Insights kept.
Transcripts deleted.
Once insights are confirmed, the raw notes and transcript are permanently deleted. It protects you, it protects them, it protects us.
Somebody in your organisation has already pasted a 1:1 transcript into ChatGPT
Teams or Google Meet weren't built to record or store sensitive workplace conversations, they’re just the easiest tools to use. Record a 1:1 there, and it becomes a real data risk with no plan behind it: nothing for when someone leaves, nothing if you're breached, nothing if you're audited. Pasting it into ChatGPT for a quick summary is already happening across most organisations. The tools are convenient, but nobody built any governance around what happens to sensitive conversation data once it lands there.
Built to reduce your risk and protect you
Our logic is simple, the safest data is the data that no longer exists. Nothing left behind means nothing left to lose in a breach, nothing left to hand over in an audit, and nothing left for someone to misuse months later. Once insights are saved, the transcript or notes in which they came from are deleted. All this happens within a system purpose-built platform that’s encrypted throughout and hosted on Amazon Web Services (AWS).
Platform security and privacy
-
The platform runs on Amazon Web Services (AWS), the same cloud infrastructure used by organisations across banking, healthcare and government, chosen for resilience and high availability. Every piece of traffic, and every file at rest, including backups, is encrypted end-to-end. Access follows a least-privilege model, so the number of people who can reach any given piece of data is kept as small as the job actually requires. If a breach ever did happen, HeyPenny is committed to notifying affected parties and the relevant authorities within 72 hours.
-
HeyPenny’s AI Agent is designed to strip personally identifiable information, names, personal health conditions, anything that could identify someone, and converts every reference to a neutral they/them pronoun. If a leader loads a manual observation instead, a second, independent technical control catches any name that slips through. The final backstop is human: leaders and org admins can review and edit any saved insight before it's used. Three separate layers, each catching what the one before might miss.
-
What gets retained is a short insight, a summary of how a psychosocial factor, like workload or autonomy, is showing up in someone's experience of work. No personal health information is tracked, only how a work-related factor is affecting the person. The transcript itself is deleted once the insights are confirmed, so the summary is what remains, not the conversation it came from.
-
A leader can see who said what, but only for their own team. Once that data aggregates up to an organisation-wide dashboard, individual attribution disappears entirely, an org admin sees the pattern, never who it came from. Dashboards also won't display anything until a minimum number of responses is met, so a small team's data can't be reverse-engineered back to one person just because there's nowhere else for it to hide.
New Zealand Privacy Act
-
Data is hosted on AWS servers in New Zealand and Australia only, never sent further offshore. Both jurisdictions carry strong privacy protections of their own, which is exactly what the Act's cross-border principle asks for, information only goes somewhere that protects it to a comparable standard.
-
Every employee can see their own profile information and insights directly, through their own login, at any time, not by submitting a request and waiting to hear back. They can comment on an insight or ask for a change whenever they want, and edit their own profile freely. If a leader ever adjusts an insight themselves, the employee is notified, so nothing about their own record changes without them knowing.
-
Before anyone's first conversation is ever recorded, they've already been told, more than once, in more than one way. They accept the terms at first sign-in. Both HeyPenny and their own organisation send them information on what the platform is, why it's being used, and how privacy and security work, and HeyPenny's customer success team follows up directly. Then, in the first 1:1 itself, the leader walks them through it again in person and confirms they're genuinely comfortable before anything begins.
Health Information Privacy Code 2020
The Health Information Privacy Code 2020 covers health information, information collected about an identifiable person's health or disability, in the course of providing them a health service. HeyPenny's data doesn't meet that bar, for three reasons. It's collected through a workplace conversation, not a clinical one. It's about someone's experience of work, not a diagnosis or treatment. And it's never linked to, or stored anywhere near, a clinical or patient record.
On top of that, the AI Agent that writes each insight is trained to leave out any personal health information that comes up in conversation. It's a hard control, built into how insights are generated, so that information never makes it into what gets saved.
"HeyPenny's AI Agent adds another pair of digital eyes, ears and neurons that ensure nothing is missed."
Alsu Sworder, Litmaps
