Legal
Privacy Policy
Last updated: 30 August 2026
Insidemind Coaching Ltd (“InsideMind”, “we”, “us”, “our”) is the controller of personal data processed in connection with the InsideMind app, website and related services (the “Service”). This Privacy Policy explains what personal data we collect, how we use it, who we share it with, how long we keep it, and the rights you have under data protection law.
We are committed to handling your personal data with care. The Service involves the journal, programmes and community work where people reflect on themselves and their relationships. We have written this policy with that in mind.
This Policy is provided in accordance with the UK General Data Protection Regulation (the “UK GDPR”) and the Data Protection Act 2018 (the “DPA 2018”), each as amended by the Data (Use and Access) Act 2025, and, in respect of cookies and electronic communications, the Privacy and Electronic Communications (EC Directive) Regulations 2003 (the “PECR”).
1.Who we are and how to contact us
Insidemind Coaching Ltd is a company registered in England and Wales with company number 12995894.
If you have any question about this Privacy Policy, or you want to exercise any of your rights under it, you can contact us at:
Email: contact@insidemind.co.uk
We have not appointed a Data Protection Officer, as we are not required to do so. Responsibility for data protection sits with our directors, and the email address above reaches them.
We are registered with the Information Commissioner’s Office, the UK data protection regulator, under registration number ZC188640.
2.What personal data we collect
We collect the following categories of personal data:
| Category | What this includes |
|---|---|
| Account data | Your name, email address, password (stored in encrypted form), country of residence, the date you joined and any profile information you choose to add (such as a profile photo and short bio). |
| Programme data | Information about the programmes and modules you enrol in, your progress, workbook entries and any responses you record in connection with the Relationship Clarity Programme or any other programme on the Service. |
| Journal entries | The free-text entries, voice notes (if available), prompts and reflections you record in your private journal. Journal entries are stored against your account. They are private to you: we do not share them with coaches or other users, and we do not read, analyse or use them for any purpose other than showing them back to you. |
| Community content | Posts, articles, comments, replies and likes you publish in the community, together with any associated profile information. This is content you have chosen to publish, and is visible to other users (and, where the post is public, to visitors to the Service). |
| Booking and session data | Information about coaching sessions you book or attend through the Service, including the coach booked, the date and time, the amount paid, your attendance, and any information you choose to share with the coach when booking (for example, what you would like to discuss). |
| Payment data | Information about the payment method you use, the amount of the transaction and the booking it relates to. Card details are collected and stored by our payment provider; we do not see or store your full card number. |
| Communications | Messages you send to us, to your coach (where the in-app messaging feature is enabled), or to our support team, including the metadata associated with those messages. |
| Device and usage data | Your device type, operating system, app version, language settings, approximate location (derived from your IP address), in-app activity (such as the screens you view and features you use), and analytics events. We use this for security, troubleshooting and improving the Service. |
| Marketing preferences | Your opt-in and opt-out settings for email and push notifications, and the categories of communications you have agreed (or not agreed) to receive. |
3.Where your personal data comes from
Almost all of the personal data we hold about you comes from you directly — when you create an account, use the Service, write in your journal, publish in the community, book a session or contact us. Some data is generated automatically by your device when you use the app, as described under “Device and usage data” above. We also receive limited information from our payment processor confirming whether a payment succeeded.
You do not have to give us any of it. But if you do not provide the data we need to operate your account and your bookings, we will not be able to provide the Service to you.
4.Information about your mental or physical health (special category data)
Sensitive data. Because the Service supports work on self-awareness and relationships, some of the information you choose to share — for example, in a journal entry, in a community post, in your booking notes, or in a coaching session — may reveal information about your mental or physical health, your sexual orientation, your religious beliefs or other matters that are treated as special category data under the UK GDPR.
We treat this data with extra care:
- we do not require you to share special category data in order to use the Service;
- where you do share it, we process it only on the basis of your explicit consent (Article 9(2)(a) UK GDPR), except where another lawful basis applies — such as Article 9(2)(e) where you have manifestly made the data public in the community, Article 9(2)(c) where it is necessary to protect someone’s vital interests in an emergency, or Article 9(2)(f) where we need it to establish, exercise or defend a legal claim;
- we apply additional security measures to data of this kind, including encryption in transit and at rest, restricted access, and audit logging; and
- you can withdraw your consent at any time by deleting the relevant content or closing your account. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
5.How we use your personal data and our legal bases
Under the UK GDPR, we must have a lawful basis for everything we do with your personal data. The table below sets out the purposes for which we use your data, and the lawful basis we rely on for each.
| Purpose | Legal basis under UK GDPR |
|---|---|
| Creating and managing your account; providing the Service to you; processing bookings; taking payment. | Performance of a contract with you (Article 6(1)(b)). Where you have asked us to take steps prior to entering into a contract (for example, creating an account), this is also the basis we rely on. |
| Operating the journal. | Performance of a contract with you (Article 6(1)(b)) for the storage and processing of the entries; explicit consent (Article 9(2)(a)) for any processing of information within an entry that constitutes special category data. You can withdraw your consent at any time by deleting the relevant entry or closing your account. |
| Operating the community; displaying your posts to other users; moderating community content. | Performance of a contract with you (Article 6(1)(b)) for hosting and displaying the content you have chosen to publish. Where a post contains special category data that you have manifestly made public, we also rely on Article 9(2)(e). Our content moderation activities also rely on our legitimate interest in keeping the Service safe and lawful, and on legal obligations under the Online Safety Act 2023. |
| Sending you operational communications (booking confirmations, reminders, refund notifications, security alerts and changes to these documents). | Performance of a contract with you (Article 6(1)(b)) and our legitimate interests in operating the Service (Article 6(1)(f)). |
| Sending you marketing communications about the Service, new programmes, events or features. | Your consent (Article 6(1)(a)). You can withdraw consent at any time using the unsubscribe link in any marketing email or in your in-app settings. |
| Responding to an emergency, or acting where we reasonably believe someone is at risk of serious harm. | Protecting someone’s vital interests (Article 6(1)(d)) and, where special category data is involved, Article 9(2)(c). Where the circumstances fall within the recognised legitimate interests introduced by the Data (Use and Access) Act 2025 — including safeguarding vulnerable individuals and responding to emergencies — we may also rely on Article 6(1)(ea). |
| Security, fraud prevention, and protecting the integrity of the Service. | Our legitimate interests (Article 6(1)(f)) in keeping the Service and our users safe, and in some cases compliance with a legal obligation (Article 6(1)(c)). |
| Analytics, product improvement and aggregate reporting on use of the Service. | Our legitimate interests (Article 6(1)(f)) in understanding how the Service is used so we can improve it. Where consent is required for non-essential cookies and analytics identifiers, we rely on your consent (Article 6(1)(a)). See Section 12. |
| Complying with our legal, regulatory, tax, accounting and record-keeping obligations. | Compliance with legal obligations (Article 6(1)(c)). |
| Establishing, exercising or defending legal claims. | Our legitimate interests (Article 6(1)(f)); where the data is special category data, Article 9(2)(f). |
7.International transfers of personal data
Some of the third parties listed in Section 6 are based outside the United Kingdom or the European Economic Area, or process data using infrastructure outside those regions. Where we transfer personal data outside the UK, we put in place safeguards required by UK data protection law, including:
- transfers to countries the UK Government has decided provide an adequate level of protection (an “adequacy regulation”), including transfers to organisations in the United States that are certified under the UK Extension to the EU–US Data Privacy Framework;
- the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, with the relevant recipient; and
- where required, supplementary technical and organisational measures (such as encryption) to address risks identified in a transfer risk assessment.
You can ask us for a copy of the relevant safeguards in place for any given transfer using the contact details in Section 1.
8.How long we keep your personal data
We keep personal data only for as long as we need it for the purposes set out in this Policy. Indicative periods are set out below.
| Category | Indicative retention period |
|---|---|
| Account, programme and journal data | For as long as your account is active. If you close your account, we delete (or irreversibly anonymise) this data within 90 days, except where a longer period is required for the reasons below. |
| Community content | Until you delete the relevant post or close your account, except that posts re-shared or replied to by other users may persist in those re-shares or replies in accordance with Section 9 of the Terms of Service. |
| Booking and payment records | Six years from the end of the financial year to which they relate, to comply with UK company, accounting, tax and VAT record-keeping obligations. |
| Marketing data | Until you withdraw consent. We retain a record of your opt-out for as long as needed to honour it. |
| Logs and security data | Up to 24 months, unless retained for longer to investigate or defend a specific incident. |
| Records relating to legal claims, regulatory matters or law-enforcement requests | Retained for the period necessary to establish, exercise or defend the claim or to comply with the relevant obligation. |
Where we are no longer required to keep your personal data, we will either delete it or anonymise it so that it can no longer be associated with you.
9.Your rights under the UK GDPR
You have the following rights in relation to your personal data:
- Right of access — to obtain a copy of the personal data we hold about you, together with information about how we use it.
- Right to rectification — to have inaccurate personal data corrected, or incomplete personal data completed.
- Right to erasure — to ask us to delete personal data we hold about you, in the circumstances permitted by law.
- Right to restrict processing — to ask us to pause our processing of your personal data while a query about it is resolved.
- Right to data portability — to receive a copy of the personal data you have provided to us, in a structured, commonly used and machine-readable format, and to ask us to transfer it to another controller where technically feasible.
- Right to object — to object to our processing of your personal data on the basis of legitimate interests (including for direct marketing).
- Right to withdraw consent — where we rely on your consent (for marketing, or for special category data in your journal or community posts), you can withdraw that consent at any time.
- Right not to be subject to solely automated decisions — with legal or similarly significant effects. We do not make any such decisions about you. See Section 14.
- Right to complain to us — to raise a complaint directly with us about how we have handled your personal data. See Section 10.
To exercise any of these rights, contact us using the details in Section 1. We will respond within one month. We may extend this period by up to a further two months where the request is complex, in which case we will tell you about the extension within the first month. If we need you to clarify what you are asking for, or to confirm your identity, the time limit does not start (or pauses) until you have given us what we need.
When we respond to a request for access, we are required to carry out a reasonable and proportionate search for the personal data we hold about you.
10.How to complain
Complain to us first. If you are unhappy with how we have handled your personal data, you can complain to us directly. Email us at contact@insidemind.co.uk with “Data protection complaint” in the subject line, or use the complaint form in the app.
We will acknowledge your complaint within 30 days of receiving it, keep you informed of progress, and tell you the outcome and our reasons.
Complain to the regulator. You also have the right to lodge a complaint with the Information Commissioner’s Office at any time — you do not have to come to us first. You can reach the ICO at ico.org.uk or on 0303 123 1113. We would, however, appreciate the opportunity to address your concerns directly.
11.How we keep your personal data secure
We use appropriate technical and organisational measures to protect personal data, including:
- encryption in transit (TLS) and at rest for personal data held in our systems;
- access controls limiting access to personal data to those who need it;
- multi-factor authentication on administrative accounts;
- regular security testing and patching of our infrastructure;
- background checks on personnel who handle personal data;
- written contracts with our processors requiring them to apply equivalent protections; and
- an incident response process that allows us to identify, contain and notify any personal data breach in line with our legal obligations.
No system is ever completely secure. If you believe your account has been compromised, please contact us as soon as possible.
Personal data breaches. In the event of a personal data breach, we will notify the Information Commissioner’s Office within 72 hours of becoming aware of the breach where there is a likely risk to your rights and freedoms (Article 33 UK GDPR). Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly, without undue delay (Article 34 UK GDPR). We maintain an incident response process covering identification, containment, assessment, notification and post-incident review.
12.Cookies and similar technologies
Our use of cookies and similar technologies is governed by the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR) and, where personal data is involved, the UK GDPR.
Our app and website use cookies and similar technologies (such as software development kits and device identifiers) for purposes including authentication, security, remembering your preferences, and analytics.
Strictly necessary technologies — for example, those that keep you logged in — cannot be disabled, as the Service would not function without them.
Technologies that do not require your consent. Following changes made by the Data (Use and Access) Act 2025, we may use certain low-risk technologies without asking for your consent, including those used only to collect statistical information so that we can improve the Service, and those used to remember display preferences such as your language. We tell you about these here, and you can object to them at any time using the controls described below.
Everything else — including any analytics or measurement that falls outside those exemptions — we use only with your consent. You can manage your preferences using the controls in your device settings and the in-app or website cookie banner, and you can change your mind at any time.
13.Children
The Service is intended for adults. You must be at least 18 years old to use the Service. We do not knowingly collect personal data from anyone under 18. If you believe a person under 18 has provided us with personal data, please contact us and we will take steps to delete it.
14.Automated decision-making and profiling
We do not make any decisions about you based solely on automated processing that produce legal or similarly significant effects, and we do not carry out any such processing involving special category data.
We may use limited automated tools to suggest content or coaches that might be of interest to you. These suggestions do not have a legal or similarly significant effect on you, and you can ask for them to be turned off in your account settings.
15.Users outside the United Kingdom
The Service is operated by InsideMind from the United Kingdom and is intended primarily for users resident in the United Kingdom. If you access the Service from outside the United Kingdom, you understand that your personal data will be processed in, or transferred to, the United Kingdom and other countries that may not have the same data protection laws as your country of residence. Where required by the laws of your country, we apply the safeguards described in Section 7.
If you access the Service from the European Union or European Economic Area, the EU General Data Protection Regulation (Regulation (EU) 2016/679) also applies to our processing of your personal data. The rights and protections in this Policy apply substantively in the same way under the EU GDPR. If we determine that our user base in the European Union or European Economic Area is such that an EU representative is required under Article 27 of the EU GDPR, we will appoint one and update this Policy with their details.
16.Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you in the app or by email at least 14 days before the changes take effect. The “Last updated” date at the top of this Policy tells you when it was last revised.
17.Contact us
If you have any question about this Privacy Policy or how we handle your personal data, please contact us: