The policies that govern the Humotron recommendation engine, our API, our commerce integrations, and our Consultants and Benefits products. Written for the people who have to review them — plain language first, detail underneath, and no attempt to hide the parts that matter.
Your customers — or your clients — connect their own trackers directly to us. Commerce partners receive ranked recommendations from their own catalogue and never any health data. Consultants see only what each client chooses to share. Ranking is determined by fit, and placement is not for sale.
| Product | What it does |
|---|---|
| Commerce | Personalised recommendations from your own catalogue, based on your customers' tracker data. Through our API, a hosted match page on your own domain, or platform apps — Shopify first, coming soon. |
| Consultants | A client-data workspace for wellness consultants and coaches. Your clients connect their trackers and choose what you can see between sessions. |
| Benefits | Humotron access bought in volume and given to your employees or customers. |
| Catalogue services | Mapping your products to the attributes the engine ranks against. |
We licence you access to the engine for use inside your own product. You're responsible for your catalogue data and for your relationship with your customers. We're responsible for the engine. Neither of us can promise the other unlimited liability, so both sides are capped — at a level appropriate to a commercial contract, not a consumer one.
Each partnership is governed by a signed agreement incorporating these terms, a commercial schedule (pricing, volumes, term), and a data processing agreement where applicable. This page is informational; the signed documents govern.
Subject to your agreement and payment, we grant a non-exclusive, non-transferable, revocable right to access the API and integrate the output into your own product, for the term agreed.
You may not sublicense, resell, or provide access to third parties; use the output to build a competing engine; or extract, train on, or reverse-engineer our models. See Acceptable Use.
What you can influence is the completeness and accuracy of your catalogue data. Better attributes give the engine more to match on. That's the legitimate route to appearing more often.
Fees, volumes and payment terms are in your commercial schedule or on our pricing page. We charge on use — for Commerce, customers who actually connect; for Consultants, active clients — so you don't pay for a plan you aren't using. Unless agreed otherwise: fees are exclusive of VAT, invoices are payable within 30 days, and we may charge statutory interest on late payment.
We own the engine, models, documentation and everything we produce. You own your catalogue data and your product. Neither party acquires the other's IP.
We may use aggregated, de-identified performance data to improve the service. This never includes your catalogue data in identifiable form or any end-user personal data.
Both parties keep the other's confidential information confidential, use it only for the partnership, and protect it with at least reasonable care. Obligations survive termination by 3 years.
We warrant we have the right to grant the licence and will provide the service with reasonable skill and care.
Neither party limits liability for death or personal injury caused by negligence, for fraud, or for anything else that cannot be limited by law.
Subject to that, and unless your agreement says otherwise:
On termination: access ends, you stop using our output and marks, each party returns or deletes the other's confidential information, and accrued fees remain payable. We retain your catalogue data for no more than 30 days before deletion.
Neither party may assign without consent, except to a group company or on a sale of the business. Neither is liable for events outside reasonable control. No partnership, agency or employment is created. These terms are governed by the laws of England & Wales, with exclusive jurisdiction of its courts.
End-users connect their wearables directly with us and consent to us processing their data. We are the controller for that data. You receive ranked product recommendations only — no health values, no scores, no derived metrics. Because no special category data reaches you through the integration, you don't take on health-data obligations you didn't already have.
| Data | Who controls it | Notes |
|---|---|---|
| End-user health data | Humotron (controller) | The end-user consents to us directly. You never receive it. |
| Recommendation output | You (controller) | Once delivered into your product, it's yours and your privacy notice applies. |
| Your catalogue data | You | Should contain no personal data. |
| Your customer's account with you | You | Your existing relationship, unchanged. |
| Client data shared with a consultant | Humotron (controller); the consultant sees only what the client approves | The client connects directly with us and can withdraw a consultant's access at any time. |
| Consultant notes and programme content | You (controller); we process it for you | Covered by our data processing agreement. |
| Benefit codes | Humotron | Sponsors see aggregate counts only — never who activated a code. |
Because the end-user authenticates their wearable directly with us and consents to our processing, we are a controller in our own right — not your processor. This keeps the relationship clean for both sides.
| You receive | You never receive |
|---|---|
| Ranked product identifiers from your catalogue | Heart rate, HRV, sleep, recovery or any biometric value |
| A confidence indicator | Computed health scores |
| A non-clinical rationale category | Anything from which a health condition could be inferred |
| A session identifier | The end-user's wearable credentials or provider tokens |
| Aggregate performance reporting | Calendar, location or lab report data |
End-users connect their trackers directly with us. We turn their data into scores, and the engine ranks against those scores. Only the ranking crosses to you — no health values, no scores. This is the same design that protects our consumers; the commercial benefit to you is a consequence of it, not the reason for it.
If you use a hosted match page — for example yourbrand.com/match — we serve it on your domain or subdomain. Your customers connect their trackers with us on that page, see our privacy notice there, and consent to us directly. You receive the same outputs as any other integration: ranked products and aggregate reporting, never health data.
We set only the cookies needed to run the page. Your own analytics, advertising or tag-manager scripts must not run on it, because anything that runs there could see what your customer does on the page.
Clients join by invitation from their consultant. They connect their own trackers with us and choose which signals their consultant can see, and for how long. A consultant can't see anything a client hasn't approved, and loses access as soon as the client withdraws it. Strava data is never shown to a consultant.
Consultants using Humotron are not providing clinical care through it, and must not use client data to diagnose, treat or prescribe.
Employers and brands that give Humotron access to their people receive aggregate counts only — how many codes were issued and activated. They never learn who activated a code, and never receive anyone's health data, readings or recommendations.
To match products well, we index publicly available product information — titles, descriptions, ingredients, specifications and prices — from brands' own websites, alongside catalogues partners share with us. We don't collect personal data this way.
If you're a brand and want us to correct or remove your products, email partners@humotron.com and we'll act within 10 working days.
Through platform apps such as Shopify, we honour the platform's mandatory privacy requests — customer data requests, customer redaction and shop redaction — within the platform's deadlines. Because merchants don't send us end-user personal data, most requests confirm that we hold nothing linked to that customer; where we do hold platform-linked data, we delete it.
Our current sub-processor list is available from privacy@humotron.com. We give notice before adding one that materially affects a partner integration. We aim to host in the UK and EU; where any provider processes outside the UK/EU, we use the UK IDTA or equivalent standard contractual clauses.
Available on request from privacy@humotron.com: data processing agreement, sub-processor list, security overview, completed security questionnaires, and our records of processing summary.
Certifications: we don't hold ISO 27001 or SOC 2 certification yet. We'll share our security overview and complete your security questionnaire on request.
Email security@humotron.com with enough detail to reproduce. We aim to acknowledge within 2 working days and will keep you updated.
Please give us reasonable time to investigate and fix before disclosing publicly. We won't pursue action against good-faith research that respects user privacy, avoids data destruction, and doesn't degrade the service.
Out of scope: social engineering, physical attacks, denial of service, and findings from automated scanners without demonstrated impact.
If a security incident affects your integration or data we hold, we'll notify you without undue delay with what we know, what we're doing, and what you may need to do. Where a personal data breach is notifiable, we'll meet our obligations to the ICO and to affected individuals.
| Type | Where | Target response |
|---|---|---|
| Live incident | incidents@humotron.com | Same working day |
| Technical / API | developers@humotron.com | 2 working days |
| Commercial | partners@humotron.com | 3 working days |
| Security | security@humotron.com | 2 working days |
| Data protection | privacy@humotron.com | 5 working days |
These are targets, not guarantees. Contractual service levels, where agreed, take precedence.
Planned maintenance is scheduled outside peak hours where possible, with advance notice for anything expected to cause downtime.
Rate limits apply per partner and are set in your agreement. We may throttle to protect platform stability, and will contact you rather than cutting you off where circumstances allow.
Your customers are your customers — first-line support is yours. If the issue is with the recommendation engine rather than your product, escalate to developers@humotron.com. Consumers using the Humotron app directly should go to humotron.com/support.
We may suspend access immediately for a serious breach, and terminate for a material breach not remedied within 30 days. For anything unlawful, we may report it to the relevant authorities.
Humotron® is a UK registered trade mark (no. UK00004179136) owned by Humotron Ltd. Use is permitted only as set out in your agreement.
We'll ask before naming you as a customer or using your logo, unless your agreement already permits it.
Unsure? Ask legal@humotron.com before publishing. It's faster than fixing it afterwards.
| Legal entity | Humotron Ltd |
| Company number | 17494452 |
| Registered in | England & Wales |
| Registered office | 46 Emmeline Avenue, Swanscombe, United Kingdom, DA10 1EA |
| VAT number | 391473380 |
| ICO registration | ZC176453 |
| Trademark | Humotron® — UK registered trade mark no. UK00004179136 |