Security & Data Protection

Your data is yours. It is encrypted, protected, and never used to train AI models or agents without your explicit consent.

Happy Whole Human Spain, S.L. (Barcelona, Spain · NIF/VAT ESB21889415), the sole legal entity operating the Happy Whole Human® ecosystem, is committed to protecting personal data through a layered approach combining privacy-by-design engineering, industry-standard infrastructure, and transparent governance.

Our security posture is governed by:

  • The EU General Data Protection Regulation (GDPR, Regulation 2016/679)
  • The Spanish Ley Orgánica 3/2018 (LOPDGDD)
  • The California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), where applicable

Full details on data handling are set out in our Privacy Policy and Terms & Conditions.

No AI Model Training on User Data

Happy Whole Human® does not use identifiable user data, including coaching conversations, assessment responses, session recordings, transcripts, or AI interactions, to train or fine-tune artificial intelligence models or agents without explicit user consent.

AI-enabled features are designed solely to support reflection, learning, and continuity. Where fully anonymized and aggregated data is used to improve platform functionality, it is processed in a manner that does not identify individual users and aligns with applicable law and ethical standards.

AI Transparency. HWH uses Anthropic as an AI service provider and Claude Haiku 4.5 as its underlying model. Our AI governance framework aligns with the EU AI Act, GDPR, and LOPDGDD.

Details on AI capabilities, safety guardrails, and grounding are on our HWH AI page.

Encrypted Data Storage

Happy Whole Human® stores platform, coaching, assessment, and AI interaction data on encrypted servers.

  • Encryption at rest. Message content, conversation history, and per-user long-term memory are encrypted at rest.
  • Encryption in transit. All communications between users, the platform, and service providers use current TLS standards.
  • Encrypted long-term memory. Personal insights stored for continuity are protected per-user.
  • Observability without content leakage. We monitor performance and costs without sending user inputs or outputs to external observability systems in production.

Bottom line: even if infrastructure is compromised, sensitive content is protected with layered controls.

AI Safety and Guardrails

HWH AI includes multiple layers of safety checks before and after responses are generated:

  • Prompt-injection and jailbreak resistance
  • PII detection and redaction (for example, emails, phone numbers, IDs)
  • Profanity and toxicity filtering
  • Violence and NSFW policy enforcement
  • Topic restrictions for sensitive contexts, configurable per agent

Grounded in your approved knowledge. For organizational deployments, Retrieval-Augmented Generation (RAG) grounds AI responses in your approved content, with agent-specific permissions to enforce access boundaries and metadata-aware retrieval to improve traceability.

Human in the loop. AI augments coaching; it does not replace professional judgment. Participation is optional. Sponsors receive aggregate views only, never private developmental content.

Operational Safeguards

  • Rate limiting to prevent abuse and manage costs
  • Automatic retry logic for resilience under load
  • Health monitoring and dependency checks
  • Secure secrets management with restricted access
  • Audit-friendly request logging and safety event tracking

Quality Assurance

  • Built-in evaluation framework to test response quality and guardrail effectiveness
  • Continuous monitoring of performance, latency, and token or cost usage
  • User feedback signals to improve outcomes over time

Privacy-First Infrastructure

Happy Whole Human® uses secure, industry-standard cloud infrastructure to support the HWH App, assessments, and AI-enabled features. All systems are designed to protect personal data using encryption at rest and encryption in transit, along with appropriate access controls and monitoring.

We work exclusively with independently audited service providers that meet recognized security and privacy frameworks, including SOC 2 Type II and ISO/IEC 27001, and that operate in alignment with GDPR and applicable data protection laws.

All infrastructure and technology partners act as data processors under contractual confidentiality and data protection obligations, and are used solely to support platform functionality, security, monitoring, and service improvement in accordance with our Privacy Policy.

A current list of primary processors is available on request for enterprise vendor review.

International Data Transfers

Personal data is primarily processed within the European Economic Area, in Spain. Some processing occurs in third countries via our service providers (including our AI service provider in the United States). Where personal data is transferred outside the EEA, we implement the safeguards required by Chapter V of the GDPR:

  • European Commission adequacy decisions, where applicable
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Supplementary technical and organizational measures, where necessary

You may request a copy of the safeguards applied to any specific transfer by contacting contact@happywholehuman.com .

Access Controls and Confidentiality

  • Authorized HWH personnel and coaches access personal data only under confidentiality obligations and only where necessary for their role
  • Individual coaching content and assessment results are not shared with employers, sponsors, or third parties unless you explicitly authorize sharing, or disclosure is required by law
  • For sponsored programs, only non-identifying administrative or aggregate information may be shared with sponsors
  • Multi-factor authentication is available for user accounts

Enterprise Deployment Options

For organizations with stronger control requirements, we can discuss:

  • Regional deployment options
  • Self-hosting strategies
  • Local-model strategies
  • Custom data-processing agreements (DPA) and Standard Contractual Clauses (SCCs)
  • Security questionnaire response and vendor onboarding support

Contact contact@happywholehuman.com to initiate an enterprise security review.

Reporting Security or AI Concerns

If you experience or observe a security incident, suspected data breach, inaccurate or unsafe AI output, technical malfunction, or privacy-related issue, please report the concern promptly by contacting contact@happywholehuman.com .

Where possible, reports should include a brief description of the issue, the date and time of the incident, and relevant context or screenshots. Reports are reviewed as part of our ongoing quality, safety, and governance processes.

You also have the right to lodge a complaint with a supervisory authority. The competent supervisory authority for Happy Whole Human Spain, S.L. is the Agencia Española de Protección de Datos (AEPD), www.aepd.es .

Related Documents

Happy Whole Human Spain, S.L.
Carrer del Bruc 5, #312, 08010 Barcelona, Spain · NIF/VAT ESB21889415
contact@happywholehuman.com · www.happywholehuman.com