Preventa P-PRI
PREVENTA P-PRIPrivacy Statement
Last updated · June 2026

Privacy Statement

This statement covers the Preventa P-PRI online self-assessment — an anonymous, public tool for measuring work-related psychosocial risk. It explains exactly what we collect, why, how long we keep it, and how the GDPR applies in an anonymous setting.

Preventa Health's wider enterprise screening services (medical screening for employees, employer dashboards, etc.) are covered by separate documentation on preventa-health.com and are not in scope here.

01

Data Controller

For the P-PRI self-assessment, Preventa Health acts as the sole data controller within the meaning of Article 4 GDPR. No employer or third-party organisation is involved in the processing chain of this public tool — the controller relationships described for Preventa's enterprise screening services do not apply to P-PRI.

02

What Data We Collect

The P-PRI assessment is anonymous. When you submit, the following is written to our database:

  • Your answers to the 65 Likert questions
  • Optional demographics: age band, sex, country, sector, role level, weekly hours — all "prefer not to say" by default
  • The computed domain scores, the composite PRI score, the result band, and any pattern flags derived from your answers
  • A submission timestamp

We do not store your name, email address, IP address, employer, device fingerprint, account, or any identifying cookie. Our hosting and edge providers process your IP address transiently to route the HTTP request, but it is not logged against your submission.

Your result page is rendered in your browser from sessionStorage, which is cleared automatically when you close the tab. We do not need to read your row back from the database to show you the result or generate the PDF.

03

Legal Basis for Processing

Processing is based on your explicit consent, which you give on the consent screen before starting. The stored data concerns work-related psychosocial factors and is held without any identifier linking it to you, so in the form it is stored it does not constitute a special category of personal data under Article 9 GDPR.

The combination of optional demographic fields (age band, sex, country, sector, role level, weekly hours) can in principle act as a quasi-identifier in small populations. For that reason, any aggregated output (benchmarks, research statistics) is only released above a minimum group size that prevents re-identification.

You may withdraw consent at any time, which stops any further processing of new submissions. Because already-submitted rows carry no identifier, we cannot locate a specific past submission to delete it individually — that is the deliberate trade-off of anonymity.

04

Purposes of Processing

We use anonymous assessment data only for the following purposes:

  • Producing anonymised, aggregated population benchmarks (with minimum group sizes that prevent re-identification)
  • Instrument validation and research on work-related psychosocial risk factors

Your personal result and PDF are generated client-side from your in-browser session and are not derived from any subsequent read of the stored row.

05

Retention Periods

Row-level anonymous P-PRI submissions are retained for 2 years from the submission timestamp, after which they are deleted. Deletion is currently administrator-initiated; we may automate this with a scheduled purge in future.

Aggregated, anonymised statistics derived from these submissions may be retained longer for research and benchmarking. Your in-browser result copy lives only in sessionStorage and is cleared when you close the tab.

06

Security

All traffic uses TLS 1.3. Submitted responses are stored encrypted at rest using AES-256 on our managed database. The ppri_submissions table is append-only at the database layer: row-level security policies allow anonymous inserts only, and deny all update and delete operations from the application.

Read access to raw submissions is restricted to a single administrator account, authorised through a role-based access check (has_role(uid, 'admin')) enforced by row-level security. There is no admin write path to participant rows.

07

Reporting a Data Breach

We handle data with care, but a breach may still occur — for example if data reaches the wrong person or is lost due to an error.

If you suspect a data breach, please report it as soon as possible. . If necessary, we will contact you within 24 hours.

08

Service Providers

As an independent data controller, Preventa uses the following service providers for P-PRI:

  • Managed backend provider — hosts the database, the administrator authentication, and admin-only server functions. Participant data is stored only in the EU region (Ireland).
  • Edge / CDN provider — terminates TLS and routes HTTP requests on a global edge network. Processes your IP transiently to deliver the response and does not persist participant data.

All service providers are bound by data processing agreements in accordance with Articles 28 and 32 GDPR. Where any service touches infrastructure outside the EEA, the European Commission's Standard Contractual Clauses (SCCs) apply.

09

Your Privacy Rights

The GDPR grants you the rights below. Because the P-PRI dataset is anonymous, several of these rights cannot be exercised against a specific row — there simply is no identifier we can match you to. We list each right honestly with how it applies here. To exercise any right, please contact us.

Right of access

Not exercisable at row level for P-PRI: we hold no identifier that links a stored submission back to you. We can describe the categories of data we hold (this statement does so in §02).

Right to rectification

Not exercisable at row level for the same reason. If you noticed an error while completing the assessment, the simplest remedy is to retake it.

Right to erasure (right to be forgotten)

We cannot identify your specific row to delete it. All rows are deleted at the end of the 2-year retention window (§05). You can also withdraw consent to stop any further processing of new submissions.

Right to restriction of processing

Applies at the dataset level. You can ask us to pause specific processing activities (e.g. research uses) — this is enforced through our internal processing rules, not at row level.

Right to object

You can decline to take the assessment, skip any optional demographic question, or stop at any time before submitting. After submission, because the data is anonymous, individual objection cannot be acted on at row level.

Right to data portability

The PDF you can download immediately after completing the assessment is your portable copy. We cannot regenerate this from the stored row because no identifier links it back to you.

Complaints

Questions or complaints: contact the privacy advisor. If your complaint is not resolved, you can contact the supervisory authority listed in §10.

10

Supervisory Authority

You have the right to lodge a complaint with a supervisory authority (Art. 13(2)(d) GDPR). Since Preventa Health B.V. is established in the Netherlands, the lead supervisory authority is:

Autoriteit Persoonsgegevens

Bezuidenhoutseweg 30

2594 AV The Hague

autoriteitpersoonsgegevens.nl

11

Contact

For questions about this privacy statement or other privacy-related matters, contact our privacy advisor.