Privacy Policy for e7D-Wellness Apps
enigma7 Pty Ltd & E7DOC PTY LTD
enigma7 Pty Ltd ("we," "us," or "our"), the legal rights owner of the e7D-Wellness apps, and E7DOC PTY LTD, our licensee and operator, are committed to protecting your privacy. We understand that as a Health Care Professional (HCP), your wellbeing is paramount, and trusting us with your data is a significant step toward reclaiming your edge. This Privacy Policy explains how we collect, use, and safeguard your information in our apps—MarisMetrics (for burnout prevention, resilience building, MarisGraph assessments, and biomarker tracking) and RechargeRX (for complementary wellness recharge practices). These apps are consumer wellness tools, not medical devices, and do not provide medical advice, diagnosis, or treatment. Always consult a qualified healthcare provider for health concerns.
We comply with the Australian Privacy Principles under the Privacy Act 1988 (Cth), the General Data Protection Regulation (GDPR) for EU users, and other applicable laws. If you’re in California, we comply with the CCPA. Our approach draws from best practices in digital health privacy, ensuring practical, empathetic protections for your data.
Introduction: Our Apps and Data Overview
MarisMetrics and RechargeRX empower HCPs like you to build resilience through self-paced tools, daily 18-minute practices, MarisGraph wellbeing scans (covering 8 pillars like Willpower, Thoughts, and Rest), and optional biomarker tracking (e.g., cortisol, Vitamin D). We collect data to personalise your experience, support your journey, and (with your consent) contribute anonymised insights to research, such as the C600 Melbourne University trial.
We only collect what's necessary to help you thrive. Your data is yours—we don't sell it, and we prioritise anonymisation where possible. By using our apps, you consent to this Policy. For details on our services, see our Terms of Service.
Data Collection
We collect the following types of data to deliver effective wellness support:
- Personal Information
- When you sign up or create a profile, we collect basic information such as your name, email address, date of birth (for age-based insights, optional), profession (e.g., nurse, doctor), country/region, and contact details. This helps tailor content and verify HCP status.
- Health and Wellness Data
- Through MarisGraph assessments, daily lessons/streaks, and self-reported inputs, we collect non-medical wellness info such as stress levels, self-harm indicators (flagged for support emails like YRNA – You Are Not Alone), concentration challenges, and habit tracking (e.g., hydration, rest). If you opt in, biomarker data (e.g., cortisol via integrated labs) is shared securely for personal insights.
- Usage and Device Data
- Automatically collected via app analytics: IP address, device type, OS, app interactions (e.g., streak progress), and timestamps. This improves app performance and personalisation.
- Sensitive Data
- We handle potentially sensitive info (e.g., trauma exposure responses) with extra care, using opt-in consents and anonymisation. No biometrics or AI-derived health diagnoses are involved—apps are wellness-focused only.
Data is collected via forms, assessments, and app usage. You control what you share; opt-ins are required for sensitive features like biomarker tracking or trial data sharing (e.g., anonymised for C600 study).
Use and Sharing of Data
We use your data to empower your resilience journey, not for profit beyond our services:
- Internal Use
- Personalise app content (e.g., suggest anchors based on MarisGraph scores), track progress (daily streaks/lessons), provide support (e.g., YRNA emails for red-flagged responses like stress/self-harm indicators), deliver relevant MG Exclusive Articles (personalised wellness resources triggered by your assessment responses), and unlock in-depth VIP Blogs (premium, member-only content for paid/discounted access users). These features are designed to give you tailored guidance and deeper insights into your wellbeing.
- Anonymised Research
- With explicit opt-in consent, we may anonymise and aggregate your data for research purposes (e.g., the C600 Melbourne University trial on HCP burnout). No identifiable information is shared without your separate, informed consent.
- Service Providers
- We share limited data with trusted partners (e.g., cloud hosts like AWS for storage, analytics tools like Metricool for app performance). All comply with our privacy standards via contracts (e.g., GDPR Data Processing Agreements).
- Legal Requirements
- We disclose if required by law (e.g., court order) or to protect safety (e.g., imminent harm risks, per ethical guidelines).
- No Sales or Third-Party Marketing
- We do not sell your data. Sharing is limited to what's necessary for app functionality—no ads or external marketing uses.
For trials like C600, data is anonymised before transfer to Melbourne University, with separate consents. We avoid FDA classification by not claiming medical efficacy—apps are for general wellness only.
User Rights
You have control over your data. Contact us at privacy@e7doc.com to exercise these rights (free, within 30 days unless complex):
- Access
- View your data and how we use it.
- Correction
- Update inaccurate info.
- Deletion
- Erase your account/data (subject to legal retention, e.g., for audits).
- Objection/Restriction
- Opt out of processing (e.g., stop emails) or restrict uses.
- Portability
- Receive your data in a structured format.
- Withdraw Consent
- Anytime for optional features (e.g., biomarker sharing)—won't affect prior lawful processing.
For GDPR users: Lodge complaints with your data authority (e.g., OAIC in Australia). We don't use automated decisions affecting legal rights.
Security Measures
Protecting your data is our priority. We use:
- Encryption (in-transit via TLS, at-rest via AES-256).
- Access controls (role-based, two-factor authentication).
- Regular audits and vulnerability scans.
- Secure servers in compliant regions (e.g., AWS Australia for AU users).
In the event of a breach, we'll notify you and the authorities promptly (within 72 hours for GDPR/APPs reportable incidents) and provide steps to mitigate harm.
Children's Privacy
Our apps are for adults 18+ (HCPs). We do not knowingly collect data from children under 13 (or 16 in some regions). If we discover such data, we'll delete it immediately. Parents: Contact us if you believe your child has provided info.
International Transfers
As an Australian company (enigma7 Pty Ltd, with E7DOC PTY LTD operations), we store data primarily in Australia. For global users or backups, data may be transferred to secure providers (e.g., EU- or AU-approved). We use Standard Contractual Clauses and adequacy decisions to ensure GDPR compliance, providing equivalent protections.
Changes to This Policy
We may update this Policy for legal/app changes. We'll notify you via app/email (30 days' advance for material changes). Continued use means acceptance—check back regularly.
Contact Information
Questions? Contact:
E7DOC PTY LTD (Operator)
Email: privacy@e7doc.com
Address: 212/3018 Surfers Paradise, Brisbane, QLD, Australia
For complaints: Australian Office of the Information Commissioner (oaic.gov.au) or your local authority.
Thank you for trusting us on your path to resilience. You're not alone—we're here to support your journey securely and empathetically.

