In crisis? Call 999 (emergency) or 116 123 (Samaritans) or text SHOUT to 85258.

GodlyNow
Legal

Privacy policy

Last updated: July 2025. This policy explains what data we collect, why we collect it, how we protect it, and your rights. We treat health and faith data with the highest level of care.

Data controller

GodlyNow Health Ltd (company number: [placeholder]) is the data controller for your personal data. Registered address: [placeholder]. Contact: privacy@godlynow.com

What we collect and why

1Account & identity data

Email, name, password hash, sign-in method (email/Google), timezone, language preference.

Lawful basis: Contract (to provide the service) and legitimate interest (account security, fraud prevention).

2Health & counselling data (Special category)

Intake responses, mood check-ins, journal entries, session notes (counsellor's clinical records), messages with your counsellor, risk assessments, care plans, faith preferences, GAD-7/PHQ-9 scores (if completed).

Special protection: This is "special category data" under UK GDPR Article 9. We process it only with your explicit consent (given during onboarding) and for the provision of health care.

3Faith & spiritual data (Special category)

Faith tradition, denomination, spiritual preferences, prayer/scripture integration choices, whether you want faith discussed in sessions.

Lawful basis: Explicit consent (Article 9(2)(a)). You control this via your profile settings and can change it at any time.

4Billing & subscription data

Plan type, payment method token (Stripe โ€” we never see full card numbers), billing history, invoice data, organisation coverage status, referral codes.

Lawful basis: Contract and legal obligation (tax records).

5Technical & usage data

IP address, device/browser info, login timestamps, feature usage (analytics, anonymised), error logs, crash reports.

Lawful basis: Legitimate interest (platform security, improvement). You can opt out of analytics in settings.

If your church or organisation covers your plan

๐Ÿ›๏ธOrganisation visibility

Your organisation sees only anonymous aggregate data for wellbeing reporting. They never see:

  • โœ— Your messages or session content
  • โœ— Your counsellor's notes about you
  • โœ— Which counsellor you see
  • โœ— Your diagnosis, mood data, or journal
  • โœ— Whether you've discussed faith, relationships, or personal matters

This is enforced by our platform architecture โ€” organisation admins literally cannot access individual clinical data. Data is separated at the database level with row-level security policies.

Who we share data with (and who we don't)

โœ“We share with (only as needed)

  • Your assigned counsellor (clinical data for your care)
  • Stripe (payment processing โ€” tokenised, no card numbers)
  • Cloudflare (hosting, DDoS protection, analytics โ€” EU/UK regions)
  • SendGrid/Mailgun (transactional emails โ€” verification, receipts)
  • Professional regulators (if a formal complaint triggers a fitness-to-practise referral)
  • Legal authorities (only when compelled by court order)

โœ—We never

  • โœ— Sell your data to third parties
  • โœ— Use your health/faith data for advertising
  • โœ— Share identifiable data with researchers without explicit consent
  • โœ— Share individual data with your organisation (see above)

International data transfers

Our primary infrastructure runs in UK (London) and EU (Frankfurt) Cloudflare regions. Stripe processes payments in the UK/EU. Any sub-processor outside the UK/EU (e.g. US- based analytics) is covered by UK Standard Contractual Clauses (SCCs) and the UK International Data Transfer Agreement (IDTA). We do not transfer health or faith data outside UK/EU without your explicit consent.

Data retention

Active account

All data retained while your account is active and for 30 days after closure (grace period for recovery).

Clinical records

Counsellor session notes retained for 7 years after last session (BACP/UKCP professional standards), then securely deleted.

Billing records

6 years after end of tax year (HMRC requirement).

Analytics/usage data

Anonymised after 13 months; aggregated reports retained indefinitely.

Deleted account

All personal data deleted within 30 days of confirmed deletion request, except where legal obligation requires retention (billing, safeguarding records).

Your rights (UK GDPR)

โœ“ Access โ€” request a copy of all data we hold about you

โœ“ Rectification โ€” correct inaccurate or incomplete data

โœ“ Erasure โ€” request deletion (subject to legal retention requirements)

โœ“ Restriction โ€” limit how we process your data

โœ“ Portability โ€” receive your data in a structured, machine-readable format

โœ“ Object โ€” object to processing based on legitimate interest (marketing, analytics)

โœ“ Withdraw consent โ€” for health/faith data processing at any time

โœ“ Complain โ€” to the ICO (ico.org.uk) if you believe we've mishandled your data

Exercise your rights: privacy@godlynow.com

Security measures

  • โœ“AES-256 encryption at rest (database, file storage, backups)
  • โœ“TLS 1.3 for all data in transit
  • โœ“Row-level security (RLS) on all clinical tables โ€” counsellors only see their own clients
  • โœ“Organisation data isolated by database policy โ€” admins cannot query individual clinical rows
  • โœ“Annual penetration testing (CREST-certified) and continuous vulnerability scanning
  • โœ“SOC 2 Type II aligned controls (access review, change management, incident response)
  • โœ“Staff access logged, monitored, and requires MFA + just-in-time elevation

Questions about your data?

Contact our Data Protection Officer atdpo@godlynow.com

Find my counsellor