1. How do we use your data?
- When you are invited to join the platform. If you receive an invitation to join our platform, this is because your employer has asked us to invite you to use MyMynd. Your employer will have sent us your name, work email address and some optional employment information (role / team / department) in advance, so we can verify you are entitled to use MyMynd. Until you decide to register directly on MyMynd, we hold this data on behalf of your employer, as their data processor. This means that if you have any questions about this initial data transfer, we would suggest contacting your employer first, because they are the data controller in relation to the initial transfer of your data to us.
- When you undertake an assessment on the MyMynd platform. The assessment is designed to assess your overall behavioural health, which covers mental health and your ability to cope with life’s challenges. When you undertake the MyMynd assessment we will usually collect your name, gender and email address, as well as any additional information you provide as part of the assessment.
- We will process this only where you have provided us with your explicit consent to do so, in order for us to provide the assessment to you .We will only collect the minimum data items necessary to provide our services to you. You can withdraw your consent to this processing at any time, by contacting us at firstname.lastname@example.org.
- We provide reports to your employer covering how their staff are feeling at an aggregated level, but your employer will never be shown the individual responses you give to your specific assessment or any identifiable data.
- If your responses suggest you need support. If your responses to the questions asked by our platform indicate that you may benefit from a follow up call, such as counselling or speaking with a psychologist, we will make you aware of this when you use the platform. Any follow-ups with our psychologists will be to validate the results of your assessment, and to suggest next steps for you. We don’t provide therapy, or a clinical diagnosis.
- If you consent, we will share your data with a third party to provide this additional support with you, and we will always make clear to you who we would introduce you to for this additional support before you consent. We will never report back to your employer that additional support has been recommended by us, or used by you, in a way that is identifiable to you.
- We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. We will inform users of any changes to the policy and if the purpose of data processing changes, consent will be re-obtained before continued use of the service.
- Please keep in mind that if we or the psychologist consider it necessary to protect your life, we or our psychologists may share your data with the appropriate emergency services.
- When you contact us. When you contact us either by phone, email or via social media with general queries, we will usually collect your name, social media handle and contact details, because it’s in our legitimate interest to make sure we can properly respond to your query.
- For video communications with you we will always use secure encrypted connections via Zoom or an alternative secure platform (e.g. Microsoft Teams, Google Meet).
- When you have agreed to receive our news updates via our Website. We will handle your personal information (such as your name and email address) to provide you with our news updates in line with any preferences you have told us about. Where you have signed up to take a MyMynd assessment, this does not mean that we will then start providing you with our news updates – you can sign up to these separately if you would like to receive them.
- When we send you our news updates because you have opted-in to receive them, we rely on your consent to contact you. If you have not opted-in and we send you our news update emails, we do this because of our legitimate interest to promote our business.
- You can unsubscribe from our updates at any time by clicking the unsubscribe link at the bottom of any of our emails, or by emailing email@example.com.
- Technical information when you use our Website. When you consent, we collect information about how you use our Website, using Mixpanel. They help us improve our website by collecting and reporting information on how you use it. The Mixpanel cookies collect information in a way that does not directly identify anyone, and the technical filenames for these cookies on your device are the ones beginning with 'mp_'.
- If our business is sold. We process your personal information for this purpose because we have a legitimate interest to ensure our business can be continued by the buyer. If you object to our use of your personal information in this way, the buyer of our business may not be able to provide services to you.
2. Who do we share your date with?
- We do not share data with other third parties, except for in any of the specific circumstances below.
- One of our registered psychologists. Where your results have highlighted patterns that may be as a result of an undiagnosed mental health problem, we will share your results with one of our registered psychologists. We only do this where you have provided us with your consent to do so, and you are under no obligation to speak to any of our psychologists that reach out to you.
- Your employer. We may provide aggregated and anonymised data back to your employer. We will not share personally identifiable data back to your employer related to your assessment.
- Business partners, suppliers and subcontractors where you have provided us with your consent to do so.
- Prospective buyers of our business under our legitimate interest to ensure our business can be continued by the buyer.
3. Where is my data stored?
We store your data with Amazon Web Services on their London servers.
4. How long do we keep your data for?
We will only retain your personal information for as long as we need it, while you are active on our platform and while you remain an employee of a MyMynd client, unless we are required to keep it for longer to comply with our legal, accounting or regulatory requirements. Where we no longer need to hold your personal information it will be deleted from all MyMynd systems.
In some circumstances we may carefully anonymise your personal data so that it can no longer be associated with you, and we may use this anonymised information indefinitely without notifying you. We use this anonymised information to analyse our programmes and support other similar programmes around the world.
What are my rights under data protection laws?
You have various other rights under applicable data protection laws, including the right to:
- access your personal data (also known as a “subject access request”);
- correct incomplete or inaccurate data we hold about you;
- ask us to erase the personal data we hold about you;
- ask us to restrict our handling of your personal data;
- ask us to transfer your personal data to a third party;
- object to how we are using your personal data; and
- withdraw your consent to us handling your personal data.
You also have the right to lodge a complaint with your relevant supervisory authority, you can find which one applies to you here.
Please keep in mind that privacy law is complicated, and these rights will not always be available to you all of the time.
Questions, comments and more detail
Your feedback and suggestions on this policy are welcome.
We’ve worked hard to create a policy that’s easy to read and clear. But if you feel that we have overlooked an important perspective or used language which you think we could improve, please let us know. You can contact us about anything relating to your rights mentioned within the policy by email at firstname.lastname@example.org.