Privacy Policy
Last updated: 23 June 2026·Version: 1.0
1. About this policy
This Privacy Policy explains how MyCapsule AS (“MyCapsule”, “we”, “us”) processes personal data when you visit https://www.mycapsule.no, register an account, use the MyCapsule platform, or otherwise interact with us.
MyCapsule is a B2B platform for continuous workforce well-being monitoring. Customers (employers) use the platform to send weekly pulse surveys to employees via SMS. This policy covers processing where MyCapsule is the data controller. When we process employee data on behalf of a customer, the customer is the data controller and MyCapsule acts as a data processor — see Section 8 and our Data Processing Agreement.
2. Data controller
MyCapsule AS
Org. no.: 931084461
Gulaksvegen 31, 4345 Bryne, Norway
Email: morten@mycapsule.eu
3. Who this policy applies to
| User group | MyCapsule's role |
|---|---|
| Website visitors | Data controller |
| Administrators (HR, managers) who register an account | Data controller |
| Health partners invited via the platform | Data controller |
| Employees who receive pulse SMS | Data processor on behalf of the customer — see Section 8 |
| Platform operators (internal super administrators) | Data controller |
4. What data we process
4.1 Website and accounts (administrators and health partners)
| Category | Data | Source |
|---|---|---|
| Identity | Email address, full name | Registration form, Google OAuth |
| Authentication | Password (stored as a cryptographic hash in Supabase Auth) | Sign-in |
| Company information | Company name, organization number, industry, country, employee band, employee count | Onboarding |
| Contact | Phone number (optional during onboarding) | Onboarding |
| Subscription | Selected plan, billing interval, seat count | Onboarding and Stripe |
| Usage | Selected active company (stored locally in the browser) | App usage |
4.2 Billing
We process email, Stripe customer ID, subscription status, plan, and seat quantity. Payment card details are handled directly by Stripe and are not stored in MyCapsule's database.
4.3 Employee data (processed on behalf of customers)
When a customer uses MyCapsule for pulse surveys, we process the following on the customer's instructions:
| Category | Data | Sensitivity |
|---|---|---|
| Identification | Phone number, optional name, department | Personal data |
| Pulse responses | Workload, energy, control, team/manager relationship, recovery (scale 1–10) | Workplace well-being |
| Health information | Whether the respondent reports physical discomfort or pain, and if so, body area | Special category data (GDPR Art. 9) |
| Survey delivery | One-time survey token, link between response and employee record on the server | Operational linkage |
4.4 Communications and operations
- SMS logs: phone number, message text (including survey URL), delivery status
- Audit logs: administrator actions, actor email, event type
- Health partner invitations: email, contact details, organization name
5. Privacy in reporting — aggregation, not individual visibility
MyCapsule is designed so that individual pulse responses are not displayed in the application.
- Response records are stored without the employee's name or phone number attached to the response itself.
- Dashboards and reports show aggregated data only. Departments or groups with fewer than 5 responses (configurable per customer, default 5) are not shown, to reduce the risk of identifying individuals.
- Direct client-side access to individual response records is blocked in the database (Row Level Security).
- A technical link exists on the server between a response and a survey token for operational purposes, but this is not exposed in customer-facing reports.
Customers are responsible for informing their employees before the first survey SMS is sent. See our Employee Information Notice template.
6. Purposes and legal bases
6.1 Where MyCapsule is the data controller
| Purpose | Legal basis (GDPR) |
|---|---|
| Create and manage your account | Contract — Art. 6(1)(b) |
| Provide and operate the platform | Contract — Art. 6(1)(b) |
| Billing and subscription management | Contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) |
| Authentication and security | Legitimate interests — Art. 6(1)(f) |
| Audit logging and abuse prevention | Legitimate interests — Art. 6(1)(f) |
| Respond to inquiries | Legitimate interests / contract — Art. 6(1)(f)/(b) |
6.2 Employee data (processor role)
Processing of employee data is carried out only on the customer's instructions under our Data Processing Agreement. The customer must have a valid legal basis with respect to their employees. Health information (pain/discomfort) requires a separate legal basis under GDPR Art. 9.
7. Where data is stored and processed
| Provider | Function | Data involved |
|---|---|---|
| Supabase (West EU (Ireland)) | Database and authentication | All application data — see Section 4 |
| Stripe | Payment processing | Email, customer ID, subscription data |
| Twilio | SMS delivery (when enabled) | Phone number, message text |
| Vercel | Application hosting | HTTP requests (infrastructure-level access logs) |
| OAuth sign-in; fonts (Google Fonts) | Email and name via OAuth; network data when fonts are loaded |
See our full subprocessor list.
8. Sharing with third parties
We do not sell personal data. We share data with subprocessors necessary to deliver the service, under data processing agreements. Processing takes place primarily in the EU/EEA (West EU (Ireland)). Where data is transferred outside the EEA, appropriate safeguards apply (e.g. Standard Contractual Clauses).
9. Retention
| Data category | Retention period |
|---|---|
| Account and profile | For the duration of the customer relationship, plus up to 12 months after termination |
| Subscription and billing records | As required by applicable accounting law (typically 5 years in Norway) |
| Employee records (on behalf of customer) | Deactivated immediately upon termination. Personally identifiable employee data is deleted or anonymized within 30 days unless a longer period is required by law or requested by the customer. |
| Pulse responses | Per customer instructions; deleted when the customer relationship ends unless otherwise agreed. Aggregated and anonymized analytics may be retained for benchmarking and historical reporting. |
| SMS logs | Up to 12 months |
| Audit logs | Up to 24 months |
10. Your rights
Where MyCapsule is the data controller, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Erasure (“right to be forgotten”) where conditions are met
- Restrict processing
- Data portability (for data you have provided)
- Object to processing based on legitimate interests
- Lodge a complaint with the Norwegian Data Protection Authority (datatilsynet.no)
Employees who receive pulse SMS should generally contact their employer (the data controller) first. We will assist the customer as needed.
Send requests to morten@mycapsule.eu. We respond within 30 days.
11. Security
We implement technical and organizational measures including:
- Encrypted communication (HTTPS/TLS)
- Role-based access control (admin, health partner, super admin)
- Row Level Security in the database
- Aggregation requirements (minimum group size) before reports are displayed
- Blocking direct client access to individual pulse responses
Read more on our Security page.
12. Children
MyCapsule is a B2B service aimed at employers. The service is not intended for persons under 16 years of age.
13. Changes
We may update this policy. Material changes will be notified via email to registered administrators or on the website. The date and version at the top of this page will be updated accordingly.
14. Contact
MyCapsule AS
Gulaksvegen 31, 4345 Bryne, Norway
Email: morten@mycapsule.eu