Privacy Policy Beta

Effective date: October 9, 2026

1. Introduction

WellnessDesk ("we," "our," or "us") operates the wellnessdesk.pro platform ("the Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Service as a licensed health professional, such as a psychologist, running your practice ("Provider"), or as a client of a Provider ("Client").

By using the Service, you consent to the data practices described in this policy. If you do not agree, please do not use the Service.

2. Our Role: Data Processor vs. Data Controller

Understanding the distinction between data controller and data processor is important:

  • For Provider account data: WellnessDesk is the data controller. We determine how and why your account information is processed.
  • For Client data entered by Providers: The Provider is the data controller, and WellnessDesk acts as a data processor on the Provider's behalf. Providers are responsible for having a lawful basis to collect and process their clients' personal data, including obtaining appropriate consent.

If you are a Client and have questions about how your Provider uses your data, please contact your Provider directly.

3. Information We Collect

Information you provide directly

  • Account information: Name and email address when you sign up via Google OAuth or email/password registration.
  • Email verification data: Verification tokens and status for email/password accounts.
  • Business information (Providers): Business name, timezone, specialties, service descriptions, pricing, availability schedules, and website/booking page content.
  • Client data (entered by Providers): Client names, email addresses, session notes, engagement records, activity assignments, and shared resources.
  • Messages: Communications sent between Providers and Clients through the platform's messaging feature.
  • Content uploads: Images, documents, and other files uploaded for booking pages, resources, or activities.
  • Professional declaration (Providers): That you certified holding the qualification, professional membership, liability insurance and authorisation your practice needs, which version of the wording you agreed to, and when you confirmed it. It lets your practice go live; we do not check the statements, you are responsible for them.
  • Payment information: Billing details are processed securely through Stripe. We do not store credit card numbers, CVVs, or full payment card data on our servers. Stripe acts as our PCI-DSS compliant payment processor.

Information collected automatically

  • Usage data: Pages visited, features used, booking interactions, and platform navigation patterns.
  • Device information: Browser type, operating system, screen resolution, and device identifiers.
  • Log data: IP addresses, access times, referring URLs, and error logs.
  • Cookies: Strictly necessary cookies for authentication and session management, plus optional analytics and advertising cookies on our marketing pages only, if you accept them (see Section 7).

Information from third-party integrations

  • Google OAuth: Name, email address, and profile picture from your Google account (when you choose to sign in with Google).
  • Google Calendar: Calendar event data when you connect your Google Calendar for scheduling synchronization. We access only the calendar data necessary to sync bookings.
  • Stripe: Payment confirmation, connected-account and payout status, and customer identifiers. We do not receive or store your full payment card details.

4. How We Use Your Information

We use the information we collect for the following purposes:

  • Service delivery: Provide, operate, and maintain the platform, including scheduling, messaging, notifications, resource sharing, and the client portal
  • Booking management: Process appointments, send confirmations, reminders, and facilitate rescheduling or cancellations
  • Video sessions: Facilitate virtual sessions through integrated video conferencing
  • Calendar sync: Synchronize bookings with your connected Google Calendar
  • Payment processing: Process your clients' payments and the platform fee, and handle checkout through Stripe
  • Professional declaration: Record that a Provider certified the qualification, professional membership, liability insurance and authorisation their practice needs, so their practice can go live under our Terms, and so we can show what was declared and when if a client or an authority asks
  • Communications: Send transactional emails (booking confirmations, reminders, verification emails), respond to support requests, and notify you of important account or Service changes
  • Security: Detect, prevent, and address fraud, unauthorized access, and other security issues
  • Improvement: Analyze usage patterns to improve platform features and user experience
  • Legal compliance: Comply with applicable laws, regulations, and legal processes

We do not use your information for behavioral advertising or sell it to third-party advertisers.

5. Data Sharing and Disclosure

We do not sell your personal information. We share data only in the following circumstances:

Service providers (sub-processors)

We use the following third-party services to operate the platform:

  • Google Cloud Platform: Application hosting, database and file storage. Location: europe-southwest1 region (Madrid, Spain).
  • Stripe, Inc.: Payment processing and payouts. Location: United States and European Union.
  • Postmark: Delivery of transactional emails (booking confirmations, reminders, account verification). Location: United States.
  • Twilio: Delivery of text-message reminders, only to Clients who opt in to them. Location: United States.
  • Cloudflare: Domain registration and DNS for custom domains a Provider chooses to buy or connect. Location: United States.
  • Google (sign-in and Calendar): Google sign-in (OAuth) and Google Calendar sync if you connect it. Location: United States.
  • Google Analytics and Google Ads: Website analytics and ad conversion measurement on our marketing pages (see Section 7). Location: United States.
  • Daily.co: Video for online sessions. Calls are not recorded or transcribed. Each video room is private to one session: the Provider and the Client each join with a personal link that stops working shortly after the session ends. Location: Call audio and video go through Daily servers in Frankfurt, Germany (European Union); Daily, Co. is based in the United States, where it keeps call logs.

The same list, with the data each one receives and the safeguard that applies, is on our sub-processors page.

Each sub-processor is contractually obligated to protect your data and process it only as needed to provide their services.

Provider-Client data sharing

Certain data is shared between Providers and their Clients as part of the professional relationship:

  • Booking details, messages, shared resources, and activity assignments are visible to both the Provider and the relevant Client
  • Provider-only session notes are not visible to Clients
  • Provider business information (name, services, availability) is visible on public booking pages

Other disclosures

  • Legal requirements: When required by law, regulation, subpoena, court order, or other legal process
  • Safety: To protect the rights, safety, or property of WellnessDesk, our users, or the public
  • Business transfers: In connection with a merger, acquisition, reorganization, or sale of assets, in which case your data would remain subject to this Privacy Policy

6. Data Security

We implement technical and organizational security measures to protect your data, including:

  • Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS (HTTPS)
  • Tenant isolation: Each Provider's data is logically isolated using row-level security (RLS) at the database level, ensuring one Provider cannot access another Provider's data
  • Access controls: Role-based access controls restrict data access to authorized personnel and functions
  • Secure authentication: Passwords are hashed using BCrypt; OAuth tokens are managed securely
  • Payment security: Credit card data is handled exclusively by Stripe (PCI-DSS Level 1 certified) and never touches our servers

While we implement commercially reasonable security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your data.

7. Cookies

We use a minimal set of cookies that are strictly necessary for the Service to function:

  • Session cookie: Maintains your authenticated session while using the platform
  • Cookie consent: Remembers your cookie preference
  • OAuth state: Temporary cookies used during the Google sign-in process for security (CSRF protection)

On our own marketing pages (the WellnessDesk website, blog, and signup), we additionally use Google Analytics 4 and Google Ads conversion cookies, but only after you accept them in the cookie banner. You can reject them with the same click, and your choice is kept for one year; if you are signed in, it is also recorded against your account. These tags are never loaded on practitioner booking pages, the client portal, or inside the provider application, so no third party tracks patients or clients there.

8. Data Retention

  • Active accounts: We retain your data for as long as your account is active and as needed to provide the Service.
  • After you close your account: When you close your account, your data is retained for 30 days to allow for reactivation or data export. After 30 days, your personal data is deleted or anonymized.
  • Account deletion: Upon request, we will delete your personal data within 30 days, except where retention is required by law (e.g., financial records, tax obligations).
  • Past identity verifications: We no longer verify Providers' identity. If you started one before, we keep its outcome and history (the professional registration you declared and, if the check passed, the name, type and expiry date of your document) while your account exists. For every check, finished or not, Stripe deletes its images and personal data at our request, within a few days.
  • Backups: Data may persist in encrypted backups for up to 90 days after deletion before being permanently removed.
  • Legal obligations: We may retain certain data longer where required by applicable law, regulation, or legal proceedings.

9. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request that we correct inaccurate or incomplete data
  • Deletion: Request that we delete your personal data (subject to legal retention requirements)
  • Portability: Request your data in a structured, commonly used, machine-readable format
  • Restriction: Request that we restrict processing of your data in certain circumstances. Clients can do this themselves under "Your privacy choices" in their portal settings
  • Objection: Object to processing of your data based on our legitimate interests, and to direct marketing at any time. Clients can object to marketing under "Your privacy choices" in their portal settings
  • Withdraw consent: Where processing is based on consent, withdraw that consent at any time

To exercise any of these rights, contact us at support@wellnessdesk.pro. We will respond to your request within 30 days (or sooner where required by law). California residents: see Section 11 for the 45-day deadline that applies to you. We may ask you to verify your identity before fulfilling your request.

10. European Economic Area (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the following additional provisions apply:

  • Legal basis for processing: We process your data based on: (a) performance of our contract with you (providing the Service); (b) your consent (where applicable); (c) our legitimate interests (improving the Service, security, fraud prevention); and (d) legal obligations.
  • International transfers: We host the Service, its database, and uploaded files in the European Union (Google Cloud, Madrid, Spain). Some sub-processors in Section 5 are based in the United States and may process personal data there: Stripe (payments), Postmark (transactional email), Twilio (text-message reminders), Cloudflare (custom domains), Google (sign-in, Calendar sync, Analytics, and Ads), and Daily.co (video sessions; call audio and video go through Frankfurt, Germany, and call logs are kept in the United States). For these transfers we rely on each provider's data processing terms, which incorporate the European Commission's Standard Contractual Clauses (SCCs).
  • Data Protection Officer: For GDPR-related inquiries, contact us at privacy@wellnessdesk.pro.
  • Supervisory authority: You have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated.

11. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

  • Right to know: You may request details about the categories and specific pieces of personal information we have collected about you, the sources, the business purposes, and the categories of third parties with whom we share it.
  • Right to delete: You may request deletion of your personal information, subject to certain legal exceptions.
  • Right to correct: You may request correction of inaccurate personal information.
  • Right to opt out of sale/sharing: We do not sell your personal information. If you accept the cookie banner on our marketing pages, Google Analytics and Google Ads receive data about your visit, which California law may treat as "sharing." You can decline in the banner at any time. We also treat the Global Privacy Control signal sent by your browser as a decline, so those tags never load for you.
  • Non-discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights.

Right to limit use of sensitive personal information

We use sensitive personal information (account log-in credentials, and the identity-document details of past verifications described in Section 8) only to provide the Service you asked for, to keep it secure and to keep the records of past verifications. We do not use it to infer characteristics about you or for advertising. Because we do not use it for other purposes, there is nothing to limit and we do not show a "Limit the Use of My Sensitive Personal Information" link. If that ever changes, we will add the link first. Health details a Provider records about their own Clients are entered and controlled by that Provider (see Section 2).

Personal information we collected in the past 12 months

CategoryExamplesSourcesPurposesDisclosed to (business purposes)
IdentifiersName, email address, phone number (for opted-in text reminders), IP address, account IDYou; a Provider who adds you as a Client; your browserService delivery, booking management, communications, securityHosting, email, text-message and video providers listed in Section 5
Customer records and payment informationBilling and payout status, Stripe customer identifiers (never full card numbers); professional registration details (Providers)You; StripePayment processing, provider verification (until 5 October 2026), legal complianceStripe
Commercial informationBookings, class packs, courses and payments made through the ServiceYou; the Provider you book withService delivery, payment processing, legal complianceHosting and payment providers (Section 5)
Internet or other network activityPages visited, features used, browser, device and log data, cookie choicesYour browser or deviceSecurity, improving the Service; marketing analytics only if you accept cookiesHosting provider; Google Analytics and Google Ads only after you accept (see below)
Approximate geolocationCountry or region derived from your IP addressYour browser or deviceSecurity and fraud preventionHosting provider
Audio and visual informationLive audio and video during a virtual session, if you join oneYouVideo sessionsVideo provider (Section 5)
Professional informationBusiness name, profession, registration number, professional declaration, services and pricing (Providers)The ProviderService delivery, provider verification (until 5 October 2026), the Provider's public pages and legal noticeHosting provider; shown publicly on the Provider's own site
Sensitive personal informationAccount log-in credentials; identity-document type, name and expiry date from past Provider identity verifications. We never received the document image or number, and we collect no biometric data.You; StripeAccount security; records of past verificationsHosting provider; Stripe

We do not sell personal information, and we did not sell it in the past 12 months. The only disclosures that California law may treat as "sharing" are the Google Analytics and Google Ads tags on our marketing pages, described above.

Retention by category

We keep each category of personal information only as long as described in Section 8: account, booking and payment records while your account is open and for 30 days after you close it; outcomes of past identity verifications while the account exists; encrypted backups for up to 90 days; and financial records for as long as the law requires.

How to make a request, and how long it takes

Email privacy@wellnessdesk.pro and say you are making a California request (know, delete, correct, or opt out of sharing). Use the email address of your account so we can verify it is you. An authorized agent may make a request for you with your written permission.

We confirm receipt within 10 business days and respond within 45 days. If we need more time we may extend that once by up to 45 more days and tell you why. If you are a Client, the personal information in your Provider's records is controlled by your Provider (Section 2), so we may refer you to them for that part of your request.

12. Healthcare Data Disclaimer

In a crisis or emergency. WellnessDesk is not an emergency or crisis service. If you or someone else may be in immediate danger or thinking about suicide or self-harm, call your local emergency number now (911 in the United States, 112 in the European Union). In the United States you can also call or text 988, the Suicide & Crisis Lifeline. In Spain you can call 024.

WellnessDesk is built for licensed health professionals, such as psychologists, who use it to run their practice. The Client data a Provider keeps in the Service can include health data, a special category of personal data under Article 9 of the GDPR: for example answers to intake questions, session notes, signed consent forms, activity submissions, and messages between the Provider and their Clients.

For this data the Provider is the data controller, and WellnessDesk processes it on the Provider's behalf as a data processor (see Section 2), as set out in Section 8 of our Terms of Service. The Provider decides why and how their Clients' data is processed and is responsible for having a lawful basis for it, including a condition under Article 9(2) of the GDPR for health data.

WellnessDesk provides software only. We do not provide health care or clinical services, and we do not give medical or psychological advice, diagnosis, or treatment. Care is provided by the Provider, not by WellnessDesk.

WellnessDesk does not act as a HIPAA business associate and does not sign Business Associate Agreements (BAAs). If you are a healthcare provider subject to the US Health Insurance Portability and Accountability Act (HIPAA), you must not use the Service for Protected Health Information (PHI).

13. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete such information promptly. If you believe a child has provided us with personal data, please contact us at support@wellnessdesk.pro.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes at least 30 days in advance by posting the updated policy on this page, updating the effective date, and sending a notification to the email address associated with your account. Your continued use of the Service after the effective date of the revised policy constitutes acceptance of the changes.

15. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:

© 2026 WellnessDesk. All rights reserved.

Accessibility