Privacy

Privacy Policy

Mind Friend AB (Sweden) · Version: 2.0 (consolidated) · Last updated: 20 July 2026 · Controller contact: talk@mindfriend.com

On this page

This Privacy Policy explains how Mind Friend AB handles your personal data when you use the MindFriend Platform. It is written primarily for Clients; if you are a Professional listed on the Platform, see §14. It is read alongside our Terms of Use, Client Service Agreement, Data Processing Agreement, and Cookie Policy.

1.

Who we are and what this covers

Mind Friend AB (“MindFriend”, “we”) operates a technology marketplace at www.mindfriend.com that connects clients with independent, registered mental-health professionals. We are not a healthcare provider. This Policy explains how we handle personal data when you use the Platform. The independent Professional you book is a separate data controller for the clinical care, notes, and health records they create — their handling of that data is governed by their own privacy notice.

2.

Our role (controller / processor)

  • We are a controller for: account creation, client and professional profiles, professional onboarding and reasonable administrative checks, search/filter, booking metadata, payment and platform-fee records, support, security logs, complaints/disputes, legal compliance, and first-party marketplace analytics (see §4).
  • We are a processor for the limited booking, messaging, and video/audio activities we carry out on behalf of the Professional.
  • The Professional is an independent controller for clinical records, diagnoses, treatment, prescriptions, safeguarding, and informed consent.
3.

Data we collect

Identity and contact data; account credentials; profile data; booking metadata (who/when/format); communications sent through the Platform; payment transaction references (we do not store card numbers); device/log/security data; and any health-related information you voluntarily provide when searching for or messaging a Professional. Health data is special-category data (UK/EU GDPR Art. 9).

Providing account, booking, and payment data is necessary to use the Platform — without it we cannot provide the service. Providing health-related information is voluntary and entirely your choice.

4.

Why we use it and our legal bases

PurposeLegal basis
Provide the Platform, bookings, paymentsPerformance of a contract (Art. 6(1)(b))
Security, fraud prevention, and keeping the Platform working and improving it — applied to account, booking, and usage data and never to the content of your health information or SessionsOur legitimate interests in operating a secure, functioning marketplace (Art. 6(1)(f))
Legal/regulatory complianceLegal obligation (Art. 6(1)(c))
Answering questions about the Platform and helping you find suitable Professionals via our AI help assistant (from our own help content — FAQ and help centre)Our legitimate interests in providing user support (Art. 6(1)(f)); not intended for health data — queries are processed by OpenAI under a data-processing agreement with Zero Data Retention
Processing health-related data you provideExplicit consent (Art. 9(2)(a))
Understanding how the marketplace is used — first-party analytics operated by us (e.g. how many searches lead to a profile view and a booking), applied to usage and booking metadata and never to the content of your health information or SessionsOur legitimate interests in operating and improving the marketplace (Art. 6(1)(f))

Our analytics is first-party only — operated by us, with no third-party analytics provider (see §6) — and we do not use your health or booking data for advertising (see §5).

5.

Data minimisation (our commitments)

We do not record Sessions, store clinical/therapy notes, generate AI summaries of your health data, or use health or booking data for advertising. We collect the minimum needed to run the marketplace.

Pseudonymised account identifier. Inside our systems your account is keyed to an internal, randomly-generated identifier that we create — not to your name. Day-to-day records such as booking metadata, security logs, and first-party analytics reference this internal identifier rather than your direct identity, keeping operational processing separated from the data that directly identifies you. Your name, email, and other contact details are held separately and used only where needed (for example, to send a booking confirmation). This is a pseudonymisation and data-minimisation measure (Art. 4(5) UK/EU GDPR) — it is not anonymisation: we can still link the identifier back to you, the data remains personal data, and we remain its controller (see §2).

AI help assistant. We offer an optional AI assistant that answers questions about the Platform using our own help content (FAQ and help centre). It can also suggest Professionals matching your request: it identifies search criteria from your message and applies deterministic, rule-based matching against Professionals’ profile information (such as specialisations, qualifications, and languages). It matches your stated criteria to profiles — it does not assess you or make any decision about you. It is not a counselling or clinical tool and is not intended for personal or health information. Your questions are sent to our AI provider (OpenAI) only to generate an answer; they are not used to train AI models, and we run it on a no-retention basis, so your messages are not stored. Please don’t enter personal or health details, and never rely on it for clinical matters.

6.

Who we share data with (sub-processors)

  • Payments: Stripe Payments Europe Ltd (Ireland)
  • Hosting: AWS — London (eu-west-2) (EU→UK transfer under the UK adequacy decision)
  • Video/audio sessions: Stream (Stream.io, Inc.) — hosted in the EU (Dublin, Ireland) (EEA processing — no third-country transfer)
  • Transactional email: Mailjet / Sinch (France, EEA)
  • Chat media storage: Cloudinary (United States) (stores audio, image, and video files shared in chat; international transfer — EU SCCs/UK Addendum; deleted under the same 14-day retention as chat messages)
  • Bot/abuse protection: Google reCAPTCHA (Google, US — international transfer under SCCs/UK Addendum; collects device/usage signals; loads only on pages with forms)
  • Optional “Sign in with Google”: if you choose to sign in with Google, Google confirms your email address to us; Google’s own processing is governed by Google’s privacy policy
  • AI help assistant: OpenAI (OpenAI Ireland Ltd for EEA/UK users; processing in the United States) (international transfer — EU SCCs + UK Addendum; under the OpenAI Data Processing Agreement with Zero Data Retention)
  • Analytics: first-party only, operated by us — no third-party analytics provider
  • Identity/credential checks: handled manually (no third-party service)

Each sub-processor is, or will be before reliance, bound by an Art. 28 contract (see the per-provider notes above). We do not sell your personal data. The current list is maintained in the Data Processing Agreement, Schedule B.

7.

International transfers

Some of our sub-processors are located outside the EEA/UK. Where personal data is transferred internationally, we put appropriate safeguards in place: - EU/EEA → United Kingdom (Platform hosting, AWS — London / eu-west-2): we rely on the EU’s UK adequacy decision. If that decision is not in force, we put EU Standard Contractual Clauses with the UK Addendum in place. - UK / EEA → third countries (bot/abuse protection via Google reCAPTCHA, US; AI help assistant via OpenAI, US): we rely on EU Standard Contractual Clauses together with the UK International Data Transfer Agreement / Addendum, plus any supplementary measures required following a transfer assessment.

If you are in the UK: for you, transfers from the UK to the EEA rely on the UK’s adequacy regulations for the EEA, and transfers to the US (Google, OpenAI, Cloudinary) rely on the UK Addendum / International Data Transfer Agreement, as described above.

You can request a copy of the relevant safeguards by emailing talk@mindfriend.com.

8.

How long we keep it

We keep personal data only as long as needed for the purposes above and any legal retention period, then securely delete or anonymise it:

Data categoryHow long
Messages, in-session chat, and chat media14 days (encrypted while stored, then automatically deleted)
Account and profile dataLife of your account, then deleted or anonymised within 90 days of closure
Booking metadataLife of your account plus up to 12 months, unless needed for a dispute
Payment and fee records7 years (bookkeeping law) — held as transaction references; we never store card numbers
Security and server logs12 months
Support and complaint records24 months after closure of the matter
Professional onboarding documents (credentials, insurance)Duration of the listing plus 24 months
Consent and agreement-acceptance recordsDuration of the account plus 6 years (evidence of contract)

Where a legal obligation, dispute, or safeguarding matter requires it, we may retain the specific records involved for longer.

9.

Your rights

Access, rectification, erasure, restriction, portability, objection, and the right to withdraw consent at any time. To exercise them: talk@mindfriend.com (we respond within one month, extendable by up to two further months for complex requests, with notice). If you are in the UK, UK GDPR applies to you and the ICO is your supervisory authority. For EU/EEA users, IMY (Sweden) is our lead supervisory authority, and you may also contact your local authority.

10.

Automated decision-making and profiling

We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. - Search ranking. Our search and filtering order Professionals in your results using the parameters disclosed to Professionals in the Professional Listing Agreement. This orders results; it does not make a decision about you. - Bot/abuse protection. Google reCAPTCHA assigns an automated risk score to detect automated abuse of our forms. It is used only to protect the Platform — not to evaluate you — and does not by itself deny you a service without a human-reviewable path. - AI help assistant. Our help assistant returns information from our own help content in response to your question; where it suggests Professionals, it matches the criteria you state against Professionals’ profiles using deterministic rules. It does not evaluate or profile you and does not make any decision about you.

11.

Security

We use commercially reasonable technical and organisational measures appropriate to the risk.

12.

Cookies

See our Cookie Policy. Note that the Platform loads Google reCAPTCHA on pages with forms (see §6); its classification is addressed in the Cookie Policy.

13.

Children

The Platform is for users aged 18 and over. We do not knowingly collect personal data from anyone under 18.

14.

If you are a Professional listed on MindFriend

This Policy is written for Clients. If you register as a Professional, Mind Friend AB is the controller of your own personal data. (This is separate from your role as an independent controller of your Clients’ clinical data — see §2.) - Data we hold about you: identity and contact data; professional title; regulatory body, registration/licence number, licence expiry and jurisdiction(s); proof of registration or accreditation; professional indemnity/insurance certificate; specialisations, fees, languages, and availability; payout-account and KYC data (held by our payment processor); and account, log, and security data. - Why, and our legal bases: to operate your listing, run the marketplace, administer platform fees and payouts, and manage the professional relationship — performance of the Professional Listing Agreement (Art. 6(1)(b)); to meet legal and regulatory obligations (Art. 6(1)(c)); and our legitimate interests in running a trustworthy marketplace, including reasonable administrative checks (Art. 6(1)(f)). - Where your data comes from: mostly from you. Where we carry out reasonable administrative checks of your credentials, some information is obtained from or verified against public professional registers (UK/EU GDPR Art. 14 source-of-data). These checks are not a certification, endorsement, or guarantee of your status — see the Professional Listing Agreement. - Your rights are the same as in §9, and the same supervisory authorities apply.

15.

Changes & contact

We may update this Policy and will notify you of material changes by email or platform notice. Contact: talk@mindfriend.com.

CONTACT

Mind Friend AB Registered office: Östermalmstorg 1, 114 42 Stockholm, Sweden · org.nr 559569-7524 Privacy and data: talk@mindfriend.com Website: www.mindfriend.com UK users: the ICO (ico.org.uk) · EU/EEA lead supervisory authority: IMY (Sweden), www.imy.se

Mind Friend AB | talk@mindfriend.com