Privacy policy
This page describes what this site, healio.ch and gethealio.ai, does with the data of the people who visit it. It does not cover the Healio application itself, which has its own terms of use and its own data protection notice, handed to the organizations that adopt it. It is short, and it is written to be read.
In short
- This site sets no cookie, uses no analytics and loads nothing from a third party.
- Only one thing on it collects data: the demo request form, and only what you write in it.
- We use that data to answer you. We do not sell it, rent it or pass it on to anyone.
- You can find out at any time what we hold about you, and have it corrected or erased.
Who is responsible
The controller, within the meaning of the Swiss Federal Act on Data Protection (FADP), is:
- Healio Technologies SA
- Rue de Bourg 27, 1003 Lausanne, Switzerland
- security@healio.ch
For any data protection question, any request for access or erasure: Raphaël Breitschmid, security@healio.ch. Someone from the team answers you.
What this site does not do
There is no account on this site, no login, no cookie, no tracking pixel, no analytics tool, and no font or script loaded from a third-party server. The pages are files served as they are. The few scripts they carry are our own, served from the site itself, and they do only a few specific interface jobs: closing the menu, animating an illustration, carrying into the form the email address you typed elsewhere on the site. They contact no server and send nothing about you.
There is therefore no cookie consent banner, because there is nothing to consent to.
Visiting the site
Like any site, this one is served by a host. That host is Cloudflare, Inc. (San Francisco, United States), which delivers the pages from its network of servers, several of them in Switzerland. To do so, Cloudflare processes the technical data that any browser sends to any server: your IP address, the browser type, the page requested, the date and the time. Cloudflare uses them to route the pages, to defend against attacks and to keep the site available, and keeps them for a limited period, under its own data protection policy.
We keep no visit log of our own. From the requests it serves, Cloudflare produces aggregated traffic statistics that we can consult and that identify nobody. Only two things leave a further trace at Cloudflare that our team can consult: sending the demo request form, and requesting an address that does not exist on the site. That trace holds the date, the address requested, the outcome and the technical data of the request; our program writes neither your details nor your message into it. Cloudflare erases it after 7 days at most.
Cloudflare is certified under the Swiss-U.S. Data Privacy Framework, which the Federal Council has recognized since 15 September 2024 as offering an adequate level of protection. As long as that certification is active, it is what authorizes this processing in the United States without additional safeguards.
The Healio application is another system: its data — the schedules, the absences, the people — is hosted in Switzerland and never travels through this site. That is what the “swiss hosting” label at the foot of this page refers to, not the site you are reading. Its own data protection notice sets it out.
Requesting a demo
The demo request form is the only place on the site where you entrust us with data. It asks you for:
- your first name and your last name;
- your work email address;
- if you wish, the name of your organization or practice, your phone number and a message: these three fields are optional.
When you send it, we add the language of the page along with the date and the time. Nothing else. The message is a free field: do not write into it any data about a patient, a member of your staff or the health of any person — the demonstration does not need it.
The small email fields on the homepage and in the footer send us nothing: they open the demo request form with your address already filled in. It travels there through your browser’s session memory or, failing that, through the address of the form page, like any requested page.
We use this data for one thing only: to get back to you, to arrange a demonstration and, if you wish, to send you an offer. We do not ask you for separate consent, because answering your request is precisely the use you write to us for. We do not use this data for prospecting unrelated to your request or for a newsletter.
Here is what happens when you press “Request a demo”:
- Your request reaches our program, running on Cloudflare’s servers. It first counts the send attempts per IP address, to block automated bulk sending: beyond 5 attempts in 60 seconds from one address, it asks you to wait a minute. That counter covers only the last 60 seconds and is never attached to your request.
- It then checks that the request is complete and readable. It records nothing: no database, no file, no copy.
- Your request is passed on to folk, our contact management tool, published by Folk Inc. (United States) and hosted at Amazon Web Services, in the United States. That is where the person from the team who will answer you reads it. folk describes its security measures and its sub-processors on its dedicated page.
- Once your request is recorded, our program tells the team in an internal Slack channel, so that they answer you quickly. That message contains nothing you wrote: the language of the page, the address of the site, a link to folk, and that is all.
If sending fails, a page tells you so, in your language, and sends you back to the form. One exception: if folk records your details but refuses your message, the thank-you page appears anyway — we have what we need to answer you, not what you wrote to us. In that case, if you hear nothing from us within two working days, write to us at security@healio.ch.
A request that does not reach folk, on the other hand, goes into that Slack channel in full: first name, last name, email address, organization, phone and message. That is deliberate. Our program keeps nothing and folk did not receive it, so that message is then the only copy of your request in existence: the team answers you from there and enters it into folk by hand. On that one path, Slack is therefore a recipient of what you write to us.
We keep your request for as long as it takes to answer it and follow it up, then we erase it. If your organization becomes a Healio customer, we keep what documents the contract, for the period the law provides; the application’s data falls under its own notice. folk’s backup copies disappear afterwards, within the period folk sets.
Who receives the data
We neither sell nor rent your data, and we disclose it only to the recipients described here, for the purposes stated: our technical processors, who act on our instructions and are bound by contract, and the sub-processors they themselves call on, such as Amazon Web Services for hosting folk.
- Cloudflare, Inc. — hosting the site and receiving the form;
- folk (Folk Inc.) — keeping and following up demo requests;
- Slack (Slack Technologies, LLC, a Salesforce, Inc. company) — internal notification of the team: the language and the address of the site on every submission, and the whole request only where it did not reach folk.
We may be required to disclose data to an authority where the law obliges us to.
Where the data is kept
The site is served from the Cloudflare data center closest to you — in Switzerland, for most of our visitors — and the form is received by a Cloudflare server; Cloudflare processes the technical data of those requests in the United States. Demo requests are kept by folk in the United States, and internal notifications by Slack in the United States, in our channel, for as long as our workspace’s retention setting provides. For any processing outside Switzerland, we rely on a Federal Council adequacy decision — which is the case for United States companies certified under the Swiss part of the Data Privacy Framework, such as Cloudflare and Amazon Web Services — or, failing that, on the standard contractual clauses recognized by the Federal Data Protection and Information Commissioner (FDPIC).
How the data is protected
The site is reachable only over an encrypted connection (HTTPS), and it enforces it. It prevents your browser from loading any script or any resource from an origin other than its own. The form is checked server-side, protected against automated submissions, and our program never logs the content of a request: on an error it notes that an error occurred, in which language, and what the destination service answered — never your details and never your message.
Your rights
You may ask us whether we process data concerning you and which data, obtain a copy of it, have it corrected or erased, and object to a processing operation. We examine each request within the limits the law provides, and we explain any refusal, any restriction and any postponement. If you wish, we also hand you that data in a common format. Write to us at the address given above: a request for access is answered free of charge within 30 days as a rule, and other requests are handled without undue delay. We may ask you to confirm your identity before disclosing data, so as not to hand it to the wrong person.
If you consider that we are not complying with the law, you may report it to the FDPIC, in Bern, or assert your rights before a civil court.
Changes
This page changes when the site changes — a new tool, a new processor, a new retention period. The date at the foot of this page gives the last modification. If we were ever to use data already entrusted to us for a purpose other than the one described here, we would tell you first.
Last updated: 7 September 2026.