1Account & identity data
Email, name, password hash, sign-in method (email/Google), timezone, language preference.
Lawful basis: Contract (to provide the service) and legitimate interest (account security, fraud prevention).
Last updated: July 2025. This policy explains what data we collect, why we collect it, how we protect it, and your rights. We treat health and faith data with the highest level of care.
GodlyNow Health Ltd (company number: [placeholder]) is the data controller for your personal data. Registered address: [placeholder]. Contact: privacy@godlynow.com
Email, name, password hash, sign-in method (email/Google), timezone, language preference.
Lawful basis: Contract (to provide the service) and legitimate interest (account security, fraud prevention).
Intake responses, mood check-ins, journal entries, session notes (counsellor's clinical records), messages with your counsellor, risk assessments, care plans, faith preferences, GAD-7/PHQ-9 scores (if completed).
Special protection: This is "special category data" under UK GDPR Article 9. We process it only with your explicit consent (given during onboarding) and for the provision of health care.
Faith tradition, denomination, spiritual preferences, prayer/scripture integration choices, whether you want faith discussed in sessions.
Lawful basis: Explicit consent (Article 9(2)(a)). You control this via your profile settings and can change it at any time.
Plan type, payment method token (Stripe โ we never see full card numbers), billing history, invoice data, organisation coverage status, referral codes.
Lawful basis: Contract and legal obligation (tax records).
IP address, device/browser info, login timestamps, feature usage (analytics, anonymised), error logs, crash reports.
Lawful basis: Legitimate interest (platform security, improvement). You can opt out of analytics in settings.
Your organisation sees only anonymous aggregate data for wellbeing reporting. They never see:
This is enforced by our platform architecture โ organisation admins literally cannot access individual clinical data. Data is separated at the database level with row-level security policies.
Our primary infrastructure runs in UK (London) and EU (Frankfurt) Cloudflare regions. Stripe processes payments in the UK/EU. Any sub-processor outside the UK/EU (e.g. US- based analytics) is covered by UK Standard Contractual Clauses (SCCs) and the UK International Data Transfer Agreement (IDTA). We do not transfer health or faith data outside UK/EU without your explicit consent.
All data retained while your account is active and for 30 days after closure (grace period for recovery).
Counsellor session notes retained for 7 years after last session (BACP/UKCP professional standards), then securely deleted.
6 years after end of tax year (HMRC requirement).
Anonymised after 13 months; aggregated reports retained indefinitely.
All personal data deleted within 30 days of confirmed deletion request, except where legal obligation requires retention (billing, safeguarding records).
โ Access โ request a copy of all data we hold about you
โ Rectification โ correct inaccurate or incomplete data
โ Erasure โ request deletion (subject to legal retention requirements)
โ Restriction โ limit how we process your data
โ Portability โ receive your data in a structured, machine-readable format
โ Object โ object to processing based on legitimate interest (marketing, analytics)
โ Withdraw consent โ for health/faith data processing at any time
โ Complain โ to the ICO (ico.org.uk) if you believe we've mishandled your data
Exercise your rights: privacy@godlynow.com