PRIVACY POLICY
Last updated: 21 May 2026
1. DEFINITIONS
1.1. Unless otherwise defined in this Privacy Policy, capitalized terms used herein shall have the meanings assigned to them in the General Terms and Conditions and any other agreements forming part of the contractual framework applicable to the use of the Platform and the Services.
1.2. Terms such as “Personal Dataˮ, “Processingˮ, “Controllerˮ, “Processorˮ and “Special Categories of Personal Dataˮ have the meanings given to them under the GDPR.
2. GENERAL INFORMATION
2.1. This Privacy Policy describes how Mindly Europe OÜ (“Mindlyˮ, “weˮ, “usˮ, “ourˮ) collects, uses, stores, shares, and otherwise processes Personal Data in connection with the use of the Platform and Services.
2.2. Mindly operates a digital platform connecting Patients with independent mental health professionals and providing technological infrastructure, scheduling tools, payment processing, customer support, and related administrative services. Mindly is not a healthcare provider and does not provide Therapy Services directly. Therapy Services are provided solely by independent Therapists using the Platform.
2.3. Although Mindly does not provide Therapy Services directly, certain Personal Data processed through the Platform may relate to a Patientʼs wellbeing, therapy needs or use of Therapy Services. Mindly processes such information only where permitted under Applicable Data Protection Laws and subject to the safeguards described in this Privacy Policy.
2.4. By accessing or using the Platform, creating an Account, accepting the General Terms and Conditions and this Privacy Policy or otherwise using the Services, Clients are informed that their Personal Data is processed in accordance with this Privacy Policy. Where consent is required for a specific Processing activity, Mindly will request it separately through the Platform or by other appropriate means. Where Processing of Special Categories of Personal Data requires explicit consent or another applicable condition, Mindly will rely on such consent or condition separately from the general acceptance of the General Terms and Conditions.
2.5. Mindly may update this Privacy Policy from time to time. Any material changes are communicated through the Platform, Website, App, e-mail notification, or other appropriate communication channels.
2.6. This Privacy Policy does not amend or replace any specific contractual allocation of data protection roles and responsibilities agreed between Mindly and Clients or other business partners.
3. CATEGORIES OF PERSONAL DATA
3.1. Mindly may process Personal Data including first and last name, date of birth, username or display name, e-mail address, telephone number, country of residence, account credentials, profile information, therapist identification information and professional licensing or certification information.
3.2. Mindly may process information relating to the provision and use of Therapy Services, including information provided by Patients during onboarding, profile completion, session booking, therapist selection, use of Platform communication tools, customer support interactions and related safety or compliance processes. Depending on the information provided by the Patient, such data may include information relating to emotional wellbeing, therapy needs, symptoms, relationships, personal circumstances or other sensitive matters. Mindly limits such Processing to what is reasonably necessary for the operation of the Platform, the facilitation of Therapy Services, and associated compliance, security, safety and legal purposes.
3.3. Mindly may process payment and billing information including Payment Data, billing address, VAT information, transaction history, subscription information, payment confirmations and invoice-related information.
3.4. Mindly may process technical and usage data including IP address, device information, browser type and version, operating system, application usage data, log files, cookies and similar technologies, session metadata, crash reports and access timestamps.
3.5. Where Services are provided to Corporate Clients or under employer-sponsored arrangements, Mindly may additionally process information relating to Designated Users, including Account administration data, eligibility or access information, service activation status and aggregated or anonymized usage information. As described in Section 8.2, Mindly does not record, store or have access to the content of Therapy Sessions or any clinical information, and such information is not included in reports provided to Corporate Clients.
3.6. Mindly does not intentionally collect more Personal Data than is necessary for the purposes described in this Privacy Policy.
4. SOURCES OF PERSONAL DATA
4.1. Mindly collects Personal Data directly from Patients, Therapists, Corporate Clients, Designated Users, Gift Card Buyers and other users interacting with the Platform.
4.2. Mindly may also receive Personal Data from Payment Processing Providers, App Stores, analytics and infrastructure providers, customer support interactions, referrals and where applicable, Corporate Clients in connection with the administration of employer-sponsored Services.
4.3. Where a Client provides Personal Data relating to another individual outside of the Platform registration or onboarding process, including in connection with referrals, emergency contacts or employer-sponsored Services, the Client warrants that they have the lawful right to provide such information and, where required, that the relevant individual has been informed. Mindly may provide such individual with relevant privacy information where required by law.
5. PURPOSES AND LEGAL BASES FOR PROCESSING
5.1. Mindly processes Personal Data only where there is a valid legal basis under Applicable Data Protection Laws.
5.2. Where this Privacy Policy refers to the performance of a contract, this means the performance of the General Terms and Conditions governing access to and use of the Platform, or another applicable agreement between Mindly and the relevant Client, Therapist, Corporate Client or other party, as applicable. Mindly does not provide Therapy Services directly and does not rely on the performance of a therapy contract between a Patient and a Therapist as the legal basis for Mindlyʼs Processing of Personal Data.
5.3. Mindly processes identity, contact, account, authentication and profile data to create, maintain and administer Accounts, enable access to the Platform, manage registration, provide Platform functionality and communicate with Clients in relation to the Services. The legal basis is the performance of the General Terms and Conditions accepted by the Client or taking steps at the Clientʼs request prior to registration.
5.4. Mindly processes administrative information necessary to enable Clients and Therapists to arrange, schedule, administer and complete Therapy Services through the Platform. Such information may include session scheduling data, selected Therapist, payment and subscription status and other non-clinical service administration data. The legal basis is the performance of the General Terms and Conditions accepted by the Client and Mindlyʼs legitimate interests in operating the Platform and facilitating administrative interactions between Clients and Therapists.
5.5. As described in Section 8.2, Mindly does not record, store or have access to the content of Therapy Sessions or any clinical information. However, certain administrative information processed through the Platform may reveal that a Client uses mental health-related services and may therefore constitute or reveal Special Categories of Personal Data. Mindly processes such data only where permitted under Applicable Data Protection Laws and where an appropriate lawful basis and, where required, an applicable condition for Processing Special Categories of Personal Data applies. Mindly relies on Article 9(2)(a) GDPR (explicit consent of the data subject) as the condition for processing data that may constitute Special Categories of Personal Data. Where applicable, Mindly may also rely on Article 9(2)(f) (establishment, exercise or defence of legal claims).
5.6. Mindly processes payment, billing, invoice, VAT and transaction data to process payments, administer subscriptions, issue invoices and comply with accounting and tax obligations. The legal basis is contract performance, legal obligation and legitimate interests.
5.7. Mindly processes contact information, account information, support communications and relevant Platform data to respond to requests, resolve issues, provide service-related communications, handle complaints, maintain service quality and resolve disputes. The legal basis is the performance of the General Terms and Conditions accepted by the Client and Mindlyʼs legitimate interests in providing support, maintaining the quality and reliability of the Platform and protecting its legal rights.
5.8. Mindly processes technical, usage, device, log, access, cookie and security-related data to operate, maintain, secure and improve the Platform, authenticate users, prevent fraud, detect misuse, investigate security incidents, troubleshoot issues, analyze usage trends and ensure Platform reliability. The legal basis is Mindlyʼs legitimate interests in operating, securing and improving the Platform, except where consent is required under Applicable Data Protection Laws, including for non-essential cookies, analytics technologies or similar tools.
5.9. Mindly processes Personal Data to comply with legal obligations, respond to lawful requests from courts, regulators, law enforcement agencies or other competent authorities, establish, exercise or defend legal claims, resolve disputes and enforce applicable agreements. The legal basis is compliance with legal obligations and Mindlyʼs legitimate interests in protecting its legal rights and interests.
5.10. Mindly processes contact details, communication preferences and limited account information to send marketing communications where permitted by law. For existing Clients, Mindly may send marketing communications about its own similar services on the basis of legitimate interests (Article 6(1)(f) GDPR), subject to the Client's right to object at any time via the opt-out mechanism included in each communication. For prospective users or where required by applicable e-privacy law, Mindly relies on prior consent (Article 6(1)(a) GDPR), which may be withdrawn at any time.
5.11. Where Services are provided to Corporate Clients or under employer-sponsored arrangements, Mindly may process Personal Data of Designated Users to administer access, verify eligibility, manage service allocation, support billing or invoicing and provide aggregated or anonymized administrative reporting. Identifiable usage information relating to Designated Users is not disclosed to Corporate Clients except as described in Section 14 of this Privacy Policy.
5.12. Where Mindly relies on consent, including explicit consent where required, the Client may withdraw such consent at any time. Withdrawal does not affect the lawfulness of Processing carried out before withdrawal, and Mindly may continue Processing where another valid legal basis applies.
6. ROLE OF MINDLY AND THERAPISTS
6.1. Mindly acts as an independent Controller in relation to the operation and administration of the Platform, including Account administration, booking and scheduling functionality, payment processing, customer support, security, fraud prevention, analytics, service communications and general business operations.
6.2. Mindly does not provide Therapy Services directly and does not determine the professional content of Therapy Services, therapeutic methods, clinical decisions, Therapist professional notes, medical records, clinical notes, diagnoses, treatment details or comparable clinical information.
6.3. Therapists act as independent Controllers in relation to Personal Data they process for the purpose of providing Therapy Services, maintaining professional notes, clinical documentation or other professional records, and complying with their own professional, legal and ethical obligations.
6.4. Where Services are provided to Corporate Clients or under employer-sponsored arrangements, the applicable agreement determines the allocation of data protection roles. Depending on the arrangement, the Corporate Client may act as Controller and Mindly may act as Processor for certain eligibility, access administration or benefit management data. In other contexts, Mindly and the Corporate Client may act as separate independent Controllers for their respective Processing activities.
6.5. Where Mindly acts as Processor on behalf of a Corporate Client or another Controller, Mindly processes Personal Data only on documented instructions of the relevant Controller and subject to a data processing agreement or other agreement satisfying Applicable Data Protection Laws.
6.6. This Privacy Policy applies to Processing activities for which Mindly acts as Controller and, where relevant, describes Processing activities carried out by Mindly as Processor. Processing carried out independently by Therapists, Corporate Clients or third-party controllers is subject to their own privacy notices and legal obligations.
7. SHARING OF PERSONAL DATA
7.1. Mindly may share Personal Data only where necessary for the operation, administration, security or legal compliance of the Platform and the Services, or where otherwise permitted under Applicable Data Protection Laws.
7.2. Mindly may share limited Personal Data with Therapists selected by Patients where necessary to arrange, schedule, administer or complete Therapy Services through the Platform. Such information may include account, booking, scheduling, payment or entitlement status and other non-clinical administrative information necessary for the relevant Therapist to provide or administer the booked Therapy Services.
7.3. Mindly may share Personal Data with third-party service providers involved in the operation of the Platform and the Services, including payment processing providers, cloud hosting and infrastructure providers, communication and video functionality providers, customer support providers, analytics providers, security providers, professional advisors, insurers and other service providers acting in accordance with applicable contractual and legal requirements.
7.4. Where Services are provided to Corporate Clients or under employer-sponsored arrangements, Mindly may provide Corporate Clients with aggregated or anonymized administrative usage reports where agreed under applicable arrangements. Reporting and disclosure of Designated User information to Corporate Clients is governed by Section 14.3 and 14.5 of this Privacy Policy.
7.5. As described in Section 8.2, Mindly does not record, store or have access to the content of Therapy Sessions or any clinical information, and such information is not included in any disclosures to Corporate Clients or other third parties.
7.6. Mindly may disclose Personal Data where reasonably necessary to detect, prevent or investigate fraud, abuse, security incidents, unauthorized access, unlawful activity, threats, misconduct or violations of applicable agreements, policies or law, and to protect the rights, property, safety and legitimate interests of Mindly, users of the Platform, Therapists, Corporate Clients or third parties.
7.7. Mindly may disclose Personal Data to courts, regulators, law enforcement agencies, tax authorities or other competent authorities where required by applicable law, legal process or lawful request, or where reasonably necessary to establish, exercise or defend legal claims.
8. THERAPY SESSIONS AND COMMUNICATIONS
8.1. Therapy Sessions conducted through the Platform are facilitated through integrated video conference, audio call or similar communication functionality.
8.2. Mindly does not record, store, transcribe or have access to the content of Therapy Sessions. Mindly does not create or maintain Therapist professional notes, medical records, clinical notes, diagnoses, treatment details or comparable clinical information.
8.3. Mindly may process administrative and technical information necessary to facilitate, operate and administer Therapy Sessions through the Platform, including session scheduling data, selected Therapist, payment and entitlement status, technical connection data and other non-clinical service administration data.
8.4. Therapists may create and maintain their own professional notes, records or clinical documentation in accordance with applicable professional obligations and laws. Such records are maintained by Therapists independently and are not created, controlled or retained by Mindly.
8.5. Communications between Clients and Mindly, including customer support communications and service-related messages, may be processed and retained where necessary to provide support, administer the Services, maintain security, prevent misuse, resolve disputes, comply with legal obligations or establish, exercise or defend legal claims.
8.6. Where Coupleʼs Therapy, joint sessions or shared chats are made available, participants acknowledge that information shared during such joint sessions or in shared chats may be visible to the Primary Patient, the Invited Partner and the Therapist as part of the therapeutic process.
9. COOKIES AND TRACKING TECHNOLOGIES
9.1. Mindly may use cookies, SDKs, pixels, local storage and similar technologies to operate the Platform, authenticate users, remember preferences, maintain security, analyze usage, improve performance and support Platform functionality.
9.2. Clients may manage cookie and tracking preferences through browser settings, device settings or Platform cookie preference tools, where available. Withdrawal of consent does not affect prior processing.
9.3. Mindly uses the following categories of cookies and similar technologies: (a) strictly necessary – required for core functionality and security, cannot be disabled; (b) functional – remember preferences and personalisation settings; (c) analytics – measure Platform usage and performance; (d) marketing – support targeted communications and campaign measurement. Categories (b)–(d) are used only with the Client's prior consent.
9.4. This Section 9 constitutes Mindly's cookie notice. A detailed list of cookies, including names, providers, purposes and storage durations, is available upon request via the contact details set out in Section 17.
10. INTERNATIONAL DATA TRANSFERS
10.1. Personal Data may be transferred to and processed in countries outside the European Economic Area where this is necessary for the operation, administration, support, security or legal compliance of the Platform and the Services, including where Mindly uses third-party service providers located outside the European Economic Area.
10.2. Where Personal Data is transferred outside the European Economic Area, Mindly relies on appropriate safeguards or lawful transfer mechanisms under Applicable Data Protection Laws, including adequacy decisions or other lawful transfer mechanisms recognised under Applicable Data Protection Laws.
10.3. Information about applicable transfer safeguards may be requested by contacting Mindly using the details set out in Section 17, subject to lawful redactions and confidentiality restrictions.
11. DATA RETENTION
11.1. Mindly retains Personal Data only for as long as necessary for the purposes for which it was collected, including to provide and administer the Services, operate the Platform, comply with legal obligations, resolve disputes, maintain security and establish, exercise or defend legal claims.
11.2. Account, profile and Platform administration data are generally retained for the duration of the Clientʼs relationship with Mindly and for a reasonable period thereafter where necessary for account closure, service administration, dispute resolution, legal compliance or legal claims.
11.3. Payment, invoice, tax, accounting and transaction records are retained for the period required under applicable accounting, tax and financial reporting laws.
11.4. Technical, access, security and fraud prevention logs are retained for limited periods necessary for Platform security, troubleshooting, fraud prevention, incident response and legal compliance, unless longer retention is necessary for investigation, dispute resolution or legal claims.
11.5. Customer support communications and service-related messages are retained for as long as necessary to handle the relevant request, provide support, maintain service quality, resolve disputes, comply with legal obligations or establish, exercise or defend legal claims.
11.6. Where Therapists maintain separate professional notes, clinical documentation or professional records, retention of such records is determined by the relevant Therapist in accordance with their own legal and professional obligations.
11.7. Upon expiration of applicable retention periods, Personal Data is deleted or anonymized in accordance with applicable law and Mindlyʼs internal data management procedures.
12. SECURITY MEASURES
12.1. Mindly implements appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access.
12.2. Such measures may include, as appropriate, access controls, authentication, role-based permissions, encryption in transit and at rest, logging and monitoring, backup procedures, vendor due diligence, confidentiality obligations and incident response procedures.
12.3. Despite these measures, no electronic transmission, storage or processing system can be guaranteed to be completely secure, error-free or immune from all vulnerabilities.
12.4. Clients are responsible for maintaining the confidentiality of their Account credentials and for protecting their Accounts against unauthorized access.
12.5. Mindly maintains internal procedures for identifying, documenting and responding to Personal Data breaches. Where Mindly acts as Controller and a Personal Data breach is likely to result in a risk to the rights and freedoms of individuals, Mindly will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of the breach, unless notification is not required under Applicable Data Protection Laws.
12.6. Where a Personal Data breach is likely to result in a high risk to affected individuals, Mindly will notify affected individuals where required by Applicable Data Protection Laws. Where Mindly acts as Processor, Mindly will notify the relevant Controller without undue delay after becoming aware of a Personal Data breach.
13. DATA SUBJECT RIGHTS UNDER GDPR
13.1. Subject to Applicable Data Protection Laws, Clients and other individuals whose Personal Data is Processed by Mindly may have the following rights: the right of access to their Personal Data; the right to rectification of inaccurate or incomplete Personal Data; the right to erasure of Personal Data in circumstances provided for under applicable law; the right to restriction of Processing; the right to data portability, where applicable; the right to object to Processing carried out on the basis of legitimate interests or for direct marketing purposes; and the right to withdraw consent at any time without affecting the lawfulness of Processing carried out before withdrawal.
13.2. Requests relating to Personal Data may be submitted to Mindly using the contact details set out in Section 17. Mindly may request reasonable information to verify the identity of the person making the request before processing the request.
13.3. Mindly will respond to requests within the timeframe required under Applicable Data Protection Laws, generally within one month under GDPR. Where permitted by law, this period may be extended if the request is complex or if Mindly receives a large number of requests.
13.4. Where a request relates primarily to Processing carried out independently by a Therapist, Corporate Client or another Controller, Mindly may redirect the request to the relevant party, advise the Client to contact that party directly, or assist in routing the request where reasonably possible and permitted by law.
13.5. Mindly may refuse or limit requests that are manifestly unfounded, excessive or repetitive, or where another restriction or exception applies under Applicable Data Protection Laws.
13.6. Clients also have the right to lodge a complaint with a competent data protection authority, including the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or the supervisory authority of their place of residence.
14. CORPORATE CLIENTS AND DESIGNATED USERS
14.1. The allocation of data protection roles between Mindly and Corporate Clients, including circumstances in which Mindly acts as Processor or as an independent Controller, is described in Sections 6.4 and 6.5.
14.2. Corporate Clients are responsible for ensuring that they have an appropriate legal basis for providing or making available Personal Data of Designated Users to Mindly, including where Personal Data is provided for eligibility verification, access administration, benefit management or invitation purposes.
14.3. Mindly may provide Corporate Clients with aggregated or anonymized administrative reporting relating to the use of the Services, where agreed under the applicable arrangement. Such reporting may include general utilization, activation, allocation, billing or similar non-clinical administrative metrics.
14.4. Mindly does not include clinical or session-content information in reports or disclosures to Corporate Clients (see Section 8.2) and does not disclose identifiable administrative usage information relating to a Designated User to a Corporate Client unless the relevant Designated User has provided explicit consent or disclosure is required or expressly permitted by applicable law
14.5. Corporate Clients are independently responsible for informing Designated Users about their own Processing activities carried out outside Mindlyʼs direct scope of responsibility, including eligibility assessment, internal administration, employee benefit management and any employment-related Processing.
15. ELIGIBILITY
15.1. The Platform is intended for individuals aged at least 18 years, or the age of legal capacity in their place of residence if higher. Where applicable law permits access from a younger age, appropriate parental or guardian consent or other safeguards are required as described in the General Terms and Conditions. Mindly does not knowingly collect Personal Data from individuals below the applicable minimum age
15.2. Where Mindly becomes aware that Personal Data has been collected from an individual who does not meet the applicable eligibility requirements, Mindly will take reasonable steps to delete, restrict or otherwise address such data in accordance with applicable law.
16. THIRD-PARTY SERVICES
16.1. Mindly may use third-party service providers in connection with the operation, administration, support, security and improvement of the Platform and the Services, including the categories of service providers described in Section 7.3 and other service providers involved in the operation and improvement of the Platform.
16.2. Where third-party service providers process Personal Data on behalf of Mindly, Mindly enters into appropriate data processing agreements or other contractual arrangements requiring such providers to process Personal Data in accordance with Mindlyʼs documented instructions, implement appropriate technical and organizational measures and comply with Applicable Data Protection Laws.
16.3. Certain third-party providers may process Personal Data as independent controllers, including where they determine their own purposes and means of Processing under their own privacy policies and legal obligations. This may include, depending on the context, payment providers, app stores or other third-party services used in connection with the Platform.
16.4. A current list of Mindlyʼs key third-party service providers or subprocessors that process Personal Data in connection with the Platform is available upon request by contacting Mindly using the details set out in Section 17.
16.5. The Platform may contain links to, or integrations with, third-party websites, applications, platforms or services that are not operated or controlled by Mindly. Mindly is not responsible for the privacy practices, security or content of such third-party services, and their Processing of Personal Data is subject to their own privacy notices and terms.
17. CONTACT INFORMATION
17.1. Questions, requests or complaints regarding this Privacy Policy or the Processing of Personal Data may be directed to:
Mindly Europe OÜ Peterburi tee 46 11415 Tallinn, Estonia E-mail: privacy@mindlyspace.com
17.2. General customer support requests may be submitted to: support@mindlyspace.com
18. FINAL PROVISIONS
18.1. This Privacy Policy is interpreted and applied in accordance with applicable Estonian law and directly applicable European Union law, including the GDPR, without prejudice to any mandatory rights or protections available to individuals under Applicable Data Protection Laws.
18.2. If any provision of this Privacy Policy is found invalid or unenforceable, the remaining provisions remain in full force and effect.
18.3. This Privacy Policy forms part of the contractual and compliance framework governing the use of the Platform and the Services, together with the General Terms and Conditions and any other applicable agreements concluded between Mindly and Clients, Therapists, Corporate Clients, service providers or other relevant parties.