| Data Category | Description |
|---|---|
| Identity Information | Full name, home address, date of birth, title |
| Contact Information | Email address, phone number |
| Communication Records | Details from any correspondence or interactions, including discussions with practitioners or clients, technical support inquiries, customer care requests, and any other information you provide |
| Platform Usage Data | Information on how you navigate and interact with the Platform (e.g., frequency of platform access, features used) |
| Health Records | Data you provide manually or automatically through the Platform, or information shared by your practitioner. This may include health history, prescription details, mood tracking, therapy progress responses, clinical questionnaire scores, and other relevant health insights |
| Practitioner Data | If you are a practitioner, this includes your identity, contact details, workplace, therapy specialization, and a securely stored (hashed) practitioner account password |
| Technical Information | Includes device type, unique device identifiers (e.g., IMEI, IDFA, IP, or MAC address), network data, operating system, browser, location, time zone, and other related details |
| User-Generated Image Data | Images or videos submitted via technical support channels while using the Platform, retained for troubleshooting and resolving customer issues |
| Marketing & Communication Preferences | Includes your marketing and communication preferences, as well as any feedback or reviews you provide |
| Purpose | Data Categories Used | Legal Basis |
|---|---|---|
| Product and services provisioning – Allow your practitioner to invite you to the Platform – Offer our Platform to you – Allow practitioners nominated by you to process your data – Apply proprietary technology to your Health Data | – Personal Identification Data – Contact Details – Communication Data – Platform Usage Data – Health Records – Practitioner Data – Technical Data – Support & Media Data | Explicit consent (for Health Data) Contractual Necessity Legal obligation Legitimate Interests to fulfil our obligations to you |
| IT operations and platform maintenance – To manage and secure the Platform, covering troubleshooting, incident management, testing, code maintenance, data analysis, reporting, customer care, and data hosting | – Personal Identification Data – Contact Details – Communication Data – Platform Usage Data – Health Records – Practitioner Data – Technical Data – Support & Media Files | Explicit consent (for Health Data) Contractual Necessity Legal obligation Legitimate Interests to fulfil our obligations to you |
| Research and development – Use anonymised data to improve our services to you and improve general quality of care, sharing data with other health services (e.g. NHS) or academic institutions | – Communication Data – Platform Usage Data – Health Records – Practitioner Data – Technical Data | Public Health Legitimate Interests to improve our offering |
| Marketing and Advertising – Promote our value proposition – Ask to rate us, leave us a review or take part in a survey – Use analytics to improve our Platform experience | – Personal Identification Data – Contact Details – Platform Usage Data – Marketing & Communication Preferences | Explicit content (opt-in) Legitimate Interests to promote our offering |
| Business Management – To manage our business activities, including maintaining financial and accounting records, performing audits and testing, and ensuring compliance with reporting and corporate governance obligations. – To inform you about any changes to our terms or this privacy notice | – Personal Identification Data – Contact Details – Communication Data – Platform Usage Data – Technical Data | Legal obligation Legitimate Interests to exercise our right, operate our business, and fulfil our obligations to you |
| Right to be Informed about Our Collection and Use of Personal Data | You have the right to be informed about the collection and use of your personal data. We ensure this by providing you with this Privacy Notice, which is regularly reviewed and updated to reflect our data processing activities. |
| Right to Access Your Personal Information | You have the right to request access to the personal information we hold about you, often called a ‘Data Subject Access Request.’ We will provide it free of charge and respond within one calendar month. Proof of identity may be required. |
| Right to Rectification of Your Personal Information | You can ask us to correct any inaccurate, incomplete, or outdated personal information we hold about you. |
| Right to Stop or Limit Our Processing of Your Data | You can object to the processing of your personal data, request its deletion if it’s held for too long, or request restrictions on how it’s processed in specific circumstances. |
| Right to Erasure | You have the right to request the erasure of your personal data, known as the ‘right to be forgotten,’ which applies only in certain situations. |
| Right to Data Portability | You have the right to receive your personal data in a structured, machine-readable format and request that it be transmitted to another data controller. |
| For More Information about Your Privacy Rights | The Information Commissioner’s Office (ICO) regulates data protection in the UK. You can visit their website for more information or to make a complaint about how we use your data. We hope you’ll raise any concerns with us first. |