Connect & Treat — Privacy Policy

Last updated: 2 September 2026

This policy explains how Connect and Treat Limited uses personal data. It is written to meet the UK GDPR, the Data Protection Act 2018, and ICO expectations for a UK marketplace that handles health-related bookings.

1. Who is responsible

1.1 The data controller is Connect and Treat Limited, company number 14825853, registered office Apollo House, Hallam Way, Whitehills Business Park, Blackpool, England, FY4 5FS. Email: hello@connectandtreat.com.

1.2 We are not your therapist. Independent therapists who treat you are separate controllers for the clinical notes they keep. We are controller for account, booking, payment metadata and Platform messages.

1.3 You can complain to the Information Commissioner's Office (ico.org.uk). Please contact us first so we can try to put things right. We will publish our ICO registration number on this page once it has been issued.

2. What we collect

2.1 Clients: name, email, phone, date of birth, account login, booking history, session format and time, payment metadata (including card last four digits via Stripe; we do not store full card numbers), Platform messages, and any information you type into booking or intake forms.

2.2 Therapists: name, email, professional details, accrediting body and membership number, qualifications, insurance, DBS evidence, photo, profile copy, bank/payout details via Stripe Connect, and documents uploaded at apply.

2.3 Technical: IP address, device and browser type, pages viewed, cookie identifiers needed to keep you signed in.

2.4 We do not sell personal data.

3. Special category data

3.1 Booking a therapist and writing in Platform messages may reveal information about your health (special category data under UK GDPR Article 9).

3.2 We process that data only where it is necessary to provide the Platform service you have asked for (health care and treatment on the basis of UK GDPR Article 9(2)(h) and Data Protection Act 2018 Schedule 1, or your explicit consent where that is the right basis), and we limit access to people who need it to run bookings, payments and support.

3.3 Clinical records of what is said in a session belong to the therapist, not to us, except to the extent something is stored in Platform messages or forms you submit to us.

4. Why we use data (lawful bases)

4.1 Contract: to create your account, take payment, run bookings, pay therapists after sessions, send booking emails, and provide dashboards.

4.2 Legitimate interests: to keep the Website secure, prevent fraud, improve the product, and handle complaints about the Platform. We do not use legitimate interests to override your interests where we process health data.

4.3 Legal obligation: tax, accounting, and answering lawful requests.

4.4 Consent: optional communications you opt into, and any cookie that is not strictly necessary (we do not currently set those).

5. Who we share with

5.1 The therapist you book, so they can deliver the session (name, contact, booking time, messages, relevant form answers).

5.2 Stripe, who processes payments and Connect payouts as a payment institution. Stripe is an independent controller or processor depending on the activity; we do not receive full card numbers.

5.3 Hosting and infrastructure providers who run the Website and database under contract (including authentication cookies described in the Cookie Policy).

5.4 Professional advisers, insurers, or authorities where the law requires it, or to protect someone's vital interests.

5.5 We do not share data with advertisers.

6. International transfers

6.1 Some processors (including Stripe) may process data in the United States or other countries. Where we do that we use a lawful UK transfer tool, such as the UK Extension to the EU-US Data Privacy Framework where the organisation is certified, or the ICO's International Data Transfer Agreement / Addendum.

7. How long we keep data

7.1 Account and booking records: while the account is open and for six years after the last booking (limitation and tax).

7.2 Payment records: six years.

7.3 Therapist vetting documents: while the therapist is listed and for six years after they leave, unless a complaint or legal claim requires longer.

7.4 Platform messages: while the account is open and for two years after the last message in the thread, unless needed for a complaint.

7.5 Server logs: up to 12 months.

7.6 You may ask us to delete your account. We will delete or anonymise what we no longer need, and keep what the law requires.

8. Your rights

8.1 You can ask for access, correction, deletion, restriction, objection, or portability, and you can withdraw consent where we rely on it. Email hello@connectandtreat.com. We may need to verify who you are.

8.2 You can complain to the ICO.

9. Children

9.1 Accounts are for people aged 18 or over, or a parent or guardian acting for a person under 18.

10. Email security

10.1 Ordinary email is not fully secure. Do not send unnecessary clinical detail by email. Use the Platform where you can.

11. Changes

11.1 We will update the date at the top when this policy changes.

12. Contact

hello@connectandtreat.com

Connect and Treat Limited, Apollo House, Hallam Way, Whitehills Business Park, Blackpool, England, FY4 5FS.

In a crisis? Help is available right now

Connect & Treat is not a crisis service. If you or someone you know is at risk, please contact a UK helpline below.