Last updated: 1 May 2026
PsychFlo processes behavioural metadata about employees on behalf of employer organisations. This page explains our obligations and yours under the General Data Protection Regulation (GDPR) and applicable data protection law in your jurisdiction.
GDPR COMPLIANCE STATUS
PsychFlo operates in two distinct data roles depending on the context:
DATA CONTROLLER
For website visitors, demo enquiry contacts, and platform account holders. PsychFlo determines the purpose and means of processing this data.
DATA PROCESSOR
For employee behavioural data processed on behalf of client organisations. The client organisation is the Data Controller. PsychFlo processes only under documented instruction set out in a signed DPA.
All client organisations that use PsychFlo to process employee data must sign a Data Processing Agreement before any employee data is ingested into the platform. The DPA covers:
Request our standard DPA
Available for review before signing any contract
Employee mental health and wellbeing information may constitute special category data under GDPR Article 9. PsychFlo is specifically designed to avoid processing special category data:
WHAT WE DO PROCESS
WHAT WE DO NOT PROCESS
All outputs are aggregated at team level (minimum five members). No individual-level outputs are generated. This architectural decision means PsychFlo does not produce data about identifiable individuals’ mental health — and therefore does not trigger Article 9 special category requirements in ordinary operation.
Client organisations (as Data Controllers) are responsible for establishing and documenting a lawful basis for processing their employees’ data using PsychFlo. We recommend and support the following approaches:
Legitimate interests (Art. 6(1)(f))
Monitoring workforce wellbeing to prevent harm and fulfil duty of care obligations is generally accepted as a legitimate interest for employers, provided a Legitimate Interests Assessment (LIA) is completed and documented. PsychFlo can provide a template LIA for client use.
Legal obligation (Art. 6(1)(c))
Employers have statutory duty of care obligations under applicable health and safety legislation. Proactive monitoring to meet these obligations may constitute a legal obligation lawful basis depending on jurisdiction.
Consent (Art. 6(1)(a))
Where clients choose to use consent as their lawful basis, PsychFlo supports opt-in employee consent flows for all employee-facing features. Consent must be freely given, specific, informed, and withdrawable without detriment.
PsychFlo is designed to make it straightforward for client organisations to respond to employee rights requests:
Subject access requests
Employees can request their own signal data through the HR admin panel. Export available within 5 business days.
Right to erasure
Individual employee records can be deleted from the platform by the HR admin at any time. Automated deletion at contract end.
Right to restriction
Individual employees can be excluded from signal collection by HR admin. Opt-out does not produce a flag visible to managers.
Right to object
Employees who object to processing can be removed from all data collection without affecting their employment record in the platform.
In the event of a personal data breach, PsychFlo will:
For GDPR-related enquiries, DPA requests, or data subject rights requests:
PsychFlo Data Protection Contact
Email: info@psychflo.com
You also have the right to complain to the relevant data protection supervisory authority in your jurisdiction.