Privacy Notice
How Mindful Message uses personal data
Last updated: 7 June 2026
A MINDFUL MESSAGE LTD controls AMM-owned counselling, case, privacy, and compliance workflows unless approved SaaS terms or a DPA state otherwise. Contact the privacy team at support@amindfulmessage.info.
Registered office: 128 City Road, London, United Kingdom, EC1V 2NX.
What The Platform Does
The platform helps organisations fund and manage referrals, appointments, assessments, feedback, and counselling or support sessions. Verified professionals deliver assigned services through the platform unless a later signed operating model says A Mindful Message is itself the clinical provider.
The platform is not an emergency service, crisis line, prescribing service, or urgent triage route. If there is immediate danger, use local emergency, safeguarding, or crisis services first.
Health Data, Advertising, And Research
- We do not use health, counselling, referral, assessment, session, or case information for advertising, retargeting, or third-party marketing pixels.
- We do not sell, rent, or share health, counselling, referral, assessment, session, or case information for targeted advertising.
- Research, service improvement, and outcome reporting use aggregate or de-identified data unless a separate notice and lawful basis applies.
- Raw verification documents are kept only for the relevant retention period unless a legal, safeguarding, complaint, regulator, or contract hold applies.
Minors And Authority
Under-18 referrals require an authority or consent record before booking where required by law, contract, safeguarding policy, or the organisation's role. The product records the authority type, name, notes, and date so the decision is not handled only in email or a manual checklist.
Data Visibility And Roles
| Role | Default access |
|---|---|
| Assigned verified professional | Referral, appointment, assessment, feedback, and session or case information needed to deliver the assigned counselling or support service. |
| Partner organisation | Workflow and status information only. No routine access to clinical notes, referral detail, assessments, feedback, or session content. |
| A Mindful Message administrator | Operational administration only. Raw clinical or session access is not routine. |
| FoxTech or support operator | No routine clinical or session access. Sensitive data is accessed for support only when necessary, time-limited, justified, and audited. |
Personal Data We Process
- names, email addresses, phone numbers, account identifiers, organisation membership, roles, and authentication records
- referral, assessment, support, appointment, counselling, casework, safeguarding, and service notes
- special-category health and mental-health information where needed to provide support
- professional onboarding, verification, credential, registration or licence, safeguarding suitability, contract, and billing information
- privacy request, consent, audit, breach, retention-hold, and compliance records
- technical records such as audit logs, request metadata, trace IDs, storage object identifiers, and web-vitals events
Where Data Comes From
Data may come from the person using the service, partner organisations, counsellors, administrators, WorkOS authentication events, product operations, support interactions, and compliance workflows.
Why We Use Data
| Purpose | Lawful basis | Special-category condition |
|---|---|---|
| Providing referral, counselling, support, appointment, and casework services | UK GDPR Article 6(1)(b), 6(1)(f), or 6(1)(e), depending on the controller relationship. | Article 9(2)(h) health or social care with the relevant UK DPA 2018 condition where applicable, or another approved condition recorded by the controller. |
| Managing accounts, authentication, roles, and security | Article 6(1)(b) or 6(1)(f). | Normally not applicable. |
| Professional verification, referral eligibility, and service governance | Article 6(1)(b) or 6(1)(f). | Criminal-record or safeguarding suitability evidence is collected only where lawful and necessary for the role, with minimisation and retention controls. |
| Billing, invoices, contracts, and one-off payment records | Article 6(1)(b) and 6(1)(c). | Not applicable. |
| Legal, safeguarding, compliance, privacy-rights, breach, audit, and retention work | Article 6(1)(c), 6(1)(d), or 6(1)(f), depending on the event. | Source-record condition, vital interests, health or social care, or legal claims where applicable. |
| Service emails and operational notifications | Article 6(1)(b) or 6(1)(f). | Not applicable. |
| Product reliability and first-party performance measurement | Article 6(1)(f). | Health and case content must not be placed in performance telemetry. |
If optional marketing or optional analytics are added later, they need separate notice wording and, where required, consent.
Who We Share Data With
- administrators, verified professionals, partner organisations, and service users according to role and need
- partner organisations for workflow and status only unless a contract and lawful basis allows more
- FoxTech Ltd while acting as processor for hosting, support, maintenance, security, and compliance operations
- WorkOS for authentication, organisation membership, access control, and webhook events
- Google Cloud for hosting, storage, logs, traces, backups, and operational monitoring
- Resend or another service email provider for generic service emails
- legal, professional, insurer, regulator, safeguarding, or law-enforcement recipients where required or justified
Service emails must remain generic and must not include referral reasons, counselling detail, assessment scores, safeguarding detail, diagnosis, or other health content unless a new email-provider and legal review approves it.
International Transfers
Some providers may process data outside the UK. Where this happens, the controller documents the provider, location, transfer safeguard, and contract terms. Providers are used for personal data only where an appropriate safeguard is in place.
How Long We Keep Data
Retention is set by record class. Mental-health and counselling records may need long retention; adult health or social-care records may need eight years; children's records may need retention until the 25th or 26th birthday; invoices and VAT records are kept for at least six years; privacy export artifacts are short-lived, normally 30 days. Retention holds pause deletion while legal, safeguarding, complaint, regulator, or incident issues remain open.
Verification uploads, identity images, and safeguarding suitability files should be reduced to decision evidence after review and deleted on the approved raw-document schedule unless a legal, safeguarding, complaint, regulator, or contract hold applies.
Your Rights
Depending on the lawful basis and circumstances, you may have rights of access, rectification, erasure, restriction of processing, objection, data portability, and to withdraw consent where consent is used.
You can use the privacy centre when signed in or the public privacy request form when you cannot sign in.
Cookies And Performance Data
The platform uses necessary authentication cookies and first-party performance reporting. It does not use optional third-party advertising or analytics cookies. Cookies, trackers, analytics, or new external processing are reviewed before being added.
Complaints
Contact support@amindfulmessage.infofirst so the controller can investigate. You can also complain to the Information Commissioner's Office in the UK at ico.org.uk/make-a-complaint.
US Health Privacy And HIPAA
Where HIPAA applies to A Mindful Message counselling workflows, this page explains permitted uses and disclosures, privacy rights, the complaint route, and the duty to protect PHI. The notice is not signed by customer organisations. Any organisation BAA or accepted SaaS terms requirement is a separate business/legal route and does not replace the platform notice.
HIPAA rights requests can be submitted through the public privacy request form or the privacy centre for access or copies, amendment, accounting of disclosures, restrictions, confidential communications, personal representative review, and complaints. HIPAA access requests are handled within 30 calendar days unless a permitted written extension or stricter state rule applies.
Complaints can be sent to support@amindfulmessage.info and, where HIPAA applies, to the HHS Office for Civil Rights. We do not retaliate for a good-faith privacy complaint or rights request.
Where HIPAA does not apply, other consumer health, state privacy, breach, or confidentiality rules may still apply. Health-data breach assessment is handled through the breach workflow, not through marketing or support tickets.
Substance-use disorder or addiction workflows, Part 2 records, and California-specific minor or telehealth exceptions stay disabled unless the required approval evidence is active for that workflow.