Data protection approach

Minding is built for therapy practices, where trust, confidentiality and clean data boundaries matter. This page explains how Minding approaches GDPR-aware websites, workflows and integrations.

Plain-English position

Before client data is touched

If a project requires Minding to access or configure systems containing client personal data, the following should be in place first:

Health data and clinical records

Therapy notes, diagnoses, intake forms and client histories may be special-category health data. Minding does not need those details for ordinary website or workflow configuration. Where forms, booking tools or reminders handle client data, they should be configured inside the practice's approved systems with the practice's privacy notice, lawful basis, retention rules and professional obligations in mind.

DPIA-ready does not mean DPIA-done

Minding can help make a workflow easier to document for a data protection impact assessment by mapping the journey, tools, data points, risks and safeguards. The practice, as controller, remains responsible for deciding whether a DPIA is required, approving it and keeping it up to date.

Typical safeguards

Integrations and subprocessors

Minding may configure tools such as Supabase, Resend, Twilio, WhatsApp Business, Stripe, Google Workspace, Google Calendar, Google Forms, Zoom, analytics providers and practice-management systems. The exact stack should be chosen per practice and documented in the project scope. No integration should be treated as approved for client data until its data-processing, security and account-ownership position has been reviewed for that practice.

What practices still need to decide

Incident and offboarding expectations

A production project should define who is contacted for a suspected incident, which systems are in scope, how access is revoked, how exports are handed over and when Minding deletes project data after completion.

Legal review

Minding designs and implements data-aware systems, but does not provide legal advice. Practices should obtain legal or data-protection advice where their processing is high risk, cross-border, novel, large-scale or clinically sensitive.