Back
DATA PRIVACY POLICY

United States

Effective date: 2026-05-19 Last updated: 2026-05-19 Data controller: Prevention at Work Group
Applicable law: CCPA/CPRA (California) + state privacy & biometric laws + applicable federal laws (HIPAA, COPPA, GLBA)

1. Who we are

CIMA is operated in the United States by Prevention at Work Foundation ("we," "us"), the U.S. operator of Prevention at Work | Group. This privacy notice describes how we collect, use, and share personal information of users residing in the United States, in compliance with applicable federal laws (HIPAA where applicable, COPPA, GLBA), the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), other state comprehensive privacy laws (including Virginia, Colorado, Connecticut, Texas, and Utah), state biometric privacy laws (including Illinois BIPA and Texas CUBI), and consumer health data laws (including Washington's My Health My Data Act).

Contact: privacidad@patworkgroup.com

2. Categories of personal information we collect

  • Identifiers: name, surname, email, date of birth, sex at birth, country.
  • Health and wellbeing information (sensitive): responses to validated questionnaires (PHQ-9, GAD-7, WHO-5), cognitive evaluations, physical measurements.
  • Biometric information (optional, granular consent): derived facial-expression and voice indicators. Processing occurs on-device — raw video and audio are never transmitted or stored.
  • Internet activity: hashed IP address, user-agent.

3. Purposes of processing

  • Provide screening, measurement, and longitudinal tracking of personal wellbeing.
  • Authenticate users via one-time email codes.
  • Generate anonymous aggregate reports (N≥5) for employer organizations, when applicable.
  • Improve CIMA using anonymized data only.

4. Biometric information

Only with your explicit, granular consent, CIMA derives numeric facial-expression indicators and voice acoustic metrics (F0, jitter, shimmer, speech rhythm) during the emotional assessment. Video and audio are processed locally in your browser and are never transmitted or stored — only the derived numeric indicators are kept.

  • Single purpose: your emotional wellbeing assessment. Nothing else.
  • No profit: we do not sell, lease, trade, or otherwise profit from biometric information.
  • Retention and destruction: derived indicators are retained while your account is active and permanently destroyed when you delete your account or 3 years after your last interaction with CIMA, whichever occurs first.
  • Written release: the in-app granular consent constitutes the written release required by state biometric privacy laws.

5. Sensitive personal information and consumer health data

We process sensitive personal information (health, biometric data) only with your explicit, informed consent and limit its use to the purposes you authorize. Where state consumer health data laws apply (e.g., Washington MHMD), your health data is collected only with consent and is never sold. You can revoke consent at any time via account settings or by emailing us.

6. Your privacy rights

Right to knowWhat personal information we collect and how we use it.
Right to deleteRequest deletion of your personal information.
Right to correctUpdate inaccurate information.
Right to opt-out of saleCIMA does NOT sell personal information.
Right to limit useRestrict use of sensitive personal information.
Right to non-discriminationExercise rights without service degradation.

Residents of other states with comprehensive privacy laws (Virginia, Colorado, Connecticut, Texas, Utah, among others) have similar rights — we honor verified requests from any U.S. resident. To exercise your rights, email privacidad@patworkgroup.com. We respond within 45 days (extendable to 90 days per CCPA §1798.130).

7. No sale or sharing for cross-context behavioral advertising

CIMA does not sell personal information and does not share it for cross-context behavioral advertising as defined by CPRA. Data shared with service providers is governed by contractual obligations consistent with CCPA §1798.140(ag).

8. Data retention and security

We retain personal information only as long as necessary for the stated purposes or as required by law. Security measures include TLS encryption in transit, encryption at rest, access controls, and audit logging.

9. Children's privacy

CIMA is not directed to individuals under 18. We do not knowingly collect data from minors. If you believe a minor has provided us with personal information, please contact us to delete it.

10. Authorized agent and complaints

California residents may designate an authorized agent to submit requests. To file a complaint, contact the California Attorney General's Office: oag.ca.gov/privacy or your state's equivalent authority.

11. Changes to this notice

We may update this notice. Changes are posted at this URL with a new "last updated" date; material changes will be notified by email.