Per-employee encryptionUK GDPR Article 32A separate key for every person.
Each employee’s coaching data is encrypted with their own key, derived from a hardware security module. Never shared with other employees, managers, or the wider organisation.
No manager visibilityICO Employment Practices Code · UK GDPR Article 5Managers see the team. Not the people in it.
Managers and HR see aggregated team patterns with k-anonymity suppression on small cells. Never an individual’s words. Never who said what.
Consent at the gateUK GDPR Article 6, 7 · Equality Act 2010Employees control what HR sees.
Anything that travels to HR or an EAP travels because the employee chose to send it. We never volunteer it. We never use coaching content for performance, hiring, or termination decisions.
Tamper-evident audit logSOC 2 · ISO 27001 · UK GDPR Article 32Every access, hash-chained.
Who saw it. When. Why. Each log entry is HMAC-chained to the one before it, so any tampering breaks the chain. Built for SOC 2 and ISO 27001 audit posture.
Crypto-shred on requestUK GDPR Article 17Right to erasure, made real.
Messages, memories, voice, journal entries. We destroy the per-employee encryption key, which makes the data permanently unreadable. No undelete. No backup loophole.