Skip to content
Data ProtectionBy design

Data Minimisation & Zero-PII Analytics

Desha.ai is built on data minimisation. Directly identifying information is segregated from health data, tokenised wherever possible, kept out of logs and analytics, and never used to train third-party models. We call this our Zero-PII principle: the analytics, monitoring and model layers operate on de-identified data.

Solicitar documentación Last reviewed June 2026
Centro de confianza de DESHA.AI

Zero-PII Storage

Data Minimisation & Zero-PII Analytics
Estado: By design
Jurisdicción: Platform-wide
Revisado: June 2026

De un vistazo

Principle
Collect the minimum; separate identity from health data
Analytics & logs
De-identified, no PII
Identifiers
Tokenised / pseudonymised
Model training
No identifiable patient data used

What “Zero-PII” means here

Some personal data is necessary to deliver care reminders and records, that data is processed under the consent and lawful bases described in our GDPR and HIPAA statements. “Zero-PII” describes the layers where identifying data is deliberately excluded: product analytics, operational logs, telemetry, and any model-improvement workflow operate on pseudonymised or aggregated data only.

How we minimise exposure

  • Identity data is stored separately from health data and linked by tokens, not by name.
  • Logs, metrics and crash reports are scrubbed of personal identifiers.
  • Analytics use pseudonymous IDs and aggregates; no raw PII leaves the secure data plane.
  • Retention is purpose-limited, with deletion on account closure and consent withdrawal.

AI & model use

Identifiable patient data is never used to train third-party foundation models. Where AI features process content to deliver the service, that happens inside our access-controlled environment, governed by consent and our processor terms.

Documentación disponible bajo petición

  • Data-minimisation & pseudonymisation overview
  • Logging / telemetry redaction summary
  • Data-retention schedule summary

Provided to qualified reviewers under a mutual NDA via contactus@desha.ai.

Esta página resume la posición de Desha.ai para revisiones de diligencia debida y no revela sistemas internos ni detalles sensibles para la seguridad. Es informativa y no constituye garantía ni asesoramiento jurídico. Para las condiciones contractuales, solicita nuestro DPA / BAA en contactus@desha.ai.