Privacy Policy

Last updated: 24 September 2026

1. Who we are

WorkMyHealth is operated by Karri AB, Swedish organisation number 559250-7700, Sandgatan 2, 263 62 Viken, Sweden. Privacy contact: info@upzdownz.com.

WorkMyHealth provides a wellness platform. For end-user activity and wellness data logged inside a workspace, the workspace's organization is the data controller and WorkMyHealth acts as data processor. For account, billing, security and support data, Karri AB is the data controller. For personal accounts, Karri AB is the controller for the account holder's own data. Corporate customers accept an Article 28 data processing agreement before any member can be invited.

The Service is only available to people who are at least 18 years old. Age is confirmed at sign-up and we do not knowingly process data about minors.

2. Data we collect

We keep the data set deliberately small. For each account we store an email address (used for sign-in and transactional emails) and an alias you choose yourself - the alias is free text and does not have to be your real name. For each workspace we store the organization name and basic settings. Activity entries record the activity type (for example steps, gym minutes, run distance), a numeric value, the date, and any optional note you add yourself. We do not collect blood pressure, heart rate, sleep, mood, diet or medical history. One optional field, a weight basis, exists so that calorie-style estimates can be calculated for your own activity entries. It is only stored if you choose to enter it in the mobile app, it is readable only by you (and by server code acting on your behalf), it is never shown to workspace administrators or on public pages, and it is deleted with your profile. We do not collect location data and do not sync with third-party health or fitness apps unless you explicitly connect one from your profile.

3. Special-category data (GDPR Art. 9)

Even though we only store training activity (not medical data), activity entries tied to a named employee can indirectly reveal information about physical health. To stay on the safe side we treat this data as special-category personal data under GDPR Art. 9 and process it in personal accounts only on your explicit consent (Art. 9(2)(a)), which you give with a separate, unticked checkbox at signup. In a corporate workspace the employer is the controller and is responsible for the applicable Art. 9 exception; the acknowledgment an invited member ticks there is not consent to Karri AB. You can withdraw consent at any time from your profile page; withdrawal immediately erases all your logged activity entries. Your account itself stays so you can re-consent later or delete it separately.

4. How we use data

To deliver the Service, authenticate users, render scoreboards, send transactional emails (invitations, password resets), and bill subscriptions. We do not use activity data for advertising, profiling with legal effects, or automated decision-making, and we do not provide medical diagnosis, treatment or occupational-health decisions.

5. Legal basis (GDPR Art. 6 and 9)

Contract performance (Art. 6(1)(b)) for delivering the Service, legitimate interest (Art. 6(1)(f)) for security and product improvement, legal obligation (Art. 6(1)(c)) for accounting records, and explicit consent (Art. 6(1)(a) and Art. 9(2)(a)) for processing of activity and wellness data in personal accounts. For corporate workspaces the customer organisation is the controller and determines and documents its own Art. 6 legal basis and, where relevant, its Art. 9 exception; Karri AB does not select or record that basis on the customer's behalf.

6. Sharing and sub-processors

We share data only with sub-processors strictly needed to run the Service (hosting, payment processing, email delivery). All sub-processors are bound by data-processing agreements and are listed, with purpose and location, on our subprocessor page. We do not sell personal data and do not share activity data with your employer beyond what is already shown inside the workspace.

7. Roles and access within a workspace

Access inside a workspace is role-based. Employees see their own activity and wellness entries. Workspace administrators receive two things: the account-administration information needed to run the workspace (alias or name, email, role, membership status, invitation state) and aggregated statistics such as workspace-level participation and trends. Any figure that fewer than five individuals contributed to is withheld entirely. These aggregates are pseudonymised, de-identified or suppressed rather than fully anonymous, because they are derived from identifiable member records inside the workspace. Being an administrator does not give access to an individual member's raw activity entries, health-related values, notes, photos or workout history. Each member can further tighten their visibility from their profile, for example hiding individual entries from aggregate views or hiding activity duration. WorkMyHealth staff do not browse customer workspace data; access by our personnel is limited to documented support, security, and maintenance purposes and is audit-logged.

8. Third-party health and fitness apps

WorkMyHealth does not sync with third-party health or fitness apps (such as Apple Health, Google Fit, Garmin, or Strava) unless you explicitly connect them from your profile. If you connect such an app, only the data scopes you approve are imported, and you can disconnect at any time, which stops further import.

9. Storage and security

The database, authentication and file storage are hosted through the managed Lovable Cloud environment in AWS eu-central-1 (Frankfurt). EU hosting does not by itself rule out support access, edge processing or transfers outside the EU; the safeguards for each provider are listed on our subprocessor page. Each workspace is logically isolated with row-level security at the database level. Profiles and activity display are private by default: by default you must be signed in and be a member of the workspace to see activity data or statistics. You may actively enable specific public or social visibility, for example a public profile, a public board entry or a badge. Public profiles, boards and badges display only the fields you have deliberately enabled for public display; internal account identifiers, email addresses and private activity details are excluded from public responses. Public visibility can be switched off again at any time from your profile. Access to activity data is further limited to the employee themselves and authorised admins of the same workspace, on a need-to-know basis. We use industry-standard encryption in transit and at rest, and keep audit logs of administrative actions.

10. Retention

Activity and wellness data is kept while your consent is active and you remain part of the workspace. If you withdraw consent, leave the workspace, or delete your account, activity entries are erased immediately. Ordinary account data is removed within 30 days of account deletion. Billing records are kept for the period required by applicable accounting law (typically 7 years). The full schedule is published in our retention schedule.

11. Your rights

You have the right to access, rectify, delete, restrict, and port your personal data, to withdraw consent at any time, and to lodge a complaint with your data protection authority. Consent withdrawal, visibility settings, data export and account deletion are self-service from your profile page, which also has a form for registering access, correction, restriction, objection, portability and deletion requests. You can also use our contact form or email info@upzdownz.com. We respond within 30 days. Corporate customers can find DPIA material on our DPIA support page.

12. Cookies

We use no analytics, advertising or tracking cookies, and we do not create a visitor identifier. Because only strictly necessary and user-requested storage is used, there is no cookie consent banner. The storage actually used is:

  • Authentication session (cookie and browser local storage, set by our authentication provider) - keeps you signed in. Duration: until sign-out or session expiry.
  • Coach portal session token (local storage) - lets an invited coach stay signed in to a coaching link. Duration: until the coaching session ends or you sign out.
  • Pending sign-up details and invitation token (local storage) - carries the workspace name or invitation you started with across email verification. Duration: removed as soon as the sign-up completes.
  • Interface preferences (local storage) - remembers collapsed sections, dismissed in-app notices and your own admin calculator inputs. Duration: until you clear your browser storage.

Nothing in this list is used to profile you or to measure traffic.

13. Contact

For privacy questions, data access requests, or to request our list of sub-processors, use our contact form. We respond within 30 days.