Privacy Policy
Effective Date: 15 September 2026
1. Introduction
This Privacy Policy applies to your use of the Spectrum.Life App (the “App”) and associated services delivered across the UK and Ireland. It explains how Spectrum.Life collects, uses, and protects your personal data and outlines your rights under data protection laws.
Data Controllers:
- In Ireland: Spectrum Wellness Limited (Company Registration No. 555787), registered office at 38-39 Fitzwilliam Square W, Dublin 2, D02 NX53, Ireland.
- In the UK: Spectrum Wellness UK Limited (Company Registration No. 11815511), registered office at Habib House, 9 Stevenson Square, Manchester, M1 1DB, United Kingdom.
Spectrum.Life entities act as independent controllers. Each entity determines its own purposes and means of processing in accordance with applicable data protection law.
2. Service Types and Providers
Spectrum.Life delivers services either directly or via trusted third-party providers (“Facilitated Services”). The data controller(s) involved vary by service type and jurisdiction.
| Service Type | Delivery Model | Data Controller(s) |
| Mental Health Services | Direct / Facilitated | Spectrum.Life |
| Nutrition & Dietetics | Facilitated | Spectrum.Life + Partner |
| Physiotherapy | Facilitated | Spectrum.Life + Partner |
| Coaching / Webinars | Direct | Spectrum.Life (UK or IE) |
| Financial Wellbeing | Facilitated | Partner |
3. Personal Data We Collect
- Identity and contact details
- Appointment and booking history
- Health and wellbeing data
- Device and App usage data
- Communications and feedback
4. Legal Basis for Processing
We process personal data under:
- Consent (Article 6(1)(a))
- Contractual necessity (Article 6(1)(b))
- Legal obligation (Article 6(1)(c))
- Vital interests (Article 6(1)(d))
- Legitimate interests (Article 6(1)(f))
- Provision of health care (Article 9(2)(h))
- Public health and safeguarding (Article 9(2)(c))
5. How We Use Your Data
- To deliver clinical and wellbeing services
- To manage bookings and appointments
- To facilitate communications with providers
- To analyse service usage and outcomes
- To improve platform security and functionality
6. Data Sharing
Your data may be shared with:
- Partnered health and wellness providers, only for service delivery
- Technology providers under strict access controls
- Clients or partners only in anonymised, aggregated form
- Legal or regulatory authorities where required
We never share identifiable health or clinical data with your employer.
Clinical Referrals Across Service Arrangements
Where you access services through a programme provided by a third party (such as an employer insurer or group protection scheme), and a Spectrum.Life clinician determines during that engagement that your clinical needs would be better met by a service delivered under a separate Spectrum.Life arrangement, we may use the personal data you have provided to facilitate that onward referral. We do this on the basis of performing our contract with you (Article 6(1)(b)) – when you contact Spectrum.Life for support, it is our role to route you to the right service for your needs, and that obligation exists regardless of which commercial arrangement a particular service sits under. Where your referral involves health data, we process that data for the purpose of providing healthcare to you (Article 9(2)(h)). You will be informed by your clinician at the point any such referral is made, and you may decline at any time. No identifiable data will be shared with your employer or insurer as a result of any such referral.
7. International Transfers
All data is stored within the UK or EEA. Any transfers outside these regions are subject to safeguards such as Standard Contractual Clauses (SCCs).
8. Data Security
- Encryption at rest and in transit
- Role-based access controls
- Secure hosting infrastructure (ISO 27001-aligned)
- Regular audits and incident response procedures
9. Your Rights
You may:
- Access your data
- Request rectification or erasure
- Withdraw consent
- Restrict or object to processing
- Request data portability
To exercise your rights, email gdprspectrumlife@spectrum.life.
10. Sector-Specific Data Processing Activities
10.1 Insurance Clients
- Data processed under consent, contract, and legitimate interests
- Shared with insurers only where necessary (e.g., underwriting, fraud prevention)
- Governed by DPA 2018, Schedule 1, Part 2 (Paragraphs 14 & 20)
- Shared data is typically pseudonymised or aggregated
10.2 Education Clients
- Processed under contract and legal obligation (Article 6(1)(c), 9(2)(h))
- Safeguarding or crisis data under vital interest (6(1)(d), 9(2)(c))
- Retention and consent practices reflect age and safeguarding laws
Funded referral programmes – discharge report sharing
Where you access services through a funded referral from your educational institution, a discharge report will be shared with your institution’s student wellbeing team at the close of your course of support. This applies where you are assessed as outside the criteria for the service and signposted to alternative support, and where you progress through a course of counselling and complete any or all of your sessions.
- The discharge report includes the following information:
- A brief summary of the nature of support provided
- Session dates, whether all sessions were completed, and the reason for non-completion where applicable
- A brief statement of therapeutic progress
- Pre- and post-intervention scores for standardised outcome measures (GAD-7, PHQ-9, and CORE-10)
- Any identified risk issues
- Whether additional support from your institution’s wellbeing team is recommended, with a brief rationale where applicable
The discharge report does not include session-by-session clinical notes, therapeutic discussions, disclosures, formulations, or interventions.
The lawful basis for sharing this information with your institution is Article 9(2)(h) of the UK GDPR – the provision of health and social care – and Article 6(1)(c) – legal obligation. You will be informed of this sharing arrangement by your institution’s wellbeing team before the referral is made, and through this Privacy Notice.
10.3 Workplace Clients
- Processed under contract and legitimate interest (Article 6(1)(b), 6(1)(f))
- Only anonymised, aggregated data shared with employers
- No special category data shared with employers
- Records retained according to clinical and legal standards
10.4 Marketing Communications
Where you are an existing client or an employee enrolled in one of our wellbeing or EAP programmes with an active Spectrum.Life account, we may use your name and work email address to send you relevant updates about Spectrum.Life’s services, programme information, and service improvements.
We use Intercom Fin, an AI-powered communications platform, to deliver some of these communications. Intercom Fin may use information about the services you are enrolled in to personalise message content. It does not use health or clinical data for this purpose. Only your name, email address, and marketing preference are shared with Intercom for this purpose.
The lawful basis for this processing is your consent (Article 6(1)(a)) for enrolled programme participants who have opted in, and our legitimate interests (Article 6(1)(f)) for existing business contacts receiving updates about services contracted by their organisation. A Legitimate Interests Assessment has been completed and is available from our DPO on request.
Your marketing preference is set to opted out by default when you register. You can opt in at any time during the appointment booking process or through your account preferences. You may withdraw your consent or opt out of marketing at any time by clicking the unsubscribe link in any communication you receive from us, or by updating your preferences in your account settings. Your preference will be updated immediately across all of our systems.
Intercom, Inc. processes your name and work email address as our data processor under a Data Processing Agreement. Intercom is based in the United States. The transfer of your data to Intercom is covered by the EU–US Data Privacy Framework (for EU data subjects) and the UK Extension to the US Data Privacy Framework (for UK data subjects), supplemented by Standard Contractual Clauses. EU and UK client data is hosted within the EU region. Further details about Intercom’s data practices are available at intercom.com/legal/privacy.