This page explains, in plain language, what SOMA collects, why, and the control you keep at every moment. We wrote it to be read, not skimmed. If anything here is unclear, write to us and a person will answer.
When you connect a wearable (such as an Apple Watch, Garmin, WHOOP or Oura device) through SOMA, we receive daily summary metrics from your device's official interface: sleep duration and quality, recovery or readiness scores, heart-rate variability, and activity load. If you choose to fill in a short preferences form, we also store what you share there, such as dietary preferences, allergies, and routine preferences.
We deliberately do not collect: continuous location tracking, message content, contacts, photos, payment details from your device, or raw sensor streams. Summaries are enough to serve you well; anything more would be appetite, not need.
Wellness data is "special category" data under the GDPR, the strictest tier there is, and we treat it accordingly. Our legal basis for processing it is your explicit consent (GDPR Articles 6(1)(a) and 9(2)(a)). That consent is specific, informed, freely given, and as easy to withdraw as it was to give. We do not make it a condition of your stay: guests who prefer not to connect receive the same warm hospitality.
Withdrawing consent: tap "Disconnect" in any SOMA message, or write to us. Data flow stops immediately, and you can ask us to erase what was already collected.
Your property's team never sees your raw numbers. They see simple, plain-language service cues, for example that a guest may appreciate a gentler morning, a recovery-focused option, or a later checkout. The precise metrics stay between you and SOMA. Preference information you explicitly provide for service reasons (such as an allergy) is shared with the relevant team, because that is exactly what it is for.
We work with a small number of carefully chosen processors: a device-data platform that provides the official connection to wearable brands, and cloud infrastructure that stores data encrypted in transit and at rest within the EU/EEA. Each is bound by a data-processing agreement. We list our current processors at [PROCESSORS PAGE / on request]. We do not, and will not, sell or rent personal data to anyone.
Daily metrics are kept for the duration of your stay plus [90] days, then aggregated or deleted. If you opt in to a travelling wellness profile, your preference summary persists across stays until you delete it. Withdraw consent or request deletion, and we erase your personal data within 30 days, except where a law requires us to keep a specific record.
Under the GDPR and similar laws, you can ask us at any time to: access a copy of your data, correct it, delete it, restrict or object to its processing, or hand it to you in a portable format. Write to privacy@soma.example and we will respond within 30 days. You also have the right to lodge a complaint with your data-protection authority, though we would rather you tell us first so we can fix it.
If we change this policy in any way that matters, we will tell connected guests directly before the change takes effect, not bury it in a changelog. The current version always lives at this address.
Questions, requests, or concerns: privacy@soma.example. Data controller: [LEGAL ENTITY NAME], [ADDRESS].