Privacy
Data protection impact assessment
Public summary · version 0.1 · 26 September 2026
We assessed how RYTM's use of health data and AI could affect members. After the measures below, the remaining risk is low to moderate, and the processing can go ahead.
Why we did it
The GDPR (Art. 35) requires an assessment when processing is likely to be high-risk. RYTM meets several criteria set by the Swedish Authority for Privacy Protection: health data on a large scale, a new technology (an AI coach) and systematic evaluation (readiness scores and personal plans).
What it covers
The RYTM member app: account and membership, health profile, shift schedule, training, nutrition, daily check-ins and RYTM Coach. The data, purposes, legal bases, providers and retention times are listed in our privacy notice. Health data is processed only with explicit consent (Art. 9(2)(a)), and RYTM Coach has a consent of its own.
Risks to members
Each risk was rated by likelihood and how much it would affect a member, before and after our measures.
| Risk | Before | After |
|---|---|---|
| Someone reads another member's health data | High | Low |
| A breach at a service provider exposes the database | Medium | Low–medium |
| Data transferred outside the EU without safeguards | Medium | Low |
| The AI coach gives wrong or harmful health advice | High | Low |
| Members write sensitive details to the coach | Medium–high | Medium |
| Health data later used for other purposes (marketing, employers) | Medium | Low |
| Data kept longer than needed | Medium | Low |
| A readiness score is seen as a judgement of fitness for work | Low | Low |
| Loss or corruption of data | Low | Low |
| Minors' health data is processed | Medium | Low |
| Misuse of the coach to reach or change other members' data | Medium | Low |
What we do about them
- Each member can reach only their own health records — enforced in the database (row-level security) and on the server, with automated tests.
- Health data is stored apart from account, order and operational data, and can only be written after explicit consent.
- RYTM Coach needs a separate consent; it never receives name, email or member number, only the fields a question needs.
- Emergencies (chest pain, fainting, self-harm) are caught before any AI call and answered with a fixed referral to 112 or healthcare.
- Numbers in plans and coach answers come from RYTM's own evidence-based calculations, not from the AI; plan changes need the member's tap.
- We collect as little as possible: body limitations are chosen from a list (no free text), only the latest weight is kept, check-ins are deleted after 60 days and coach conversations after 90 days; all health data at the latest 12 months after a membership ends.
- One-click export of all data, one-step deletion of health data or the whole account.
- Our AI provider does not train on the data and deletes it within 30 days.
- Encryption in transit and at rest, message quotas and a monthly budget ceiling on the AI.
- Adults only: a health profile needs an age of 18+.
Conclusion and review
The largest remaining risk is that members write sensitive details to the coach; we reduce it with clear information, short retention and a way to delete conversations at any time. We review this assessment every year, and before any new use of health data.
Questions: [privacy@rytmclub.com].