Privacy policy

Your body's data belongs to you. Full stop.

This page explains, in plain language, what SOMA collects, why, and the control you keep at every moment. We wrote it to be read, not skimmed. If anything here is unclear, write to us and a person will answer.

Effective date: [DATE] · Applies to: guests of SOMA partner properties and visitors to this site

The short version

What we collect, and what we deliberately don't

When you connect a wearable (such as an Apple Watch, Garmin, WHOOP or Oura device) through SOMA, we receive daily summary metrics from your device's official interface: sleep duration and quality, recovery or readiness scores, heart-rate variability, and activity load. If you choose to fill in a short preferences form, we also store what you share there, such as dietary preferences, allergies, and routine preferences.

We deliberately do not collect: continuous location tracking, message content, contacts, photos, payment details from your device, or raw sensor streams. Summaries are enough to serve you well; anything more would be appetite, not need.

Why we process it (the legal part, in human words)

Wellness data is "special category" data under the GDPR, the strictest tier there is, and we treat it accordingly. Our legal basis for processing it is your explicit consent (GDPR Articles 6(1)(a) and 9(2)(a)). That consent is specific, informed, freely given, and as easy to withdraw as it was to give. We do not make it a condition of your stay: guests who prefer not to connect receive the same warm hospitality.

Withdrawing consent: tap "Disconnect" in any SOMA message, or write to us. Data flow stops immediately, and you can ask us to erase what was already collected.

What your hotel actually sees

Your property's team never sees your raw numbers. They see simple, plain-language service cues, for example that a guest may appreciate a gentler morning, a recovery-focused option, or a later checkout. The precise metrics stay between you and SOMA. Preference information you explicitly provide for service reasons (such as an allergy) is shared with the relevant team, because that is exactly what it is for.

Who helps us process it

We work with a small number of carefully chosen processors: a device-data platform that provides the official connection to wearable brands, and cloud infrastructure that stores data encrypted in transit and at rest within the EU/EEA. Each is bound by a data-processing agreement. We list our current processors at [PROCESSORS PAGE / on request]. We do not, and will not, sell or rent personal data to anyone.

How long we keep it

Daily metrics are kept for the duration of your stay plus [90] days, then aggregated or deleted. If you opt in to a travelling wellness profile, your preference summary persists across stays until you delete it. Withdraw consent or request deletion, and we erase your personal data within 30 days, except where a law requires us to keep a specific record.

Your rights

Under the GDPR and similar laws, you can ask us at any time to: access a copy of your data, correct it, delete it, restrict or object to its processing, or hand it to you in a portable format. Write to privacy@soma.example and we will respond within 30 days. You also have the right to lodge a complaint with your data-protection authority, though we would rather you tell us first so we can fix it.

Changes to this policy

If we change this policy in any way that matters, we will tell connected guests directly before the change takes effect, not bury it in a changelog. The current version always lives at this address.

Talk to a human

Questions, requests, or concerns: privacy@soma.example. Data controller: [LEGAL ENTITY NAME], [ADDRESS].