access

    When you connect Fitbit or Pixel Watch, you grant us three read-only Google Health scopes. We read only the data covered by those scopes:

    • Sleep (googlehealth.sleep.readonly) — daily sleep duration and sleep efficiency.
    • Activity & fitness (googlehealth.activity_and_fitness.readonly) — daily steps and movement/exercise summaries.
    • Health metrics & measurements (googlehealth.health_metrics_and_measurements.readonly) — heart rate (including resting heart rate), heart-rate variability, and blood oxygen where your device provides it.

    We do not request access to your Google email, contacts, calendar, files or location history, and to no profile data beyond the account identifier needed to maintain the connection.

    How we use it

    We use the data solely for your personal health report: the recovery, activity and cardiovascular components of your 14-day view, your derived readiness score, — when a wearable is connected — your resting heart rate as an input to your biomarker score, and the personal lifestyle recommendations written for you. Only if you have given separate consent do the values contribute to anonymised, aggregated reporting for your employer, subject to minimum group sizes. Your individual wearable data is never visible to your employer.

    How we store and protect it

    We store daily summary values (not raw per-second sensor streams) in our EU-hosted database. Data is encrypted in transit (TLS 1.3) and at rest (AES-256). Access and refresh tokens are encrypted and held server-side only, and never reach your browser. Row-level database policies mean only you, and clinical staff involved in your screening, can read your records; administrative access is logged in an audit trail.

    Raw and aggregated data

    Raw data means the daily summary values linked to your account: they are used only for your own report and for the personal recommendations described above. Aggregated data means anonymised group statistics, produced only with your separate consent and only above a minimum group size, so no individual can be identified. Neither raw nor aggregated Google user data is sold, used for advertising or advertising profiles, or shared with any party other than the sub-processors listed in section 9 and in our public sub-processor register.

    Retention and deletion

    If you disconnect the device in the platform, syncing stops immediately, we revoke our access with Google, and we delete the connection together with its tokens. Previously synced daily values remain part of your health record under the retention periods in section 6 and are deleted when your health data is deleted, or earlier on request via privacy@preventa-health.com.

    AI and machine learning

    Your wearable values may be used to generate your personal recommendations and the written parts of your report through an EU-hosted AI service. That service processes the data only to produce that one response for you; it is not used to train, fine-tune or improve any model, ours or a third party's, and it is never used to build models or profiles about other people.

    Sharing

    We do not sell Google user data, never use it for advertising or advertising profiles, and do not share it with third parties beyond the sub-processors in section 9 and our public sub-processor register.

    Limited Use

    Preventa Health's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

    Oura

    If you connect an Oura ring instead, the same principles apply: we read sleep, readiness and heart-rate summaries through the Oura API, use them only for your health report and for aggregated reporting you consented to, and stop syncing and delete the connection as soon as you disconnect.

    11. Your Privacy Rights

    When we process your personal data, you have rights under the GDPR. You can exercise these rights by submitting a request via privacy@preventa-health.com. More information can be found on the website of the Autoriteit Persoonsgegevens.

    Right of access

    You have the right to access the personal data we process about you.

    Right to rectification

    You have the right to have your personal data corrected if it is inaccurate or incomplete.

    Right to erasure (right to be forgotten)

    Under certain circumstances, you have the right to have your data deleted.

    Right to restriction of processing

    You have the right to temporarily restrict the processing of your personal data.

    Right to object

    You may object to further processing of your data. We must then cease processing.

    Right to data portability

    You have the right to receive a copy of your data in a structured, commonly used, machine-readable format.

    Complaints

    If you have questions or complaints, you can contact the privacy advisor at privacy@preventa-health.com. If your complaint is not satisfactorily resolved, you can contact the supervisory authority.

    12. Supervisory Authority

    You have the right to lodge a complaint with a supervisory authority (Art. 13(2)(d) GDPR). Since Preventa Health B.V. is established in the Netherlands, the lead supervisory authority is:

    Autoriteit Persoonsgegevens
    Bezuidenhoutseweg 30
    2594 AV The Hague
    autoriteitpersoonsgegevens.nl

    13. Contact

    For questions about this privacy statement or other privacy-related matters, please contact our privacy advisor via:

    privacy@preventa-health.com