PrivacyWhat we collect.
Why. And how we keep it isolated.
The short version: only what we need, only for as long as we need it, never shared, never pooled.
What we collect
We collect only what is needed to engineer, certify, and deliver a Knowledge Asset to you: the documents and data you upload, the people on your team who use the platform, and the queries your AI sends.
We do not collect information about your end users beyond what your engagement requires.
Your data is yours
Per-customer isolation is structural: each organisation's sources, facts, and audit logs live in a dedicated tenancy. Your data is not pooled, not used to train shared models, and not shared with any third party without your written consent.
Source documents you upload remain owned by you. Healthattica™ receives only the rights it needs to build, certify, and operate the Knowledge Asset you commission.
Cookies and analytics
This site uses no third-party analytics or advertising trackers. We rely on minimal, first-party telemetry to keep the page running and surface obvious errors.
If we add any analytics tooling, it will be documented here first.
Audit log access
The tamper-evident audit log on every Knowledge Asset is exportable on demand and verifiable independently. We do not gate visibility into your own usage data.
Your rights (GDPR / UK GDPR)
Under the General Data Protection Regulation and equivalent regimes, you have the right to access your personal data, to have it rectified or erased, to restrict or object to processing, and to data portability. You also have the right to withdraw consent at any time and to lodge a complaint with your supervisory authority.
To exercise any of these rights, write to privacy@healthattica.com. We respond to verified requests within thirty days and will not extend the deadline without telling you why.
Reporting a security issue
If you believe you have found a vulnerability in our software, infrastructure, or a deployed Knowledge Asset, write to security@healthattica.com. Coordinated disclosure details are published at /.well-known/security.txt. We will acknowledge your report within two working days.
General contact
Anything else - commercial, partnership, press, support - write to hello@healthattica.com.