Privacy Statement

Privacy Policy

Last edited August 2021

1.0 Introduction

1.1 The Paranimo platform is provided by Paranimo Limited (Company Number 11992617).

1.2 This policy will explain how Paranimo limited uses the personal data we collect from users when using our website. The security and privacy of our users’ personalusers personal data is central to our service and we want this document to give our users the confidence to use our platform without concern or anxiety.

1.3 The UK Data Protection Act 2018 sets out the data protection rights for UK citizens.  More information can be found here:

https://ico.org.uk/for-organisations/guide-to-data-protection/introduction-to-data-protection/about-the-dpa-2018/

1.4 This platform acts as a marketplace to facilitate therapists providing their services to clients and the matching of those seeking Mental Health support with those able to provide that Mental Health support. As such our user base is split into two user types: “Therapists” and “Clients”. A “Therapist” is a Mental Health support provider and a “Client” is someone looking for Mental Health support.

1.6 The data required for each user is different and is required by us for different reasons, which we will aim to set out in this document.

2.0 Our general principles for personal data collection and processing

2.1 We will keep personal data collection to the absolute minimum required to provide our service.

2.2 We only collect personal data for specified, explicit and legitimate purposes.

2.3 We will only use personal data for purposes stated herein, and will gain permission before making any change to those stated purposes.

2.4 We will transfer data to third parties where the third party provides the functionality required for delivery of our services. These services are described in section 7.8. Where the third party is a client’s therapist, the client will have to give consent to begin and sustain the engagement. 

2.5 We will maintain organisational and technical procedures to allow you to exercise your rights under the law.

2.6 We will maintain organisational and technical procedures to ensure all data is kept securely and lawfully.

3.0 What data will we collect?

3.1 Age Restriction

3.2 We do not knowingly collect personal data from individuals under the age of 18 years old. This is why we need this data to be given to us. If you are under 18 years of age you cannot use this service or give us your personal data.

3.3 By using our services, you are confirming that you are at least 18 years old.

3.4 Paranimo collects the following data:

3.5 We only collect data that is required for either the running of the platform or which could be useful in establishing a connection between a Client and a Therapist and help facilitate delivery of a Therapist’s service.

3.6 A client looking for Mental Health support will only need to provide an email address, password, and a phone number. Clients can choose a display name for use on the platform. This display name can be a real name or an invented pseudonym if the client wishes to remain anonymous. Every other piece of data provided by a Client will be optional. You can keep everything else blank and only tell a Therapist what you feel comfortable with over a secure video call. 

3.7 Though the only personal data required is registration information, the effectiveness of the Paranimo service may be reduced if you do not wish to share other personal data. 

3.8 The following personal data is required for registration and authentication purposes.

3.8.1 Personal identifiable data required for registration of all users:

  • 3.8.1.1 Email
  • 3.8.1.2 Password

3.8.2 Clients can also choose a display name, this can be changed or set to a random ID.

3.8.3 Therapists will be expected to provide more personal information to prove they are trained to provide mental health support effectively. This includes:

  • 3.8.3.1 Full name
  • 3.8.3.2 Professional Organisation Membership and Organisation ID or other unique identifier if requested
  • 3.8.3.3 Personal biographical information you wish to share

3.8.4 All client personal data, described below, are optional. These fields may contain special category data under the GDPR. The data which are currently, or planned to be, requested:

  • 3.8.4.1 Personal biographical information you wish to share with a Therapist
  • 3.8.4.2 Mental Health Goals
  • 3.8.4.3 Frustrations
  • 3.8.4.4 Profile pictures
  • 3.8.4.5 Medical and mental health information

3.8.5 Therapists may also have the option to supply Paranimo with profile images and video content for use on their profile.

3.8.6 If a client contacts Paranimo directly to organise a phone based session Paranimo will need to collect a phone number to allow the session to take place and may also need a name or ID if the client is a member of a Paranimo Connect Scheme.

3.9 By providing such data you are consenting to the data being used and processed by us.

3.10 Correspondence, or a record of correspondence, is kept if you should contact either the Paranimo business or another user through the platform.

3.11 We will use Mixpanel to record session information. This data will be stored by Mixpanel and accessed by Paranimo through their platform dashboard. When a user is logged in to Paranimo, Mixpanel will have access to a unique authentication ID so we can identify registered users from non registered users and an email address to allow us to respond to customer support tickets by checking a users activity. It will also see display names and email addresses so we can coordinate customer support and examine how users are using the platform. Information we use includes:

  • 3.11.1 Operating system – For the purposes of best fixing issues reported to customer support
  • 3.11.2 Browser – For the purposes of best fixing issues reported to customer support
  • 3.11.3 Timestamps  – For the purposes of best fixing issues reported to customer support
  • 3.11.4 Page requests  – For the purposes of best fixing issues reported to customer support
  • 3.11.5 Location data – Our service is restricted to the UK.

3.12 Mixpanel will also record details of actions you carry out through the platform. This includes information about video call length, start times, stop time, and participant IDs. This information will be required for handling refund requests where a therapist failed to turn up to an appointment. This will also include information such as when you begin registration, complete registration, begin the booking process, select a available time slot, beginning and complete payment processing, cancelling a session, rescheduling a session, and when a therapist changes their matching profile information. This information is required for dealing with customer support issues and questions and to investigate any unauthorised actions reported on a user’s account.

3.13 We will never record any content from video call sessions.

3.14 Telephone calls made to our support number (0333 090 1772) are recorded for compliance, quality control, and staff training purposes. This data is stored by Circleloop.

3.15 Where information is supplied to us through third parties, we ensure by contract that GDPR compliant consent exists.

4.0 How do we collect your data?

4.1   Personal data may be  voluntarily given to Paranimo by you, through the website, or as meta-data passed to us through the standard data flows in online communication.

4.2   We may receive personal data (email only) via referrals, where someone that knows your email address may suggest you join the platform.

4.3   We may also receive personal data from:

4.3.1 Other professional organisations who may provide to us personal data (Title , Full name, Qualifications, Professional Organisation Membership, Organisation ID or other unique identifier, Personal biographical information you wish to share) belonging to Therapists

4.3.2  Charities and unions (who may provide client Age, Email, Phone number and/or membership profiles, with data owners consent).

4.4   If an existing user does refer you to Paranimo, Paranimo will send you a link to register via the email address provided by the referrer. If you do not want to join then ignore the link and your email address will be removed from our records after 3 days.

4.5  We are also able to manually begin the registration process for new Therapists who are in communication with Paranimo representatives. In this case, a Therapist must give the Paranimo representative a contact email address which will then be used by Paranimo to begin the registration process.

5.0 Why is data collected?

5.1 The legal basis of the uses of the information held about you are: 

5.1.1 Consent of the user

5.1.2 Where necessary to perform our contract with you 

5.2 The Paranimo platform essentially has two faces; the Therapist profiles and the Client profiles. These have different purposes and so Therapist profile and Client profile data is used very differently.

5.3 For Therapist profile data is collected for:

  • 5.3.1 Registration and login functionality
  • 5.3.2 To advertise your skills and experiences on the site through a publicly viewable profile page
  • 5.3.3 Processing bookings and payment
  • 5.3.4 Management of your account and profile data

5.4 For Client profile data is collected for:

5.4.1 Registration and login functionality

5.4.2 To show a Therapist data about you in advance of booking a therapy session to inform their support through a private profile page, only viewable when Clients give permission to specific Therapists.

5.4.3 To process bookings and payment

5.4.4 Management of your account and profile data

6.0 How will we process your data?

6.1 To deliver our service

6.1.1These services include, but are not limited to:

  • 6.1.1.1 Registration and Login
  • 6.1.1.2 Creating your profile
  • 6.1.1.3 Managing your profile
  • 6.1.1.4 Advertising bookings availability
  • 6.1.1.5 Managing your calendar
  • 6.1.1.6 Making bookings
  • 6.1.1.7 Paying for bookings
  • 6.1.1.8 Having a video call

6.2 Communication:

6.2.1 If we need to notify you about changes to our service or platform.

6.2.2 Update you regarding any new features or new functionality of existing features.

6.2.3 Notifications regarding your communication with other users of the platform.

6.2.4 Notification about your scheduled events on the platform (for example, when a booking is made, payment confirmation, session reminders).

6.2.5 Answer questions you may have for us and manage ongoing communication.

6.3 Analysis:

6.3.1 We will analyse how users interact with the website to make sure the functionality is  working as effectively as possible, is understood by our users, and is behaving as intended.

6.3.2 We will analyse usage of the platform to assess growth and inform how we develop the business.

6.3.3 Ensure that our service works effectively for your device and browser.

6.3.4 Assessing the effectiveness of therapy.

7.0 How do we share Personal Data

7.1 Sensitive personal data will not be shared with any third party unless you give permission except where obliged to do so by law, regulation, or legal process.

7.2 Only a Client’s chosen Therapist can see a Client’s profiles (which may contain special category data) for as long as the Client gives them permission. If user uses the “ask a counsellor”, the counsellor will be able to see the users registered email address in order to reply to the users questions.

7.3 Client personal information displayed on the profile page, intended to be viewed by therapists, is encrypted and is only shared with Therapists using the platform, who the client has consented to share information with. Paranimo staff will only be able to decrypt sensitive information displayed on a clients profile page when;

  • 7.3.1. Given permission to do so.
  • 7.3.2. Required to do so by law or regulation.
  • 7.3.3. Where it is in the public interest, or necessary for scientific or statistical purposes (and in accordance with governing legislation).

7.4 In order to market each Therapist’s skills, their profile pages are publicly available and matching functionality can be usable by the public. 

7.5 Paranimo may share some piece of personal data with third parties in the following circumstances:

7.5.1 A personal identifier, such as User ID or username, or email address, will be shared with third party service providers where the third party service is required for Paranimo’s core services.

7.5.2 Verification of professional organisations membership claims.

7.5.3 For marketing purposes, only where you consent to this.

7.5.4 Where sharing data is necessary for protecting the rights or safety of the Parnaimo staff, partners or users.

7.5.5 Where obliged to do so by law, regulation, or legal process.

7.5.6 Where required for producing legally compliant invoicing.

7.6 If Paranimo is acquired by a third party they will have to obtain consent to change your acceptance of these policies but personal data will be considered a transferable asset.

7.7 If any statements or feedback created by Clients is used by Paranimo for any kind of testimonial for marketing purpose this will be done following appropriate negotiation and consent.

7.8 We make use of third party software services to allow the platform to perform the services we need to operate. The third party organisations we are using to provide functionality required for the delivery of the services are:

7.8.1 Auth0. Auth0 provides the user authentication and authorisation services required for secure registration, login, and access controls. We are using Auth0 because they have excellent permission and access control which will allow detailed control over what users are able to see. You can review their privacy policy here: https://auth0.com/privacy/. We are using Auth0’s EU servers.

7.8.2 Mixpanel. Mixpanel is used to analyse the usage of the platform and the way users interact with Paranimo. We use this data for investigating issues raised to customer support and to check user data in the case such as rescheduling or cancellations, or analyse user activity, for example to investigate suspicious usage. You can review their privacy policy here: https://mixpanel.com/legal/privacy-policy/. We are using Mixpanel’s EU based data center, which is located in the Netherlands.

7.8.3 Stripe. Payment processing is performed by Stripe. They are one of the biggest payment processors and you will have to sign up to Stripe inorder to receive payments through the Paranimo platform. You can find their privacy policy here: https://stripe.com/gb/privacy.

7.8.4 Freshworks. To manage customer support tickets we use a service called Freshworks. They provide a service called Freshdesk which integrates with our support email address and tracks our progress fixing any issues and answering questions to ensure we get back to everyone effectively. They also host content such as support articles where we explain how the website works and how to use the features. You can review their privacy policy here: https://www.freshworks.com/privacy/.

7.8.4 Sendgrid. To send notification emails at the right time we use a service called Sendgrid. Sendgrid is part of Twilio. They specialise in sending electronic communications of many forms but we are specific using them to send timed emails to notify everyone about events such as bookings, reschedules, cancellations, and reminders for sessions one day, one hour, and 15 minute before their scheduled start times. You can view the privacy policy of Twilio/Sengrid here: https://www.twilio.com/legal/privacy.

7.8.5 Twilio. Twilio is an online communications service that provides the foundations for video conferencing and messaging systems. We use this service to create our virtual therapist rooms. They own Sendgrid and their privacy policy is linked in section 7.8.6.

7.8.6 Circleloop. Our support number is supplied by a company called Circleloop. We use this service to have a single phone number which can be answered by multiple people supporting customers at Paranimo and can be used on various devices, not just a phone. You can review their privacy policy here: https://www.circleloop.com/privacy. They keep customer data in Amazon Web Service (AWS) (in Ireland and London). You can see their GDPR statement here:https://www.circleloop.com/gdpr.

7.9.7 PaymentRails. Paymentrails is a service to automate the payout of payments to many recipients. We use this service to send payments out to therapists working with our business customers. The Paymentrails UK Privacy Policy can be found here:

https://www.paymentrails.com/privacy-uk/

7.1.8 All US based company Privacy Policies state they are compliant with the EU-US Privacy Shield. More information on this agreement can be found here: https://www.privacyshield.gov/welcome.

8.0 How do we store your data?

8.1 All customer data will be stored in the cloud on the AWS and accompanying services. We are currently using the region EU-west-1 Ireland within AWS. AWS GDPR information can be found here: https://aws.amazon.com/compliance/gdpr-center/.

8.2 We will do our best to ensure personal data is protected but we cannot guarantee security of personal data. Aside from the data required to register all other data is optional and does not need to be included to use the service but the addition of personal data is at your own risk.

8.3 We take appropriate administrative and technological measures to ensure personal data is protected. We limit data access based on who the information belongs to and the sensitivity of the data. Our staff will have the minimum contact with personal data in order to carry out their jobs. 

8.4 We will retain your information for only as long as is necessary to fulfill any of the services we provide or to comply with applicable legislation, regulatory requests and relevant orders from competent courts. This typically means 7 years but users can change or delete personal information at any time.

9.0 Account security

9.1 Whether provided by Parranimo or chosen by you, your login password is your responsibility to keep confidential. On all websites you have accounts with, you should endeavour to change your password regularly, use a strong password, never share your password with anyone, and use our multi factor authentication wherever possible. If you give other people access to your account, we have no way of knowing whether the information sent from your device originates from you or them. You cannot be sure they did not share this information. By agreeing to use the Paranimo platform, you accept that we will treat information sent from your account as your own.

9.2 You are solely liable for any order, payments, or any other transactions placed using your login information.

9.3 Please ensure that you sign out of your account when you are not using the platform. This can help prevent, for example, the unauthorised access of your account via a third party gaining access to your device while logged in.

10.0 Will your data be shared with others?

10.1 We will not share your personal data with any third party without your consent except in the case of third party software or service providers who are required for the functionality of the Paranimo platform.

10.2 Therapist data will be viewable as a freely accessed public profile to help a Therapist support as many Clients as they can. 

10.3 Client data will be only viewable to their own Therapist and only after they have given consent to making their profile viewable to a Therapist. This consent can be withdrawn at any time through your profile. All profile data will be encrypted.

10.4 Where a client wishes to organise a phone based session without using the platform, instead by talking to a representative of Paranimo directly, Paranimo will pass a phone number to the Therapist to allow the session to take place.

11.0 Marketing

11.1 All marketing messages we send you are opt in. We will not send you anything without permission and if you wish to stop receiving marketing messages you can opt out at any time. (we need to have an unsubscribe link in emails)

11.2 We do not plan to contact our users with advertisements from third parties (non Paranimo users), if this policy changes we may ask you to agree to the new terms. We may want to share content created by Therapists who use the Platform. Subject to each user’s stated consent, we may use your contact information to contact you to share such material.

11.3 Paranimo would like to contact you regarding changes within the platform, such as new features and updates.

11.4 You can update your preferences at any time, either using the ‘unsubscribe’ link provided on all marketing emails, by logging into your Paranimo account, or by contacting us directly by phone or email.

12.0 Privacy policies of other Websites?

12.1 Our privacy policy only applies to action taken on our website.

13.0 Change to our privacy policy?

13.1 Our privacy policy is under regular review and will be updated on this webpage.

14.0 What are your data protection rights?

14.1 How to contact appropriate authorities

Data protection and personal data in the United KIngdom is regulated by the Information Commissioner’s Office (ICO) https://ico.org.uk.

14.2 As a user of our platform you are able to send specific requests to us in accordance with your data rights under GDPR. These include:

  • 14.3.1 Your right to access: You can request to see all the personal data we hold about you. You also have the right request that we explain terminology we use if it is unclear.
  • 14.3.2 Your right to rectification (this means correct inaccuracies): You have the right to request any data you believe to be inaccurate be corrected. You can also request we complete data you believe is incomplete.
  • 14.3.3 Your right to erasure: You have the right to ask us to delete data about you, under certain circumstances.
  • 14.3.4 You have the right to restrict processing: You have the right to request that Paranimo restricts the processing of your personal data, under certain circumstances.
  • 14.3.5 Your right to portability: You have the right to request that Paranimo transfer the data that we have collected to another organisation, or directly to you, under certain circumstances.
  • 14.3.6 The right to object to processing: You have the right to object to Paranimo processing your personal data, under certain circumstances.

15.0 How to contact us

15.1 If you have any questions regarding our privacy policy, or to exercise your rights under data protection regulation, please contact us.

Email: [email protected]

Cookies Policy

1.0 Introduction

1.1 We want to be transparent with our policy regarding our use of cookies. 

1.2 This document explains our cookie policy, specifically explaining: 

  • 2.0 What cookies are
  • 3.0 How we use cookies
  • 4.0 How to manage your cookies

1.3 We hope this explains everything but if you have any questions, please feel free to contact us at [email protected]. The cookie policy described herein applies to the Paranimo subdomains app.paranimo.co.uk, therapist.paranimo.co.uk, and admin.paranimo.co.uk.

2.0 What are Cookies?

2.1 Cookies are text files stored on your browser to collect data and log certain visitor behaviour data. When you visit a site, cookies can be used to track things such as what users do and make sure users are interacting with the site in the way it was planned. They are also used to hold login information to authenticate a user has logged in or to check authorisation to perform action within the website.

2.2 Most browsers automatically accept cookies but this can be changed in your browser settings. They are often important to a website’s security and functionality though, so be aware that disabling them might stop the website from working properly.

2.3 For further data, visit:

www.allaboutcookies.org

www.yourchoicesonline.eu

www.networkadvertising.org

2.4 Third party cookies managing apps and browser plugs also exist that allow you to control cookies on your device.

3.0 How do we use Cookies?

3.1 We use a service called Cookiehub to manage Cookies. You can view the Cookies we use and set permissions for which cookies you consent to using by selecting the Cog icon in the bottom left of the page.

4.0 How to manage your cookies?

4.1 You can manage use of or disable cookies in your specific browsers settings. The default behaviour of most browsers is to allow cookies so unless you specifically disable cookies, or use a browser that disables cookies by default, cookies will be used while you are browsing the internet. This includes the Paranimo platform which will issue cookies to your browser. Disabling this function will likely prevent you from using some website functionality.

4.2 Some browsers allow you to give consent for each cookie being used. This will give you more control but will affect your user experience.

4.3 If you disable cookies from Paranimo you will prevent the register and login process from working and will not be able to use the platform.

4.4 Guides for managing cookies for the most common browsers can be found below. If you choose to disable cookies, some features of our Site or Services may not operate as intended.

Chrome: https://support.google.com/chrome/answer/95647?hl=en

Explorer: https://support.microsoft.com/en-us/help/17442/windows-internet-explorer-delete-manage-cookies

Safari: https://support.apple.com/guide/safari/manage-cookies-and-website-data-sfri11471/mac

Firefox: https://support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer

Opera: https://help.opera.com/en/latest/web-preferences/#cookies