Security, Privacy & Compliance

Security, Privacy & Compliance at ONU Health

Your data, held to the standard your health deserves

Health data deserves a higher standard of care than most information people share online. This page explains, in plain language, how ONU approaches security and which compliance frameworks the platform is built around.

How we protect it

How ONU protects your data

Encryption in transit and at rest

Your data is encrypted both while moving between your device and ONU's systems, and while stored.

Strict internal access controls

Access to identifiable health data is limited to what's operationally necessary.

Clinical oversight of the AI health engine

The frameworks the AI health engine uses to interpret biomarkers are reviewed by medical advisors before deployment.

Data minimization

ONU works to collect and retain only the health data needed to deliver the product's core functionality.

Compliance frameworks

The compliance frameworks behind ONU

HIPAAHIPAA
GDPRGDPR
NHSNHS
ISO 9001ISO 9001
ISO 27001ISO 27001
ISO 42001ISO 42001
C5C5
SOCSOC
CyberCyber

HIPAA

The US federal standard governing the privacy and security of protected health information. ONU's data handling practices are built around HIPAA's privacy and security requirements.

GDPR

The EU's comprehensive data protection law. ONU's practices are built to align with GDPR's requirements around consent, data minimization, and user rights.

ISO 27001

The internationally recognized standard for information security management systems — a structured framework for identifying and reducing security risk on an ongoing basis.

ISO 42001

A newer, AI-focused management system standard, covering how an organization governs the development and use of AI systems responsibly.

SOC compliance

Independent audit frameworks assessing an organization's controls around security, availability, and confidentiality.

NHS compliance

Alignment with UK National Health Service data-handling and information-governance standards, relevant to ONU's UK market operations.

For the complete, current scope of ONU's certifications and audit status, contact ONU's compliance team directly — this page is intended as a plain-language overview.

Your rights

Your rights over your own data

Regardless of where you're located, ONU is built around a simple principle: your health data belongs to you. You can review, export, or delete your data through your account settings, and ONU's full Privacy Policy details exactly what's collected, how it's used, and how to exercise your rights over it. ONU's Consumer Health Data Policy addresses health-data-specific handling in further detail.

What we don't do

What ONU does not do with your data

ONU does not sell identifiable health data to third parties, does not share individual health data with employers under any ONU for Companies program, and does not use your health data for advertising targeting outside of ONU's own product.

FAQ

Frequently asked questions

ACTION

Know it before it happens

ONU provides you with tools to build your healthy future; now it's your time to use them!