For organizations · What you never see
Privacy limits are baked into the product
Most workplace wellness data is thin because employees are answering an instrument their employer controls. With SPARKS, the organization never sees anyone’s answers. This confidentiality is built into every layer of our system so that the honest answer is also the safe one. Every action is confidential and private.
Here is precisely what an organization can see, what it can never see, and why that boundary is worth more to you than the data it withholds.
The boundary
Two columns, no exceptions
What your organization sees
- Aggregate patterns across cohorts of thirty people or more
- Your strain and sentiment measures against industry benchmarks
- Movement over time, including before and after an intervention
- Participation and adoption rates
- Cohort-level risk signals relevant to retention
- Delivery and effect of any custom content you push
What your organization never sees
- Any individual’s responses to any assessment
- Any individual’s assessment results
- Any individual’s journal entries or coaching activity
- Any identifying information to say who has or has not used the platform
- Any cohort small enough to identify a person by inference
- Anything that could be re-joined to an identity on request, at any price
Employers never see you. That promise is made to the individual on the SPARKS Trust and Security page. This page is the same promise, restated for the person signing the contract, because you need to be able to say it out loud to your workforce and have it be true.
How it is enforced
Design, not policy
A privacy promise that depends on people following a rule is a promise that will eventually be broken. These are structural.
-
Minimal signup
No last name is required. Users are encouraged to sign up with a masked email address. The system is built to hold as little identifying information as it can function with.
-
Responses are separated from identity
After analysis, assessment responses are disintermediated from the account that produced them. There is no intact record sitting behind an access control waiting for someone to be granted the wrong permission.
-
Scores return to the individual only
Results are visible to the person who took the assessment. They are not routed to a manager, an HR system, a school or a third party.
-
Organizations receive aggregates protected by k‑anonymity
A minimum cohort size of thirty is enforced before any group appears in reporting. Smaller groups are suppressed rather than rounded, because rounding a group of four still tells you about four people.
-
Encryption and access limited by design
Everything entered is encrypted, and access is limited by architecture rather than by policy alone. Individuals can review, download or delete their data.
Full detail on Trust and Security · Human Ethics Policy Statement
Why this helps you
Three commercial reasons to want the blindfold
Participation is the whole ballgame
Published research puts typical EAP utilization below 8%, with only 19% of employers reporting above 8%. Programs that require an employee to identify themselves to their employer get the participation you would expect. Privacy is not a concession here; it is the reason there is enough data to read.
You cannot mishandle what you never hold
An employer that holds individual mental health data carries a duty of care, a disclosure risk and a discovery risk. Aggregate-only reporting removes that category of exposure rather than managing it.
It survives the town hall
Whatever you roll out will be met with “who sees this?” You need an answer that holds up when a skeptical employee reads the documentation themselves. Minimum cohort thirty, results to the individual only, is that answer.
Straight answers
Questions administrators ask
| Question | Answer |
|---|---|
| Can we see results for one team of twelve? | No. The cohort minimum is thirty. The team can be reported inside a larger grouping, or not at all. |
| Can we find out whether a specific employee is using it? | No. Participation is reported as a rate across the population, never as a list. |
| Can we request individual data during an investigation or a legal matter? | No. The architecture separates responses from identity, so there is no individual record to produce. |
| Can we integrate it with our HRIS to enrich employee records? | No. Organizational reporting is aggregate and stays aggregate. Your own HRIS attrition data can be compared against the trend line at cohort level on your side. |
| What happens if an employee leaves? | Their SPARKS account belongs to them, not to the employer. They can continue as an individual user, and they can delete their data at any point. |
| Does this replace our EAP? | No. It works alongside it, and it gives you a measure of whether the EAP and the rest of your spend are doing anything. |
Next Step: Send this page to your privacy officer
We would rather answer the hard questions in the first meeting than the fifth.
Sources
- C. D. Brooks and J. Ling, “An Evaluation of the Utilization of Employee Assistance Programs,” Journal of Insurance Regulation, vol. 39, no. 8, NAIC, 2020.
- SPARKS, Trust and Security.
