02 · Trust Center · Updated February 8, 2026 · Version 1.1

Privacy & Security Policy

Comprehensive Data Protection for Enterprise Wellness. How we collect, use, store, and protect data when you use our enterprise wellness platform.

Document
Privacy & Security Policy
Version
1.1
Last Updated
February 8, 2026
Owner
Ruhavyn Security Team
Classification
Public

1. Introduction

Ruhavyn, operated by Healing Sun Haven LLC, is committed to protecting the privacy and security of your personal information. This policy explains how we collect, use, store, and protect data when you use our enterprise wellness platform.

Our Principles

  • Privacy by Design: Security and privacy are built into every feature from the start
  • Data Minimization: We only collect data necessary to provide our services
  • Transparency: We clearly explain what we do with your data
  • User Control: You control your personal data and can export or delete it anytime
  • No Data Sales: We never sell your personal information to third parties

2. How We Protect Your Data

Encryption

LayerStandardDetails
Data at RestAES-256All stored data encrypted in database
Data in TransitTLS 1.3All connections encrypted end-to-end
BackupsAES-256Encrypted backups in separate location
API KeysSHA-256Hashed, never stored in plaintext

Database Security

Our database implements comprehensive security controls:

  • 37 RLS-Protected Tables: Row Level Security on all data tables
  • 80 Security Policies: Fine-grained access controls
  • 48 Hardened Functions: All database functions secured against injection
  • Company Isolation: Multi-tenant data completely separated
  • User Isolation: Personal data only accessible to data owner

Authentication

  • Industry-Standard Authentication: Enterprise-grade authentication service
  • bcrypt Hashing: Passwords never stored in plaintext
  • JWT Tokens: Secure session management
  • MFA Support: Multi-factor authentication via SSO providers
  • Enterprise SSO: SAML 2.0 and OIDC support

3. What Data We Collect

Data We Collect

CategoryData ElementsPurpose
AccountEmail address, display nameAuthentication, communication
ProfileAvatar, preferred name, mantraPersonalization
WellnessMood entries, diary entriesCore service functionality
UsageFeature access, session durationAnalytics, improvement
TechnicalDevice type, browser, IP addressSecurity, troubleshooting

Data We DO NOT Collect

  • Social Security numbers
  • Financial or banking information
  • Medical records or diagnoses
  • Health insurance information
  • Biometric data
  • Location tracking

Sensitive Data Handling

Diary Entries & Personal Reflections:

  • Encrypted at rest (AES-256)
  • Protected by Row Level Security, so only the user can access
  • Employers cannot read employee diary entries
  • Never shared with AI services without explicit consent
  • Never used for training AI models

Sacred Release Entries:

  • When a user chooses Sacred Release, the text of the entry is permanently deleted once its poetic summary has been generated
  • The entry text is removed from active systems at that point, and from backups within the 7-day point-in-time recovery window

4. How We Use Data

Primary Uses

PurposeData UsedLegal Basis
Service DeliveryAccount, profile, wellness dataContract performance
AnalyticsAggregated, anonymized usageLegitimate interest
SupportAccount, usage dataContract performance
SecurityTechnical data, audit logsLegitimate interest
CommunicationEmail addressConsent / Legitimate interest

What We Never Do

  • Sell personal data to third parties
  • Share individual wellness data with employers
  • Use personal data for advertising
  • Train AI on user-submitted content
  • Make automated decisions that affect users

Aggregated Analytics

For enterprise clients, we provide anonymized, aggregated analytics only:

  • Overall engagement rates (no individual data)
  • Feature adoption trends
  • Aggregate mood trends (minimum 10 users for anonymity)
  • ROI metrics based on usage patterns
Privacy Threshold: Analytics require minimum 10 users to prevent individual identification.

5. Third-Party Services

We carefully select third-party partners who meet our rigorous security and privacy standards. All infrastructure and service providers we work with must:

  • Maintain SOC 2 Type II certification
  • Comply with ISO 27001 standards
  • Support GDPR and CCPA compliance
  • Provide HIPAA-ready infrastructure where applicable
  • Sign Data Processing Agreements with strict confidentiality terms

Categories of Third-Party Services

Service CategoryPurposeSecurity Standards
Database & AuthenticationSecure data storage, user authenticationSOC 2 Type II, ISO 27001, HIPAA-ready
Payment ProcessingSubscription billing, payment securityPCI DSS Level 1, SOC 2 Type II
AI InfrastructureTherapeutic AI features, natural language processingSOC 2 Type II, enterprise-grade privacy
Enterprise SSOSingle Sign-On for corporate clientsSOC 2 Type II, ISO 27001

AI Service Privacy

When AI features are used:

  • Only non-sensitive context (preferred name, general mood) is shared
  • No PII or PHI sent to AI services
  • No data used for AI model training
  • All AI providers maintain SOC 2 Type II certification

Third-Party Oversight

We maintain strict contractual agreements with all service providers, ensuring:

  • Data is used only for specified purposes
  • No resale or secondary use of data
  • Regular security audits and compliance reviews
  • Immediate notification of any security incidents
  • Right to audit and terminate for non-compliance

For a complete list of sub-processors and detailed vendor security information, enterprise clients may contact: info@healingsunhaven.com

6. Your Privacy Rights

GDPR Rights (EU/EEA Users)

RightDescriptionHow to Exercise
AccessObtain a copy of your dataSettings → Export Data
RectificationCorrect inaccurate dataSettings → Profile
ErasureDelete your account and dataSettings → Delete Account
PortabilityReceive data in machine-readable formatSettings → Export Data (JSON)
RestrictionLimit how we process dataContact: support@healingsunhaven.com
ObjectionObject to certain processingContact: support@healingsunhaven.com
Withdraw ConsentRevoke previously given consentSettings or contact us

CCPA Rights (California Users)

  • Right to Know: What personal information we collect
  • Right to Delete: Request deletion of your data
  • Right to Opt-Out: We do not sell personal data
  • Non-Discrimination: No penalty for exercising rights

Exercising Your Rights

Self-Service Options:

  • Export data: Settings → Privacy → Export My Data
  • Delete account: Settings → Account → Delete Account

Contact Us:

7. Data Retention & Deletion

Retention Periods

Data TypeRetention PeriodReason
User account dataDuration of account + 30 daysService provision
Diary entriesUntil user deletesUser-controlled
Sacred Release entriesPermanently deleted once the poetic summary is generated (backups: within 7 days)User-chosen release
Mood entriesUntil user deletesUser-controlled
Audit logs90 daysSecurity & compliance
API request logs90 daysSecurity monitoring
Backups7 days (PITR)Disaster recovery
Deleted account dataPurged within 30 daysGDPR compliance

Account Deletion Process

When you delete your account:

  1. Immediate: Account deactivated, no further access
  2. Within 24 hours: Personal data removed from active systems
  3. Within 7 days: Removed from backups (PITR window)
  4. Within 30 days: Complete purge from all systems
  5. Audit logs: Anonymized, retained for compliance

Enterprise Employee Offboarding

When an employee is deactivated by their company admin:

  • Access immediately revoked
  • Personal wellness data (diary, mood) retained for user if they return
  • Can request full deletion through support

Cross-Border Data Transfers

For transfers of Personal Data from the European Economic Area, United Kingdom, or Switzerland to the United States:

  • Standard Contractual Clauses (SCCs): Module Two (Controller to Processor) per European Commission Decision 2021/914
  • Supplementary Measures: Encryption (AES-256 at rest, TLS 1.3 in transit), access controls, and contractual protections
  • Data Residency: Primary processing occurs in the United States. EU data residency is available upon request for enterprise clients, subject to additional terms.

8. Security Measures

Technical Controls

Access Control:

  • Role-Based Access Control (RBAC): Admin, Member, Service
  • Company-scoped data isolation
  • User-level data isolation via authenticated checks
  • JWT token validation on all requests

Database Security:

  • Row Level Security (RLS) on all 37 tables
  • 80 security policies enforcing access rules
  • 48 hardened database functions with secure configurations
  • Parameterized queries preventing SQL injection

API Security:

  • API keys hashed with SHA-256
  • Rate limiting by tier
  • HTTPS-only connections
  • HMAC-SHA256 webhook signatures

Operational Security

Monitoring:

  • Real-time security monitoring
  • Automated alerting for anomalies
  • Failed authentication tracking
  • API error rate monitoring

Audit Logging:

  • Admin actions logged with IP, timestamp, details
  • 90-day retention
  • Tamper-proof storage
  • Exportable (CSV/JSON) for compliance

Compliance Certifications

FrameworkStatusNotes
SOC 2 Type IReadyFormal audit Q2 2026
SOC 2 Type IIPlannedTargeted Q4 2026
GDPRCompliantEU hosting available
CCPACompliantPrivacy controls implemented
HIPAAReadyBAA available upon request
ISO 27001AlignedVia certified infrastructure

9. Incident Response

Our Commitment

In the event of a security incident affecting your data:

ActionTimeline
ContainmentWithin 4 hours of detection
AssessmentWithin 24 hours
Customer notificationWithin 2–3 business days
Regulatory notificationAs required by applicable law (e.g., GDPR)
Post-incident reportWithin 7 days

What We Communicate

In the event of a breach affecting your data:

  • Nature of the incident
  • Types of data affected
  • Estimated number of affected users
  • Steps we're taking to remediate
  • Steps you can take to protect yourself
  • Contact for questions

Reporting Security Issues

Found a security vulnerability?

Security Team: support@healingsunhaven.com

Response Time: Within 24 hours

Bug Bounty: Planned Q3 2026

Ruhavyn uses only essential cookies required for authentication and session management. We do not use:

  • Tracking cookies
  • Advertising cookies
  • Third-party analytics cookies
  • Social media tracking pixels

Essential cookies are strictly necessary for the platform to function and cannot be disabled. No user consent banner is required as these cookies do not track personal behavior.

11. Contact Us

Privacy Inquiries

Data Protection Contact

Email: support@healingsunhaven.com

Response: Within 5 business days

Security Inquiries

Security Team

Email: support@healingsunhaven.com

Response: Within 24 hours (critical), 5 days (general)

General Support

Support Team

Email: support@healingsunhaven.com

Response: Within 24 hours

Legal Entity

Healing Sun Haven LLC

Address available upon request for enterprise contracts

Updates to This Policy

We may update this policy periodically. Material changes will be communicated via:

  • Email notification to account holders
  • In-app notification
  • Updated "Last Updated" date

Continued use after changes constitutes acceptance.

Enterprise Security Documentation

This document provides a comprehensive overview of our privacy and security practices. For additional detailed documentation, including:

  • Complete sub-processor list with vendor details
  • SOC 2 Readiness Report
  • Data Processing Addendum (DPA)
  • Vendor Security Questionnaire responses
  • Detailed security architecture diagrams
  • Compliance certification status
  • Penetration testing reports

Interested enterprise clients may contact: info@healingsunhaven.com