BioSystems One Inc. · Pre-release notice
Privacy notice
How ErgoThrive handles account information, workplace evidence, assessment records, posture data, and operational metadata during the pre-release period.
Last updated: September 9, 2026
Who operates ErgoThrive
ErgoThrive is developed and operated by BioSystems One Inc. This notice explains the information processed by the current pre-release occupational ergonomics platform.
Information we process
- Account information such as name, email address, avatar, job title, authentication identifier, and workspace role.
- Organization, project, assessment, worksheet, result, corrective-action, and report records entered by authorized users.
- Workplace images, videos, file metadata, checksums, documented authorization basis, and retention deadlines.
- Posture landmarks, derived angles, confidence values, model provenance, assessor corrections, and review history.
- Subscription state and plan selection. Payment instruments are not collected by ErgoThrive while payments are disabled.
- Security, audit, device, and request metadata needed to operate, diagnose, and protect the service.
Why we process information
Information is used to authenticate users, isolate organization workspaces, manage projects, produce ergonomic screening outputs and reports, preserve assessment traceability, secure uploaded evidence, provide support, and maintain the service.
An organization is responsible for ensuring it has an appropriate lawful basis and authority before uploading workplace media or personal information. The upload workflow requires the user to document that authorization.
Workplace media and retention
Uploaded media is stored in private Supabase Storage buckets. New uploads enter quarantine and cannot be attached to an assessment until the configured security workflow marks them clean. Client-side file checks are supplemental and do not replace server-side malware scanning.
Each upload records the organization’s configured retention deadline. Automated production deletion is not represented as operationally approved until the scanner, scheduler, alerting, and restore/deletion drill are independently qualified. Authorized deletion requests are therefore handled through a verified support process.
Automatic posture fitting
When a user chooses posture fitting, the displayed image or paused video frame is analyzed locally in the browser. ErgoThrive downloads a pinned MediaPipe model and WebAssembly runtime, but the fitting operation does not send the displayed source pixels to the model-hosting service.
Model identity, inference settings, confidence, derived landmarks and angles, and later human corrections may be retained with the assessment for traceability. Automated output is assistive and remains subject to competent human review.
Service providers and transfers
The current service uses Supabase for hosted database, authentication, and private storage; Cloudflare for application delivery and security; Google when a user chooses Google authentication; and pinned model-hosting endpoints for browser posture assets. Stripe sandbox objects are prepared, but payment processing is disabled.
Provider locations and international-transfer safeguards must be assessed for each customer’s jurisdiction and contract. A final subprocessor list and data-processing addendum require counsel and vendor review before contractual enterprise use.
Access, export, correction, and deletion
Organization owners and administrators can download a structured export of workspace records and evidence metadata from Settings. The export excludes passwords, authentication secrets, payment identifiers, binary media, and generated report files.
To request access, correction, a complete portable copy, or deletion, contact support@biosystemsone.com. BioSystems One will verify identity and authority and review retention requirements and legal holds before acting. Response timelines and jurisdiction-specific rights remain subject to the final counsel-approved policy.
Security and data sharing
ErgoThrive uses authenticated access, tenant row-level security, private storage, restrictive browser security headers, audit history, and integrity controls. No security measure eliminates all risk, and production readiness depends on the controls identified in the release gate.
BioSystems One does not design the service to sell workplace data or use customer media for advertising. Information may be disclosed when required by law, to protect the service, or to approved service providers operating under appropriate terms.
Changes and contact
This notice may change as the service, contracts, and legal review develop. Material changes should be dated and communicated through the service or the organization’s designated contact.