Privacy Policy

Powered by Paranimo Privacy Policy

Last edited August 2021

Introduction

The Paranimo platform is provided by Paranimo Limited (Company Number 11992617).

This policy will explain how Paranimo limited uses the personal data we collect from users when using our website. The security and privacy of our users' personal data is central to our service and we want this document to give our users the confidence to use our platform without concern or anxiety.

The UK Data Protection Act 2018 sets out the data protection rights for UK citizens.  More information can be found here:https://ico.org.uk/for-organisations/guide-to-data-protection/introduction-to-data-protection/about-the-dpa-2018/

This platform acts as a marketplace to facilitate therapists providing their services to clients and the matching of those seeking Mental Health support with those able to provide that Mental Health support. As such our user base is split into two user types: “Therapists” and “Clients”. A “Therapist” is a Mental Health support provider and a “Client” is someone looking for Mental Health support.

The data required for each user is different and is required by us for different reasons, which we will aim to set out in this document.

Our general principles for personal data collection and processing

We will keep personal data collection to the absolute minimum required to provide our service.

We only collect personal data for specified, explicit and legitimate purposes.

We will only use personal data for purposes stated herein, and will gain permission before making any change to those stated purposes.

We will transfer data to third parties where the third party provides the functionality required for delivery of our services. Where the third party is a client’s therapist, the client will have to give consent to begin and sustain the engagement. 

We will maintain organisational and technical procedures to allow you to exercise your rights under the law.

We will maintain organisational and technical procedures to ensure all data is kept securely and lawfully.

What data will we collect?

Age Restriction
We do not knowingly collect personal data from individuals under the age of 18 years old. This is why we need this data to be given to us. If you are under 18 years of age you cannot use this service or give us your personal data. By using our services, you are confirming that you are at least 18 years old. We do not ask Clients for their date of birth.

Paranimo collects the following data:

We only collect data that is required for either the running of the platform or which could be useful in establishing a connection between a Client and a Therapist and help facilitate delivery of a Therapist’s service.

A client looking for Mental Health support will only need to provide an email address, password, and a phone number. Clients can choose a display name for use on the platform. This display name can be a real name or an invented pseudonym if the client wishes to remain anonymous. Every other piece of data provided by a Client will be optional. You can keep everything else blank and only tell a Therapist what you feel comfortable with over a secure video call. 

Though the only personal data required is registration information, the effectiveness of the Paranimo service may be reduced if you do not wish to share other personal data. 

Email address
We require an email address for login, to send emails, and to allow access to business funded sessions. We do not share email addresses with therapists.

Age Restriction
We do not knowingly collect personal data from individuals under the age of 18 years old. If you are under 18 years of age you cannot use this service or give us your personal data. By using our services, you are confirming that you are at least 18 years old.

Name
We allow users to add any name, including anonymous usernames, and expect therapists to provide their real, full names.

Client
This information will be used to identify you in the client list of your therapist but you can remove your name from their list at any time by withdrawing your consent to share from within your profile.

Therapist
Therapist names will be viewable on therapists public profiles.

Availability
Clients and Therapists can select blocks of time and days of the week they are generally available to make suggesting booking times easier.

Therapists will be expected to provide more personal information to prove they are trained to provide mental health support effectively. This includes:
Full name
Professional Organisation Membership and Organisation ID or other unique identifier
Personal ID such as driving licence or passport
DBS checks
Insurance documentation
Personal biographical information

Therapists may also have the option to supply Paranimo with profile images and video content for use on their profile.

If a client contacts Paranimo directly to organise a phone based session Paranimo will need to collect a phone number to allow the session to take place and may also need a name or ID if the client is a member of a Paranimo Scheme.By providing such data you are consenting to the data being used and processed by us.

Correspondence, or a record of correspondence, is kept if you should contact either the Paranimo business or another user through the platform.

We will never record any content from video call sessions.

Where information is supplied to us through third parties, we ensure by contract that GDPR compliant consent exists.

How do we collect your data?

Personal data may be  voluntarily given to Paranimo by you, through the website, or as meta-data passed to us through the standard data flows in online communication.

We may receive personal data (email only) via referrals, where someone that knows your email address may suggest you join the platform.

We may also receive personal data from:
Other professional organisations who may provide to us personal data (Title , Full name, Qualifications, Professional Organisation Membership, Organisation ID or other unique identifier, Personal biographical information you wish to share) belonging to Therapists. 
Businesses, charities and unions  may provide client Email, Phone number, with data owners consent, as part of onboarding clients onto the Paranimo system.

If an existing user does refer you to Paranimo, Paranimo will send you a link to register via the email address provided by the referrer. If you do not want to join then ignore the link and your email address will be removed from our records after 3 days.

We are also able to manually begin the registration process for new Therapists who are in communication with Paranimo representatives. In this case, a Therapist must give the Paranimo representative a contact email address which will then be used by Paranimo to begin the registration process.

Why is data collected?

The legal basis of the uses of the information held about you are: 
Consent of the user
Where necessary to perform our contract with you 

The Paranimo platform essentially has two faces; the Therapist profiles and the Client profiles.

These have different purposes and so Therapist profile and Client profile data is used very differently.

For Therapist profile data is collected for:
Registration and login functionality
To advertise your skills and experiences on the site through a publicly viewable profile page
Processing bookings and payment
Management of your account and profile data

For Client profile data is collected for:
Registration and login functionality
To show a Therapist your name in advance of booking a therapy session, only viewable when Clients give permission to specific Therapists.
To process bookings and payment
Management of your account 

How will we process your data?

To deliver our service
These services include, but are not limited to:
Registration and Login
Creating your profile
Managing your profile
Advertising bookings availability
Managing your calendar
Making bookings
Paying for bookings
Having a video call

Communication:
If we need to notify you about changes to our service or platform.
Update you regarding any new features or new functionality of existing features.
Notifications regarding your communication with other users of the platform.
Notification about your scheduled events on the platform (for example, when a booking is made, payment confirmation, session reminders).Answer questions you may have for us and manage ongoing communication.

Analysis:
We will analyse how users interact with the website to make sure the functionality is  working as effectively as possible, is understood by our users, and is behaving as intended.
We will analyse usage of the platform to assess growth and inform how we develop the business.
Ensure that our service works effectively for your device and browser.
Assessing the effectiveness of therapy.

How do we share Personal Data

Sensitive personal data will not be shared with any third party unless you give permission except where obliged to do so by law, regulation, or legal process.

Only a Client’s chosen Therapist can see a Client's Name for as long as the Client gives them permission. 

In order to market each Therapist's skills, their profile pages are publically available and matching functionality can be usable by the public. 

Paranimo may share some piece of personal data with third parties in the following circumstances:
A personal identifier, such as User ID or email address, will be shared with third party service providers where the third party service is required for Paranimo’s core services.
Verification of professional organisations membership claims.F
or marketing purposes, only where you consent to this.
Where sharing data is necessary for protecting the rights or safety of the Parnaimo staff, partners or users.Where obliged to do so by law, regulation, or legal process.
Where required for producing legally compliant invoicing.

If Paranimo is acquired by a third party they will have to obtain consent to change your acceptance of these policies but personal data will be considered a transferable asset.

If any statements or feedback created by Clients is used by Paranimo for any kind of testimonial for marketing purpose this will be done following appropriate negotiation and consent.

We make use of third party software services to allow the platform to perform the services we need to operate. The third party organisations we are using to provide functionality required for the delivery of the services are:

Auth0. Auth0 provides the user authentication and authorisation services required for secure registration, login, and access controls. We are using Auth0 because they have excellent permission and access control which will allow detailed control over what users are able to see. You can review their privacy policy here: https://auth0.com/privacy/. We are using Auth0’s EU servers.

Stripe. Payment processing is performed by Stripe. They are one of the biggest payment processors and you will have to sign up to Stripe inorder to receive payments through the Paranimo platform. You can find their privacy policy here: https://stripe.com/gb/privacy.

Whereby. Whereby is an online communications service that provides the foundations for video conferencing and messaging systems. We use this service to create our virtual therapist rooms https://whereby.com/information/tos/privacy-policy/

Circleloop.
Our support number is supplied by a company called Circleloop. We use this service to have a single phone number which can be answered by multiple people supporting customers at Paranimo and can be used on various devices, not just a phone. You can review their privacy policy here: https://www.circleloop.com/privacy. They keep customer data in Amazon Web Service (AWS) (in Ireland and London). You can see their GDPR statement here:https://www.circleloop.com/gdpr.


All US based company Privacy Policies state they are compliant with the EU-US Privacy Shield. More information on this agreement can be found here: https://www.privacyshield.gov/welcome.

How do we store your data?

All customer data will be stored in the cloud on the AWS and accompanying services. We are currently using the region EU-west-1 Ireland within AWS. AWS GDPR information can be found here: https://aws.amazon.com/compliance/gdpr-center/.

We will do our best to ensure personal data is protected but we cannot guarantee security of personal data. Aside from the data required to register all other data is optional and does not need to be included to use the service but the addition of personal data is at your own risk.

We take appropriate administrative and technological measures to ensure personal data is protected. We limit data access based on who the information belongs to and the sensitivity of the data. Our staff will have the minimum contact with personal data in order to carry out their jobs. 

We will retain your information for only as long as is necessary to fulfil any of the services we provide or to comply with applicable legislation, regulatory requests and relevant orders from competent courts. This typically means 7 years but users can change or delete personal information at any time.

Account security

Whether provided by Parranimo or chosen by you, your login password is your responsibility to keep confidential. On all websites you have accounts with, you should endeavour to change your password regularly, use a strong password, never share your password with anyone, and use our multi factor authentication wherever possible. If you give other people access to your account, we have no way of knowing whether the information sent from your device originates from you or them. You cannot be sure they did not share this information. By agreeing to use the Paranimo platform, you accept that we will treat information sent from your account as your own.

You are solely liable for any order, payments, or any other transactions placed using your login information.

Please ensure that you sign out of your account when you are not using the platform. This can help prevent, for example, the unauthorised access of your account via a third party gaining access to your device while logged in.

Will your data be shared with others?

We will not share your personal data with any third party without your consent except in the case of third party software or service providers who are required for the functionality of the Paranimo platform.

Therapist data will be viewable as a freely accessed public profile to help a Therapist support as many Clients as they can. 

Client data will be only viewable to their own Therapist only after they have given consent to a Therapist. This consent can be withdrawn at any time through your profile. 

Where a client wishes to organise a phone based session without using the platform, instead by talking to a representative of Paranimo directly, Paranimo will pass a phone number to the Therapist to allow the session to take place.

Marketing

All marketing messages we send you are opt in. We will not send you anything without permission and if you wish to stop receiving marketing messages you can opt out at any time. (we need to have an unsubscribe link in emails).

We do not plan to contact our users with advertisements from third parties (non Paranimo users), if this policy changes we may ask you to agree to the new terms. We may want to share content created by Therapists who use the Platform. Subject to each user's stated consent, we may use your contact information to contact you to share such material.

Paranimo would like to contact you regarding changes within the platform, such as new features and updates.You can update your preferences at any time, either using the ‘unsubscribe’ link provided on all marketing emails, by logging into your Paranimo account, or by contacting us directly by phone or email.

Privacy policies of other Websites?

Our privacy policy only applies to action taken on our website.

Change to our privacy policy?

Our privacy policy is under regular review and will be updated on this webpage.

What are your data protection rights?

How to contact appropriate authorities
Data protection and personal data in the United Kingdom is regulated by the Information Commissioner’s Office (ICO) https://ico.org.uk.

As a user of our platform you are able to send specific requests to us in accordance with your data rights under GDPR. These include:
Your right to access: You can request to see all the personal data we hold about you. You also have the right request that we explain terminology we use if it is unclear.
Your right to rectification (this means correct inaccuracies): You have the right to request any data you believe to be inaccurate be corrected. You can also request we complete data you believe is incomplete.Your right to erasure: You have the right to ask us to delete data about you, under certain circumstances.
You have the right to restrict processing: You have the right to request that Paranimo restricts the processing of your personal data, under certain circumstances.
Your right to portability: You have the right to request that Paranimo transfer the data that we have collected to another organisation, or directly to you, under certain circumstances.
The right to object to processing: You have the right to object to Paranimo processing your personal data, under certain circumstances.

How to contact us

If you have any questions regarding our privacy policy, or to exercise your rights under data protection regulation, please contact us.

Email: support@paranimo.co.uk