Privacy Policy

Effective date to 8 July 2026

Introduction

Spectrum.Life (“Spectrum.Life”, “we”, “us”, or “our”) respects your privacy and the confidentiality of your personal data. This Privacy Notice explains how we collect, use, store, share and protect your personal data when you use any of our services, visit our websites or mobile applications, or interact with us.

We have written this Notice in plain language while keeping it legally robust. It is designed to cover all the services we provide in the United Kingdom and Ireland, across all audiences we serve – including users of services provided via an employer, educational institution or insurer, website visitors, customers, and business contacts.

This Notice reflects our obligations under the EU General Data Protection Regulation (GDPR), the UK GDPR, the Data Protection Act 2018, the ePrivacy Regulations, the EU Digital Services Act, the EU NIS2 Directive, the EU Artificial Intelligence Act, and other applicable laws. By using any of our services, you acknowledge the terms set out here.

Who We Are

Spectrum Wellness Limited (trading as Spectrum.Life) and Spectrum Wellness UK Limited are the entities responsible for processing your personal data, depending on where you are based.

  • Ireland: is Spectrum Wellness Limited (Company Registration No. 555787), registered office at 38-39 Fitzwilliam Square W, Dublin 2, D02 NX53, Ireland.
  • United Kingdom: The Data Controller is Spectrum Wellness UK Limited (Company Registration No. 11815511), registered office at Habib House, 9 Stevenson Square, Manchester, M1 1DB, United Kingdom.

We determine the purposes and means of processing your personal data (acting as “controller”) for most of the services we provide directly to you. In some cases – for example, where we deliver services on behalf of a client organisation such as an employer, college or insurer – we may act as a “processor”, processing your personal data strictly under the client organisation’s instructions. Where this applies, the client organisation is the controller and their own privacy notice governs the processing, alongside this one.
Where we deliver clinical services through an independent clinical partner – for example, where an affiliate clinician or specialist provider delivers physiotherapy, counselling or other referral services – that partner typically acts as a data processor, processing your personal data on our instructions and under our contractual controls. In limited cases, where a partner operates entirely within their own systems and under their own clinical governance (for example, a diagnostic testing provider), they may act as an independent data controller for the services they deliver directly to you. Where this applies, we will make the arrangement clear to you at the point of referral.

Data Protection Officer

We have appointed a Data Protection Officer (DPO) who is responsible for overseeing compliance with this Notice and with data protection law. You can contact the DPO for any privacy-related query or to exercise your rights:

  • Email: gdprspectrumlife@spectrum.life
  • Post: Data Protection Officer, Spectrum Wellness Limited, 38-39 Fitzwilliam Square W, Dublin 2, D02 NX53, Ireland.

Supervisory Authorities

  • Ireland: You have the right to lodge a complaint with the Data Protection Commission (DPC) – www.dataprotection.ie.
  • United Kingdom: You have the right to lodge a complaint with the Information Commissioner’s Office (ICO) – www.ico.org.uk.

We would appreciate the opportunity to address any concerns directly before you contact a regulator, but you can contact a supervisory authority at any time.

Services Covered by This Notice

This Notice applies to all Spectrum.Life services delivered in the United Kingdom and Ireland, including but not limited to:

  • Employee Assistance Programme (EAP):24/7 workplace wellbeing and short-term counselling services for employees of our client organisations.
  • Student Assistance Programme (SAP): Counselling and wellbeing support for students of partner educational institutions.
  • Coaching : Wellbeing, life, executive and health coaching programmes.
  • Clinical Services:Clinical counselling, psychotherapy, digital psychologist support and related health services delivered by qualified professionals.
  • Virtual Primary Care (Digital GP / Virtual GP and Advanced Nurse Practitioner services): Remote GP and ANP consultations, including prescription and onward referral. “Digital GP” and “Virtual Primary Care” (VPC) refer to the same underlying service.
  • Digital Mental Health (DMH) and iCBT: Self-guided digital programmes, including internet-based Cognitive Behavioural Therapy.
  • Neurodiversity Assessments: Online neurodiversity screening and clinical assessment services.
  • Online Physiotherapy: Remote physiotherapy consultations and programmes delivered by qualified practitioners.
  • Adult and Elder Care Signposting: Information and signposting to support caring responsibilities (non-clinical).
  • Legal Information Support: General legal information services (non-advisory).
  • Financial Wellbeing Support: Financial wellbeing information, guidance, and referral to regulated financial or retirement planning partners.
  • Structured Counselling and Professional Referrals: Onward referral to vetted independent clinicians or specialist services.
  • Workshops and Training: Wellness workshops, webinars and educational sessions.
  • Wellbeing Content: Articles, videos, podcasts and related content on our platforms.
  • Life Mobile App: Our mobile application providing access to the services listed above.
  • Life Web Platform: Our websites and web portals providing access to the services listed above.
  • Transcription (Heidi AI): Optional AI-assisted clinical documentation for certain sessions, as described in Section 9.
  • Future Services: Any new services we introduce are covered by this Notice unless we tell you otherwise.

Where a specific service has additional privacy considerations (for example, EAP confidentiality towards your employer, or duty-of-care arrangements in SAP), we have called these out in Section 12.

Personal Data We Collect

We only collect the personal data we need to provide our services and to meet our legal, regulatory and contractual obligations. The types of personal data we may process are summarised below.

  • Identity Data:Name, date of birth, gender, and the organisation you are associated with (for example, your employer, college or insurer).
  • Contact Data:Email address, phone number and postal address.
  • Health and Wellbeing Data:Information relating to your health, wellbeing or mental health that you share with us during clinical, coaching or support interactions. This includes medical history, symptoms, assessment scores, clinician notes and prescription information (special category data under GDPR / UK GDPR).
  • Technical Data:IP address, device type, operating system, browser, unique device identifiers and usage logs collected automatically when you use our apps or websites.
  • Usage Data:Information about how you interact with our services – pages or features used, content viewed, clicks, sessions, crash reports, engagement statistics.
  • Transaction and Billing Data:Invoice references, payment confirmations and limited financial information where you pay us directly for a service. Card data is handled by our PCI-DSS accredited payment processor and is not stored by us.
  • Communication Data:The content of messages you send to us or through our services – including emails, chat messages, SMS, support tickets, forum or community posts and survey or feedback responses.
  • Audio and Transcript Data: We may record calls or voice sessions for quality, training and safeguarding purposes; where we do, recordings are retained for up to 12 months before secure deletion. Separately, where you and your clinician agree to use AI-assisted transcription, short-lived audio from that session is processed solely to generate a draft transcript. Only clinician-approved notes are saved to your record; the audio is deleted once transcription is complete. You may decline AI-assisted transcription at any time without affecting your access to the underlying service.
  • Profile Data:Username, avatar, goals, preferences and other information you add to your account.
  • Cookies and Tracking Data:Information collected via cookies, pixels and similar technologies, as described in Section 11.
  • Service-Specific Data:Some services require particular information – for example, prescription details for Virtual Primary Care, neurodiversity assessment responses, or workshop attendance. We will always tell you at the point of collection what information is needed.

Where you integrate a third-party app or device (for example, a fitness tracker), we only receive and use the data you have authorised, and only for the purposes of the service you have chosen.

How We Collect Your Data

  • Directly from you:When you register, complete a wellbeing assessment, attend a session, contact support, or otherwise interact with us.
  • Through your use of our Services:Technical and usage data are collected automatically through cookies, analytics and similar technologies.
  • From your sponsoring organisation:Your employer, educational institution or insurer may share identity and contact details with us to enable your access to the services they provide you.
  • From healthcare providers or referral partners:For example, a GP, student support team or partner clinician may share relevant information with your consent to facilitate a referral or continuity of care.
  • From integrated third-party apps or devices:Where you choose to connect a third-party service (for example, Apple Health, Google Fit or Fitbit), we receive the data you authorise.

How we use your data

We use your personal data for the following purposes. Each purpose is underpinned by a lawful basis, as set out in Section 7.

  • To deliver our services and manage your account:Registering you, authenticating you, scheduling and delivering sessions, providing clinical or coaching interventions, and giving you access to content.
  • To provide Virtual Primary Care and related clinical services:Taking a clinical history, conducting consultations, issuing prescriptions and making onward referrals, in line with professional clinical standards.
  • To provide optional AI-assisted clinical documentation:Where you and your clinician agree, processing short-lived audio to create a draft transcript or summary that a clinician reviews before it is saved to your record (see Section 9).
  • To personalise your experience:Tailoring content and recommendations based on your preferences and interaction history.
  • To communicate with you:Sending service-related messages (appointment reminders, Notice updates, security alerts) and – where you have opted in – newsletters and promotional communications.
  • To maintain and improve our services:Analysing usage, debugging issues, developing features and improving performance and accessibility. Where feasible we use aggregated or pseudonymised data.
  • To ensure security and compliance:Detecting and preventing fraud or misuse, securing our systems and infrastructure, and meeting obligations under data protection, cyber-security and clinical governance rules.
  • To meet legal and contractual obligations: For example, retaining financial records for tax and audit, responding to lawful requests from authorities, or fulfilling a contract with your sponsoring organisation.
  • To operate insurance-funded services and manage billing:Where your service is funded through a private medical insurer, confirming eligibility and processing invoices, and managing any shortfall billing as described in Section 12.
  • To conduct research and analytics:Using aggregated or pseudonymised data to analyse outcomes and publish trends. We would only use data that could identify you for research with your explicit consent or under another appropriate legal basis.
  • For marketing (with consent):Sending you information about our services that we think may interest you. See Section 17.

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider we need to use it for another compatible purpose and are permitted by law. If we need to use your data for an unrelated purpose, we will inform you and explain the legal basis first.

Legal Bases for Processing

Depending on the context, one or more of the following lawful bases under GDPR and UK GDPR will apply.

  • Performance of a contract (Article 6(1)(b)):Where processing is necessary to deliver a service you have requested, or to carry out pre-contractual steps at your request.
  • Consent (Article 6(1)(a)) and Explicit Consent (Article 9(2)(a)):Where you have given us clear, specific, informed and freely-given consent – for example, for marketing communications, optional integrations, optional AI-assisted transcription, and certain processing of special category data outside the healthcare context.
  • Legitimate interests (Article 6(1)(f)):Where processing is necessary for our legitimate interests (or those of a third party) and not overridden by your rights – for example, to secure our platforms, to improve our services, or to communicate with business contacts. We balance our interests against your rights each time we rely on this basis.
  • Legal obligation (Article 6(1)(c)):Where we need to process data to comply with a legal or regulatory obligation (for example, tax law, clinical record-keeping obligations, or safeguarding duties).
  • Vital interests (Article 6(1)(d)):In rare, emergency situations where processing is needed to protect your life or the life of someone else.
  • Provision of health or social care (Article 9(2)(h)):For the processing of health data by or under the responsibility of a health professional or someone subject to an equivalent duty of confidentiality – this is our primary basis for processing special category clinical data.
  • Employment and social protection (Article 9(2)(b)):Where necessary for our client organisation to meet obligations or exercise rights in employment or social protection law (for example, certain EAP contexts).

We may rely on different bases concurrently for different aspects of the same processing. We ensure a valid basis applies to every activity.

Special Category Data (Health and Mental Health Information)

Many Spectrum.Life services involve health and mental health data. This is “special category” data under GDPR and UK GDPR and receives additional protection.

  • Who accesses it:Only authorised clinicians, coaches, clinical supervisors and – on a strict need-to-know basis – named technical support staff. All staff are bound by confidentiality obligations, and clinicians are additionally bound by the standards of their professional regulator.
  • What we do with it:We use health and mental health data to deliver the services you have requested, to ensure your safety, to meet our contractual and legal obligations, and (in limited circumstances) to report anonymised aggregate statistics to a sponsoring organisation. We do not use your health or sensitive data for marketing or advertising.
  • Transcription:Where AI-assisted transcription is used in a clinical session, processing is carried out by or under the responsibility of clinicians bound by confidentiality. You may decline transcription at any time without affecting access to the underlying service.
  • Clinical partners:Where clinical services are delivered through an independent clinical partner, they remain bound to the same confidentiality and security standards, and we make the partner arrangement clear to you.

Artificial Intelligence in Our Services

Spectrum.Life uses artificial intelligence (AI) to support – not to replace – the people who deliver our services. This section explains how we use AI today, how we may use it in future, and the safeguards we apply. It reflects our obligations under the EU AI Act, GDPR / UK GDPR and relevant clinical governance standards.

Our guiding principles

  • Human oversight first:Any output from an AI system that could materially affect you is reviewed by a suitably qualified human before it reaches your record, informs a clinical decision, or is acted upon.
  • No solely-automated decisions with significant effects:In line with Article 22 of GDPR / UK GDPR, we do not make decisions that produce legal or similarly significant effects on you based solely on automated processing, including profiling.
  • Purpose limitation:AI is only used for clearly defined purposes that support the delivery, safety and quality of our services.
  • No training on your data without lawful basis:We do not permit third-party AI providers to use your personal or clinical data to train their own general-purpose models. Any model improvement that uses your data is carried out under appropriate contractual controls, with your rights preserved.
  • Transparency:Where AI is used in a way that directly affects your experience, we tell you – at the point of use where practical.
  • Data protection by design:We carry out Data Protection Impact Assessments (DPIAs) and, where required, AI-specific assessments before deploying AI systems that process personal data.

Current uses of AI

  • Clinical documentation assistance (Heidi AI):Optional, consent-based transcription and note-drafting to support clinicians during or after a session. Audio is short-lived. Draft notes are reviewed, edited and approved by the clinician before being saved to your record.
  • Content recommendations:Lightweight algorithms that surface wellbeing content we think may be relevant based on your stated preferences and engagement. These recommendations do not produce legal or similarly significant effects.
  • Analytics and service improvement:AI and machine-learning techniques applied to aggregated or pseudonymised data to understand engagement, improve our platform and identify usability issues.
  • Security and abuse prevention:Automated tools that help us detect fraud, spam, abusive content (on any community features) and security threats.
  • Assistive chat / AI-supported self-help:Conversational tools that provide information and signposting, with clear disclosure that you are interacting with an AI and with fast, visible routes to a human where appropriate.

Potential future uses of AI

As we develop our platform we may expand our use of AI to include, for example:

  • Clinical triage support:AI-assisted triage to help route you to the most appropriate service or clinician. Any triage outcome that affects the service offered to you will be reviewed or confirmed by a qualified human.
  • Summarisation:AI-generated summaries of clinical encounters, coaching sessions or long-form content, always reviewed by a human before being saved or shared.
  • Personalisation:Richer personalisation of wellbeing content and programme recommendations, subject to your settings and consents.

Before we introduce any new AI use that could materially affect you, we will update this Notice, complete a DPIA and – where required by the AI Act – complete a Fundamental Rights Impact Assessment.

Classification under the EU AI Act

We classify every AI system we operate under the EU AI Act’s risk framework. We do not use, and will not use, AI systems that fall into the Act’s “prohibited practices” category. Where a system we operate is considered “high-risk” (for example, if it is used for clinical triage in a way the Act designates as high-risk), we will meet the corresponding obligations, including risk management, data governance, technical documentation, logging, human oversight and post-market monitoring. Where a system is limited-risk (for example, an AI chat interface), we will provide clear transparency to you.

Your rights around AI

  • Right to a human review: You can ask for human review of any significant outcome that has been informed by an AI system, and you can contest that outcome.
  • Right to object:You can object to processing based on legitimate interests, including any AI-driven personalisation; we will stop unless we have compelling legitimate grounds that override your rights, or we need to continue for the establishment, exercise or defence of legal claims.
  • Right to decline optional AI features:Optional AI features (such as transcription) are exactly that – optional. Declining will not reduce your access to the underlying service.

Automated Decision-Making

As set out in Section 9, Spectrum.Life does not make decisions that produce legal effects concerning you, or similarly significantly affect you, based solely on automated processing (including profiling). If we ever introduce such a decision-making process, we will update this Notice, tell you directly, obtain any required consent, and give you meaningful information about the logic, significance and expected consequences – together with clear rights to obtain human intervention, express your point of view, and contest the decision.

Cookies and Tracking Technologies

Our websites and apps use cookies, pixels, local storage and similar technologies. On your first visit we present a cookie banner that allows you to accept all, reject non-essential, or make a granular choice. You can change your choices at any time through the banner or your browser settings.

Categories of cookies we use

  • Strictly necessary:Required for the platform to function – for example, authentication, session, load-balancing and security. These cannot be switched off.
  • Functional:Remember preferences such as language or display settings.
  • Analytics / performance: Help us understand how the platform is used so we can improve it. We use Google Analytics and Posthog for this purpose. Analytics cookies are only set where you consent.
  • Marketing/ Advertising: Set only with your explicit consent, to deliver or measure our own marketing (we do not sell your data to third parties for their own marketing).
  • Third-party cookies: Embedded content (such as a third-party video player) may set its own cookies. Those are governed by the relevant third party’s privacy notice.

Blocking strictly necessary cookies will prevent parts of our services from working. Our apps do not currently respond to browser “Do Not Track” signals in a standardised way; we rely on your consent choices in the banner and your browser settings.

Who We Share Your Data With

Spectrum.Life does not sell your personal data. We do, however, need to share personal data with a limited set of trusted third parties so that we can run our operations and deliver services. We do so only in the ways described below.

Group companies

We may share personal data with other entities within the Spectrum.Life group where needed to deliver or support the services (for example, Spectrum Health for online physiotherapy). All group entities are bound to the protections set out in this Notice.

Sub-processors and service providers

We use trusted third-party providers to help us deliver our services. Each is contractually bound to process your data only on our documented instructions, to keep it confidential, to implement appropriate technical and organisational security measures, and not to use your data for their own purposes. Our current sub-processors and key third-party providers are set out in the table below. We maintain this list and will keep it updated.

Sub-Processor / Third Party Services Involved Data Type Processing Location
TelecomStack 24/7 Employee Assistance Programme (EAP); telephony, call handling and service delivery PII and special category data EEA
Salesforce EAP; Virtual Primary Care (Digital GP and Advanced Nurse Practitioners); clinical records management platform PII and special category (health) data EEA
Amazon Web Services (AWS) Digital Mental Health hosting; Virtual Primary Care hosting; cloud platform PII and special category data EEA
Twilio Digital Mental Health; Virtual Primary Care; SMS and voice communications Limited PII (name, phone, email, communication metadata) EEA and United States (global infrastructure)
Spectrum Health Online physiotherapy PII and special category (health) data EEA
Care Concierge Adult and elder care signposting (non-clinical) PII (limited referral details) EEA
Affiliate Network (independent clinicians and specialist providers) Structured counselling and professional referrals PII and special category (health) data EEA
Google Analytics Web analytics across our platforms and digital content Limited PII, anonymised usage data EEA
Posthog Inc. Digital platform analytics; behavioural event tracking for UX improvement and feature development. Limited PII, Pseudonymous usage data EEA and United States (global infrastructure)
Microsoft 365 / Azure Internal operations, communications and document management across all services. PII, including staff and client communications EEA
Tableau Reporting and dashboards for operational insights. PII and special category data (encrypted and access-controlled) EEA
Law Express General legal information support (EAP) PII (limited identity and case context) EEA
Financial Health Financial wellbeing support (EAP). PII (contact and case-related data) EEA
Blacktower Financial and retirement planning referrals (UK EAP only). PII (financial planning contact data) United Kingdom
Amwell (SilverCloud) Digital Mental Health and iCBT programmes. PII and special category (health) data EEA
Heidi AI Optional AI-assisted clinical documentation and transcription. PII and special category (health) data (masked in storage)> EEA
Stripe Payment processing for private appointments. Payment metadata (no card data processed by Spectrum.Life) Ireland (EEA)
SimplyBook.Me Event booking and appointment scheduling; booking confirmations. Limited PII (name, email, booking date/time, service selection) EEA
Signature RX Virtual Primary Care – prescribing. PII and special category (health) data, including prescription information United Kingdom (primary) and Ireland/EEA (backup)
Psymplicity Virtual Primary Care – mental health assessments and treatment records. PII and special category (health) data United Kingdom
MessageBird EAP live chat clinical support service; SMS and outbound messaging communications. PII and special category (health) data (live chat); limited PII (name, phone, communication metadata) (SMS). EEA

A full, current list of our sub-processors is maintained internally and is available on request from our DPO.

Independent clinicians, consultants and agents

We engage qualified clinicians, coaches, medical consultants and specialist contractors to deliver parts of our service. They are bound by strict confidentiality obligations and, in the case of healthcare professionals, the ethical rules of their professional regulator. IT and security consultants with incidental access to systems containing personal data are bound by equivalent contractual obligations and act only on our instructions.

Insurance Partners (for insurance-funded services)

Where your service is funded by a private medical insurer, we may share limited information with that insurer for eligibility and billing purposes – for example, confirming the number of sessions you have used, a membership reference, or an invoice reference. We do not share clinical content, session notes or diagnostic information with insurers unless you have explicitly consented or we are legally required to do so. Further detail on employer, educational-institution and insurer information-sharing is set out in Section 13.

Payment and billing partners

Payments for services you pay us for directly (including private appointments and any shortfall balance not covered by an insurer) are processed by a PCI-DSS-compliant payment processor acting as our processor. Where a shortfall balance remains unpaid after reasonable efforts, we may refer limited billing details (name, contact details, invoice reference) to a regulated debt-collection partner following an internal clinical and compliance review. Financial records are retained for seven years in line with tax and accounting requirements. You can object to processing for debt recovery at any time by contacting our DPO.

Business transfers

If Spectrum.Life undergoes a merger, acquisition, restructuring or asset sale, personal data may be transferred as part of the transaction. Your data will continue to be protected in line with this Notice or a superseding notice we will make available to you before any changes take effect.

Legal and regulatory disclosures

We may disclose personal data where required by law, to respond to lawful requests from authorities, to protect the rights, property or safety of Spectrum.Life or others, to investigate or defend against legal claims, or to prevent fraud. Where we can lawfully notify you of a request, we will.

We do not sell your data

We do not sell your personal data, and we do not allow our service providers to use it for their own marketing or unrelated purposes.

Sharing with Employers, Educational Institutions and Insurers

Many Spectrum.Life services are made available to you through your employer, college or insurer. We understand that confidentiality of your use of these services matters – especially in a workplace, educational or insurance context. This section explains exactly what is, and what is not, shared with those sponsoring organisations.

Employee Assistance Programme – confidentiality with your employer

If you access the EAP through your employer, the content of your counselling sessions, assessments and interactions is strictly confidential.

  • Aggregate reporting:Your employer may receive periodic anonymised and aggregated reports on EAP usage across their workforce (for example, total uptake and broad categories of presenting issues). These reports do not identify individuals.
  • Registration or eligibility confirmation:In some cases, and only where necessary, minimal information may be provided for programme administration (for example, confirming that a named employee has registered, to support billing). We will never share the content of your sessions or the issues you discussed with your employer.
  • Emergency situations:In extremely rare cases involving a grave and immediate risk (for example, a credible threat of serious harm), we may need to involve emergency services or, where appropriate, designated safeguarding contacts. We limit any disclosure to what is strictly necessary.

Clinical referrals across service arrangements

Where you contact Spectrum.Life through a programme provided by an employer insurer or group protection scheme, and a clinician determines during that engagement that your clinical needs would be better met by a service delivered by Spectrum.Life under a separate arrangement with your employer, we may use the personal data you have provided to facilitate that onward referral. We do this on the basis of performing our contract with you (Article 6(1)(b)) – when you contact Spectrum.Life for support, it is our role to route you to the right service for your needs, and that obligation applies regardless of which commercial arrangement a particular service sits under. Where your referral involves health data, we process it for the purpose of providing healthcare to you (Article 9(2)(h)). Your clinician will inform you at the point any such referral is made, and you may decline at any time. No identifiable data about your referral will be shared with your employer or insurer.

Student Assistance Programme – working with your institution

For SAP, we operate within the institution’s duty of care to students. At the start of the service, you will be asked to agree to a defined scope of information-sharing with designated staff at your institution (for example, confirmation of engagement, or a support recommendation). We do not share session notes or sensitive clinical detail for academic or disciplinary purposes. In emergency situations – for example, where there is a serious immediate risk to you or others – we may contact an appropriate institutional safeguarding contact even where consent has not been given at that moment, limited to what is needed to address the emergency.

Insurance-funded services

Where your service is funded by a private medical insurer:

  • Administrative information only:We typically share only the minimum information needed for eligibility verification and billing (for example, membership reference, number of sessions, invoice reference). The insurer does not receive clinical notes or diagnostic detail.
  • Programme-level reporting:Insurers may receive aggregated, anonymised reports on usage and outcomes across their covered population.
  • Claims and complaints:If your service is tied to an insurance claim, or if a complaint requires us to respond to your insurer, we limit disclosure to what is necessary and will normally redirect or seek your consent for anything beyond basic usage confirmation.
  • Shortfall billing:Where your insurer does not cover the full cost of treatment, we may invoice you for the shortfall. We process limited personal and financial information for this purpose. Payment is handled by our PCI-DSS-compliant payment processor. See Section 12 for further detail.

International Data Transfers

Spectrum.Life primarily stores and processes personal data within the European Economic Area (EEA) and the United Kingdom. Some of our sub-processors have global infrastructure – most notably, Twilio for SMS and voice communications may route some traffic through infrastructure outside the EEA. Where personal data is transferred outside the EEA or the UK to a country that is not considered to have an adequate level of data protection, we put one or more of the following safeguards in place:

  • Standard Contractual Clauses (SCCs):The European Commission’s approved SCCs, together with the UK International Data Transfer Addendum where UK personal data is transferred.
  • EU-US Data Privacy Framework (DPF) and UK Extension (“Data Bridge”):Where a US recipient is certified under the DPF, we may rely on the Framework and its UK Extension for UK personal data.
  • Binding Corporate Rules (BCRs):Where a provider has approved BCRs, we may rely on those for intra-group transfers.
  • Article 49 derogations:In narrow, specific cases – for example, with your explicit consent or where a transfer is necessary to perform a contract with you.

Post-Schrems II, we conduct transfer impact assessments for transfers to third countries and apply supplementary measures (for example, encryption in transit and at rest) where appropriate. You can request details of the safeguards in place for any specific transfer by contacting the DPO.

Your Choices and Control

  • Providing data:You can decide not to provide certain personal data, but some services cannot be delivered without specific information.
  • Communication preferences:Manage marketing and notification preferences in your account settings or via the unsubscribe link in any marketing message.
  • Integrations:Connect or disconnect third-party apps and devices at any time in your settings.
  • Privacy settings:Adjust any in-app privacy settings (such as profile visibility in community features).
  • Withdrawal of consent:Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of past processing.
  • Transcription opt-out:You can decline the use of AI-assisted transcription at any time and request a non-transcribed session.

Data Retention

We keep personal data only for as long as needed for the purposes we collected it, subject to legal, regulatory and clinical-governance requirements. Our headline retention periods are:

Data Category Retention Period
Clinical records (including Virtual Primary Care, counselling, psychotherapy, neurodiversity assessments) Typically 10 years from the date of the last session, or longer for services delivered to minors, in line with clinical-governance and statutory requirements (including, for example, until age 25 or 26 for records relating to minors where required by law).
Call and voice recordings Up to 365 days from the date of the recording, after which they are securely deleted.
Audio used for AI-assisted transcription Not retained beyond what is needed to generate the transcript. The resulting clinician-approved notes form part of the clinical record and follow that schedule.
Account and profile data For as long as your account is active. Deleted or anonymised within a reasonable period after closure, subject to any legal holds.
Support and communication logs Typically 24 to 36 months, unless required longer for a complaint or investigation.
Financial and transaction records Minimum 7 years, to meet tax and accounting obligations.
Analytics data Raw identifiable analytics data is retained for short periods. Aggregated and anonymised analytics may be retained indefinitely.
Legal hold For as long as a legal, regulatory or litigation hold applies.

When personal data is no longer needed, we either securely delete it or anonymise it so it can no longer be associated with you.

Data Security

Information security is central to what we do. Our controls are aligned with ISO/IEC 27001 and with the heightened cyber-security standards under the EU NIS2 Directive. Key measures include:

  • Encryption:Personal data is encrypted in transit (TLS) and at rest.
  • Access control:Role-based access, least privilege, and multi-factor authentication for staff and administrators.
  • Network and platform security:Firewalling, monitoring, vulnerability management, secure software development and regular patching.
  • People security:Pre-employment screening, confidentiality obligations, and regular mandatory security and privacy training.
  • Testing and assurance:Regular internal audits, independent penetration testing, and third-party security due diligence.
  • Incident response:A documented incident response and breach notification process. We will notify the relevant supervisory authority within the statutory timeframe (generally 72 hours) where required, and notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
  • Your part:Use a strong, unique password, enable any multi-factor authentication we offer, and never share your credentials. We will never ask for your password by email. Please report any suspected unauthorised access to our DPO immediately.

Marketing Communications

Spectrum.Life may send you communications to keep you informed about our services, new content and wellbeing resources. You remain in control of what you receive.

  • Service communications:Regardless of your marketing preferences, we will send you essential service messages that are necessary for the performance of our contract with you or for security and administrative reasons. These include appointment reminders, account confirmations (such as password resets), critical service updates, changes to terms or policies, and security or downtime alerts. You cannot opt out of these messages because they are not promotional. They are necessary for the safe and effective use of the service.
  • Newsletters and wellbeing content:Where you have opted in, we may send periodic newsletters containing general wellbeing content, articles, success stories or wellness challenges.
  • Promotional communications and new services:With your consent, we may send you information about new Spectrum.Life services or programmes, events such as webinars or workshops, or relevant offers. We may also notify you of complementary services from our partners, but those communications will always come from Spectrum.Life. We do not give your contact information to third parties for them to contact you directly without your separate consent.
  • Channels:We may communicate with you via email, in-app messaging, push notifications, SMS or occasionally by telephone. The channel used will depend on the contact information you have provided and the nature of the message. Standard messaging and data rates may apply for SMS.
  • Opting in:When you first register or use our services, we will ask for your consent before sending marketing or non-essential communications. If you do not consent, you will not receive them.
  • Opting out:You can opt out of marketing communications at any time by:
  • clicking the unsubscribe link in any marketing email;
  • replying STOP to any SMS;
  • updating your preferences in your account settings; or
  • contacting the DPO at gdprspectrumlife@spectrum.life.

We will process opt-out requests as soon as possible. Even if you opt out of marketing, you will still receive essential service communications as described above. Your decision on marketing will not affect your access to core services.

  • Frequency:We aim to keep our communications useful and proportionate. You can typically expect a monthly newsletter and occasional announcements.
  • Third-party marketing:Life will not share or sell your contact information to third-party companies for their own direct marketing unless you separately consent to that with the relevant partner. Any promotional message you receive should be from Spectrum.Life. If you receive marketing from a third party and believe we shared your data improperly, please contact the DPO immediately.
  • Business-to-business communications:If you represent a company or organisation that uses or has expressed interest in our services, we may send business-to-business communications to your work contact information on the basis of legitimate interest. For example, information about new programmes relevant to your organisation. These communications have their own opt-out process and are managed on a separate marketing list. This Notice primarily addresses personal consumer data.
  • No sale of data:We do not sell or rent your contact information to third parties for their own marketing or unrelated purposes.

Children’s Privacy

  • General access:If you are under 16, you should not create an account on our general adult-focused platform.
  • Specialist services:For services designed for children and young people, consent is obtained from the parent, guardian or sponsoring institution as appropriate. Information provided to minors is age-appropriate.
  • No marketing to children:We do not profile, target market, or advertise to children.
  • Accidental collection:If we become aware that we have inadvertently collected personal data from a child without the required consent, we will delete it unless retention is legally required (for example, safeguarding).
  • Parents and guardians:If you believe a child has submitted personal data to us without the required consent, please contact the DPO and we will act promptly.

Links to Other Sites

Our websites and apps may contain links to third-party websites or resources. This Notice does not apply once you leave our platform. Please review the privacy notice of any external site you visit. A link from our platform is not an endorsement.

Your Rights

You have the following rights under GDPR and UK GDPR. Most rights can be exercised free of charge, and we will respond within one month (extendable by up to two further months for complex or voluminous requests, in which case we will let you know).

  • Right to be informed:This Notice, and the information we give at the point of collection, is how we deliver this right.
  • Right of access:You can ask for a copy of the personal data we hold about you, together with information about how we process it.
  • Right to rectification:You can ask us to correct inaccurate or incomplete data.
  • Right to erasure (“right to be forgotten”):You can ask us to delete your personal data in certain circumstances. Some data may be retained where we are legally required to keep it.
  • Right to restrict processing:You can ask us to pause processing in certain circumstances (for example, while the accuracy of data is being checked).
  • Right to data portability:Where processing is based on consent or contract and carried out by automated means, you can ask for a machine-readable copy of the data you have provided, or for it to be transmitted directly to another controller where technically feasible.
  • Right to object:You can object to processing based on legitimate interests or public-interest tasks, and absolutely to any processing for direct marketing.
  • Rights in relation to automated decision-making and AI:As set out in Sections 9 and 10, you have the right not to be subject to solely-automated decisions with legal or similarly significant effects, to obtain human review of significant AI-informed outcomes, and to contest those outcomes.
  • Right to withdraw consent:Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of past processing.
  • Right to lodge a complaint:With the Irish Data Protection Commission (DPC) or the UK Information Commissioner’s Office (ICO) – or the supervisory authority in your EU country of residence.

How to Contact Us and Exercise Your Rights

  • Email:gdprspectrumlife@spectrum.life
  • Post:Data Protection Officer, Spectrum Wellness Limited, 38-39 Fitzwilliam Square W, Dublin 2, D02 NX53, Ireland.

We may need to verify your identity before acting on a rights request, to make sure we do not disclose your data to anyone else. We do not discriminate against people who exercise their rights, and we will explain any case where we cannot fully action a request (for example, where we have a legal obligation to retain particular data).

Complaints

If you are not satisfied with how we have handled your personal data or a rights request, you can lodge a complaint with a supervisory authority.

  • Ireland – Data Protection Commission (DPC):dataprotection.ie. Address: 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland. Phone: +353 578 684 800.
  • United Kingdom – Information Commissioner’s Office (ICO):org.uk. Address: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom. Phone: +44 303 123 1113.
  • Other EU/EEA authorities:Contact details are on the European Data Protection Board (EDPB) website.

We would, however, appreciate the chance to address any concern directly first.

Updates to This Notice

We may update this Privacy Notice from time to time to reflect changes in our services, our use of technology (including AI), the third parties we work with, or changes in the law. We will publish the latest version on our website with a revised effective date. Where changes are material, we will also notify you directly – for example, by email, in-app message or on-screen notice – before they take effect. Historical versions are available on request.

By continuing to use our services after an updated Notice takes effect, you accept the updated terms, except where we are required by law to seek your explicit consent, in which case we will do so separately.

If you have any questions about this Privacy Notice, please contact our DPO at gdprspectrumlife@spectrum.life.