The wellness platform procurement checklist, with TriageFit's answers

Before a company buys a wellness platform, HR, IT, legal and finance each put their own questions to the vendor. This checklist gathers those questions by who asks them and gives TriageFit's answer to each, along with the published page that commits to it in writing. The corporate terms, the data processing agreement, the data flows, the security page and the sub-processor list can all be read before anyone buys.

By TriageFit · Published

Every function that signs off a wellness platform arrives at procurement with its own questions. HR asks whether joining is voluntary and what people will be told, IT and security ask where the data sits and who can sign in, legal and the data protection officer ask who controls which data and what happens when the contract ends, and finance asks about the price, the invoice and the renewal. TriageFit answers all of them on published pages a buying team can read before it spends anything, and each answer here comes with the document that commits to it.

Questions HR asks

Is taking part voluntary?

Yes, and the corporate terms commit the company to keeping it that way. Accepting a seat can never be made a condition of anyone's employment, whether a person accepted or declined cannot be used in any decision about them, and the company agrees to tell people that joining is optional and what it will be able to see. The same clause rules out any attempt to work out who stands behind a group figure.

What does each person see before they accept?

The invitation arrives by email and opens a page that sets out the offer before anything is agreed. It tells the person that the company is funding the seat, so the membership costs them nothing while it runs, that the company can see they enrolled along with group numbers that are withheld for any group smaller than five, and that it can never see their training, check-ins, messages or anything about their health. The link works once, lapses after seven days and can only be accepted from an account under the invited address.

What if someone already pays for TriageFit?

If they take the seat, their own plan stops at the end of the period they have already paid for and nothing more is charged to them after that. The funded seat carries their membership from there, with their training, history and data exactly as they were.

What happens when someone leaves?

An organisation admin removes them from the People tab and the seat goes back into the pool for the next person, and anyone can also leave from their own settings. Their funded seat ends when they go, and they can start a subscription of their own whenever they like.

Questions IT and security ask

Where is the data held?

The application and the database both run in Frankfurt, uploaded files are stored under EU jurisdiction and error monitoring runs in Germany. Requests to the AI that coaches each member run in EU regions only, with a check that refuses to start one against any region outside the EU, and the sub-processor list shows where every provider on it runs.

How are the data and the accounts protected?

All traffic runs over TLS, the platform encrypts what it stores, and database backups are encrypted with a public key whose private half is held offline. Every route that reads member data checks who is signed in and whether that account is entitled to the specific record, so nobody reaches another person's data by changing an identifier, and when a member of staff reads a health record, a dedicated audit trail records who read what and when. Every admin account on the company side, billing admins included, has to use two-factor authentication with an authenticator app, and until it is enrolled the account reaches nothing beyond enrolment, its own settings and signing out. Card and bank details are entered with the payment provider and never rest on TriageFit's servers.

What does IT have to set up?

The organisation is set up in the browser in a minute or two, with no integration to configure. Invitations go out by email from the People tab, one at a time or from a CSV file, and the roster can be downloaded as a CSV whenever the company wants its own copy.

Who is the controller of which data?

TriageFit holds two roles, divided by the data. For the roster the company provides, it is the company's processor and acts on its instructions. That roster holds the work email of each invitee, the role the company gives them, whether it funds their seat and up to four optional labels in the company's own words, such as a department or a site. For everything a person does in their coaching, TriageFit is an independent controller in its own right, and the company does not receive any of it. The invitation form has no field for a name, a home address, a date of birth or a payroll number, so none of them can be entered.

How are sub-processors added?

The data processing agreement authorises the providers on the published sub-processor list, which shows what each one does and where it runs. Before a new provider processes roster data, or an existing one materially changes what it does, the list is updated and the company's billing contact is emailed far enough ahead to object. If an objection made on data protection grounds cannot be resolved, the company can end the agreement for the affected service, and TriageFit stays fully liable for the providers it uses. Where a provider processes roster data outside the European Economic Area, the agreement requires a valid transfer mechanism under Chapter V of the GDPR, such as an adequacy decision or standard contractual clauses, to be in place before that processing happens.

What are the breach and audit terms?

TriageFit notifies the company without undue delay after becoming aware of a breach affecting roster data, describing what happened, the likely consequences, the measures taken or proposed and a contact point, and adds to the notice as more becomes known. TriageFit provides the information needed to show compliance with Article 28 of the GDPR, starting with the procurement pack itself. Beyond the pack, the company or an auditor it appoints can carry out audits and inspections on 30 days' notice, at its own cost and in business hours, once in any twelve months unless a supervisory authority requires more or a breach has affected roster data in that period.

What happens at the end of the contract?

The company chooses in writing whether its roster data is deleted or returned, and if no choice arrives within 30 days it is deleted. Each person's own coaching data sits outside that choice, since TriageFit holds it as controller in its own right. The corporate terms are governed by Irish law.

How is health data handled?

Each person's health data is processed only with their explicit consent. The corporate terms record that the coaching is not medical care, and if safety screening leads TriageFit to adjust or pause someone's coaching, that stays between TriageFit and the person without the company being told.

Questions finance asks

What does a seat cost?

A seat is priced per person per year with VAT included, at €500 a seat for 10 to 24 seats, €450 a seat for 25 to 49 seats, €415 a seat for 50 to 99 seats and €375 for 100 or more, and every seat in a pack is charged at the band the pack's size falls in. Adding seats that carry a pack into a cheaper band reprices every seat in it from that invoice on, and a pack can be billed in euro, pounds or dollars, with the same bands in each.

What will the invoice show?

Each invoice shows the Irish VAT separately from the total, and a VAT number given at checkout is printed on it. A company established outside Ireland whose supply is reverse-charged can give its VAT number at checkout, or within 30 days of the invoice, and the invoice is reissued without the Irish VAT and that element refunded.

How is it paid and renewed?

The first twelve months are paid in full at checkout, by card, or by SEPA direct debit when the pack is billed in euro. A pack runs for twelve months and an email arrives about 30 days before it renews. Seats can be added from the portal at any time and are invoiced pro rata for the rest of the term, a reduction takes effect at renewal, a price change comes with 30 days' notice, and a failed payment leaves 14 days to put it right before the pack lapses.

Where each answer is written down

QuestionWhere it is answered
Voluntary participation and what the company may not doCorporate terms
Processor and controller roles, breaches, audits and exitData processing agreement
What the company provides and what comes back to itData flows
Encryption, sign-in and access controlSecurity
Every provider, what it does and where it runsSub-processors
Prices, what a seat includes and how to buy, on one printable pageThe one-sheet

Buying once the review is closed

A pack of 10 to 50 seats can be bought on the business page, where the organisation is set up in a minute or two and the portal link goes to the billing address by email. For a team larger than 50 seats, the enquiry form on the same page reaches a real person, who replies by email with a quote, volume pricing and the rollout steps.

What an employer can see goes further into the privacy side, and the corporate wellness programme covers what each person gets from a seat week to week.

Questions people ask

Can we read the contract documents before we buy?
Yes. The corporate terms, the data processing agreement, the data flows, the security page and the sub-processor list are all public, so legal, IT and the data protection officer can each review them in full before anyone commits to a pack. The one-sheet puts the prices, what a seat includes and how to buy on a single printable page for the rest of the buying team.
Can a billing admin see who has joined?
A billing admin sees the seat counts on the overview, meaning how many seats were bought, redeemed, held by open invitations and still free, along with the billing tab for invoices, VAT details and the payment method. The people list and the reports stay closed to that role, so finance can run the account without seeing who took a seat.
Does each person sign up with their work email?
The invitation goes to the work email the company provides, and it can only be accepted from an account under that same address. What the person then does in their coaching stays in their own account, and the company's view is the roster and group figures with at least five people behind each one.
Who at the company can open the workforce report?
Organisation admins can open the aggregate report, which a billing admin cannot. Every figure in it needs at least five contributors before it shows, and below that the report says why the number is missing. No role at the company can reach an individual member's logs, messages or health data by any route.

Read next