humotron logo‹ back to Humotron for Business‹ back
Humotron for Business · legal & policies

Terms for teams
building on us.

The policies that govern the Humotron recommendation engine, our API, our commerce integrations, and our Consultants and Benefits products. Written for the people who have to review them — plain language first, detail underneath, and no attempt to hide the parts that matter.

Version 1.1Last updated 23 September 2026Humotron Ltd · 17494452
Start here

How the commercial relationship works.

A map of the policies below and the principles behind them. If you're reviewing us for procurement, start with this and then read Data & Privacy.
Last updated 23 September 2026 · Version 1.1
The short version

Your customers — or your clients — connect their own trackers directly to us. Commerce partners receive ranked recommendations from their own catalogue and never any health data. Consultants see only what each client chooses to share. Ranking is determined by fit, and placement is not for sale.

These pages are informational
Every partnership runs on a signed agreement. Where these pages and your agreement differ, your agreement governs. Nothing here is an offer or a binding commitment.

§01 Our principles

  • You never see a heartbeat. Health data doesn't cross the boundary into your systems. Not as a courtesy — as architecture.
  • Placement isn't for sale. Ranking reflects fit against the end-user's data. That's what makes the recommendation worth showing, and we won't sell it at any price.
  • Clear boundaries. We're upfront about who controls what data and who's responsible for what.
  • No surprises. Breaking changes get notice. Sub-processor changes get notice.

§02 What we offer

ProductWhat it does
CommercePersonalised recommendations from your own catalogue, based on your customers' tracker data. Through our API, a hosted match page on your own domain, or platform apps — Shopify first, coming soon.
ConsultantsA client-data workspace for wellness consultants and coaches. Your clients connect their trackers and choose what you can see between sessions.
BenefitsHumotron access bought in volume and given to your employees or customers.
Catalogue servicesMapping your products to the attributes the engine ranks against.

§03 The policies

  • Partner Terms — the commercial agreement framework.
  • Data & Privacy — who controls what, and why you don't receive health data.
  • Security — how we protect the platform, and how to report a vulnerability.
  • Service & Support — availability, support routes, and how changes are handled.
  • Acceptable Use — what you may and may not do with the API.
  • Brand Use — how our name and marks may be used.
  • Company & Contact — who we are and where to write.
Partner Terms

The commercial framework.

The terms on which businesses access the Humotron engine. Your signed agreement takes precedence over anything here.
Last updated 23 September 2026 · Version 1.1
The short version

We licence you access to the engine for use inside your own product. You're responsible for your catalogue data and for your relationship with your customers. We're responsible for the engine. Neither of us can promise the other unlimited liability, so both sides are capped — at a level appropriate to a commercial contract, not a consumer one.

§01 Agreement structure

Each partnership is governed by a signed agreement incorporating these terms, a commercial schedule (pricing, volumes, term), and a data processing agreement where applicable. This page is informational; the signed documents govern.

§02 The licence

Subject to your agreement and payment, we grant a non-exclusive, non-transferable, revocable right to access the API and integrate the output into your own product, for the term agreed.

You may not sublicense, resell, or provide access to third parties; use the output to build a competing engine; or extract, train on, or reverse-engineer our models. See Acceptable Use.

§03 Your responsibilities

  • Catalogue accuracy. You warrant that product data you supply is accurate, that claims are substantiated, and that you have the right to supply it.
  • Regulatory compliance for your products. Product safety, labelling, advertising and health-claim rules for what you sell remain yours. We rank; you sell.
  • Your customer relationship. Your terms, your privacy notice, your customer service, your fulfilment.
  • Credential security. Keep API keys secure and tell us immediately if they're compromised.
  • Honest presentation. Don't present recommendations as medical advice or clinical findings, and don't imply an endorsement we haven't given.

§04 Our responsibilities

  • Provide the engine substantially as documented.
  • Maintain the security measures described in the Security policy.
  • Give reasonable notice of breaking API changes.
  • Rank on fit — never on payment.

§05 Ranking integrity

Not negotiable
Ranking position is determined by fit against the end-user's data. We do not sell placement, weighting or inclusion priority, and no commercial term will change a ranking. If we ever did, the recommendation would be worth nothing to your customer — and to you.

What you can influence is the completeness and accuracy of your catalogue data. Better attributes give the engine more to match on. That's the legitimate route to appearing more often.

§06 Fees

Fees, volumes and payment terms are in your commercial schedule or on our pricing page. We charge on use — for Commerce, customers who actually connect; for Consultants, active clients — so you don't pay for a plan you aren't using. Unless agreed otherwise: fees are exclusive of VAT, invoices are payable within 30 days, and we may charge statutory interest on late payment.

§07 Intellectual property

We own the engine, models, documentation and everything we produce. You own your catalogue data and your product. Neither party acquires the other's IP.

We may use aggregated, de-identified performance data to improve the service. This never includes your catalogue data in identifiable form or any end-user personal data.

§08 Confidentiality

Both parties keep the other's confidential information confidential, use it only for the partnership, and protect it with at least reasonable care. Obligations survive termination by 3 years.

§09 Warranties and disclaimers

We warrant we have the right to grant the licence and will provide the service with reasonable skill and care.

What we don't warrant
Recommendations are algorithmic outputs based on consumer wearable data. We don't warrant they are accurate, complete, suitable for any individual, or that they will increase your conversion or revenue. The engine is provided "as is" beyond the express warranties above.

§10 Liability

Neither party limits liability for death or personal injury caused by negligence, for fraud, or for anything else that cannot be limited by law.

Subject to that, and unless your agreement says otherwise:

  • Neither party is liable for indirect or consequential loss, loss of profit, revenue, goodwill or anticipated savings.
  • Each party's total liability is capped at the fees paid or payable in the 12 months before the claim.
  • The cap does not apply to your payment obligations, breach of the licence scope, or either party's indemnities.

§11 Indemnities

  • We indemnify you against third-party claims that the engine infringes their IP, subject to prompt notice and our control of the defence.
  • You indemnify us against claims arising from your catalogue data, your products, your customer relationships, or your presentation of our output.

§12 Term and termination

  • Term as set out in your agreement.
  • Either party may terminate for material breach not remedied within 30 days of notice.
  • Either party may terminate immediately on insolvency.
  • We may suspend access immediately for a security threat, unlawful use, or serious Acceptable Use breach.

On termination: access ends, you stop using our output and marks, each party returns or deletes the other's confidential information, and accrued fees remain payable. We retain your catalogue data for no more than 30 days before deletion.

§13 General

Neither party may assign without consent, except to a group company or on a sale of the business. Neither is liable for events outside reasonable control. No partnership, agency or employment is created. These terms are governed by the laws of England & Wales, with exclusive jurisdiction of its courts.

Data & Privacy

Why you never receive health data.

The part your privacy and procurement teams need. Who controls what, what crosses the boundary, and what doesn't.
Last updated 23 September 2026 · Version 1.1
The short version

End-users connect their wearables directly with us and consent to us processing their data. We are the controller for that data. You receive ranked product recommendations only — no health values, no scores, no derived metrics. Because no special category data reaches you through the integration, you don't take on health-data obligations you didn't already have.

§01 The roles

DataWho controls itNotes
End-user health dataHumotron (controller)The end-user consents to us directly. You never receive it.
Recommendation outputYou (controller)Once delivered into your product, it's yours and your privacy notice applies.
Your catalogue dataYouShould contain no personal data.
Your customer's account with youYouYour existing relationship, unchanged.
Client data shared with a consultantHumotron (controller); the consultant sees only what the client approvesThe client connects directly with us and can withdraw a consultant's access at any time.
Consultant notes and programme contentYou (controller); we process it for youCovered by our data processing agreement.
Benefit codesHumotronSponsors see aggregate counts only — never who activated a code.

Because the end-user authenticates their wearable directly with us and consents to our processing, we are a controller in our own right — not your processor. This keeps the relationship clean for both sides.

If your integration differs
If your implementation involves you sending us end-user personal data, the analysis changes and a data processing agreement is required. Tell us at the design stage — it's much easier to resolve then.

§02 What crosses the boundary

You receiveYou never receive
Ranked product identifiers from your catalogueHeart rate, HRV, sleep, recovery or any biometric value
A confidence indicatorComputed health scores
A non-clinical rationale categoryAnything from which a health condition could be inferred
A session identifierThe end-user's wearable credentials or provider tokens
Aggregate performance reportingCalendar, location or lab report data

§03 The split-data architecture

End-users connect their trackers directly with us. We turn their data into scores, and the engine ranks against those scores. Only the ranking crosses to you — no health values, no scores. This is the same design that protects our consumers; the commercial benefit to you is a consequence of it, not the reason for it.

§04 Hosted match pages

If you use a hosted match page — for example yourbrand.com/match — we serve it on your domain or subdomain. Your customers connect their trackers with us on that page, see our privacy notice there, and consent to us directly. You receive the same outputs as any other integration: ranked products and aggregate reporting, never health data.

We set only the cookies needed to run the page. Your own analytics, advertising or tag-manager scripts must not run on it, because anything that runs there could see what your customer does on the page.

§05 Consultants

Clients join by invitation from their consultant. They connect their own trackers with us and choose which signals their consultant can see, and for how long. A consultant can't see anything a client hasn't approved, and loses access as soon as the client withdraws it. Strava data is never shown to a consultant.

Consultants using Humotron are not providing clinical care through it, and must not use client data to diagnose, treat or prescribe.

§06 Benefits

Employers and brands that give Humotron access to their people receive aggregate counts only — how many codes were issued and activated. They never learn who activated a code, and never receive anyone's health data, readings or recommendations.

§07 Product catalogue data

To match products well, we index publicly available product information — titles, descriptions, ingredients, specifications and prices — from brands' own websites, alongside catalogues partners share with us. We don't collect personal data this way.

If you're a brand and want us to correct or remove your products, email partners@humotron.com and we'll act within 10 working days.

§08 Platform privacy requests

Through platform apps such as Shopify, we honour the platform's mandatory privacy requests — customer data requests, customer redaction and shop redaction — within the platform's deadlines. Because merchants don't send us end-user personal data, most requests confirm that we hold nothing linked to that customer; where we do hold platform-linked data, we delete it.

§09 Your obligations

  • Tell your customers, in your own privacy notice, that recommendations are generated by a third-party engine.
  • Don't attempt to re-identify end-users or reverse-engineer health information from recommendations.
  • Don't combine our output with other data to infer health conditions.
  • Don't use recommendation output for advertising targeting beyond the product surface it was delivered for.
⚠ Inference is prohibited
Attempting to infer health status from recommendation patterns — yours or anyone's — is a material breach and grounds for immediate suspension. It would also likely make you a controller of special category data without a lawful basis.

§10 Sub-processors and transfers

Our current sub-processor list is available from privacy@humotron.com. We give notice before adding one that materially affects a partner integration. We aim to host in the UK and EU; where any provider processes outside the UK/EU, we use the UK IDTA or equivalent standard contractual clauses.

§11 Procurement documents

Available on request from privacy@humotron.com: data processing agreement, sub-processor list, security overview, completed security questionnaires, and our records of processing summary.

Security

How we protect the platform.

Our security posture, and how to report something if you find it.
Last updated 23 September 2026 · Version 1.1

§01 Controls

  • Encryption in transit and at rest across all environments.
  • Access control — least privilege, with production access restricted and logged.
  • Environment separation — sandbox runs on synthetic data, entirely separate from production.
  • Credential management — per-partner keys, rotatable and immediately revocable.
  • Logging — per-partner API access logs retained for 12 months.
  • Architecture — the split-data design keeps raw biometric streams off our systems entirely.

Certifications: we don't hold ISO 27001 or SOC 2 certification yet. We'll share our security overview and complete your security questionnaire on request.

§02 Reporting a vulnerability

Email security@humotron.com with enough detail to reproduce. We aim to acknowledge within 2 working days and will keep you updated.

Please give us reasonable time to investigate and fix before disclosing publicly. We won't pursue action against good-faith research that respects user privacy, avoids data destruction, and doesn't degrade the service.

Out of scope: social engineering, physical attacks, denial of service, and findings from automated scanners without demonstrated impact.

§03 Incidents

If a security incident affects your integration or data we hold, we'll notify you without undue delay with what we know, what we're doing, and what you may need to do. Where a personal data breach is notifiable, we'll meet our obligations to the ICO and to affected individuals.

§04 Your side

  • Store API credentials securely — never in client-side code or a public repository.
  • Rotate credentials on your own schedule and whenever staff change.
  • Tell us immediately at security@humotron.com if credentials may be compromised.
  • Use TLS for all calls.
Service & Support

Availability, support and changes.

What you can expect operationally — and what we'll commit to contractually versus what we won't publish.
Last updated 23 September 2026 · Version 1.1
On service levels
We don't publish an uptime commitment on this page, because a number we can't yet evidence is worth nothing to you. Service levels are agreed per contract against measured performance. If your agreement contains an SLA, it governs.

§01 Support routes

TypeWhereTarget response
Live incidentincidents@humotron.comSame working day
Technical / APIdevelopers@humotron.com2 working days
Commercialpartners@humotron.com3 working days
Securitysecurity@humotron.com2 working days
Data protectionprivacy@humotron.com5 working days

These are targets, not guarantees. Contractual service levels, where agreed, take precedence.

§02 API versioning and changes

  • Breaking changes: at least 90 days' notice, with the previous version supported through a migration window.
  • Non-breaking additions: may be released without notice. Build tolerantly — ignore fields you don't recognise.
  • Deprecation: announced with a clear end-of-life date.
  • Emergency changes: we may act immediately for a security issue, and will tell you as soon as we can.

§03 Maintenance

Planned maintenance is scheduled outside peak hours where possible, with advance notice for anything expected to cause downtime.

§04 Rate limits

Rate limits apply per partner and are set in your agreement. We may throttle to protect platform stability, and will contact you rather than cutting you off where circumstances allow.

§05 End-user support

Your customers are your customers — first-line support is yours. If the issue is with the recommendation engine rather than your product, escalate to developers@humotron.com. Consumers using the Humotron app directly should go to humotron.com/support.

Acceptable Use

What you may and may not do.

The boundaries on API use. Breach can mean immediate suspension.
Last updated 23 September 2026 · Version 1.1

§01 You may not

  • Resell or sublicense API access, or provide it to third parties.
  • Reverse-engineer the engine, or use output to train a competing model.
  • Systematically extract output to build a derivative dataset or product.
  • Re-identify end-users or infer health conditions from recommendations.
  • Misrepresent output as medical advice, clinical findings, or a diagnosis.
  • Exceed agreed rate limits or circumvent technical restrictions.
  • Use the API for unlawful purposes or in breach of applicable regulation.
  • Supply catalogue data you don't have rights to, or claims you can't substantiate.
  • Present recommendations in a way that implies Humotron endorses a specific brand.

§02 Prohibited applications

⚠ Not permitted under any agreement
The engine must not be used for insurance underwriting or pricing, employment decisions, credit decisions, or any other purpose that could materially disadvantage an individual based on inferences about their health. These uses are prohibited regardless of what any commercial term says.

§03 Consequences

We may suspend access immediately for a serious breach, and terminate for a material breach not remedied within 30 days. For anything unlawful, we may report it to the relevant authorities.

Brand Use

Using our name.

How the Humotron name and marks may be used in your product and marketing.
Last updated 23 September 2026 · Version 1.1

§01 The mark

Humotron® is a UK registered trade mark (no. UK00004179136) owned by Humotron Ltd. Use is permitted only as set out in your agreement.

§02 Generally permitted

  • A factual statement that recommendations are powered by Humotron.
  • Using our logo in the form and proportions we supply.
  • Naming us in a customer-facing explanation of how recommendations work.

§03 Not permitted

  • Implying endorsement of your products by Humotron.
  • Suggesting a partnership, certification or approval beyond what exists.
  • Altering, recolouring or redrawing the mark.
  • Using the name in your own product name, domain or app title.
  • Issuing a press release naming us without prior written approval.

§04 Your marks

We'll ask before naming you as a customer or using your logo, unless your agreement already permits it.

§05 Questions

Unsure? Ask legal@humotron.com before publishing. It's faster than fixing it afterwards.

Company & Contact

Who we legally are.

Entity details and the right inbox for each kind of question.
Last updated 23 September 2026 · Version 1.1

§01 Company details

Legal entityHumotron Ltd
Company number17494452
Registered inEngland & Wales
Registered office46 Emmeline Avenue, Swanscombe, United Kingdom, DA10 1EA
VAT number391473380
ICO registrationZC176453
TrademarkHumotron® — UK registered trade mark no. UK00004179136

§02 Contacts

  • Partnerships & commercial: partners@humotron.com
  • Technical & API: developers@humotron.com
  • Incidents: incidents@humotron.com
  • Security: security@humotron.com
  • Data protection: privacy@humotron.com
  • Legal: legal@humotron.com

§03 Consumer policies

If you're looking for the policies covering the Humotron consumer app and website, they're in our UK & EU, India and Global editions.

humotron logo

The recommendation engine that reads tracker data into fit — without ever handing you a heartbeat.

Humotron policies//Business v1.1//health data never crosses to partners//London 51.5°N
Follow
© 2026 Humotron Ltd. Humotron® is a registered trademark of Humotron Ltd. Registered in England & Wales, company no. 17494452. · These pages are informational and provided in good faith; they are not legal advice and do not form an offer. Signed agreements govern.