Your privacy matters to us. This policy explains how we collect, use, and protect your personal information.
Last updated: 2 July 2026
BeeWell ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our platform, and sets out your rights under the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Irish Data Protection Acts 1988–2018.
Data Controller: BeeWell Therapy Solutions Limited, Ireland. Contact details are provided in Section 11 below.
We collect information you provide directly and information collected automatically when you use our platform.
Special category data: We do not collect or store the content of therapy sessions. The therapeutic relationship and session content remain confidential between you and your therapist. Where any information you provide reveals special category data (for example, health information you choose to include in your profile), we only process it with your explicit consent or another basis permitted under Article 9 GDPR.
Children: Our platform is intended for users aged 18 and over. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a child, we will delete it promptly.
Data protection responsibility on BeeWell is split between the platform and independent therapists, depending on the type of data involved. This section explains who is responsible for what.
We act as the data controller — meaning we decide how and why the data is processed — for:
Therapists registered on BeeWell are independent professionals, not our employees. For the data they generate in the course of providing therapy, each therapist acts as an independent data controller in their own right, including for:
This means a therapist, not BeeWell, is legally responsible for how this information is used, stored, and protected, and for responding to your rights requests about it — in the same way your GP or an independent counsellor would be. BeeWell provides the technical infrastructure (connecting, messaging, video hosting) as a processor, but does not read, review, or use message or note content for our own purposes.
As a processor for messaging, we do not monitor or access the content of client-therapist communications as a matter of course. We may access it only where necessary to:
We never access message content for marketing, analytics, or quality-assurance purposes.
If you submit a data rights request to us (see Section 8), we will action anything within our control as controller directly. Where your request relates to data a therapist controls — such as session notes — we will forward it to the relevant therapist on your behalf and let you know we've done so, as they are best placed to respond to it.
We only process your personal data where we have a valid legal basis to do so under Article 6 GDPR. The table below sets out our purposes and the corresponding legal basis for each.
| Purpose | Examples | Legal basis (GDPR Art. 6) |
|---|---|---|
| Provide and manage the service | Creating your account, verifying therapists, managing bookings, rescheduling/cancelling, hosting video sessions via Google Meet, processing payments | Performance of a contract (Art. 6(1)(b)); legitimate interest in platform safety for therapist checks (Art. 6(1)(f)) |
| Connect clients and therapists | Webform enquiries, in-platform chat, calendar-based scheduling | Performance of a contract (Art. 6(1)(b)) |
| Reviews and communications | Client reviews, booking confirmations and reminders, customer support | Performance of a contract; legitimate interest in platform trust and support (Art. 6(1)(b) & (f)) |
| Marketing communications | Optional newsletters or promotions, where you have opted in | Consent (Art. 6(1)(a)) — you may withdraw at any time |
| Platform improvement and security | Aggregated analytics, reCAPTCHA, fraud/abuse monitoring | Legitimate interest in improving and securing our services (Art. 6(1)(f)) |
| Legal compliance | Tax records, responding to lawful requests from authorities | Legal obligation (Art. 6(1)(c)) |
Automated decision-making: We do not carry out any processing, including profiling, that produces legal or similarly significant effects on you based solely on automated decision-making.
Some of our service providers are located outside the European Economic Area (EEA), including in the United States. Where we transfer personal data outside the EEA, we ensure an adequate level of protection through mechanisms such as the European Commission's Standard Contractual Clauses, an applicable adequacy decision, or, where relevant, the EU-US Data Privacy Framework.
| Provider | Purpose | Location | Safeguard |
|---|---|---|---|
| Stripe | Payment processing | EU / United States | EU-US Data Privacy Framework and/or Standard Contractual Clauses |
| Google Calendar & Meet | Session booking and hosting | United States | Standard Contractual Clauses |
| Google reCAPTCHA | Bot and abuse protection on sign-up | United States | Standard Contractual Clauses |
| Neon | Secure data storage | EU / United States | Adequacy decision or Standard Contractual Clauses |
| Amazon Web Services | Image storage | EU / United States | Adequacy decision or Standard Contractual Clauses |
| Resend | Send emails | United States | Standard Contractual Clauses |
| ImprovMX | Forward emails | EU / United States | Adequacy decision or Standard Contractual Clauses |
| Vercel | Website hosting | EU / United States | EU-US Data Privacy Framework and/or Standard Contractual Clauses |
You can request further details of the safeguards we use for a specific transfer by contacting us at .
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, in line with the following schedule. At the end of the relevant period, data is securely deleted or anonymised.
| Data category | Retention period |
|---|---|
| Account & profile information | For as long as your account is active, plus a backup for 30 days after account deletion to allow reactivation and prevent fraud |
| Booking and session history | 6 years from the date of the session, for dispute resolution and safeguarding purposes |
| Payment and financial records | 7 years, to meet Irish tax and accounting obligations |
| Therapist verification documents | For the duration of the therapist's membership, plus 6 years after they leave the platform |
| Technical / usage data | Up to 26 months in identifiable form, then aggregated or deleted |
| Marketing consent records | Until you withdraw consent, plus a record of the withdrawal for 3 years |
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse:
All data transmitted using SSL/TLS encryption
Data stored on secure, access-controlled servers
Passwords hashed using industry-standard algorithms
Limited staff access on a need-to-know basis
In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will notify the Irish Data Protection Commission within 72 hours and, where required, inform you directly, in accordance with Articles 33 and 34 GDPR.
Under the GDPR, you have the following rights regarding your personal data:
Request a copy of the personal data we hold about you.
Request correction of inaccurate or incomplete data.
Request deletion of your personal data ('right to be forgotten'), subject to our retention obligations above.
Request restriction of processing in certain circumstances.
Receive the data you provided us, in a structured, commonly used, machine-readable format.
Object to processing based on our legitimate interests, including profiling, or to direct marketing at any time.
Where processing is based on consent, withdraw it at any time without affecting the lawfulness of processing before withdrawal.
We do not use automated decision-making or profiling that produces legal or similarly significant effects on you.
To exercise any of these rights, please contact us at . We will respond within one month of receiving your request, as required by Article 12 GDPR (this period may be extended by a further two months for complex requests, in which case we will explain why). We may need to verify your identity before actioning a request.
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Where changes are material, we will notify you by email or via a prominent notice on the platform before the changes take effect. The "Last updated" date at the top of this page shows when this policy was last revised.
If you have any questions about this Privacy Policy or our data practices, please contact us:
If your query relates to therapy session content or notes rather than your BeeWell account, we will route it to the relevant therapist — see Section 2, Roles and Responsibilities.
You also have the right to lodge a complaint with the Irish Data Protection Commission (DPC) if you believe your rights have been violated, or with the supervisory authority in your own EU member state of residence.
We're committed to transparency. Reach out if you have any concerns.