RYTM

Privacy

Data protection impact assessment

Public summary · version 0.1 · 26 September 2026

We assessed how RYTM's use of health data and AI could affect members. After the measures below, the remaining risk is low to moderate, and the processing can go ahead.

Why we did it

The GDPR (Art. 35) requires an assessment when processing is likely to be high-risk. RYTM meets several criteria set by the Swedish Authority for Privacy Protection: health data on a large scale, a new technology (an AI coach) and systematic evaluation (readiness scores and personal plans).

What it covers

The RYTM member app: account and membership, health profile, shift schedule, training, nutrition, daily check-ins and RYTM Coach. The data, purposes, legal bases, providers and retention times are listed in our privacy notice. Health data is processed only with explicit consent (Art. 9(2)(a)), and RYTM Coach has a consent of its own.

Risks to members

Each risk was rated by likelihood and how much it would affect a member, before and after our measures.

RiskBeforeAfter
Someone reads another member's health dataHighLow
A breach at a service provider exposes the databaseMediumLow–medium
Data transferred outside the EU without safeguardsMediumLow
The AI coach gives wrong or harmful health adviceHighLow
Members write sensitive details to the coachMedium–highMedium
Health data later used for other purposes (marketing, employers)MediumLow
Data kept longer than neededMediumLow
A readiness score is seen as a judgement of fitness for workLowLow
Loss or corruption of dataLowLow
Minors' health data is processedMediumLow
Misuse of the coach to reach or change other members' dataMediumLow

What we do about them

Conclusion and review

The largest remaining risk is that members write sensitive details to the coach; we reduce it with clear information, short retention and a way to delete conversations at any time. We review this assessment every year, and before any new use of health data.

Questions: [privacy@rytmclub.com].