Averos Health
Privacy PolicyHow Averos Health collects, uses, safeguards, and governs data in annual checkup & staff operations across web, app, and API experiences.
April 26, 2026
This policy is paired with contractual controls and your organization’s internal compliance obligations.
Purpose-limited processing
We process data to provide secure staff operations, scheduling, and reporting workflows for annual checkup programs.
Security-first handling
Administrative controls, role-based access, and account safeguards are used to reduce unauthorized access risk.
Transparency & control
Organizations can request access, correction, export, or deletion actions according to applicable laws and contractual terms.
This Privacy Policy explains how Averos Health collects, uses, shares, and protects personal information when you use our websites, applications, APIs, and related services (collectively, the “Services”).
By using the Services, you acknowledge this Privacy Policy. Where required by law, we seek consent or rely on another valid legal basis before processing personal data.
In many deployments, your organization acts as the data controller for operational and participant information entered into the platform, while Averos Health acts as a processor or service provider under contract.
For account administration, security logs, and direct service communications, Averos Health may act as an independent controller where required.
Depending on usage, we may collect:
Where applicable (including under GDPR/UK GDPR), we rely on one or more legal bases: performance of a contract, legitimate interests, legal obligations, and consent where required.
When we rely on legitimate interests, we apply balancing assessments and safeguards proportionate to the nature of the data.
We do not sell personal information. We may share data with trusted subprocessors and service providers (such as cloud hosting, email delivery, and monitoring providers) under contractual controls.
We may disclose information when legally required, to protect rights/safety, or during corporate transactions (e.g., merger or acquisition), subject to confidentiality obligations.
If personal data is transferred across jurisdictions, we use appropriate safeguards such as contractual protections, risk assessments, and supplementary controls where required by applicable law.
We retain information for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, and maintain security audit trails.
Retention periods vary by data category, contractual requirements, and applicable regulations.
We implement administrative, technical, and organizational safeguards designed to protect data against unauthorized access, disclosure, alteration, and destruction.
No system is completely risk-free. Customers and users are responsible for secure credential management, device hygiene, and local policy compliance.
We may use cookies and related technologies to enable essential functionality, security, session continuity, and service analytics. Browser controls can be used to manage cookie preferences.
Depending on jurisdiction, individuals may have rights to access, correction, deletion, restriction, objection, portability, and withdrawal of consent (where consent applies).
Requests can be routed through your organization administrator or via official contact channels. We may verify identity before completing requests.
The Services are intended for organizational and professional use, not for direct use by children as a standalone consumer product. Where applicable, organizations are responsible for lawful handling of minor-related records.
We may update this Privacy Policy periodically to reflect legal, technical, or operational changes. The latest version date is shown above. Material changes may be communicated through service notices.
For privacy questions, data requests, or incident-related concerns, contact your organization administrator or use the official contact channels published by Averos Health.
Legal notice. This document is a comprehensive privacy template for product and engineering teams. It does not constitute legal advice. Have qualified counsel review and adapt this policy for your entity, jurisdictions, and compliance requirements before production use.