We normally control information about therapist accounts, payments and use of our website. Therapists normally control information about their own clients, while we process that information on their behalf.
1. Who we are
Therapy Diary App is operated by [FULL LEGAL NAME], a sole trader trading as Therapy Diary App.
Our business address is [BUSINESS ADDRESS].
For privacy questions, contact: [PRIVACY EMAIL].
ICO registration number: [ICO REGISTRATION NUMBER OR “NOT APPLICABLE”] .
2. Scope and our privacy roles
This policy applies to:
- visitors to our public website;
- therapists who create or use an account;
- people who contact us for support or information;
- clients who use a therapist’s booking page or client portal; and
- other people whose information is processed through the service.
When we act as controller
We act as controller when we decide why and how personal information is used. This normally includes therapist account, billing, security, support and website information.
When we act as processor
A therapist normally decides why their clients’ information is collected and used. For that information, the therapist is normally the controller and we act as their processor.
Clients should contact their therapist first about information held within that therapist’s practice account. We will assist the therapist where reasonably required.
3. Information we collect
Therapist account information
- name;
- email address;
- practice name;
- account and authentication identifiers;
- subscription status;
- account creation and login information;
- availability and booking settings; and
- communications with our support service.
Billing information
Our payment provider may process payment-card details, billing address, transaction information, payment status and fraud prevention information.
We generally receive payment status, customer identifiers and limited transaction information rather than complete payment-card details.
Client and appointment information
Information entered by therapists or their clients may include:
- client name;
- email address;
- appointment dates and times;
- appointment duration;
- booking and cancellation information;
- client account and authentication identifiers;
- self-booking permissions; and
- other information entered into available fields.
Technical information
We may collect:
- IP address;
- browser and device type;
- operating system;
- login and security logs;
- error and diagnostic information;
- pages or features accessed; and
- approximate location derived from an IP address.
Public-page information
Information a therapist chooses to publish through a public availability page may be visible to anyone with access to that page.
4. Where information comes from
We may obtain information:
- directly from you when you create or use an account;
- from your therapist when they create a client record;
- from clients when they use self-booking or a client portal;
- automatically from devices, browsers and service logs; and
- from payment, email, hosting and security service providers.
5. How and why we use information
| Purpose | Information | Lawful basis |
|---|---|---|
| Creating and managing therapist accounts | Identity, contact, account and authentication information | Performance of a contract |
| Providing the service and its features | Account, settings, technical and usage information | Performance of a contract and legitimate interests |
| Processing subscriptions and payments | Billing identifiers, transaction and subscription information | Performance of a contract and legal obligations |
| Providing support and responding to enquiries | Contact information and communications | Performance of a contract and legitimate interests |
| Keeping the service secure | Login records, IP addresses, device, diagnostic and security information | Legitimate interests and legal obligations |
| Improving and troubleshooting the service | Usage, error, diagnostic and feedback information | Legitimate interests |
| Maintaining business and tax records | Account, billing and transaction information | Legal obligations |
| Sending service messages | Contact and account information | Performance of a contract |
| Sending optional marketing | Name, email address and marketing preferences | Consent or legitimate interests, where legally permitted |
| Establishing or defending legal claims | Relevant account, communication and usage information | Legitimate interests and legal obligations |
Our legitimate interests include operating a reliable business, protecting accounts, preventing misuse, providing support and improving the service. We consider whether those interests are overridden by the rights and interests of the people concerned.
Where we rely on consent, you may withdraw it at any time. This will not affect processing that took place before consent was withdrawn.
6. Information processed for therapists
When we host or otherwise process information about a therapist’s clients, we normally do so only under the therapist’s instructions and to provide the service.
The therapist is responsible for:
- deciding what client information is collected;
- identifying an appropriate lawful basis;
- providing clients with suitable privacy information;
- responding to privacy-rights requests;
- ensuring information is accurate and relevant; and
- deciding how long client information should be retained.
We may process limited client information for our own purposes where necessary to secure the service, prevent fraud, comply with law or establish and defend legal claims.
7. Health and other sensitive information
Information showing that a person has booked or attended an appointment with a therapist may reveal or imply information about their physical or mental health.
Health information is treated as special-category personal data under UK data-protection law and requires additional protection.
Therapists are responsible for identifying both:
- a lawful basis under Article 6 of the UK GDPR; and
- an applicable condition under Article 9 for special-category information.
Therapy Diary App does not ask users to enter unnecessary therapy notes or detailed clinical records into general appointment fields.
9. International transfers
Some service providers may process information outside the United Kingdom.
Where UK data-protection rules relating to international transfers apply, we will use a recognised transfer mechanism. This may include:
- a UK adequacy regulation;
- the UK International Data Transfer Agreement;
- the UK Addendum to approved standard contractual clauses;
- another legally permitted safeguard; or
- an applicable legal exception.
You may contact us for more information about the safeguards used for a particular provider.
10. How long we keep information
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, security and dispute-resolution requirements.
| Information | Proposed retention period |
|---|---|
| Active therapist account information | For the duration of the account |
| Closed therapist account information | [CHOOSE A PERIOD, FOR EXAMPLE 30 DAYS] before operational deletion, except where longer retention is required |
| Therapists’ client and appointment data | For the duration of the therapist’s account and [CHOOSE A DELETION PERIOD] after account closure |
| Backup copies | Removed through normal backup rotation within [BACKUP RETENTION PERIOD] |
| Payment and accounting records | For the period required by applicable tax and accounting law |
| Support communications | [SUPPORT RETENTION PERIOD] |
| Security logs | [SECURITY LOG RETENTION PERIOD] |
| Marketing preferences | Until you unsubscribe, plus a limited suppression record to respect your choice |
Information may be retained for longer where necessary to meet a legal obligation, investigate misuse, resolve a dispute or establish or defend a legal claim.
11. How we protect information
We use technical and organisational measures designed to protect information against unauthorised access, loss, alteration or disclosure.
These measures may include:
- access controls and authentication;
- encrypted network connections;
- restricted administrative access;
- security logging and monitoring;
- backups and recovery procedures;
- software updates and vulnerability management; and
- confidentiality obligations.
No internet-based service can guarantee absolute security. Users must keep their login details secure and notify us promptly of suspected unauthorised access.
12. Your data-protection rights
Depending on the circumstances, you may have the right to:
- request access to your personal information;
- ask for inaccurate information to be corrected;
- ask for information to be deleted;
- ask us to restrict how information is used;
- object to certain processing;
- receive certain information in a portable format;
- withdraw consent where processing relies on consent; and
- object to decisions based solely on automated processing where applicable.
These rights are not absolute and may not apply in every situation.
To exercise a right relating to your therapist’s records, contact the therapist first. To exercise a right relating to information we control, email [PRIVACY EMAIL].
We may need to confirm your identity before completing a request.
14. Children’s information
Therapist accounts are intended for people aged 18 or over.
A therapist may use the service to manage appointments involving a child where this is lawful and appropriate for their practice. The therapist is responsible for identifying the appropriate lawful basis, providing privacy information and obtaining any required authority from a parent, guardian or the child.
15. Changes to this policy
We may update this policy when our service, suppliers or legal obligations change.
The latest version will be published on this page with a revised “last updated” date. We will provide additional notice where a change materially affects how information is used.
16. Questions and complaints
Please contact us first so that we have an opportunity to address your concern.
You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data-protection matters.
Information Commissioner’s Office:
ico.org.uk/make-a-complaint