---
title: Customer Data Use Policy
---


**Sahha Pty Ltd (ABN 26 649 986 505)**
**Version 1.0 — Effective 24 July 2026**

## Plain-language summary

*This summary is provided for convenience and does not replace the policy below. If there is any inconsistency, the policy below prevails.*

If you build on Sahha, the health data you receive through our API belongs to your End Users, and it arrives with strings attached — from us, from the law, and from the platforms it originates from (Apple HealthKit, Google Health Connect, Samsung Health, Garmin and other wearable and health data providers). In short:

- **Use the data only to deliver and improve the features your End User connected it for.** That includes engagement and service communications about your own product. Anything beyond your service needs the user's separate, explicit consent — and some uses stay off-limits regardless of consent because the platforms the data comes from prohibit them.
- **Never** share it with ad networks or data brokers, never sell it, and never use it to underwrite, price to a user's detriment, or decide anyone's eligibility for credit, insurance, employment, lending, housing or benefits. Opt-in rewards and insurance benefit programs are permitted where the data use is the disclosed product and can only ever benefit the user.
- These rules apply to **everything** you get through Sahha — raw platform data, Sahha's scores, biomarkers and insights, and anything you derive from any of it.
- Tell your End Users what you're doing, get their express consent before connecting, delete their data when they disconnect, keep it secure, and tell us within 48 hours if something goes wrong.

This policy forms part of your API Licence Agreement with us. Breaching it can result in suspension of your API access and termination of your agreement.

---

## 1. About this policy

1.1. This Customer Data Use Policy (**Policy**) sets out the rules that apply to your access to, and use of, data obtained through Sahha's Services. It exists to protect End Users and to give effect to obligations that apply to the Sahha platform under applicable privacy laws and under the terms of the Platform Partners whose data flows through our Services.

1.2. This Policy is incorporated by reference into, and forms part of, the API Licence Agreement between you and Sahha Pty Ltd (**Agreement**). Capitalised terms not defined in this Policy have the meanings given in the Agreement. A breach of this Policy is a breach of the Agreement.

1.3. This Policy applies to you if you are a Sahha customer — that is, any individual or entity that has accepted the Agreement, holds an Account, or accesses or uses the Services or the API, including through Sandbox or Production Environments.

1.4. This Policy operates alongside, and does not replace:

- (a) our [Privacy Policy](https://docs.sahha.ai/docs/legal/privacy-policy), which describes how we handle your personal information as our customer;
- (b) our [End User Privacy Policy](https://docs.sahha.ai/docs/legal/end-user-privacy-policy), which describes how we handle End Users' data; and
- (c) any Data Processing Addendum (DPA) entered into between you and us under clause 16.5 of the Agreement.

1.5. To the extent of any inconsistency between this Policy and the Agreement in relation to your collection, use, storage, disclosure or other handling of Covered Data, this Policy prevails.

## 2. Definitions

In this Policy:

**Covered Data** means all data and information that you or your Personnel obtain from or through the Services, in any form, including:

- (a) health, activity, sleep, body, nutrition, reproductive health, vital signs, device and sensor data originating from a Platform Partner or an End User's device;
- (b) scores, biomarkers, insights, trends, predictions, visualisations and any other outputs generated by Sahha (including derived information such as fitness age, well-being scores and risk indicators);
- (c) End User identifiers, demographic information and account information delivered through the Services; and
- (d) any data derived from, combined with, or produced using any of the above, in whole or in part, including model outputs, inferences, segments and labels,

regardless of the original source of the data, and whether or not the data has been transformed, aggregated or processed after receipt. Covered Data that has been De-identified in accordance with clause 4.6 remains subject to clauses 4.6, 5 and 6.

**De-identified** means processed such that the data cannot reasonably be used to identify, or be linked to, a particular End User, device or household, taking into account the means reasonably likely to be used, and includes a binding commitment not to attempt re-identification.

**End User** has the meaning given in the Agreement: a user of your services who grants you access to their information through the API.

**Platform Partner** means a third-party platform, operating system feature, device manufacturer or health data provider from which data is made available through the Services, including Apple (HealthKit), Google (Health Connect), Samsung (Samsung Health), Garmin, and other wearable and health data providers we integrate with from time to time.

**Platform Terms** means the terms, policies and guidelines of a Platform Partner that apply to data originating from that Platform Partner, as amended from time to time, including those referenced in the Annex to this Policy.

**Platform-Restricted Data** means Covered Data that originates from a Platform Partner, or is derived in whole or in part from data originating from a Platform Partner (including Sahha-generated outputs computed using such data), where the applicable Platform Terms restrict the use in question.

**User-Visible Feature** means a feature or service of your application or product that: (a) the End User connected their data to receive; (b) is apparent to, and reasonably expected by, the End User from your application's user interface and disclosures; and (c) provides a direct benefit to that End User.

## 3. Uniform application — no derivation loophole

3.1. The restrictions in this Policy apply uniformly to all Covered Data. In particular, and for the avoidance of doubt:

- (a) restrictions are not removed or reduced because data has been transformed, scored, modelled, inferred from, aggregated with other data, or otherwise derived from Covered Data;
- (b) Sahha-generated outputs (including scores, biomarkers and insights) are Covered Data and carry the same restrictions as the underlying source data; and
- (c) where Covered Data is commingled with data from other sources, the combined data set must be handled as Covered Data unless the Covered Data (and anything derived from it) is first fully and verifiably removed.

## 4. Permitted uses

You and your Personnel may access and use Covered Data **only** as follows:

4.1. **User-Visible Features.** To provide, maintain, personalise and improve User-Visible Features of the application or product that the relevant End User connected their data to, consistent with the disclosures you have made to that End User and the consent they have given. This includes personalising in-service recommendations of features, content or programs offered within that application or product.

4.2. **Service communications and engagement.** To personalise and send communications to an End User about the application or service they connected their data to — including engagement, retention and re-activation messaging, progress updates, coaching prompts and program reminders — including through your internal marketing and engagement systems, provided that:

- (a) the communications relate to the service the End User connected their data to, and are consistent with your disclosures and the End User's consents and communication preferences;
- (b) the End User can easily opt out of non-essential communications at any time;
- (c) any marketing, engagement or messaging platform used to deliver them is engaged as your service provider in accordance with clause 6.1(a) and is prohibited from using Covered Data for its own purposes (including advertising or model training); and
- (d) you do not use Platform-Restricted Data to promote products or services other than the connected service where the applicable Platform Terms prohibit advertising, marketing or use-based data mining.

4.3. **Opt-in insurance, rewards and benefit programs.** Where your product is an insurance, benefits, wellness or rewards program in which the use of Covered Data is itself the disclosed, core feature of the program (for example, activity-based rewards, premium discounts or cashback), to administer that program, provided that:

- (a) the End User explicitly opts in to the program by an affirmative act, with clear, prominent disclosure of how Covered Data affects their rewards, discounts or benefits, and may withdraw at any time;
- (b) Covered Data — and the absence of, or any decline in, Covered Data — is not used to underwrite, price, deny, cancel or vary the underlying product to the End User's detriment, to determine eligibility for cover, or to assess claims, in each case outside the benefits expressly disclosed in the opt-in program;
- (c) an End User who withdraws from, or declines to join, the program suffers no consequence other than not receiving the program benefits; and
- (d) the use complies with applicable Platform Terms and applicable insurance and anti-discrimination laws, noting that some Platform Partners impose additional restrictions or approval requirements on insurance-related uses of their data.

4.4. **Support, security and compliance.** To:

- (a) respond to support requests initiated by the relevant End User;
- (b) detect, investigate and prevent fraud, abuse, security incidents and violations of your terms or applicable law; and
- (c) comply with applicable laws, regulations and valid legal process.

4.5. **Secondary uses with separate consent.** For any purpose beyond clauses 4.1 to 4.4 — including training or fine-tuning machine learning or artificial intelligence models on identifiable Covered Data, research, the development of products not connected to the relevant End User, or promoting products or services other than the connected service — **only if all of the following are met**:

- (a) you obtain the End User's separate, explicit, informed, purpose-specific consent, given by an affirmative act, that is distinct from (and not bundled with) their consent to connect their data or accept your general terms;
- (b) the consent describes the specific use, the categories of Covered Data involved, and any recipients;
- (c) the End User can refuse or withdraw consent without losing access to the User-Visible Features they connected for, and withdrawal is honoured promptly;
- (d) for research involving human subjects, the research is conducted under the oversight of an accredited ethics committee or institutional review board, or an equivalent independent review; and
- (e) the use is not a Prohibited Use under clause 5, and does not involve Platform-Restricted Data where the applicable Platform Terms prohibit the use — consent under this clause cannot authorise a use that Platform Terms prohibit. Where Platform Terms impose stricter conditions on a secondary use than this clause, the Platform Terms prevail.

4.6. **De-identified internal analytics.** To perform internal product analytics and improvement for your own application using Covered Data that has first been De-identified, provided that you:

- (a) do not attempt to re-identify any End User, and contractually prohibit anyone you share such data with from doing so;
- (b) do not use De-identified data for any Prohibited Use; and
- (c) do not represent De-identified outputs as being about an identifiable individual.

## 5. Prohibited uses

You and your Personnel must **never**, directly or indirectly, use, or permit any other person to use, Covered Data (whether identifiable or De-identified, and whether alone or in combination with other data):

5.1. for third-party advertising purposes, including sharing Covered Data with any advertising platform, network or exchange, cross-context behavioural advertising, advertising measurement or attribution for third parties, or building advertising or marketing audiences for any third party; or use Platform-Restricted Data for any advertising, marketing or use-based data mining purpose prohibited by the applicable Platform Terms, including promoting products or services other than the connected service (clause 4.2 governs permitted service communications and engagement);

5.2. to sell, license, rent or otherwise transfer the data for consideration, or to disclose it to a data broker or to any person you know or ought reasonably to know deals in personal information;

5.3. to determine, or as an input into determining, any individual's eligibility for, or the terms of, credit, lending, insurance, employment, housing, education, government benefits, or immigration status — or for any other purpose that produces legal or similarly significant effects on an individual — except: (a) to deliver the disclosed benefits of an opt-in program conducted in accordance with clause 4.3; or (b) with the End User's explicit consent where expressly permitted by applicable law and applicable Platform Terms;

5.4. to re-identify, or attempt to re-identify, any individual from De-identified, aggregated or anonymised data;

5.5. for surveillance of individuals on behalf of, or for disclosure to, any third party, except as required by valid legal process;

5.6. in any manner that is deceptive, discriminatory, unlawful, or inconsistent with the disclosures made to, and consents given by, the relevant End User; or

5.7. in any manner prohibited by applicable Platform Terms, including the restrictions summarised in the Annex.

## 6. Onward disclosure

6.1. You must not disclose, transfer or provide access to Covered Data to any third party except:

- (a) to your service providers, solely to the extent necessary for them to perform services for you in support of a use permitted under clause 4, and only where they are bound by written obligations at least as protective as this Policy (including the Prohibited Uses in clause 5 and a prohibition on their own independent use of the data);
- (b) to the relevant End User, or at their direction;
- (c) as required by applicable law or valid legal process, provided that (to the extent lawful) you notify us before disclosure; or
- (d) with the End User's separate, explicit consent obtained in accordance with clause 4.5.

6.2. In the event of a merger, acquisition, insolvency or other transfer of your business, Covered Data may only be transferred to a successor that agrees in writing to be bound by this Policy, and you must ensure End Users are given notice of the transfer.

6.3. You remain fully responsible and liable for the acts and omissions of any person to whom you disclose Covered Data.

## 7. End User transparency and consent

7.1. Before using the API to access data about an End User, you must (consistent with clauses 11.2(b) and 16.4 of the Agreement):

- (a) obtain the End User's express, informed consent to the collection of their data through Sahha, including the categories of data collected, the sources (including relevant Platform Partners), the purposes of use, and the recipients;
- (b) make available to that End User a privacy policy and collection notice that accurately describes your practices, discloses your use of Sahha as a service provider/processor, and links to Sahha's [End User Privacy Policy](https://docs.sahha.ai/docs/legal/end-user-privacy-policy); and
- (c) provide an in-product means for the End User to disconnect their data sources and to withdraw consent, at least as easily as consent was given.

7.2. You must maintain records sufficient to demonstrate, for each End User, when and how consent (including any clause 4.3 program opt-in and any clause 4.5 secondary-use consent) was obtained, and provide those records to us on request under clause 11.

7.3. You must honour End User rights requests (access, correction, deletion, portability, restriction and objection) as required by applicable law, and cooperate with us where an End User directs a request to Sahha in respect of data you control.

## 8. Data deletion

8.1. You must delete Covered Data relating to an End User (including data derived from it, other than data validly De-identified under clause 4.6) within **30 days** after the earliest of:

- (a) the End User disconnecting their data source or your application;
- (b) the End User withdrawing consent or requesting deletion; or
- (c) termination or expiry of your Agreement with us.

8.2. Clause 8.1 does not require deletion of Covered Data that you are required by applicable law to retain, or that is the subject of a legal hold, provided the data is retained only for that purpose, protected in accordance with clause 9, and deleted when the requirement ends.

8.3. Covered Data residing in routine backups may be deleted in the ordinary course of your backup cycle, provided the backups are encrypted, access-controlled, and not restored to active systems except for disaster recovery — in which case deleted Covered Data must be re-deleted promptly.

## 9. Security requirements

You must, at a minimum:

9.1. encrypt Covered Data in transit and at rest using industry-standard encryption;

9.2. restrict access to Covered Data to Personnel who need it for a permitted use, under unique credentials, with multi-factor authentication for administrative access, and ensure such Personnel are bound by confidentiality obligations;

9.3. not store, process or display Covered Data in non-production environments (testing, staging, development), or in logs, analytics tools or error-tracking tools, except in De-identified or synthetic form;

9.4. keep your Access Credentials and API keys secure and confidential in accordance with clause 8.3 of the Agreement, and never embed production credentials in client-side code or public repositories; and

9.5. maintain a written information security program with administrative, technical and physical safeguards appropriate to the sensitivity of health data, including vulnerability management, secure development practices and personnel training.

## 10. Incident notification

10.1. You must notify us at **support@sahha.ai** within **48 hours** of becoming aware of any actual or reasonably suspected: unauthorised access to, or acquisition, use, disclosure, loss or destruction of, Covered Data; or compromise of your Access Credentials or systems that process Covered Data. This is in addition to your obligation under clause 11.2(h) of the Agreement.

10.2. Your notice must describe (to the extent known) the nature of the incident, the categories and approximate volume of Covered Data and End Users affected, the actions taken, and a contact point. You must supplement the notice as further information becomes available.

10.3. You must cooperate with us, take prompt steps to contain and remediate the incident, and not make any public statement naming Sahha or a Platform Partner in connection with the incident without our prior written consent, except as required by law.

10.4. Nothing in this clause limits or replaces your own notification obligations to End Users or regulators under applicable law.

## 11. Verification and enforcement

11.1. **Production gating.** Before we issue production API keys, and thereafter on request, you must provide us with:

- (a) the URL of your published End User-facing privacy policy; and
- (b) a description (or demonstration) of your End User consent flow.

We may decline or defer production access where these materially fail to meet this Policy.

11.2. **Attestation.** By accepting the Agreement, signing up for or signing in to your Account, activating production access, or continuing to use the Services after the effective date of this Policy, you accept this Policy and represent and warrant that you comply, and will continue to comply, with it.

11.3. **Evidence of compliance.** On reasonable written notice, you must provide us with information and records reasonably necessary to demonstrate your compliance with this Policy (including records under clause 7.2), within 10 Business Days of our request. We will treat such materials as your Confidential Information under clause 15 of the Agreement.

11.4. **Suspension and termination.** Without limiting any other rights we have, we may suspend your access to the Services in accordance with clause 19 of the Agreement where we reasonably believe you have breached this Policy, and a material breach of this Policy is a material breach of the Agreement for the purposes of clause 20.3. We may also take enforcement action where required by a Platform Partner, including restricting access to data originating from that Platform Partner.

11.5. **Platform Partner requirements.** You acknowledge that Platform Partners may require us to verify downstream compliance, and you authorise us to confirm to a Platform Partner, on request, that you are bound by this Policy and the status of any enforcement action.

## 12. Compliance with laws

12.1. In addition to clause 16 of the Agreement, you must comply with all privacy, data protection and consumer health data laws applicable to your collection, use, storage and disclosure of Covered Data, which may include: the Privacy Act 1988 (Cth) and the Australian Privacy Principles; the New Zealand Privacy Act 2020; the EU and UK General Data Protection Regulation and the UK Data Protection Act 2018; US state laws including the California Consumer Privacy Act (as amended), the Washington My Health My Data Act and Nevada SB 370; and, where you are a covered entity or business associate, the US Health Insurance Portability and Accountability Act (HIPAA).

12.2. Where you require Sahha to process personal data as your processor or service provider under such laws, you should contact us regarding a Data Processing Addendum under clause 16.5 of the Agreement. This Policy is not a DPA.

12.3. Where applicable law is stricter than this Policy, the law prevails. Where this Policy is stricter than applicable law, this Policy prevails as a contractual obligation.

## 13. Changes to this Policy

13.1. We may update this Policy from time to time, including where required by law or by Platform Terms. We will give you at least 30 days' written notice of material changes (or shorter notice where required by law or a Platform Partner, in which case we will give as much notice as reasonably practicable).

13.2. If you do not agree to a material change, you may terminate the Agreement in accordance with its terms before the change takes effect. Your continued use of the Services, or signing in to your Account, after the effective date of a change constitutes acceptance of the updated Policy. We may also require affirmative acceptance (for example, an in-dashboard confirmation) for material changes.

## 14. Contact

Questions about this Policy, requests for a DPA, and incident notifications: **support@sahha.ai**.
Privacy Officer: Sahha Pty Ltd — see our [Privacy Policy](https://docs.sahha.ai/docs/legal/privacy-policy) for contact details.

---

## Annex — Platform Partner requirements

The following summaries are provided for convenience. They do not modify, and are in addition to, your obligations under the applicable Platform Terms, which you must review and comply with directly. Where Platform Terms are stricter than this Policy, comply with the Platform Terms.

**A. Apple HealthKit.** Data obtained via HealthKit must not be used or disclosed to third parties for advertising, marketing or other use-based data mining purposes, or sold to advertising platforms, data brokers or information resellers. HealthKit data may be shared with third parties only for purposes of improving health and fitness management or health research, and only with user permission. Your app must include a privacy policy and comply with the Apple Developer Program License Agreement and App Review Guidelines (including Guideline 5.1.3).

**B. Google Health Connect.** Data obtained via Health Connect is subject to Google's Limited Use requirements: use must be limited to providing or improving features visible in your app's user interface, transfers are permitted only to service providers under equivalent restrictions, for security purposes, or to comply with law, and human access is limited to narrow cases (user consent, security, legal compliance, or aggregated internal operations). No use for advertising, no sale, no transfer to data brokers, and no use in determining creditworthiness or lending eligibility. You must publish an accurate privacy policy URL and complete any declarations Google requires.

**C. Samsung Health.** Data obtained via Samsung Health is subject to Samsung's partner and data-access terms, including restrictions on purposes of use, onward disclosure and retention, and requirements for user consent and revocation.

**D. Garmin and other wearable / health data providers.** Data obtained from Garmin and other integrated providers (as listed in our documentation from time to time) is subject to the relevant provider's API and data terms, which typically prohibit use for advertising, resale, onward transfer outside user-facing features, and require deletion on user disconnection. We will notify you where a provider imposes material additional requirements; such requirements form part of the applicable Platform Terms.

Data from our direct wearable integrations (including Garmin) is delivered to you on a pass-through basis: Sahha does not transform it or incorporate it into Sahha-generated outputs, and retains it only in a transient delivery cache for up to 3 days before automatic deletion. Once delivered, you are the primary custodian of this data. This does not relax your obligations in any way — pass-through data is Covered Data, and your consent, use, deletion and security obligations under this Policy apply in full.

---

*Sahha Pty Ltd (ABN 26 649 986 505). This Policy forms part of the API Licence Agreement. Version 1.0 — 24 July 2026.*
