Vela Health · Privacy

Legal

Privacy Policy

Last updated: 13 August 2026

The short version

1. Who we are

Vela Health is a clinic staff dashboard operated by Phuket Medical Clinic (Bangtao) Co., Ltd., trading as Phuket Medical Clinic — Laguna ("PMC Laguna", "we", "us", "our"). It displays WHOOP physiological data belonging to guests who have explicitly consented to share it with their care team.

PMC Laguna is the data controller for the personal data described in this policy.

Registered entity Phuket Medical Clinic (Bangtao) Co., Ltd.
บจก. ภูเก็ต เมดิคอล คลินิก (บางเทา)
Company registration / Tax ID 0835567011370
Registered address 58/1 Cherngtalay, Thalang, Phuket 83110, Thailand
Privacy contact Laguna@phuketmedicalclinic.com
Telephone +66 96 236 2449

Phuket Medical Clinic operates other branches as separate legal entities. This policy covers only guests of PMC Laguna who connect a WHOOP account to Vela Health.

2. What this policy covers

This policy applies when:

It does not cover WHOOP itself. WHOOP's own handling of your data is governed by the WHOOP Privacy Policy.

3. What we collect

3.1 WHOOP data — only with your consent

When you authorize Vela Health through WHOOP's OAuth consent screen, you choose which permissions ("scopes") to grant. Vela Health requests these, and receives nothing outside them:

ScopeWhat we receiveWhy
read:recovery Recovery score, heart rate variability, resting heart rate Core readiness signal reviewed by your care team
read:sleep Sleep duration, sleep performance, start and end times Track sleep quality across the program
read:cycles Day strain and average heart rate for a physiological cycle Understand daily load against recovery
read:workout Activity type and accumulated strain per workout Distinguish training load from daily-life load
read:profile Your WHOOP name and email address Match your WHOOP account to your clinic record

We do not request location data, and we do not receive data from any WHOOP member who has not completed the consent flow.

3.2 WHOOP access credentials

The OAuth access token and refresh token WHOOP issues for your connection. These are stored encrypted, are never displayed to clinic staff, and are never shared with anyone.

3.3 Clinic and account data

Your name, the program you are enrolled in, and your connection status. Separately, we hold accounts for clinic staff — name, email, role, and organization.

3.4 Technical data

Standard server logs — IP address, browser user agent, and timestamps — kept for security, troubleshooting, and abuse prevention.

3.5 Lab report data (planned)

Draft — not yet live. This subsection describes a feature in development. It is not part of the currently published policy and must be reviewed by the clinic operator before it is deployed.

When lab report upload is enabled, a member of your care team may upload a PDF of your lab results to Vela Health. We keep the PDF, and the analyte values, units, and reference ranges a member of staff has reviewed and confirmed from it. A value our extraction process cannot read is recorded as missing, never guessed. How the PDF is read is described in section 5.

3.6 Expanded WHOOP data (planned)

Draft — not yet live. This subsection describes data we plan to start storing under the WHOOP scopes described in section 3.1, plus one new scope not currently requested. It is not part of the currently published policy. Once approved, the table below replaces the table in section 3.1.

We plan to store more detail from the scopes above, and to request one new scope. If you already connected WHOOP, you do not need to do anything for the first five rows below — the app will simply begin storing more of the data already covered by the permission you granted. The last row, read:body_measurement, is new: it only applies once you are asked to, and choose to, re-authorize Vela Health on WHOOP's consent screen. Your existing connection is unaffected until then.

ScopeWhat we plan to receiveWhy
read:recovery Recovery score, heart rate variability, resting heart rate, blood oxygen saturation (SpO₂), skin temperature, and a flag indicating whether your WHOOP device was still calibrating when a reading was taken Core readiness signal reviewed by your care team
read:sleep Sleep duration, sleep performance, start and end times, time spent in each sleep stage (light, deep, REM, and awake), sleep disturbances, number of sleep cycles, sleep efficiency, sleep consistency, breathing rate during sleep, your calculated sleep need, and whether a sleep session was a nap Track sleep quality across the program
read:cycles Day strain and average heart rate for a physiological cycle, calories burned, and maximum heart rate for the day Understand daily load against recovery
read:workout Activity type, start and end times, accumulated strain, average and maximum heart rate, calories burned, distance, altitude gain, and time spent in each heart-rate zone, per workout Distinguish training load from daily-life load
read:profile Your WHOOP name and email address Match your WHOOP account to your clinic record
read:body_measurement (new scope) Height, weight, and maximum heart rate. Applies only after re-authorization — this scope is not requested for guests who connected before this change; your care team will ask you to reconnect your WHOOP account if this data is needed for your program. Support accurate strain and heart-rate-zone context for your care team

WHOOP does not make steps, VO₂ max, or Stress Monitor data available to third-party applications through its API, so Vela Health does not, and cannot, collect them.

4. How we use it, and our legal basis

WHOOP recovery, sleep, and strain data describes your health. Under Thailand's Personal Data Protection Act B.E. 2562 (2019) ("PDPA") this is sensitive personal data, and we process it on the basis of your explicit consent — given once on WHOOP's consent screen, and again at clinic intake.

We use the data to:

We do not:

5. Who can see your data

No other third parties receive your data.

ProcessorWhat it doesWhere it runs
Supabase Hosts the database holding your connection and metrics Singapore
Vercel Runs the application and serves this website Singapore

We do not use any AI or machine-learning provider on your data. Your health data is never sent to a language model or stored in a vector database.

Anthropic — AI processing of lab reports (planned)

Draft — not yet live. Describes a feature in development; not part of the currently published policy.

When lab report upload is enabled, the content of an uploaded lab report PDF is sent to the Anthropic API (Claude) so that analyte values can be read from it automatically. A member of your care team then reviews, and confirms or corrects, every value before it is shown anywhere in the dashboard — nothing an automated process reads from your report is treated as final until a person confirms it.

Anthropic acts as a data processor for this narrow purpose only. Processing is governed by Anthropic's commercial API Terms of Service, which state that content submitted through the API is not used to train Anthropic's models. Those terms, not this policy, are the authoritative source for exactly how Anthropic handles the content — we will confirm the then-current terms, and any data processing agreement needed, before this feature goes live.

Later, the same processor may also generate a clinician-facing summary of your WHOOP trends and confirmed lab results for your care team ("in-app interpretation"). That summary is explicitly not a diagnosis and, like lab extraction, is processed on our servers rather than sent to you directly.

External AI clients (MCP) — planned

Draft — not yet live. Describes a feature in development; not part of the currently published policy.

We plan to let clinic staff connect external AI assistants (for example, Claude or ChatGPT) to Vela Health so those assistants can read guest data on the staff member's behalf. This only happens after the staff member individually logs in and explicitly approves the connection and what it may read, using an industry-standard authorization protocol (OAuth 2.1). There is no shared or always-on access — each connection belongs to one authenticated staff member.

Access granted this way is:

6. Cross-border transfer

WHOOP operates from the United States, and our database and application run in Singapore. Your data therefore leaves Thailand. Where personal data is transferred abroad we rely on your explicit consent under section 28 of the PDPA, and we require appropriate contractual safeguards from the providers involved.

7. How we protect it

No system can be guaranteed perfectly secure. We work to protect your data using measures appropriate to its sensitivity, but we cannot promise absolute security.

8. How long we keep it

DataRetention
WHOOP metrics (recovery, sleep, strain, workouts) For the duration of your program, then 12 months, after which they are deleted or irreversibly anonymized
WHOOP OAuth tokens Deleted immediately when you disconnect or withdraw consent
Audit logs 24 months, for security and compliance
Server logs 90 days
Lab report PDFs and extracted results (planned) Draft, pending confirmation: the same schedule as WHOOP metrics above — for the duration of your program, then 12 months, after which they are deleted or irreversibly anonymized
Sleep detail — stages, disturbances, cycles, efficiency, consistency, respiratory rate, sleep-need, nap flag, bed/wake times (planned) Draft, pending confirmation: the same schedule as WHOOP metrics above — for the duration of your program, then 12 months, after which they are deleted or irreversibly anonymized
Workouts — sport, times, strain, heart rate, calories, distance, altitude, heart-rate zone durations (planned) Draft, pending confirmation: the same schedule as WHOOP metrics above — for the duration of your program, then 12 months, after which they are deleted or irreversibly anonymized
Body measurement — height, weight, maximum heart rate (planned, new scope) Draft, pending confirmation: kept only while you are enrolled in a program; deleted, along with the rest of your guest record, when you are no longer enrolled — not the 12-month tail that applies to the WHOOP metrics rows above

9. Disconnecting and your rights

Disconnecting WHOOP

You can stop sharing at any time, using either route — both work on their own:

  1. Ask your care team to use Disconnect on your record in the Vela Health dashboard; or
  2. Revoke Vela Health's access directly from your WHOOP account settings.

What happens when you disconnect: we stop receiving new WHOOP data immediately, delete the stored OAuth tokens, and stop displaying your metrics to staff. If you also want your historical metrics erased, email us and we will delete them.

Your rights under the PDPA

Subject to the Act's conditions, you may:

To exercise any of these, email Laguna@phuketmedicalclinic.com, or speak to reception at the clinic. We respond within 30 days. Withdrawing consent may mean your care team can no longer monitor your recovery data as part of your program.

10. Children

Vela Health is not intended for individuals under 18. Where a guest is a minor, we obtain consent from a parent or legal guardian as required by the PDPA. If we learn that we hold a minor's data without proper consent, we delete it.

11. Cookies

The dashboard uses a strictly necessary session cookie so clinic staff can stay signed in. We do not use advertising cookies or third-party analytics trackers.

12. Changes to this policy

We will post any updates on this page with a revised "Last updated" date. If a change materially affects how we handle WHOOP data, we will notify affected guests and, where the law requires it, ask for consent again.

13. Contact us

Questions, requests, or complaints about privacy:
Phuket Medical Clinic (Bangtao) Co., Ltd.
58/1 Cherngtalay, Thalang, Phuket 83110, Thailand
Laguna@phuketmedicalclinic.com · +66 96 236 2449