Privacy Policy
Last updated: 7 June 2026 · Effective date: 7 June 2026
1. Introduction
VaultAir Systems (Pty) Ltd ("VaultAir", "we", "us", or "our") operates Jan on Health ("JoH"), a digital health and wellbeing companion available at https://janonhealth.com and through WhatsApp.
This Privacy Policy explains how we collect, use, store, share, and protect personal information when you:
- visit our Website;
- use JoH on WhatsApp or related channels;
- subscribe to our articles or newsletters;
- contact us; or
- interact with us in any other way.
We are committed to protecting your privacy and handling your information responsibly. This Policy is designed to comply with:
- the Protection of Personal Information Act, 2013 (POPIA) in South Africa;
- the General Data Protection Regulation (GDPR) in the European Union and European Economic Area;
- the UK GDPR and Data Protection Act 2018;
- United States privacy laws, including principles aligned with the Health Insurance Portability and Accountability Act (HIPAA) where applicable; and
- other applicable data protection laws in countries where we operate.
Please read this Policy together with our Terms of Service.
2. Who Is Responsible for Your Data?
Data controller / responsible party:
VaultAir Systems (Pty) Ltd
Company registration number: 2025/540482/07
Registered address: Stellenbosch, 7600, Western Cape, Republic of South Africa
Email: privacy@vaultair.systems
Website: https://janonhealth.com
Information Officer (POPIA):
Jan Pool
Email: privacy@vaultair.systems
Subject line: Information Officer
You may contact the Information Officer at the address above for any matter relating to the processing of your personal information. (POPIA requires responsible parties to register their Information Officer with the Information Regulator of South Africa.)
EU/UK representative (GDPR Article 27 / UK GDPR):
VaultAir does not currently maintain an establishment in the European Economic Area or United Kingdom. If you are in the EEA or UK, contact our Information Officer at privacy@vaultair.systems with the subject line EU/UK Privacy. Where applicable law requires us to appoint an EU or UK representative under Article 27, we will appoint one and publish their contact details on this page.
3. Important Notice About Health Information
JoH is a wellbeing companion, not a healthcare provider. We are not a HIPAA covered entity and not a business associate under HIPAA unless we enter into a separate written agreement stating otherwise.
However, because you may share health-related information with JoH, we treat that data as special category personal data under GDPR and special personal information under POPIA. We apply enhanced safeguards and require your explicit consent before processing this data for the Service.
Do not use JoH for medical emergencies. Call your local emergency number.
4. What Information We Collect
We collect information you provide directly, information generated through your use of the Service, and limited technical information.
4.1 Information you provide
| Category | Examples | Purpose |
|---|---|---|
| Contact details | WhatsApp phone number, name, email (if provided) | Account setup, communication, support |
| Conversation content | Text messages, captions, voice notes, images, videos, documents, locations | Provide and personalise the Service |
| Health and wellbeing information | Symptoms you mention, conditions, medications, fitness goals, dietary preferences, habits, mental wellbeing topics | Personalise guidance and maintain context |
| Language preference | Preferred language for responses | Deliver the Service in your language |
| Consent records | Acceptance or rejection of Terms and Privacy Policy, timestamp | Legal compliance and audit |
| Support requests | Messages asking to speak to a person, bug reports, product feedback | Customer support and product improvement |
| Payment-related information | Subscription tier, billing status, transaction references | Manage subscriptions (payment card details are handled by Paystack, not stored by us) |
| Website forms | Contact form submissions, newsletter sign-ups | Respond to enquiries, send updates |
4.2 Information collected automatically
| Category | Examples | Purpose |
|---|---|---|
| Usage and technical data | Message timestamps, delivery status, device/browser type (Website), IP address (Website), API logs | Operate, secure, and improve the Platform |
| Derived profile data | Facts, goals, and short-term context extracted from conversations | Personalise responses |
| Observability data | Error logs, performance traces (via Pydantic Logfire) | Monitor reliability and fix issues |
4.3 WhatsApp and Meta
When you use JoH on WhatsApp, Meta Platforms, Inc. processes your messages and metadata under WhatsApp's own privacy policy. We receive message content and related data through the WhatsApp Business Platform to provide the Service.
4.4 Website cookies
Our Website may use cookies and similar technologies. See Section 12 (Cookies) below.
5. How We Use Your Information
We use personal information only for lawful purposes, including to:
- provide, operate, and maintain JoH;
- personalise your experience using conversation history, facts, goals, and short-term context;
- generate AI-powered responses and safety checks;
- detect language and translate messages where supported;
- manage subscriptions, trials, and billing;
- record and verify your consent;
- respond to support requests and escalation to human staff;
- send service messages (for example, trial expiry or payment reminders);
- monitor, debug, and improve the Platform;
- detect abuse, fraud, and security incidents;
- comply with legal obligations; and
- enforce our Terms of Service.
We do not sell your personal information.
We do not use your health information for third-party advertising.
5.1 Direct marketing
We send newsletters and other marketing communications only where you have opted in, or where otherwise permitted by applicable law (including section 69 of POPIA). Every marketing message includes a simple way to opt out, and you can unsubscribe at any time using the unsubscribe link or by emailing support@vaultair.systems.
Service messages (for example, consent confirmations, trial-expiry notices, payment reminders, and security notices) are not marketing. They are necessary to provide the Service and to comply with our legal obligations, and you cannot opt out of them while you use the Service.
6. Legal Bases for Processing
Depending on your location and the type of data, we rely on one or more of the following legal bases:
| Legal basis | When it applies |
|---|---|
| Consent | Health-related information, marketing communications (where required), and WhatsApp onboarding |
| Contract | Providing the Service you request, including subscriptions |
| Legitimate interests | Security, fraud prevention, service improvement, and internal analytics (balanced against your rights) |
| Legal obligation | Tax, accounting, regulatory, and law enforcement requests |
For special category / sensitive data (including health information), we rely primarily on your explicit consent under GDPR Article 9 and equivalent provisions under POPIA.
You may withdraw consent at any time (see Section 10). Withdrawal does not affect processing already performed and may mean we can no longer provide the Service.
7. Artificial Intelligence and Automated Processing
JoH uses automated processing, including AI models (currently from OpenAI), to:
- classify and understand your messages;
- extract facts, goals, and short-term context;
- generate responses;
- validate content for safety;
- detect language and translate text; and
- suggest follow-up questions.
No solely automated decision is made that produces legal or similarly significant effects on you (such as credit, employment, or insurance decisions). AI outputs are informational only and are not professional medical advice.
Training of AI models. Our AI subprocessors process your messages only to generate responses and safety checks for you. We use these providers under their business/API terms, and we do not permit your conversations or health information to be used to train third-party AI models, except where we tell you clearly in advance and obtain any consent required by law.
Prompts and responses may be logged for quality, safety, debugging, and compliance. We apply access controls and retention limits to these logs.
8. How We Protect Your Information
We implement appropriate technical and organisational measures, including:
- De-identification: WhatsApp phone numbers are mapped to internal user identifiers (UUIDs) so phone numbers are not stored directly in core user and conversation tables;
- Encryption in transit: HTTPS/TLS for data in motion;
- Encryption at rest: Database and infrastructure encryption where supported by our cloud provider;
- Access controls: Role-based access, API keys, and authentication for internal systems;
- Webhook security: Signature verification for WhatsApp webhooks;
- Caching limits: Recent conversation data in Redis cache with time-limited retention (for example, approximately 4 hours for active sessions);
- Automatic expiry: Short-term health context (episodes) expires automatically, typically within 1–90 days depending on context;
- Audit trails: Consent records and operational logs for accountability;
- Safety validation: Automated checks on AI-generated responses; and
- Vendor assessment: Due diligence on subprocessors that handle personal data.
No system is completely secure. Please use strong device security and avoid sharing information you are not comfortable storing digitally.
9. Data Retention
We retain personal information only as long as necessary for the purposes described in this Policy, unless a longer period is required by law.
| Data type | Typical retention |
|---|---|
| Account and profile data | While your account is active, plus a reasonable period after deletion for backup and legal purposes |
| Conversation history | While your account is active; deletable on request |
| User facts and goals | While relevant and your account is active |
| Short-term episodes | Until automatic expiry (typically 1–90 days) or deletion |
| Consent records | For the duration of the relationship and as required for legal and audit purposes |
| Billing records | As required by tax and accounting law (typically 5–7 years) |
| Cache data (Redis) | Short-term (for example, hours) for active sessions |
| Logs and observability data | Limited retention for troubleshooting and security |
When data is no longer needed, we delete or anonymise it in accordance with our retention schedule.
10. Your Rights
Depending on where you live, you may have the following rights regarding your personal information:
| Right | Description |
|---|---|
| Access | Request a copy of personal information we hold about you |
| Rectification | Correct inaccurate or incomplete information |
| Erasure | Request deletion ("right to be forgotten") |
| Restriction | Ask us to limit processing in certain circumstances |
| Portability | Receive your data in a structured, machine-readable format (where applicable) |
| Objection | Object to processing based on legitimate interests |
| Withdraw consent | Withdraw consent at any time where processing is consent-based |
| Complaint | Lodge a complaint with a supervisory authority |
10.1 How to exercise your rights
Email us at privacy@vaultair.systems with the subject line "Privacy Request". We may need to verify your identity (for example, by confirming your WhatsApp number).
We aim to respond within 30 days (or sooner where required by law, such as one month under GDPR).
10.2 South Africa (POPIA)
You may request access to, correction of, or deletion of personal information, and object to processing where POPIA allows. You may also complain to the Information Regulator (South Africa) at https://inforegulator.org.za.
10.3 European Union / UK (GDPR)
You have the rights listed above and may contact your local data protection authority. For EU users, authorities are listed at https://edpb.europa.eu. For UK users, contact the ICO at https://ico.org.uk.
10.4 United States
Residents of certain US states (including California, Virginia, Colorado, and others) may have additional rights such as knowing what personal information is collected, requesting deletion, and opting out of certain processing. We do not sell personal information.
While we are not a HIPAA covered entity, we apply administrative, technical, and physical safeguards appropriate to the sensitivity of health-related information you choose to share.
11. Sharing and Subprocessors
We share personal information only as described below. All subprocessors are bound by contractual obligations to protect your data.
| Recipient | Role | Location |
|---|---|---|
| Meta / WhatsApp | Messaging platform and delivery | Global |
| OpenAI | AI model processing (response generation, safety, language) | United States and other regions |
| Amazon Web Services (AWS) | Cloud hosting, database (PostgreSQL), cache (Redis), and transactional email (Amazon SES) | Primarily eu-west-1 (Ireland) and related AWS regions |
| Paystack | Payment processing | Africa / applicable payment regions |
| Pydantic Logfire | Observability, logging, and error monitoring | European Union (Logfire EU region) |
| Google (Google Ireland Limited / Google LLC) | Website analytics (Google Analytics 4), loaded only with your consent | EU and United States |
| Substack | Newsletter / article subscription delivery (if you subscribe) | United States |
| Professional advisers | Legal, accounting, or compliance (when needed) | Various |
| Law enforcement / regulators | When required by valid legal process | As applicable |
We may also share information in connection with a merger, acquisition, or sale of assets, with notice where required by law.
A current list of subprocessors is available on request at privacy@vaultair.systems.
12. International Data Transfers
VaultAir is based in South Africa. Your information may be processed in South Africa, the European Union, the United States, and other countries where our subprocessors operate.
Where personal data is transferred from the EEA, UK, or other jurisdictions requiring safeguards, we rely on appropriate mechanisms such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- UK International Data Transfer Agreement or Addendum where applicable;
- Adequacy decisions where available; and
- Your explicit consent where required.
You may request a copy of applicable transfer safeguards by contacting us.
13. Cookies and Website Analytics
When you visit our Website, we and our service providers may use cookies, local storage, and similar technologies as follows:
| Tool / type | Category | Purpose | Provider |
|---|---|---|---|
| Session and security cookies | Essential | Required for the Website to function (for example, security and basic operation) | First-party (Jan on Health) |
Cookie consent preferences (localStorage) | Essential | Remembers your cookie choices so we do not ask again on every visit | First-party (Jan on Health) |
| Google Analytics 4 (GA4) | Analytics (consent required) | Page views, approximate location, device/browser type, and how visitors use the Website | Google Ireland Limited / Google LLC (Google Privacy Policy) |
GA4 is loaded only after you accept Analytics cookies in our cookie consent banner. You can change your preferences at any time by clearing site data in your browser or revisiting the banner after clearing cookie-consent-preferences from local storage.
You can also manage cookies through your browser settings. Disabling essential cookies or storage may affect Website functionality.
This section applies to the Website only. The WhatsApp Service does not use browser cookies.
14. Children's Privacy
JoH is intended for users aged 18 and over. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it promptly.
15. Data Breach Notification
If a personal data breach (a "security compromise" under POPIA) is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and affected users as required by POPIA, GDPR, UK GDPR, and other applicable laws. Where GDPR/UK GDPR applies, we aim to notify the competent authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Under POPIA, we notify the Information Regulator and affected data subjects as soon as reasonably possible after discovery.
16. Third-Party Links
Our Website may link to third-party sites (for example, Substack, Instagram, Facebook, or payment pages). We are not responsible for the privacy practices of those sites. Review their privacy policies before providing personal information.
17. Changes to This Policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date and, where changes are material, notify you through the Website, WhatsApp, or email.
If changes require renewed consent under applicable law (for example, for health data processing), we will ask for your consent before applying the changes to the Service.
18. Contact Us
For privacy questions, rights requests, or complaints:
VaultAir Systems (Pty) Ltd
Company registration number: 2025/540482/07
Registered address: Stellenbosch, 7600, Western Cape, Republic of South Africa
Information Officer: Jan Pool
Email: privacy@vaultair.systems
Subject line: Privacy Request or Information Officer
Website: Contact us
This Privacy Policy should be read together with our Terms of Service.