Data Protection

Data Processing Agreement

Version: 2.0 (consolidated) · Last updated: 20 July 2026 · Effective: 20 July 2026

Pursuant to Article 28 of EU GDPR (Regulation (EU) 2016/679). This agreement forms part of MindFriend’s legal and data protection framework.

On this page

This Data Processing Agreement (“DPA”) is incorporated by reference into the Professional Listing Agreement: by accepting that agreement, the Professional accepts this DPA. It is published alongside the MindFriend Terms of Use, Client Service Agreement, and Privacy Policy for transparency — Clients are not a party to this DPA; their rights are set out in the Privacy Policy.

Background — What Is a DPA and Why Does MindFriend Need One?

A Data Processing Agreement is a legally binding contract required by Article 28 of the EU General Data Protection Regulation (EU GDPR). It must be in place whenever one organisation, the Data Controller, engages another organisation, the Data Processor, to process personal data on its behalf.

Mind Friend AB, a Swedish technology company operating under EU GDPR, occupies two distinct roles by activity.

As a Data Controller, MindFriend determines the purposes and means of processing personal data it collects and uses for its own marketplace — including account creation, client and professional profiles, professional onboarding and verification, search and filtering, booking metadata, payment and platform-fee records, support, security logs, complaints, legal compliance, and first-party marketplace analytics (usage and funnel measurement operated by MindFriend itself, with no third-party analytics provider and never applied to health or session content). In this role MindFriend must have DPAs in place with every third-party Sub-processor that touches personal data.

As a Data Processor for Professionals, when MindFriend facilitates the booking connection between a Client and a Professional, MindFriend processes certain Client personal data on behalf of the Professional, who is the Data Controller for the clinical service. In this role this DPA governs what MindFriend can and cannot do with that data.

How MindFriend’s roles map to the data is set out in more detail in the MindFriend Privacy Policy, with which this DPA is intended to be consistent.

PART A — MindFriend as Data Processor for Professionals

This Part A governs the processing of Client personal data by MindFriend on behalf of Professionals who use the Platform to deliver clinical services. In this context, the Professional is the Data Controller and MindFriend is the Data Processor.

1

Parties

Data Controller: the individual mental health Professional — including psychologist, psychiatrist, therapist, counsellor, or other registered practitioner — registered on the MindFriend Platform who has accepted the Professional Listing Agreement.

Data Processor: Mind Friend AB, incorporated in Sweden, operating the Platform at www.mindfriend.com.

This Part A applies automatically and without further action from the date the Professional completes registration on the Platform.

2

Subject Matter, Nature, Purpose, and Duration of Processing

MindFriend processes Client personal data on behalf of Professionals solely to provide the booking and communication infrastructure that supports the delivery of the Professional’s services. The processing carried out by MindFriend on behalf of the Professional (as processor) is limited to: facilitating and recording the booking connection between Client and Professional, scheduling Sessions, transmitting Client communications through messaging and chat tools, and providing the video/audio session infrastructure the Professional uses to deliver their service.

For the avoidance of doubt, MindFriend processes account, profile, payment and platform-fee, support, security-log, and first-party marketplace-analytics data as a Data Controller in its own right (not on behalf of the Professional), as described in the MindFriend Privacy Policy. Those activities are outside the scope of this Part A.

MindFriend processes Client data only to the extent necessary to provide the Platform’s booking and communication functionality. MindFriend does not process clinical notes, therapy records, or session content, does not record Sessions, and does not generate AI summaries of health or session data. These are the sole responsibility of the Professional.

Categories of personal data: identity data, contact data, booking data, communication data, and special-category data voluntarily disclosed by the Client when searching for or messaging a Professional through the Platform.

Categories of data subjects: Clients who register on the MindFriend Platform to search for and book appointments with Professionals.

Duration: MindFriend processes Client personal data on behalf of each Professional for the duration of the Professional’s active registration on the Platform. Upon termination of the Professional’s listing, MindFriend will retain data only for periods required by applicable law and its own data retention policy, after which data will be securely deleted or anonymised.

3

MindFriend’s Obligations as Data Processor

MindFriend will process Client personal data only on documented instructions from the Professional as Controller, as set out in this DPA and the Professional Listing Agreement, and not for any other purpose.

MindFriend will ensure that all personnel authorised to process Client personal data are subject to binding confidentiality obligations, either by contract or statutory duty.

MindFriend will implement and maintain commercially reasonable technical and organisational measures appropriate to the risk to protect Client personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, in accordance with Article 32 EU GDPR. The specific measures currently implemented are set out in Schedule C, and are kept under review and strengthened as the Platform develops.

MindFriend will not engage any new Sub-processor to process Client personal data without giving Professionals at least 14 days’ prior written notice (via the Platform or email). If a Professional reasonably objects and MindFriend cannot offer a reasonable alternative, the Professional may terminate their listing before the change takes effect.

MindFriend will impose on all Sub-processors data protection obligations equivalent to those in this DPA and remains liable to the Professional for the acts and omissions of its Sub-processors.

MindFriend will provide reasonable assistance to enable Professionals to respond to Client data subject rights requests under EU GDPR, including rights of access, rectification, erasure, restriction, portability, and objection.

MindFriend will notify the Professional without undue delay after becoming aware of any personal data breach involving Client personal data processed under this DPA, providing the information reasonably required for the Professional to meet their own notification obligations.

MindFriend will provide reasonable assistance to the Professional in carrying out data protection impact assessments and consulting the relevant supervisory authority where required under Article 36 EU GDPR.

Upon termination of the Professional’s listing, MindFriend will, at the Professional’s written request, either securely delete or return all Client personal data processed on the Professional’s behalf, unless retention is required by applicable law.

MindFriend will make available to the Professional all information reasonably necessary to demonstrate compliance with this DPA. Audit rights are normally satisfied by MindFriend’s written responses to a reasonable audit questionnaire and by available third-party certifications or reports; on-site inspections take place only where required by law or a supervisory authority, with reasonable notice and no more than once per year.

4

Professional’s Obligations as Data Controller

The Professional, as Data Controller, must ensure there is a lawful basis for processing Client personal data through the Platform and that Clients have been properly informed of such processing through a compliant privacy notice or Notice of Privacy Practices.

The Professional must provide MindFriend with documented processing instructions that comply with EU GDPR.

The Professional must ensure that any special-category data, including health and mental health information, disclosed through the Platform is collected with explicit Client consent.

The Professional must comply with all applicable data protection laws, including EU GDPR, in connection with clinical data and records held outside the Platform.

The Professional must handle all data subject rights requests that relate to clinical care records directly, without relying solely on MindFriend.

PART B — MindFriend as Data Controller: Sub-processor Obligations

This Part B sets out the obligations that MindFriend, as Data Controller, imposes on all third-party service providers (“Sub-processors”) who process personal data on MindFriend’s behalf.

Every Sub-processor engaged by MindFriend must comply with these requirements under a written agreement that imposes obligations at least equivalent to those in this DPA.

5

Sub-processor Selection and Requirements

MindFriend uses only Sub-processors that provide sufficient guarantees to implement appropriate technical and organisational data protection measures in accordance with Article 28(1) EU GDPR.

Before engaging any new Sub-processor, MindFriend conducts a vendor assessment to verify the Sub-processor’s data protection practices, security measures, and contractual commitments. Before integrating any third-party service that will process personal data, MindFriend will obtain and execute a written data protection agreement with that provider, add the provider to Schedule B, and notify registered users where required.

Every Sub-processor engaged by MindFriend must process personal data only on MindFriend’s documented instructions, implement appropriate security measures, not engage further sub-processors without written consent, assist with data subject rights requests, notify MindFriend promptly of any breach, delete or return personal data on termination, and permit audits and inspections as required by MindFriend.

MindFriend reviews and updates this DPA, and Schedule B, whenever it engages a new Sub-processor, materially changes its processing activities, or when applicable data protection laws change.

6

International Data Transfers

Where any Sub-processor processes personal data outside the European Economic Area, MindFriend ensures that appropriate safeguards are in place in accordance with Chapter V EU GDPR.

MindFriend’s current processing involves the following cross-border transfers, documented in Schedule B alongside each Sub-processor entry:

  • EU/EEA → United Kingdom (Platform hosting on AWS — London / eu-west-2). This transfer relies on the European Commission’s adequacy decision for the United Kingdom. If that adequacy decision is not in force, MindFriend will put EU Standard Contractual Clauses with the UK Addendum in place for this transfer.
  • United Kingdom / EEA → third countries (e.g., bot-protection; AI help assistant). Where a Sub-processor processes personal data in a country without an adequacy decision, MindFriend relies on Standard Contractual Clauses approved by the European Commission, together with the UK International Data Transfer Agreement or the UK Addendum to the EU SCCs for the UK leg, plus any supplementary measures required following a transfer impact assessment. MindFriend will assess whether a representative under Article 27 UK GDPR is required in respect of its UK data subjects and appoint one where required.
7

Data Subject Rights

As Data Controller, MindFriend is responsible for responding to data subject rights requests from Clients and Professionals regarding personal data it controls.

MindFriend will respond to verified requests within one month of receipt, extendable by two further months for complex requests with notice.

MindFriend will provide a mechanism for data subjects to submit rights requests via talk@mindfriend.com.

Where a rights request relates to data held by a Sub-processor, MindFriend will instruct the Sub-processor to assist within 5 working days of receiving the request.

MindFriend will maintain records of all rights requests received and responses provided.

8

Personal Data Breach Notification

In the event of a personal data breach affecting data for which MindFriend is the Data Controller, MindFriend will notify the Swedish Authority for Privacy Protection (IMY) without undue delay and within 72 hours of becoming aware of a breach likely to result in a risk to the rights and freedoms of data subjects. Where the breach affects UK data subjects and UK GDPR applies, MindFriend will notify the UK Information Commissioner’s Office (ICO) within the same 72-hour period.

MindFriend will notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

MindFriend will document all breaches, including those not notified to the supervisory authority, in an internal breach register.

MindFriend will cooperate fully with Sub-processors to contain and investigate any breach and implement remedial measures.

MindFriend requires all Sub-processors to notify MindFriend of any breach involving MindFriend’s data within 24 hours of becoming aware of it.

9

Governing Law and Supervisory Authority

This DPA is governed by the laws of Sweden and EU GDPR.

The lead supervisory authority for Mind Friend AB is the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten (IMY), Drottninggatan 29, SE-104 20 Stockholm, www.imy.se.

Data subjects located in other EU member states may also contact their local national data protection authority. UK data subjects may also contact the UK Information Commissioner’s Office (ICO).

10

Duration and Termination

This DPA is effective from the date the relevant underlying agreement is accepted and remains in force for as long as MindFriend processes personal data under that agreement.

Termination of the underlying agreement automatically terminates this DPA, subject to any post-termination data retention obligations set out herein.

Schedule A — Details of Processing (Part A, processor relationship)

Subject matter: provision of booking, scheduling, and communication infrastructure through the MindFriend Platform on behalf of the Professional. (Payment processing and account management are carried out by MindFriend as controller and are outside this Schedule.)

Duration: for the duration of the Professional’s active registration on the Platform, plus any legally required retention period thereafter.

Nature of processing: collection, storage, transmission, display, organisation, and deletion of personal data through the Platform’s booking and communication tools.

Purpose of processing: facilitating the booking of mental health Sessions between Clients and Professionals, enabling scheduling and communication, and sending appointment reminders.

Type of personal data: identity data, contact data, booking records, chat or message content, and any health-related information voluntarily disclosed through the Platform.

Categories of data subjects: Clients seeking mental health support who register on the Platform.

Data Controller: the individual Professional registered on the MindFriend Platform.

Data Processor: Mind Friend AB, Sweden.

Schedule B — Approved Sub-processors

This Schedule lists MindFriend’s current approved Sub-processors who process personal data on MindFriend’s behalf. MindFriend will update this list and notify registered users of any material changes with at least 14 days’ prior notice.

Stripe Payments Europe Ltd

Purpose
Payment processing and payout
Location
Ireland (EEA)
Transfer mechanism
None needed (EEA) — Stripe DPA, EU SCCs Module 2

Cloudinary

Purpose
Storage of media files shared in chat (audio/image/video)
Location
United States
Transfer mechanism
International transfer — Cloudinary DPA + EU SCCs / UK Addendum; deleted under the 14-day chat retention

AWS

Purpose
Platform hosting and storage
Location
London, United Kingdom (eu-west-2)
Transfer mechanism
EU→UK transfer relies on the UK adequacy decision; AWS Art. 28 DPA (incl. SCCs covering any non-UK support access)

Stream (Stream.io, Inc.)

Purpose
Video/audio session infrastructure
Location
EU — Dublin, Ireland (EEA)
Transfer mechanism
None needed (EEA hosting) — Stream Data Processing Addendum, incorporated into the product terms

Mailjet (Sinch)

Purpose
Transactional email
Location
France (EEA)
Transfer mechanism
None needed (EEA) — Mailjet / Sinch DPA

Google reCAPTCHA

Purpose
Bot / abuse protection on forms
Location
United States (Google)
Transfer mechanism
International transfer — Google DPA + EU SCCs / UK Addendum; collects device/usage signals

OpenAI

Purpose
AI help assistant (answers product questions from our own help content)
Location
OpenAI Ireland Ltd (EEA/UK); processing in the US
Transfer mechanism
International transfer — OpenAI DPA + EU SCCs / UK Addendum; Zero Data Retention

Analytics

Purpose
None as Sub-processor — analytics is first-party only, operated by MindFriend (see Privacy Policy §4/§6)
Location
Transfer mechanism
None — no third-party analytics provider (only Google reCAPTCHA, listed above)

ID / credential verification

Purpose
Manual — no sub-processor
Location
Transfer mechanism
Manual process; ID documents held with secure storage and retention limits

Schedule C — Technical and Organisational Security Measures

MindFriend applies commercially reasonable technical and organisational measures appropriate to the risk (Article 32 GDPR), including:

  • encryption in transit (TLS) across the Platform;
  • passwords stored using one-way hashing and never in plaintext;
  • no storage of card or payment-method data by MindFriend (payments are handled by the PCI-DSS-compliant processor Stripe);
  • encryption at rest of stored messages and in-session chat;
  • role-based access control limiting staff access to personal data;
  • network firewall and DDoS protection; and
  • server-side logging of access to personal data.

These measures are kept under review and strengthened as the Platform develops.

CONTACT

Mind Friend AB Privacy and data: talk@mindfriend.com Support: talk@mindfriend.com Website: www.mindfriend.com Supervisory authority: www.imy.se

Mind Friend AB | talk@mindfriend.com