素材輪播

Protecting personal data

is of paramount importance to us and we ensure safety and security at every step of the way.

Summary

Withings Security Insurance Plan relates exclusively to Withings' activities with professionals. Please refer to our privacy policy for information on security measures designed to secure individual user data.

Data security

Withings is committed to maintaining a secure environment that enables you to use our products and services. We protect your personal data through compliance with multiple standards (ISO 27001:2022, ISO 27701:2019 & HDS).

Certifications & Standards

To factor data privacy into our products and services, we strive for the highest standards of personal data protection.

HDS

Health Data Hosting — version 1.1 final - May 2018 for activities 1 to 6 in accordance with the certification reference system provided by ASIP Santé.

Includes all systems, people and processes involved in the design, development, operations, validation and support of applications and services hosted by Withings which include the processing or disclosure of personal health data.

The certification referential includes: NF ISO/IEC 27001:2017, ISO/IEC 27018:2014, NF ISO/IEC 20000-1:2011, as well as additional requirements.

In accordance with the HDS reference system, you can consult the table of representations of guarantees concerning our activities as a subcontractor via this link.

Download certificate

ISO 27001:2022

Withings provides the service of a hosting provider in accordance with the requirements of the International Organization for Standardization 27001:2022 standards.

It includes all systems, people and processes involved in the design, development, operations, validation and support of applications and services hosted by Withings and especially the processing of personal health data.

In accordance with the HDS reference system, you can consult the table of representations of guarantees concerning our activities as a subcontractor via this link.

Download certificate

ISO 27701:2019

Withings demonstrates its capacity to follow the state of the art in terms of Privacy protection worldwide (such as GDPR). In order to do so, internal processes are continuously audited to ensure that Privacy protection is taken into account at each step of activities (internal or external) conducted by Withings.

Download certificate

Services & applications security

We deliver, maintain and manage data protection across our applications,services and products at all stages of their lifecycle.

Framework security controls

Withings relies on modern security control techniques to limit exposure to the top 10 OWASP security risks. These inherent controls reduce our exposure to SQL Injection (SQLi), Cross Site Scripting (XSS), and Cross Site Request Forgery (CSRF), among others.

Agile organization, code review and testing

All development activities are organized using the AGILE method, with the establishment of sprints and prioritization of tasks with the Product Management team. All sprints are historized. Developers will perform unit tests, functional integration tests, and security tests. Features are reviewed by the Security team and are evaluated through peer reviews before deployment.

Software Quality Assurance

The Software Quality Assurance department tests services and applications before moving on to production (manual and automatic tests).

Environments separations and test data

The development and test environments are logically separated from the production environment. No personal production data is used in our development or test environments.

Infrastructure protection

Since protection of data is part of how we take care of our users, we call upon the best security solutions to protect personal data.

Physical facilities

For B2C activities and B2B activities in Europe, Withings hosts its servers thanks to BSO in data centers located in France. To ensure 24/7 operation and constant availability of services, BSO data centers are equipped with redundant power systems and are subject to environmental controls.

For B2B activities in the US, Withings hosts its servers thanks to GCP in data centers located in the US. To ensure 24/7 operation and constant availability of services, Google data centers are equipped with redundant power systems and are subject to environmental controls.

On site security

BSO’s and GCP data centers are designed with a multi-layered security model that includes custom-designed electronic access cards, alarms, vehicle access control barriers, security fencing, metal detectors, and biometric technologies. Each data center is also equipped with a laser beam intrusion detection system. The data centers are monitored 24 hours a day, 7 days a week using high-resolution indoor and outdoor cameras that can detect and track intruders.

Location of data hosting

Upon request, the client may request to regionalize the processing of its data to an available location of MED·PRO services. Withings respects the client's choice and informs clients if one or more services are not regionalizable.

HR Security

The limited staff that handles data in the Withings Cloud is subject to regular vetting and continuous training on how to mitigate the risks involved in processing personal data. -

Background and competency checks

Withings conducts background checks on all new employees in accordance with local laws. These checks are also performed for contractors. Background checks may include technical and general skills, previous employment, and criminal record checks if required.

Confidentiality agreement

All employees must sign non-disclosure and confidentiality agreements. This confidentiality agreement remains valid after the end of the employment contract.

Role and responsibilities definition

Withings ensures that all roles and responsibilities are well defined and understood by the individuals to which they are assigned.

Disciplinary procedure

Withings has put disciplinary procedures in place in the event of a breach of entrusted responsibilities, based on a scale of sanctions defined in the internal regulations.

Continuous improvement

As an innovative IoT company, we make sure that we are always one step ahead of current data protection standards. This is supported by regular internal and external audits.

Internal audit plan

All processes are audited by internal audit teams or by external service providers.

Management review

Management reviews ensure that the management systematically reviews ISMS, assesses opportunities for improvement, and decides on the measures necessary to ensure the relevance, adequacy, and effectiveness of ISMS.