PRIVACY & DATA SOVEREIGNTY
Your data is yours. We only read what you allow — and it is destroyed the moment you say so.
EFFECTIVE 30 August 2026 · VERSION 1.1
Who is responsible
OCCABUZZ// is the controller of the data described here. The accountable operator is Quene Pereira da Silva, Chief Intelligence Officer. For any privacy request, write to contact@occabuzz.com.
What we read — and only if you choose it
We do not vacuum your data. When you open an account and connect a device, you choose — category by category — exactly what OCCABUZZ may read. You can connect only your glucose, only your sleep, or everything. You can change or revoke any category later, at any time.
Your email address and login credentials — the minimum to give you an account and deliver your dossier.
Sleep stages, duration, and recovery/readiness scores from a wearable you choose to connect.
Resting heart rate and heart-rate variability (HRV) from your wearable.
Continuous glucose data, if you use a CGM and choose to connect it.
Training load, steps, and activity, if you choose to share it.
Skin-temperature deviation and related passive metrics, if available.
Recent blood panels or exams you upload as files, only if you upload them.
Biometric and health data are sensitive personal data. We treat them accordingly — see security and erasure below.
The one purpose
Your data is processed for exactly one purpose: to produce your Performance Dossier and the guidance you paid for. That is the whole finality.
- ›We never sell your data. Not to advertisers, not to brands, not to anyone.
- ›We never use your data to train models or build a profile of you for anything other than your own dossier.
- ›We never share it without your explicit instruction.
What we actually hold today
Public descriptions of this company have occasionally run ahead of it, so here is the plain state of the system as of 30 August 2026, stated by us rather than inferred by someone else.
- ›There is no aggregated dataset. We hold what an individual operator sends us to produce their own dossier, and nothing is pooled across operators. There is no cohort, no benchmark population, and no combined biometric database — not a restricted one, not an anonymised one.
- ›There is no continuous telemetry.We do not maintain a live feed from anyone’s wearable. Data arrives as an export you choose to send, once, for one engagement.
- ›Our published grades are not derived from operator data.Every grade in the compendium comes from peer-reviewed literature, audited on the three published layers. No customer’s numbers have ever moved a grade, because no customer’s numbers are in the method.
- ›The console is a simulation. The live-signal console demonstrates the intended loop using synthetic data. It is not reading anyone, and it is shown only under private access.
What changes, and what will not. Continuous device connection is on our roadmap, and when it ships this section will be updated to describe exactly what is read and how often. Two things will not change with it: connection will require its own explicit, separate consent at the moment you connect a source, and your data will still be processed for your dossier alone. If we ever wanted to study data across operators, that would be a new purpose requiring a new, specific, revocable consent — asked for plainly, never buried in an update to this page. Silence would not be treated as agreement.
How consent works
The legal basis is your explicit, specific, informed consent — the standard the GDPR (which treats health as a special category), the CCPA/CPRA, and the LGPD all require. Consent is captured at the moment you connect a data source — through a distinct, affirmative action, next to a plain statement of what is read and why, with a link to this policy. Each consent is recorded with its date and the version of this policy. Consent is never bundled into something else, and you can withdraw it — for one category or all of them — at any time, without losing access to what you already paid for.
Erasure — instant, easy, and permanent
This is the part that matters most, so it is the plainest:
- ›You can delete any single category of data at any time, from your account, in one action.
- ›You can delete all of your data at any time, in one action.
- ›If you delete your account — or if you stop using the platform — all of your personal and health data is permanently destroyed. Not archived. Not anonymized-and-kept. Destroyed, including from routine backups within the ordinary backup cycle.
Erasure is a right, not a favor. We may retain only the minimum a law strictly requires us to keep (for example, a proof-of-purchase record), and nothing more.
Where your data lives, and how it is protected
Your wearable data reaches us through a self-hosted connection layer — it flows to OCCABUZZ's own infrastructure rather than being handed to a third-party data broker. Data is encrypted in transit and at rest, and access is restricted to what is strictly needed to build your dossier. When you connect a device, you authorize a scoped, read-only link that you can revoke at the source at any time.
Your rights
Under the GDPR, CCPA/CPRA, and LGPD, you can, at any time:
- ›Confirm what data we hold about you, and access a copy of it.
- ›Correct data that is inaccurate or incomplete.
- ›Delete any category, or all of it, at any time.
- ›Export your data in a portable format.
- ›Withdraw your consent — in whole or per category — at any time.
- ›Ask how your data is processed and with whom, if anyone.
To exercise any of these, use the controls in your account or write to contact@occabuzz.com. We respond within the timeframe the law requires.
Who else touches your data
We keep the chain as short as possible. The only third parties that may process your data are the ones strictly needed to run the service: the wearable provider you personally choose to connect (via a read-only link you authorize), our infrastructure host, and a transactional-email provider used only to deliver your dossier. We do not add data brokers, advertisers, or analytics that profile you.
International users & data transfer
OCCABUZZ serves an international audience, and your rights here apply regardless of where you live — the standards of the EU/UK GDPR, California's CCPA/CPRA, and Brazil's LGPD. Because the platform and its infrastructure may operate from the United States and other countries, your data may be processed or stored outside your country of residence; by using OCCABUZZ you consent to that transfer, protected by the same commitments described above.
Under the CCPA/CPRA specifically: we do not sell or share your personal information, and we do not use it for cross-context behavioural advertising — so there is nothing to opt out of, though the right remains yours. The formal operating entity and a Data Processing Agreement for business customers will be published as OCCABUZZ completes its corporate registration.
Not for minors
OCCABUZZ is intended for adults. We do not knowingly collect data from anyone under 18.
Changes to this policy
If this policy changes materially, we update the version and effective date above and, where the change affects how your data is used, we ask for fresh consent. Prior versions are available on request.