Trust Center

Trust starts with clear answers.

Understand how BurnoutZero handles data, privacy and AI.

Overview

How BurnoutZero protects employee data. Last updated September 19, 2026.

Enforced privacy guarantees

  • k-anonymity floor: a manager never sees a team figure built from fewer than 5 people who shared data in that period (10 under the works-council preset), and the software will not accept a lower setting.
  • Consent as the join key: only data from employees who opted in is ever included in any aggregate.
  • Differencing protection: aggregates are withheld when comparing two cohorts could re-identify an individual.
  • No individual burnout score, check-in, or activity ever reaches a manager or admin, only privacy-protected aggregates.
  • Single sign-on (OIDC/SAML) and SCIM provisioning run on our own infrastructure, no third-party identity broker.

Employee data rights

  • Self-service data export: any employee can download a complete JSON copy of their own data at any time.
  • Right to erasure: any employee can permanently delete their account and data themselves.
  • Configurable retention: each organization sets how long reports and health snapshots are kept (1–60 months).
  • Legal hold: organizations can suspend deletion for litigation or audit.

Hosting & sub-processors

The application, the database and its backups are hosted in the EU, with Hetzner in Finland.

Sub-processorPurposeLocation
Hetzner Online GmbH

Application & database hosting, and backups

EU (Finland)
Mistral AI

AI insight generation and calendar classification, model mistral-small-2603. Receives check-in reflections, and meeting titles and descriptions, which can mention people outside your company. Attendee counts only, never attendee names or addresses. Not used to train any model.

European Union (France)
Stripe

Subscription billing

USA / EU
Google

Calendar integration (only when an employee connects it)

USA / EU
Microsoft

Outlook calendar integration (only when an employee connects it)

USA / EU
Expo

Mobile push notification delivery. Receives the device push token and the notification text, which never contains names, scores, or wellbeing, health or calendar data.

USA
Apple (APNs) and Google (FCM)

Final delivery of the same push notifications to iPhone and Android devices.

USA
HubSpot

Three separate things, and only the first depends on cookies: website analytics and support chat, after cookie consent; demo requests you submit; and paying customers' name, email and plan, to manage the customer relationship (not cookie-dependent). Never wellness, check-in or calendar data.

EU data centre (Germany); US company
Microsoft Clarity

Public website analytics, only after cookie consent. Never loaded for signed-in users.

USA
Sentry

Error monitoring for the website and backend. Installed but not currently active; when active it receives technical error diagnostics only, never wellness data.

Not active

Compliance

GDPR

Data-rights and retention controls available; deployment and legal assessment required

SOC 2 Type II

No completed audit report published here

Trust resources

Security questions or to report a vulnerability: security@burnoutzero.com