Privacy · Preventa Work Experience
Privacy Statement
This statement explains in clear language what Preventa processes, why we use it, who receives it, and the choices and rights available to you.
Last updated: 12 September 2026
Who is responsible for your data
Preventa Health B.V., established in the Netherlands, is the data controller for Preventa Work Experience. We decide why and how the information described here is processed.
This statement covers the public assessment, personal reports and purchases, result emails, retakes, therapist-call booking, company survey links, and staff console on workstresstest.eu. Other Preventa Health services may have separate privacy information.
Information we process
Depending on how you use the service, we process:
- Assessment information: your answers to 59 questions, optional age band, sex, country, sector, role level and weekly hours, calculated scores, result level, stress type, pattern markers, language, completion time and anonymous session information.
- Optional feedback: a rating and any comment you choose to provide. Do not include names or sensitive identifying details in comments.
- Purchase and delivery information: payment status, amount, currency, package, transaction reference, purchase date, report access status, retake entitlement and service-delivery events. Stripe handles the payment details entered at checkout.
- Email delivery information: if you ask for a result email, the address is used to send it and delivery events may be recorded. The email address itself is not stored with your assessment in our main assessment database.
- Private-link activity: technical events such as report opens, PDF downloads, booking-link clicks, retake opens and completion. Private report and retake links contain signed, time-limited access information.
- Booking information: if you choose to book the included call, the booking provider processes the details you submit to arrange it. We record limited booking-funnel events so we can understand whether the service is being reached.
- Company surveys: a company or team code, if you entered through a dedicated link. Individual reports remain subject to the access rules shown to you; company reporting is aggregated where promised.
- Staff accounts: email address, authentication events, assigned role and activity needed to operate the restricted management console.
- Website and campaign information: cookie preferences and, with consent, analytics, advertising identifiers and campaign parameters. Standard server security logs may temporarily contain IP address, browser and request information.
Anonymous answers and identifiable service data
We do not ask public participants for a name, employer or account before the assessment. Assessment answers are designed to be stored without a direct identity. Optional demographic combinations can still increase re-identification risk in very small groups, so we restrict raw access and apply minimum group sizes to aggregate reporting.
A purchase, email request, booking or staff account necessarily involves identifiable service data. We keep that data separate from answers wherever practical. A payment reference or private access link may allow us to connect a service event to an anonymous submission so we can deliver what was bought, prevent duplicate payment and support a retake.
Because anonymous answers may not be traceable back to you, we may be unable to locate or delete a specific submitted assessment. This limitation does not apply to identifiable purchase, booking, email or account records that we can reasonably match to you.
Why we use information and our legal bases
We process information for the following purposes:
- to calculate and display your results, create the PDF, send a requested email and provide a retake or call — to perform the service or contract you requested;
- to process payment, keep transaction records, prevent duplicate payment and meet tax and accounting duties — performance of contract and legal obligation;
- to operate company links, restricted staff access, security controls, troubleshooting and service measurement — our legitimate interests in providing a safe and reliable service;
- to improve and validate the assessment and produce anonymised, aggregate benchmarks or research — consent where required and our legitimate interests, with safeguards against re-identification;
- to use non-essential analytics and advertising cookies — your consent, which you can change at any time.
Assessment content can reveal information about stress and wellbeing. We ask for explicit consent before submission where this may be treated as health-related or other special-category data. You can stop before submitting without saving your answers.
Reports, email and private access links
Your immediate result is held in your browser session so the page and PDF can be produced. If you buy a full report, we retain the submission and entitlement records needed to unlock it, issue a private report link and provide the included retake.
Result and retake links are personal. Do not forward them. Anyone who receives a valid link may be able to open the linked report or retake until the link expires or is used. If you think a link was shared by mistake, contact us.
When you request a result email, we send it to the address you enter. Email is not a fully confidential channel, so use an address and device you control.
Payments and Stripe Link
Stripe processes checkout and payment information as an independent controller or processor, depending on the activity. We receive payment confirmation and limited transaction details, not your full card number. Optional Stripe Link lets you save payment information with Stripe and is governed by Stripe's own privacy notice and terms.
We retain purchase records required to provide access, handle support, prevent fraud and meet financial record-keeping obligations.
Booking the included call
If your package includes a call, the booking interface is supplied by YourMindTality or its scheduling provider. Information you enter there is used to schedule and provide the call under that provider's privacy information. Do not include more health information than needed to arrange the appointment.
The call is optional. Preventa may record that a booking link was opened or a booking step was reached, but does not use those events to change your assessment score.
Cookies and analytics
Essential local storage and cookies support language, security, session continuity, payment return and your cookie choice. They do not require advertising consent.
If you accept non-essential cookies, we use Google Analytics 4 to understand site use and the LinkedIn Insight Tag to measure campaigns. These services may process pseudonymous identifiers and device or interaction data. Consent remains denied until you accept. You can reopen from the footer at any time.
Campaign parameters may be stored for up to 30 days and attached to a completed assessment for aggregate campaign reporting. We do not use them to alter your result.
Who receives information
Access is limited to authorised Preventa staff and service providers who need it for their work. Providers include our managed hosting and database service, edge and security infrastructure, Stripe for payments, our transactional email provider, the call booking provider, and—only with consent—Google and LinkedIn for analytics or advertising measurement.
Company customers do not receive identifiable public participant answers. Where a dedicated company survey is used, reporting follows the arrangements and minimum-group safeguards communicated for that survey.
We may disclose information where required by law, to protect rights and security, or in connection with a corporate reorganisation subject to appropriate safeguards. We do not sell assessment answers.
International transfers
We prefer European hosting for assessment data. Some providers may process limited data outside the European Economic Area. Where required, transfers rely on an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful safeguard. You can ask us for more information about the safeguards relevant to your data.
How long we keep information
- Anonymous assessment submissions and linked feedback: normally up to 2 years.
- Browser result data: for the browser session, unless your browser retains it longer or you clear it sooner.
- Private report links: normally 30 days; underlying paid access and transaction records may remain longer.
- Retake entitlement: available for 12 months after purchase; related service events may remain with the purchase record.
- Purchase and financial records: as long as needed to provide the service and meet Dutch tax, accounting and legal requirements.
- Email delivery, booking, security and staff-account records: only as long as reasonably needed for delivery, support, security, audit and legal obligations.
- Cookie choice: normally 6 months. Campaign parameters: up to 30 days.
Aggregated information that no longer identifies a person may be kept longer for statistics, research and assessment improvement.
Security
We use encrypted connections, managed encryption at rest, role-based access, restricted administrator and therapist permissions, signed private links, row-level database controls, monitoring and backups. Staff access is authenticated and limited by role.
No online system is completely risk-free. If you suspect unauthorised access, a misdirected email or a shared private link, contact us promptly at privacy@preventa-health.com. We assess incidents and notify affected people and authorities where the law requires.
Your rights
Subject to the GDPR and its conditions, you can ask for access, correction, deletion, restriction, portability or objection, and you can withdraw consent without affecting earlier lawful processing. You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. The assessment creates guidance, not such a legal decision.
We may need to verify your identity before acting. For genuinely anonymous answers, Article 11 GDPR may mean we are not required to collect extra identifying information solely to match you to a row. We will still act on identifiable purchase, account, email or booking information where we can verify it.
Contact privacy@preventa-health.com. You may also complain to the Autoriteit Persoonsgegevens, Bezuidenhoutseweg 30, 2594 AV The Hague, or another competent EEA supervisory authority.
Changes and contact
We may update this statement when the service, providers or law changes. The date at the top shows the latest version. Material changes will be highlighted where appropriate.
Questions, rights requests or privacy complaints can be sent to the privacy adviser at privacy@preventa-health.com. General service questions can be sent to contact@workstresstest.eu.