Legal
Privacy Policy
Last updated: 13 August 2026
The short version
- We only receive your WHOOP data after you approve it on WHOOP's own consent screen.
- It is used for one purpose: letting your clinical care team follow your recovery, sleep, and strain during your program.
- We never sell your data, never use it for advertising, and never share it with insurers or employers.
- You can disconnect at any time — we stop receiving data immediately and delete your access tokens.
1. Who we are
Vela Health is a clinic staff dashboard operated by Phuket Medical Clinic (Bangtao) Co., Ltd., trading as Phuket Medical Clinic — Laguna ("PMC Laguna", "we", "us", "our"). It displays WHOOP physiological data belonging to guests who have explicitly consented to share it with their care team.
PMC Laguna is the data controller for the personal data described in this policy.
| Registered entity | Phuket Medical Clinic (Bangtao) Co., Ltd. บจก. ภูเก็ต เมดิคอล คลินิก (บางเทา) |
|---|---|
| Company registration / Tax ID | 0835567011370 |
| Registered address | 58/1 Cherngtalay, Thalang, Phuket 83110, Thailand |
| Privacy contact | Laguna@phuketmedicalclinic.com |
| Telephone | +66 96 236 2449 |
Phuket Medical Clinic operates other branches as separate legal entities. This policy covers only guests of PMC Laguna who connect a WHOOP account to Vela Health.
2. What this policy covers
This policy applies when:
- a guest connects their WHOOP account to Vela Health;
- clinic staff view guest data inside the Vela Health dashboard; or
- anyone visits velahealth.cloud.
It does not cover WHOOP itself. WHOOP's own handling of your data is governed by the WHOOP Privacy Policy.
3. What we collect
3.1 WHOOP data — only with your consent
When you authorize Vela Health through WHOOP's OAuth consent screen, you choose which permissions ("scopes") to grant. Vela Health requests these, and receives nothing outside them:
| Scope | What we receive | Why |
|---|---|---|
read:recovery |
Recovery score, heart rate variability, resting heart rate | Core readiness signal reviewed by your care team |
read:sleep |
Sleep duration, sleep performance, start and end times | Track sleep quality across the program |
read:cycles |
Day strain and average heart rate for a physiological cycle | Understand daily load against recovery |
read:workout |
Activity type and accumulated strain per workout | Distinguish training load from daily-life load |
read:profile |
Your WHOOP name and email address | Match your WHOOP account to your clinic record |
We do not request location data, and we do not receive data from any WHOOP member who has not completed the consent flow.
3.2 WHOOP access credentials
The OAuth access token and refresh token WHOOP issues for your connection. These are stored encrypted, are never displayed to clinic staff, and are never shared with anyone.
3.3 Clinic and account data
Your name, the program you are enrolled in, and your connection status. Separately, we hold accounts for clinic staff — name, email, role, and organization.
3.4 Technical data
Standard server logs — IP address, browser user agent, and timestamps — kept for security, troubleshooting, and abuse prevention.
3.5 Lab report data (planned)
Draft — not yet live. This subsection describes a feature in development. It is not part of the currently published policy and must be reviewed by the clinic operator before it is deployed.
When lab report upload is enabled, a member of your care team may upload a PDF of your lab results to Vela Health. We keep the PDF, and the analyte values, units, and reference ranges a member of staff has reviewed and confirmed from it. A value our extraction process cannot read is recorded as missing, never guessed. How the PDF is read is described in section 5.
3.6 Expanded WHOOP data (planned)
Draft — not yet live. This subsection describes data we plan to start storing under the WHOOP scopes described in section 3.1, plus one new scope not currently requested. It is not part of the currently published policy. Once approved, the table below replaces the table in section 3.1.
We plan to store more detail from the scopes above, and to request one new
scope. If you already connected WHOOP, you do not need to do anything for
the first five rows below — the app will simply begin storing more of the
data already covered by the permission you granted. The last row,
read:body_measurement, is new: it only applies once you are
asked to, and choose to, re-authorize Vela Health on WHOOP's consent screen.
Your existing connection is unaffected until then.
| Scope | What we plan to receive | Why |
|---|---|---|
read:recovery |
Recovery score, heart rate variability, resting heart rate, blood oxygen saturation (SpO₂), skin temperature, and a flag indicating whether your WHOOP device was still calibrating when a reading was taken | Core readiness signal reviewed by your care team |
read:sleep |
Sleep duration, sleep performance, start and end times, time spent in each sleep stage (light, deep, REM, and awake), sleep disturbances, number of sleep cycles, sleep efficiency, sleep consistency, breathing rate during sleep, your calculated sleep need, and whether a sleep session was a nap | Track sleep quality across the program |
read:cycles |
Day strain and average heart rate for a physiological cycle, calories burned, and maximum heart rate for the day | Understand daily load against recovery |
read:workout |
Activity type, start and end times, accumulated strain, average and maximum heart rate, calories burned, distance, altitude gain, and time spent in each heart-rate zone, per workout | Distinguish training load from daily-life load |
read:profile |
Your WHOOP name and email address | Match your WHOOP account to your clinic record |
read:body_measurement (new scope) |
Height, weight, and maximum heart rate. Applies only after re-authorization — this scope is not requested for guests who connected before this change; your care team will ask you to reconnect your WHOOP account if this data is needed for your program. | Support accurate strain and heart-rate-zone context for your care team |
WHOOP does not make steps, VO₂ max, or Stress Monitor data available to third-party applications through its API, so Vela Health does not, and cannot, collect them.
4. How we use it, and our legal basis
WHOOP recovery, sleep, and strain data describes your health. Under Thailand's Personal Data Protection Act B.E. 2562 (2019) ("PDPA") this is sensitive personal data, and we process it on the basis of your explicit consent — given once on WHOOP's consent screen, and again at clinic intake.
We use the data to:
- show your care team your recovery, sleep, and strain trends during your program;
- compute a personal baseline and flag meaningful deviations from it for staff follow-up;
- record an audit log of which staff member viewed or acted on which record; and
- keep the service secure, available, and working correctly.
We do not:
- sell, rent, or trade your personal data;
- use it for advertising, marketing, or profiling unrelated to your care;
- use it to train machine-learning or AI models; or
- disclose it to insurers, employers, or data brokers.
5. Who can see your data
- Authorized clinic staff on your care team. Access is role-restricted and every record view and privacy action is written to an audit log.
- Infrastructure providers that host the service on our behalf under contract, limited to what is needed to run it — listed in full below.
- WHOOP, as the source of the data.
- Authorities or regulators, where we are legally required to disclose.
No other third parties receive your data.
| Processor | What it does | Where it runs |
|---|---|---|
| Supabase | Hosts the database holding your connection and metrics | Singapore |
| Vercel | Runs the application and serves this website | Singapore |
We do not use any AI or machine-learning provider on your data. Your health data is never sent to a language model or stored in a vector database.
Anthropic — AI processing of lab reports (planned)
Draft — not yet live. Describes a feature in development; not part of the currently published policy.
When lab report upload is enabled, the content of an uploaded lab report PDF is sent to the Anthropic API (Claude) so that analyte values can be read from it automatically. A member of your care team then reviews, and confirms or corrects, every value before it is shown anywhere in the dashboard — nothing an automated process reads from your report is treated as final until a person confirms it.
Anthropic acts as a data processor for this narrow purpose only. Processing is governed by Anthropic's commercial API Terms of Service, which state that content submitted through the API is not used to train Anthropic's models. Those terms, not this policy, are the authoritative source for exactly how Anthropic handles the content — we will confirm the then-current terms, and any data processing agreement needed, before this feature goes live.
Later, the same processor may also generate a clinician-facing summary of your WHOOP trends and confirmed lab results for your care team ("in-app interpretation"). That summary is explicitly not a diagnosis and, like lab extraction, is processed on our servers rather than sent to you directly.
External AI clients (MCP) — planned
Draft — not yet live. Describes a feature in development; not part of the currently published policy.
We plan to let clinic staff connect external AI assistants (for example, Claude or ChatGPT) to Vela Health so those assistants can read guest data on the staff member's behalf. This only happens after the staff member individually logs in and explicitly approves the connection and what it may read, using an industry-standard authorization protocol (OAuth 2.1). There is no shared or always-on access — each connection belongs to one authenticated staff member.
Access granted this way is:
- Read-only — a connected assistant can view data; it cannot edit, delete, or confirm anything.
- Scoped — limited to the specific data the staff member approved for that connection.
- Audited — every read is logged, the same way a staff member viewing your record directly is logged.
- Revocable — the staff member, or the clinic, can disconnect a client at any time, which ends its access immediately.
6. Cross-border transfer
WHOOP operates from the United States, and our database and application run in Singapore. Your data therefore leaves Thailand. Where personal data is transferred abroad we rely on your explicit consent under section 28 of the PDPA, and we require appropriate contractual safeguards from the providers involved.
7. How we protect it
- All traffic is encrypted in transit using HTTPS/TLS.
- WHOOP OAuth tokens are encrypted at rest under a dedicated secret.
- Role-based access control — staff can only reach guests within their own organization.
- Access to guest records and privacy actions is recorded in an append-only audit log.
- Incoming WHOOP webhooks are signature-verified before being accepted.
No system can be guaranteed perfectly secure. We work to protect your data using measures appropriate to its sensitivity, but we cannot promise absolute security.
8. How long we keep it
| Data | Retention |
|---|---|
| WHOOP metrics (recovery, sleep, strain, workouts) | For the duration of your program, then 12 months, after which they are deleted or irreversibly anonymized |
| WHOOP OAuth tokens | Deleted immediately when you disconnect or withdraw consent |
| Audit logs | 24 months, for security and compliance |
| Server logs | 90 days |
| Lab report PDFs and extracted results (planned) | Draft, pending confirmation: the same schedule as WHOOP metrics above — for the duration of your program, then 12 months, after which they are deleted or irreversibly anonymized |
| Sleep detail — stages, disturbances, cycles, efficiency, consistency, respiratory rate, sleep-need, nap flag, bed/wake times (planned) | Draft, pending confirmation: the same schedule as WHOOP metrics above — for the duration of your program, then 12 months, after which they are deleted or irreversibly anonymized |
| Workouts — sport, times, strain, heart rate, calories, distance, altitude, heart-rate zone durations (planned) | Draft, pending confirmation: the same schedule as WHOOP metrics above — for the duration of your program, then 12 months, after which they are deleted or irreversibly anonymized |
| Body measurement — height, weight, maximum heart rate (planned, new scope) | Draft, pending confirmation: kept only while you are enrolled in a program; deleted, along with the rest of your guest record, when you are no longer enrolled — not the 12-month tail that applies to the WHOOP metrics rows above |
9. Disconnecting and your rights
Disconnecting WHOOP
You can stop sharing at any time, using either route — both work on their own:
- Ask your care team to use Disconnect on your record in the Vela Health dashboard; or
- Revoke Vela Health's access directly from your WHOOP account settings.
What happens when you disconnect: we stop receiving new WHOOP data immediately, delete the stored OAuth tokens, and stop displaying your metrics to staff. If you also want your historical metrics erased, email us and we will delete them.
Your rights under the PDPA
Subject to the Act's conditions, you may:
- access your personal data and request a copy;
- have inaccurate data corrected;
- request erasure, or anonymization, of your data;
- request that we suspend use of your data;
- object to certain processing;
- request your data in a portable format;
- withdraw your consent at any time — this does not affect processing already carried out; and
- lodge a complaint with Thailand's Personal Data Protection Committee (PDPC).
To exercise any of these, email Laguna@phuketmedicalclinic.com, or speak to reception at the clinic. We respond within 30 days. Withdrawing consent may mean your care team can no longer monitor your recovery data as part of your program.
10. Children
Vela Health is not intended for individuals under 18. Where a guest is a minor, we obtain consent from a parent or legal guardian as required by the PDPA. If we learn that we hold a minor's data without proper consent, we delete it.
11. Cookies
The dashboard uses a strictly necessary session cookie so clinic staff can stay signed in. We do not use advertising cookies or third-party analytics trackers.
12. Changes to this policy
We will post any updates on this page with a revised "Last updated" date. If a change materially affects how we handle WHOOP data, we will notify affected guests and, where the law requires it, ask for consent again.
13. Contact us
Questions, requests, or complaints about privacy:
Phuket Medical Clinic (Bangtao) Co., Ltd.
58/1 Cherngtalay, Thalang, Phuket 83110, Thailand
Laguna@phuketmedicalclinic.com · +66 96 236 2449