Last updated: 16 August 2026
Data protection approach
Minding is built for therapy practices, where trust, confidentiality and clean data boundaries matter. This page explains how Minding approaches GDPR-aware websites, workflows and integrations.
Plain-English position
- The practice remains the controller for its client and clinical records.
- Minding is usually a processor when it handles practice-client data on the practice's written instructions.
- Minding is a controller for its own website enquiries, client account admin and business records.
- Minding's public website forms are for practice enquiries only, not therapy-client data.
Before client data is touched
If a project requires Minding to access or configure systems containing client personal data, the following should be in place first:
- A written statement of work describing the systems and data involved.
- A data-processing agreement with Article 28-style processor terms.
- A list of approved subprocessors and integrations for the project.
- Named access owners, least-privilege access and MFA where supported.
- An agreed retention, export and deletion/offboarding plan.
- A secure channel for any records or credentials that must be shared.
Health data and clinical records
Therapy notes, diagnoses, intake forms and client histories may be special-category health data. Minding does not need those details for ordinary website or workflow configuration. Where forms, booking tools or reminders handle client data, they should be configured inside the practice's approved systems with the practice's privacy notice, lawful basis, retention rules and professional obligations in mind.
DPIA-ready does not mean DPIA-done
Minding can help make a workflow easier to document for a data protection impact assessment by mapping the journey, tools, data points, risks and safeguards. The practice, as controller, remains responsible for deciding whether a DPIA is required, approving it and keeping it up to date.
Typical safeguards
- Practice-owned domains, accounts and payment processors.
- Server-side secrets and no public exposure of service keys.
- Rate limiting and validation on lead forms.
- Clear separation between website enquiries and therapy-client records.
- Provider selection based on data-processing terms, security features and fit.
- Audit trails, role-based access and MFA where the chosen provider supports them.
- Documented client journey from discovery to booking, payment, forms and reminders.
Integrations and subprocessors
Minding may configure tools such as Supabase, Resend, Twilio, WhatsApp Business, Stripe, Google Workspace, Google Calendar, Google Forms, Zoom, analytics providers and practice-management systems. The exact stack should be chosen per practice and documented in the project scope. No integration should be treated as approved for client data until its data-processing, security and account-ownership position has been reviewed for that practice.
What practices still need to decide
- Lawful basis and transparency wording for clients.
- Whether explicit consent is needed for particular forms or communications.
- Clinical-record retention and deletion duties.
- Professional-body, insurance and jurisdiction-specific requirements.
- Whether SMS, WhatsApp or email is appropriate for each type of message.
- How urgent, risk-related or crisis communications are handled outside automation.
Incident and offboarding expectations
A production project should define who is contacted for a suspected incident, which systems are in scope, how access is revoked, how exports are handed over and when Minding deletes project data after completion.
Legal review
Minding designs and implements data-aware systems, but does not provide legal advice. Practices should obtain legal or data-protection advice where their processing is high risk, cross-border, novel, large-scale or clinically sensitive.