Trust Center
Trust starts with clear answers.
Understand how BurnoutZero handles data, privacy and AI.
Overview
How BurnoutZero protects employee data. Last updated September 19, 2026.
Enforced privacy guarantees
- k-anonymity floor: a manager never sees a team figure built from fewer than 5 people who shared data in that period (10 under the works-council preset), and the software will not accept a lower setting.
- Consent as the join key: only data from employees who opted in is ever included in any aggregate.
- Differencing protection: aggregates are withheld when comparing two cohorts could re-identify an individual.
- No individual burnout score, check-in, or activity ever reaches a manager or admin, only privacy-protected aggregates.
- Single sign-on (OIDC/SAML) and SCIM provisioning run on our own infrastructure, no third-party identity broker.
Employee data rights
- Self-service data export: any employee can download a complete JSON copy of their own data at any time.
- Right to erasure: any employee can permanently delete their account and data themselves.
- Configurable retention: each organization sets how long reports and health snapshots are kept (1–60 months).
- Legal hold: organizations can suspend deletion for litigation or audit.
Hosting & sub-processors
The application, the database and its backups are hosted in the EU, with Hetzner in Finland.
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Application & database hosting, and backups | EU (Finland) |
| Mistral AI | AI insight generation and calendar classification, model mistral-small-2603. Receives check-in reflections, and meeting titles and descriptions, which can mention people outside your company. Attendee counts only, never attendee names or addresses. Not used to train any model. | European Union (France) |
| Stripe | Subscription billing | USA / EU |
Calendar integration (only when an employee connects it) | USA / EU | |
| Microsoft | Outlook calendar integration (only when an employee connects it) | USA / EU |
| Expo | Mobile push notification delivery. Receives the device push token and the notification text, which never contains names, scores, or wellbeing, health or calendar data. | USA |
| Apple (APNs) and Google (FCM) | Final delivery of the same push notifications to iPhone and Android devices. | USA |
| HubSpot | Three separate things, and only the first depends on cookies: website analytics and support chat, after cookie consent; demo requests you submit; and paying customers' name, email and plan, to manage the customer relationship (not cookie-dependent). Never wellness, check-in or calendar data. | EU data centre (Germany); US company |
| Microsoft Clarity | Public website analytics, only after cookie consent. Never loaded for signed-in users. | USA |
| Sentry | Error monitoring for the website and backend. Installed but not currently active; when active it receives technical error diagnostics only, never wellness data. | Not active |
Compliance
GDPR
Data-rights and retention controls available; deployment and legal assessment required
SOC 2 Type II
No completed audit report published here
Trust resources
Security questions or to report a vulnerability: security@burnoutzero.com