Legal
Privacy Policy
Last updated: 12 August 2026
The short version
- We only receive your WHOOP data after you approve it on WHOOP's own consent screen.
- It is used for one purpose: letting your clinical care team follow your recovery, sleep, and strain during your program.
- We never sell your data, never use it for advertising, and never share it with insurers or employers.
- You can disconnect at any time — we stop receiving data immediately and delete your access tokens.
1. Who we are
Vela Health is a clinic staff dashboard operated by Phuket Medical Clinic (Bangtao) Co., Ltd., trading as Phuket Medical Clinic — Laguna ("PMC Laguna", "we", "us", "our"). It displays WHOOP physiological data belonging to guests who have explicitly consented to share it with their care team.
PMC Laguna is the data controller for the personal data described in this policy.
| Registered entity | Phuket Medical Clinic (Bangtao) Co., Ltd. บจก. ภูเก็ต เมดิคอล คลินิก (บางเทา) |
|---|---|
| Company registration / Tax ID | 0835567011370 |
| Registered address | 58/1 Cherngtalay, Thalang, Phuket 83110, Thailand |
| Privacy contact | laguna@phuketmedicalclinic.com |
| Telephone | +66 96 236 2449 |
Phuket Medical Clinic operates other branches as separate legal entities. This policy covers only guests of PMC Laguna who connect a WHOOP account to Vela Health.
2. What this policy covers
This policy applies when:
- a guest connects their WHOOP account to Vela Health;
- clinic staff view guest data inside the Vela Health dashboard; or
- anyone visits velahealth.cloud.
It does not cover WHOOP itself. WHOOP's own handling of your data is governed by the WHOOP Privacy Policy.
3. What we collect
3.1 WHOOP data — only with your consent
When you authorize Vela Health through WHOOP's OAuth consent screen, you choose which permissions ("scopes") to grant. Vela Health requests these, and receives nothing outside them:
| Scope | What we receive | Why |
|---|---|---|
read:recovery |
Recovery score, heart rate variability, resting heart rate | Core readiness signal reviewed by your care team |
read:sleep |
Sleep duration, sleep performance, start and end times | Track sleep quality across the program |
read:cycles |
Day strain and average heart rate for a physiological cycle | Understand daily load against recovery |
read:workout |
Activity type and accumulated strain per workout | Distinguish training load from daily-life load |
read:profile |
Your WHOOP name and email address | Match your WHOOP account to your clinic record |
We do not request location data, and we do not receive data from any WHOOP member who has not completed the consent flow.
3.2 WHOOP access credentials
The OAuth access token and refresh token WHOOP issues for your connection. These are stored encrypted, are never displayed to clinic staff, and are never shared with anyone.
3.3 Clinic and account data
Your name, the program you are enrolled in, and your connection status. Separately, we hold accounts for clinic staff — name, email, role, and organization.
3.4 Technical data
Standard server logs — IP address, browser user agent, and timestamps — kept for security, troubleshooting, and abuse prevention.
4. How we use it, and our legal basis
WHOOP recovery, sleep, and strain data describes your health. Under Thailand's Personal Data Protection Act B.E. 2562 (2019) ("PDPA") this is sensitive personal data, and we process it on the basis of your explicit consent — given once on WHOOP's consent screen, and again at clinic intake.
We use the data to:
- show your care team your recovery, sleep, and strain trends during your program;
- compute a personal baseline and flag meaningful deviations from it for staff follow-up;
- record an audit log of which staff member viewed or acted on which record; and
- keep the service secure, available, and working correctly.
We do not:
- sell, rent, or trade your personal data;
- use it for advertising, marketing, or profiling unrelated to your care;
- use it to train machine-learning or AI models; or
- disclose it to insurers, employers, or data brokers.
5. Who can see your data
- Authorized clinic staff on your care team. Access is role-restricted and every record view and privacy action is written to an audit log.
- Infrastructure providers that host the service on our behalf under contract, limited to what is needed to run it. Our server is provided by Hostinger International Limited and located in Kuala Lumpur, Malaysia.
- WHOOP, as the source of the data.
- Authorities or regulators, where we are legally required to disclose.
No other third parties receive your data.
6. Cross-border transfer
WHOOP operates from the United States, and our server is located in Malaysia. Your data therefore leaves Thailand. Where personal data is transferred abroad we rely on your explicit consent under section 28 of the PDPA, and we require appropriate contractual safeguards from the providers involved.
7. How we protect it
- All traffic is encrypted in transit using HTTPS/TLS.
- WHOOP OAuth tokens are encrypted at rest under a dedicated secret.
- Role-based access control — staff can only reach guests within their own organization.
- Access to guest records and privacy actions is recorded in an append-only audit log.
- Incoming WHOOP webhooks are signature-verified before being accepted.
No system can be guaranteed perfectly secure. We work to protect your data using measures appropriate to its sensitivity, but we cannot promise absolute security.
8. How long we keep it
| Data | Retention |
|---|---|
| WHOOP metrics (recovery, sleep, strain, workouts) | For the duration of your program, then 12 months, after which they are deleted or irreversibly anonymized |
| WHOOP OAuth tokens | Deleted immediately when you disconnect or withdraw consent |
| Audit logs | 24 months, for security and compliance |
| Server logs | 90 days |
9. Disconnecting and your rights
Disconnecting WHOOP
You can stop sharing at any time, using either route — both work on their own:
- Ask your care team to use Disconnect on your record in the Vela Health dashboard; or
- Revoke Vela Health's access directly from your WHOOP account settings.
What happens when you disconnect: we stop receiving new WHOOP data immediately, delete the stored OAuth tokens, and stop displaying your metrics to staff. If you also want your historical metrics erased, email us and we will delete them.
Your rights under the PDPA
Subject to the Act's conditions, you may:
- access your personal data and request a copy;
- have inaccurate data corrected;
- request erasure, or anonymization, of your data;
- request that we suspend use of your data;
- object to certain processing;
- request your data in a portable format;
- withdraw your consent at any time — this does not affect processing already carried out; and
- lodge a complaint with Thailand's Personal Data Protection Committee (PDPC).
To exercise any of these, email laguna@phuketmedicalclinic.com, or speak to reception at the clinic. We respond within 30 days. Withdrawing consent may mean your care team can no longer monitor your recovery data as part of your program.
10. Children
Vela Health is not intended for individuals under 18. Where a guest is a minor, we obtain consent from a parent or legal guardian as required by the PDPA. If we learn that we hold a minor's data without proper consent, we delete it.
11. Cookies
The dashboard uses a strictly necessary session cookie so clinic staff can stay signed in. We do not use advertising cookies or third-party analytics trackers.
12. Changes to this policy
We will post any updates on this page with a revised "Last updated" date. If a change materially affects how we handle WHOOP data, we will notify affected guests and, where the law requires it, ask for consent again.
13. Contact us
Questions, requests, or complaints about privacy:
Phuket Medical Clinic (Bangtao) Co., Ltd.
58/1 Cherngtalay, Thalang, Phuket 83110, Thailand
laguna@phuketmedicalclinic.com · +66 96 236 2449