Our ApproachAbout UsBlog

Privacy & Cookies Policy of the Koa Foundations App

Summary of Privacy Policy - Reading time 2 mins

This summary helps you to quickly understand the main points of the Privacy Policy. It is provided for convenience only. Because it does not replace our full Privacy Policy, please read the full Privacy Policy to understand the complete picture of how we handle personal information.

We’re Koa Health.

We have created Foundations to help you manage stress and improve your health and wellbeing. We manage all of your data in Foundations.

We only collect the information we need to run and improve Foundations.

We collect your information to help you support and maintain your health and wellness. We may collect additional information with your permission or to comply with applicable law.

You can choose not to share some information with us.

You can use the settings menu to understand what information you can stop sharing with us, and what App functions you will lose access to if you stop sharing.

We share information about you with third-party service providers.

This helps us provide some parts of the service (such as notifications). We ask our service providers to keep your information safe.

We may share anonymized information with organizations that we work with.

If you have access to Foundations through your employer, we may share anonymized summary reports with this organization (such as how many sign-ups there have been). Beyond our services providers and clients, we may also share anonymized information with researchers to help us improve Foundations. We do not share any information that could identify you.

You need to be 16 or over to use Foundations.

By using Foundations you are telling us that you are at least 16 years old.

We work hard to keep your information safe.

We work to protect your information from being lost, stolen or misused. Because no system is perfect, you can help by keeping your password and account details safe.

We use your information to contact you.

This helps us communicate with you and respond to your questions. We never use your sensitive information in our communications with you.

Full policy

This Privacy Policy applies to any collection and/or processing of personal data (hereinafter “Personal Data”) performed as a result of your use of the app Koa Foundations (the “App”). All data collected by the App will not be processed for any other reason than what is outlined in this policy.

Note that this App might collect personal sensitive information that is health-related (hereinafter “Sensitive Data”). If you do not agree with this Policy, please do not access or use the App and the Services.

1. Who collects, controls and processes your personal data?

The Data Controller responsible for collecting and processing your data changes depending on your location:

When in the USA and Canada:

Koa Health Digital Solutions Limited (hereinafter “Koa”), a company registered in the United States (“US”) with its registered address at 75 state street, Boston MA 02109, United States of America. You can contact Koa at privacy@koahealth.com for any privacy related matter.

When in the UK, the EEA and other countries:

Koa Health B.V. (hereinafter “Koa”), a company registered in the Netherlands (registered number 78707838) with registered address at Basisweg 10, 1043 AP, Amsterdam, The Netherlands.

Koa is the Data Controller of all Personal Data collected through the App. Regardless of your location, your data will be processed as indicated in this privacy policy.

Where the App is offered by an employer (Customer) to its employees, Koa may provide aggregated insights related to usage of the App, so that they can understand its impact. For example, we may provide information on what percentage of people who used the App have found it to be beneficial. These insights will never include personal information and your employer will not be able to know your name, email address nor see any raw data you have entered into the App.

Koa may choose to conduct a study with invited users. In this case, users will be invited by Koa or a third-party agency and Koa will process personal data as indicated in the study's privacy policy, overriding this one. You can contact Koa at privacy@koahealth.com for any privacy related matter. The Data Protection Officer (Judith Vieberink)​ for Koa may be contacted at dpo@koahealth.com​.

2. Why do we collect personal data about you and what do we do with it?

Help you manage your stress

The main purpose of the App is to help you better understand and manage your stress. In order to achieve that purpose, we collect and process information, including personal data. We analyze information from your interaction with the app, like your favorite activities and personal preferences, in order to offer you recommendations, activities and programs that may help you manage your stress.

Your consent is the basis for the collection and process of personal data to manage your stress, including data collected through questionnaires. Some personal data collected for this purpose may be considered health data. You can remove this consent within the settings of the app, or at any time by contacting us at privacy@koahealth.com using, if possible, the same email address with which you registered in the App.

Personalized notifications based on your activity

We may optimize the notifications we send you by basing these on your preferences or activity within the app, in order to make them as relevant as possible. For example, we may inform you about new programs we think you might be interested in based on your preferences. This processing may include the use of cookies or similar technologies, as detailed in our cookies policy. The lawful basis for this processing is your consent. You will be asked for consent the first time you use the app, as part of the onboarding. You can manage and remove your consent at any time within the app settings.

Provision of basic App services:

If you create an account in our App, we will process some personal data for providing basic services of the App such as registration, authentication or support.

As we strictly need some personal data for the functioning of the App, the lawful basis of this processing is the performance of a contract, specifically the Terms & Conditions of the App. Sensitive data is not collected or processed for this purpose.

Improving the functioning of the App and our services:

We process personal data to improve the App performance, usability and to provide a better service. This includes aspects related to performance, navigation, availability and usability. To do this we consider things like how often and for how long you use the App, how you navigate between screens, the activities you use, and which screens you spend more time on. We might also ask for your feedback through email or the App. In some cases the functionality of the App uses third party services to support analytics and navigation and these functions may involve cookies as described in our cookies policy (as detailed in section 11 below).

Our legitimate interest is the legal basis for this processing. Where we use cookies for this purpose, your consent is the basis for collecting and processing personal data for this purpose. Sensitive data (such as wellbeing scores) is not collected or processed for this purpose.


We process your contact data to send you information about our services or products, such as product updates and new content. We may use third party services to facilitate such communications.

Our legitimate interest is the legal basis for this processing. Sensitive data (such as wellbeing scores) is not collected or processed for this purpose. You can opt-out of these communications using the “unsubscribe” option in one of our emails.

When using Foundations as part of a healthcare insurance plan in the US:

When you are using Foundations as part of your healthcare insurance plan in the US, we will receive information from them to verify your eligibility to access and use our App. This information has been provided to Koa by your insurance company.

3. What personal data do we collect about you and how?

The App’s functionalities require the collection of personal data. Sometimes you provide us with data, sometimes data about you is collected or inferred through your use of the App or generated by us through analysis. We collect and process the minimum personal data necessary for each of the different purposes, and we will only keep it for as long as we provide you with a service. Should the purposes of the data collected change, we will inform you beforehand and ask for your consent again where applicable, before we process any data.

Since our service is focused on helping you manage your stress, some of the personal information that you share or we collect from you might be related to health conditions or stress behaviors. This is not directly sought by the App, but answers to questions may relate to a medical condition. The App and any information and/or services provided by the App are not intended to be used in the detection, diagnosis, prevention, monitoring, prediction, prognosis, therapy, treatment or alleviation of any condition, disease or vital physiological processes or for the transmission of time sensitive health information. See our Terms & Conditions.

When you create an account within the App, you share with us the following information:

  • Name
  • Email Address

When you use the App and answer our questionnaires and tests, you share with us the following information:

  • Your goals for using the app, such as feeling overwhelmed, trouble sleeping, etc
  • Information on your perception of your mental health with questions around your mood, sleep and how stressed or overwhelmed you have felt over the past week. We use standardized scales that are widely used by healthcare specialists and scientists worldwide and collect this information so that you can better understand your wellbeing and see how it might change over time.
  • Information related to the activities provided within the App, such as text you insert into the App within the journaling activities.
  • Your opinion on the App and its functionality, if you choose to provide us feedback.
  • Periodic information about how you feel and your mood (e.g. stressed, happy) through the answers you give to our questionnaires and activities.

Through the use of cookies (read our cookies policy) we collect and process the following information:

  • User activity in the App: Frequency of access to the App, time spent on different screens, functions used etc.

We monitor your activity in the App to improve your experience.

By analyzing aggregated data from everyone who uses the App, we can draw conclusions and make improvements, for example, if loading times are slow or if information is too hard to find.

4. Do we share personal data about you with others?

We do not share any personal information about you with our customers. We will only share aggregated or unidentifiable information that cannot be related to an individual.

On the legal basis mentioned in Section 3, we may share some of your personal data with service providers for specific activities such as hosting, providing customer support, analytics or application functionality such as notifications. We only share the minimum information and authorize our service providers to process your information following our instructions. We make sure that our service providers erase all your personal information right after their services are finished. We take the appropriate measures to ensure that providers outside the EEA comply with EEA standards and this privacy policy in every processing of personal data they perform on our behalf, by requiring appropriate safeguards and guarantees such as Standard Contractual Clauses.

Internal team members will process your personal data following professional responsibilities and contractual obligations only for the purposes established in this Privacy Policy. We take appropriate measures to guarantee the fair and confidential use of all personal data by our employees.

5. How long do we keep your data?

We may retain your personal data for different periods of time, depending on the type of data involved and the purposes of the processing, but generally, following these criteria:

  • As long as you are an active user of our services or we have legal obligations to retain the data.
  • If you are not active in our App, we will erase your data after 24 months from the last time you used it.
  • You may be offered Koa Foundations by your employer for a trial period. In such cases, we might need to delete your data at the end of our agreement with your employer, if we have agreed to such a condition. Normally, this would be after the first three months of the trial.
  • We will also erase or stop processing your data if you withdraw consent or require us to do so. In these cases, we will erase your data or anonymize it in such a manner that is no longer identifiable.

The data protection laws give you a series of rights regarding the personal information that we manage about you. Specifically, the rights of access, rectification, erasure, limitation, objection, portability, as well as not being subject to automated decision making and to being able to remove your consent.

You can exercise these rights by contacting us at privacy@koahealth.com. When sending us a request, use if possible the same email address with which you registered in the App and the right you want to request. If you decide to exercise one of these rights through a representative, it will be necessary to provide the documentation to authorize the request.

We will respond to your requests within a maximum of 30 days. That period may be extended by an additional 30 days if necessary. In the event of such extension, we will notify you within one month of receipt of the request, together with the reasons for the delay.

If you feel your data privacy rights have been breached, you also have the right to file a complaint with a Data Protection Control Authority (e.g., the Dutch Data Protection Authority, the Information Commissioner’s Office).

In order to register and use our services you must be over 16 years old. Therefore, by signing up you confirm that you meet this condition. We may contact you to confirm this. We do not knowingly collect information from those younger than 16 years. If you are a parent or guardian and believe that your child has used the App you may contact us at privacy@koahealth.com and we will respond promptly.

7. How do we keep your data safe?

Koa is responsible for ensuring the security, integrity and confidentiality of your personal information. Therefore, as part of our commitment and in compliance with current legislation, we have adopted the most demanding and robust security measures and technical means to prevent their loss, misuse or access without your authorization.

We protect all communications between the App and the servers in line with best practice by using TLS for encryption and server authentication. We use ISO 27001 certified systems in order to protect your registration information including email and password. We store your personal data in an encrypted database.

Also, we promise to act quickly and responsibly in the event that the security of your data may be in danger, and to inform you if necessary.

8. Changes to this Privacy Policy

We may modify this Privacy Policy from time to time, and will post any revisions on our App.  We will indicate at the bottom of the Privacy Policy the Effective Date of the most recent update.  If we believe an update requires additional notice to you or your consent, we will contact you to provide that notice or seek that consent.

9. Protected Health Information and HIPAA

When you are using Foundations as part of your healthcare insurance plan in the US, we might receive from your insurer your email address, which we will use to give you access to the App.

If you are receiving Foundations from your US health insurer, some of the information we collect about you is “Protected Health Information” (“PHI”) under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”).  Generally speaking, the following information will be PHI: (a) the information we receive from your healthcare insurance carrier and (b) information you provide in the App that relates to your past, present, or future physical or mental health or condition; the provision of health care to you; or the past, present, or future payment for the provision of health care to you.

We want to make sure you know that, notwithstanding anything else in this Privacy Policy, we only use and share PHI as permitted by HIPAA and our business associate agreement with your healthcare insurance carrier. This means we only use and share your PHI with your healthcare insurance carrier to support your treatment or upon your direction or consent. Your healthcare insurance carrier will provide you with a “Notice of Privacy Practices” that explains how they use your PHI in compliance with HIPAA.

Note that PHI can be deidentified in which case it is no longer considered PHI. This can be done by removing 18 specific types of identifier from the information pursuant to HIPAA regulations. We may deidentify PHI, in accordance with HIPAA, and use it as non-PHI for the purposes listed in Section 2.

10. California residents and CCPA

If you are a resident of the State of California in the United States, we comply with the California Consumer Privacy Act (“CCPA”) with regard to your Personal Data.

The CCPA gives California residents a right to know what kind of Personal Data Koa is collecting, how it is used, and how it is shared.  All of this information is set forth above in this Privacy Policy.

The CCPA gives California residents a right to know whether their Personal Data is being sold. This includes sharing with a third party for monetary or other valuable consideration for a purpose that is not a “business purpose” as set forth in the CCPA.  Koa does not sell your Personal Data. Since Koa does not sell your Personal Data, it does not provide a sales opt-out process.

As required by the CCPA, Koa does not discriminate in response to privacy rights requests.

The CCPA gives California residents the right to know what data is being collected about them, a right to access that data and obtain a copy of it, and the right to request deletion of such data.  For requests or information related to these rights you can contact Koa at privacy@koahealth.com, and you may also exercise your rights as follows: You may designate an authorized agent to submit requests to exercise your data protection rights to Koa. Such authorized agent must be registered with the California Secretary of State and must submit proof that you have given the agent authorization to act on your behalf.

The CCPA requires that we indicate whether we honor “Do Not Track” or “DNT” settings in your browser concerning targeted advertising. Our Services do not currently use targeted advertising, and thus do not respond to web browser “Do Not Track” signals or other mechanisms that provide a method to opt out of the collection of information on the App.

Any disclosures we provide will only cover the 12 month period preceding the request of a verifiable consumer request. Our response will explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a CCPA-compliant format to provide your Personal Data that should allow you to transmit the information from one entity to another without hindrance.

We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.

11. Cookies Policy

What are cookies?

Cookies are small data files that are placed on your computer or mobile device when you visit a website or use an app. Cookies are widely used by online service providers in order (for example) for services to work and/or function, or to work more efficiently, as well as to provide reporting information.

Cookies set by the Data Controller are called "first party cookies". Cookies set by parties other than the Data Controller are called "third party cookies". Third party cookies enable third party features or functionality to be provided through the app you are using (such as interactive content and analytics). The third parties that set these third party cookies can recognize your device both when it visits the service in question and also when it visits certain other websites or services.

Why do we use cookies and other tracking technologies?

The third party cookies or similar tracking technologies we work with help us to track and target the activity of our users. For example, we use cookies for analytics, configuration, and other purposes. Every cookie we use is described in more detail below.

What cookies do we use?

App cookies:

Analytics: we collect technical data from our App in a pseudo-anonymous manner so that we can better understand how users interact with our App. This is used to be able to better understand and track activities within the App to inform you based directly on your activities and to be able to improve the App services overall.

Personalized notifications: we collect technical data from our App in a pseudo-anonymous manner so that we can send users more relevant notifications based on how they interact with the App.

How can I deactivate cookies or similar tracking technologies?

You can withdraw consent for the usage of cookies in the settings section of the App, or by following the instructions of section 6 of this Privacy Policy.

Effective from: September 2022