← Back to Policies

Privacy Policy

How we collect, use, and protect your personal information

Policy Information

Last Updated: [INSERT DATE]

Version: 1.0

Effective From: [INSERT DATE]

1. Introduction

Welcome to clear minds. We are committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our workplace mental health and wellness support services.

ClearMinds Ltd is the data controller for the personal information we collect and process. We are registered with the Information Commissioner's Office (ICO) under registration number: [INSERT ICO REGISTRATION NUMBER].

Your Privacy Matters

We understand that you're trusting us with sensitive personal information, including health data. We take this responsibility seriously and are committed to maintaining the highest standards of data protection and confidentiality.

2. Information We Collect

2.1 Information You Provide Directly

When you use our services, we collect:

2.2 Information We Collect Automatically

When you use our website or app, we may automatically collect:

3. How We Use Your Information

We use your personal information for the following purposes:

3.1 Providing Our Services

3.2 Improving Our Services

3.3 Reporting to Corporate Clients

3.4 Legal and Regulatory Requirements

⚠️ Important: Confidentiality with Your Employer
Your employer will NOT receive any information about your individual sessions, the concerns you discuss, or any identifiable information without your explicit consent. We only provide aggregated, anonymised statistics about overall service usage to help employers understand service utilization.

4. Legal Basis for Processing

Under UK GDPR, we process your personal data under the following legal bases:

4.1 For Standard Personal Data

4.2 For Health Data (Special Category Data)

5. Who We Share Your Information With

We only share your personal information when necessary and with appropriate safeguards:

5.1 Our Clinical Team

5.2 Service Providers (Data Processors)

We work with trusted third-party service providers who process data on our behalf under strict contractual obligations:

All service providers are required to maintain the same high standards of data protection and confidentiality.

5.3 Your Employer (Corporate Clients)

5.4 Healthcare Professionals

5.5 Legal and Regulatory Authorities

We may share information when legally required:

6. International Data Transfers

We prioritize UK-based data storage and processing. Your data is primarily stored on servers located in the United Kingdom.

In limited circumstances, we may use service providers that process data outside the UK (e.g., Google Analytics). When this occurs, we ensure:

7. How Long We Keep Your Information

We retain your personal data only as long as necessary for the purposes outlined in this policy:

Data Type Retention Period
Clinical records (adults) 8 years from your last contact with us
Clinical records (children/young people under 18) Until your 25th birthday OR 8 years from last contact (whichever is longer)
Account information Duration of your use of services + 2 years
Communication records (emails, calls) Duration of services + 2 years
Website usage data (cookies, logs) 26 months

After these periods, we securely delete or anonymise your information in accordance with our Data Retention Policy.

8. Your Rights

Under UK GDPR, you have the following rights regarding your personal data:

8.1 Right of Access

You can request a copy of the personal data we hold about you. We will provide this free of charge within one month.

8.2 Right to Rectification

You can ask us to correct any inaccurate or incomplete personal data.

8.3 Right to Erasure ('Right to be Forgotten')

You can request deletion of your personal data in certain circumstances. Note: We may need to retain some data for legal or regulatory reasons (e.g., clinical records).

8.4 Right to Restrict Processing

You can ask us to limit how we use your data in certain situations.

8.5 Right to Data Portability

You can request your data in a machine-readable format to transfer to another provider.

8.6 Right to Object

You can object to processing based on legitimate interests or for direct marketing.

8.7 Right to Withdraw Consent

Where we process your data based on consent, you can withdraw it at any time.

8.8 Rights Related to Automated Decision-Making

You have rights regarding automated decisions. Currently, we do not use fully automated decision-making that affects you.

How to Exercise Your Rights

To exercise any of these rights, please contact our Data Protection Officer:

Email: dpo@clearmindseap.com

Phone: [DPO PHONE NUMBER]

Post: Data Protection Officer, ClearMinds Ltd, [INSERT ADDRESS]

We will respond within one month of receiving your request.

9. How We Protect Your Information

We implement robust technical and organisational security measures to protect your personal data:

9.1 Technical Security

9.2 Organisational Security

10. Cookies and Website Tracking

Our website uses cookies to improve your experience. Cookies are small text files stored on your device.

10.1 Types of Cookies We Use

For detailed information, please see our Cookie Policy.

10.2 Managing Cookies

You can control cookies through your browser settings. Note that disabling some cookies may affect website functionality.

11. Children's Privacy

We provide services to young people aged 13 and over. For children under 16, we may seek parental consent depending on the circumstances and legal requirements.

Children's records are retained until their 25th birthday or 8 years from last contact (whichever is longer), in line with professional guidelines.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make significant changes, we will:

We encourage you to review this policy periodically.

13. Contact Us

If you have any questions, concerns, or complaints about this Privacy Policy or how we handle your personal data, please contact us:

Data Protection Officer

Email: dpo@clearmindseap.com

Phone: [DPO PHONE NUMBER]

Post: Data Protection Officer, ClearMinds Ltd, [INSERT ADDRESS]

14. Complaints

If you're not satisfied with how we've handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office (ICO)

Website: www.ico.org.uk

Phone: 0303 123 1113

Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

However, we encourage you to contact us first so we can try to resolve your concerns.

Your Trust is Important to Us

We're committed to protecting your privacy and personal data. If you have any questions or concerns, please don't hesitate to contact our Data Protection Officer. We're here to help.