Myndspace – Legal Information
Privacy Policy
Myndspace (“we”, “our”, or “us”) is a mental health practice management platform designed to support therapists and their clients with appointment management, session coordination, clinical record keeping, and service-related communication. We are committed to protecting user privacy and handling personal and sensitive data responsibly and securely.
By using Myndspace, you agree to the practices described in this Privacy Policy.
Information We Collect
- Name and identity details
- Contact information such as phone number and email address
- Appointment and scheduling metadata
- Therapist notes and session summaries
- Mood tracking data
- Assessment scores and structured clinical inputs
- Communication consent preferences (including WhatsApp opt-in status)
- Technical and usage data required for system reliability
Myndspace does not store audio or video recordings of therapy sessions and does not store in‑app chat conversations.
How We Use Your Data
- Managing appointments and session workflows
- Maintaining therapist clinical records within the platform
- Sending appointment reminders and follow-up notifications
- Providing service-related communications
- Maintaining platform reliability and security
- Improving system performance and user experience
- Meeting legal and operational obligations
We do not use personal data for advertising or behavioral marketing.
Legal Basis for Processing
- User consent
- Service necessity
- Legitimate operational interests
- Legal obligations where applicable
WhatsApp Communication
If you explicitly opt in, we may send appointment reminders and essential follow-up notifications via WhatsApp using the WhatsApp Business API.
- No promotional or marketing messages are sent
- Only minimal delivery metadata (such as message ID and status) is stored
- Full message histories are not stored in our database
- You may opt out at any time
Data Categories & Sensitivity
Because Myndspace supports mental health practice workflows, stored records may include sensitive health-related information such as therapist notes, session summaries, mood tracking inputs, and assessment scores. We apply elevated safeguards and collect only necessary data.
Infrastructure & Hosting Security
Myndspace is hosted on Microsoft Azure cloud infrastructure with secured environments and hardened configurations.
- Network isolation and firewall protections
- Threat monitoring controls
- Secure service deployment practices
- Azure SQL Server with built-in security controls
- HTTPS-only access enforced
Authentication & Credential Protection
User authentication is managed by Azure Active Directory B2C.
- Passwords stored only by the authentication provider
- Myndspace does not store raw passwords
- Secure token-based authentication
- Encrypted authentication flows
Encryption Measures
- TLS/HTTPS encryption for data in transit
- Encryption of sensitive data at rest
- Azure SQL encryption enabled
- Encrypted automated backups
- Signed and time-limited auth tokens
Access Control & Data Isolation
- Therapists can access only their own client records
- No cross-therapist data visibility
- Administrative access restricted to platform owner
- No additional staff routine access
- Least-privilege access principles applied
Data Sharing & Service Providers
We do not sell or trade personal data and do not share it for advertising.
Data may be processed by trusted providers only where required:
- Microsoft Azure (hosting & database)
- Azure AD B2C (authentication)
- WhatsApp Business API – Meta Direct (reminders)
- Security and monitoring providers
Backups & Recovery
- Automated Azure backups enabled
- Encrypted backups
- Restricted backup access
- Provider recovery mechanisms available
Data Retention
Data is retained while therapist and client accounts remain active and may be deleted when accounts are closed or verified deletion requests are received.
- User data deletion supported
- Account deactivation supported
- Data export available upon request
User Rights
- Access personal data
- Correct inaccurate data
- Withdraw communication consent
- Request deletion
- Request data copy
Requests: contact@myndspace.app
Compliance Position
Myndspace is designed with HIPAA-aligned security safeguards and healthcare data protection best practices. Compliance responsibilities may vary based on therapist configuration and usage context.
Children’s Privacy
The platform is not intended for independent use by minors without therapist or guardian involvement.
Policy Updates
We may update this policy periodically. Continued use constitutes acceptance of updates.
Contact
Email: contact@myndspace.app
Terms of Service
Use of the Platform
Myndspace is intended for therapist practice management and session coordination. Use must be lawful and appropriate.
User Responsibilities
- Keep credentials confidential
- Provide accurate information
- No misuse or unauthorized access
- No reverse engineering or interference
Communication Consent
Opt‑in users may receive service-related reminders via approved channels including WhatsApp.
Service Availability
Service availability is not guaranteed and may be interrupted for maintenance or technical reasons.
Limitation of Liability
The platform is provided “as is” without liability for indirect or consequential damages.
Changes to Terms
Continued use after updates constitutes acceptance.
User Data Deletion Policy
To request deletion, email contact@myndspace.app with subject line Data Deletion Request and your registered contact details.