Integrate — Privacy Policy
Last updated Version 1.0 — Closed Pilot
About this policy
Integrate is a record-keeping and support tool for practitioners who work with people through experiential and transformational care — coaching, facilitation, somatic work, breathwork, psychedelic-assisted care and related approaches. Integrate does not provide care itself and is not a medical device. Each practitioner remains solely responsible for their own practice.
This policy explains what we do with your personal information. We have written it in plain language, because the information involved is sensitive and you deserve to understand it without a lawyer.
Integrate is currently in a closed, invitation-only pilot. We expect to update this policy as the service grows, and we will tell you when we do.
Most of this policy is written for participants — the people practitioners work with. Section 10 is written for practitioners.
1. Who we are
With Integrate Ltd, a private limited company incorporated in England and Wales, company number 17395953, registered office at 469a Roman Road, London, England, E3 5LX ("Integrate", "we", "us", "our").
Applicable law. Because we are incorporated in the United Kingdom, the UK GDPR and the Data Protection Act 2018 apply to everything we do. Because we process personal data of people in the EU and EEA, the EU GDPR also applies to that processing. Where this policy says "GDPR", it means whichever applies to you, or both.
If you are outside the UK and EU, we apply the same standards to your information. Your local law may give you additional rights, and we will honour them.
Contact for privacy questions, rights requests and complaints: privacy@joinintegrate.com
Data protection contact: privacy@joinintegrate.com. We have not appointed a statutory Data Protection Officer at this stage. The law requires one only where an organisation's core activities involve large-scale processing of special category data, and a closed pilot does not meet that threshold. We reassess this at least every six months and will appoint one if the threshold is met.
2. Our role and your practitioner's role
This matters, and we want to be honest about it.
For your account and how the platform runs — your name, email address, sign-in activity and similar — we are the data controller. We decide how that information is used, and this policy governs it.
For your care information — what you share in screening forms, reflections you write, notes your practitioner records, decisions they make about your care — your practitioner or their organisation is the data controller, and we act as their data processor on their instructions. They decide what is collected and why; we provide the secure system it lives in.
In practice: for questions about your care record, your practitioner is the first point of contact, and they will have their own privacy information for you. For questions about the platform itself, come to us. We will always help you reach the right place.
3. The information we hold
3.1 Information you or your practitioner provide
- Identity and contact details — name, email address, phone number, date of birth, country.
- Screening and intake information — health information you share so a practitioner can assess whether their work is suitable and safe for you. This is health data and carries the highest level of protection.
- Information you create as you go — reflections, journal entries, responses to check-ins and surveys, intentions and goals.
- Messages — communications between you and your practitioner through the platform.
- Session records — appointments, attendance, and notes your practitioner makes about your care.
- Consent records — what you agreed to, when, and any withdrawal of consent.
- Community information — if you take part in community features, what you choose to share there, including peer connections and encrypted messages.
- Waiting list details — if you have asked to be added to a waiting list, your email address and anything you provided at sign-up.
3.2 Information created automatically
- Access and audit records — a deliberate log of who accessed what and when, so that access to sensitive information is accountable.
- Technical information — sign-in events, device type, approximate location (country/city, derived from your IP address) and session activity, needed to run and secure the service.
3.3 Health information is special
Most of what a practitioner records about your care is "special category" data. It carries extra legal protection, and we treat it accordingly.
Practitioners using Integrate include regulated health and care professionals bound by professional secrecy, and independent practitioners — coaches, breathwork and retreat facilitators — who are not. Which applies to your practitioner determines the legal basis for your care information:
- If your practitioner is a regulated professional bound by professional secrecy, they rely on the provision of health or social care as their basis (Article 9(2)(h) GDPR, read with Article 30 UAVG for Dutch practitioners and Schedule 1 paragraph 2 of the Data Protection Act 2018 for UK practitioners).
- If your practitioner is not bound by such an obligation, they rely on your explicit consent (Article 9(2)(a) GDPR), which you may withdraw at any time.
Your practitioner will tell you which applies to you, and it is stated in the consent you give when you join. We process your care information on their instructions in either case. The basis that applies also determines what can be deleted — see sections 8 and 12.
4. Why we process it and our legal basis
What we do, Legal basis
What we do: Provide the platform, your account and sign-in
Legal basis: Performance of a contract with you (Art. 6(1)(b))
What we do: Enable your practitioner to deliver and record your care
Legal basis: On your practitioner's instructions, as their processor. Their basis is either the provision of health or social care under professional secrecy (Art. 9(2)(h)) or your explicit consent (Art. 9(2)(a)) — see section 3.3
What we do: Keep the service secure, prevent misuse and maintain audit records
Legal basis: Our legitimate interests in security and accountability (Art. 6(1)(f)); legal obligation (Art. 6(1)(c))
What we do: Respond when you contact us
Legal basis: Our legitimate interests in supporting you (Art. 6(1)(f))
What we do: Provide community and peer connection features
Legal basis: Our legitimate interests in providing the functionality (Art. 6(1)(f)), and your consent for specific interactions
What we do: Hold your details on our waiting list
Legal basis: Your consent (Art. 6(1)(a)), which you may withdraw by asking us to remove you
What we do: Comply with applicable law, including record-keeping obligations
Legal basis: Legal obligation (Art. 6(1)(c))
Where we rely on legitimate interests, we have considered whether they are outweighed by your rights, and we will explain our reasoning if you ask.
A note on consent for care. Where your practitioner asks for your explicit consent to work with your health information, that consent belongs to your care relationship with them, not to us. You can withdraw it, and withdrawing it does not affect anything done lawfully before you did.
5. Automated decisions
We do not make automated decisions about you that have legal or similarly significant effects, and we do not profile you in that way.
The platform may highlight information for a practitioner's attention — for example, drawing their attention to something in a screening response. These are prompts to a human being, never decisions. Every judgement about your care is made by your practitioner.
6. Who your information is shared with
We do not sell your personal information. We do not use it for advertising. We do not share it for anyone else's marketing.
6.1 Your practitioner and their organisation
Your practitioner, and where you are cared for by an organisation, the colleagues within it who need access for your care or its administration. Access is limited by role: administrative staff cannot see care content, and practitioners see only the people they care for.
6.2 Our service providers
These companies process data on our behalf, under contracts that carry equivalent data protection obligations:
Provider, What they do, Where data is stored
Provider: Supabase Inc.
What they do: Database and user authentication
Where data is stored: Frankfurt, Germany (EU)
Provider: Amazon Web Services, Inc.
What they do: Encryption key management
Where data is stored: Frankfurt, Germany (EU)
Provider: Vercel Inc.
What they do: Application hosting
Where data is stored: Frankfurt, Germany (EU)
Provider: Resend, Inc.
What they do: Email delivery
Where data is stored: Ireland (EU)
Provider: Sentry (Functional Software, Inc.)
What they do: Error monitoring
Where data is stored: United States
6.3 Google Calendar
Where your practitioner has connected their Google Calendar to Integrate, session appointments may appear in it. Google then holds those appointment details under its own terms. The details of what we do with a practitioner's Google data are in section 10.2.
6.4 Regulators and authorities
Where the law requires it — a legal obligation, a court order, or a serious risk to someone's safety. Your practitioner's professional duties may also require disclosure in specific circumstances.
6.5 A successor organisation
If Integrate is acquired, merged or restructured, personal information may be transferred to the successor, subject to equivalent obligations. We will tell you if this happens.
7. Where your information is held and international transfers
Your information is stored in the European Union (Frankfurt, Germany). We chose our infrastructure to keep it there, even though we are a UK company.
EU to UK. When EU-based practitioners or organisations send personal data to us, that is a transfer from the EU to the United Kingdom. We rely on the European Commission's adequacy decision for the UK, renewed on 19 December 2025 and running to 27 December 2031.
Onward transfers. Supabase, Amazon Web Services, Vercel, Resend and Sentry are headquartered in the United States. Data is stored in the EU, and each provider's data processing terms include the safeguards required for any access from outside the EU and UK (the EU Standard Contractual Clauses and the UK addendum to them). Error reports sent to Sentry are held in the United States under the same safeguards. They are stripped before sending and contain no care content, identities or message bodies.
8. How long we keep it
Information, How long
Information: Care records — practitioner bound by a statutory record-keeping duty
How long: For the period their national law requires. For Dutch practitioners bound by the WGBO this is 20 years from the last change to the record (Article 7:454(3) BW). Records subject to a statutory duty cannot be deleted on request during that period.
Information: Care records — practitioner relying on your explicit consent
How long: For as long as your care relationship with that practitioner continues, and deleted on request (see section 12.3).
Information: Account information
How long: 12 months after your account is closed, then deleted.
Information: Access and audit records
How long: For as long as the record they relate to exists.
Information: Waiting list details
How long: Until you ask us to remove you, or 12 months if you do not join.
Information: Backups
How long: Up to 7 days after deletion from the live system, after which they age out automatically.
We will always tell you honestly what can and cannot be deleted, and why. We will never hide behind a legal retention obligation without explaining it.
9. How we protect it
We built this platform for sensitive information from the start.
- Encryption. Sensitive content is encrypted so that each person's information is protected by its own individual key (AES-256-GCM, per-person key, held in a managed key service). Encrypted content is unreadable without it.
- Separation by design. Practices are separated at the database level, so information cannot cross between them. Access is enforced by the system, not by convention.
- Role-based access. Administrative staff cannot see care content. Practitioners see only the participants they care for.
- Authentication. Practitioner and staff accounts use authenticated sign-in, and we are adding passkey-based multi-factor authentication before real participant information enters the system. Participant access is protected by email one-time passcodes.
- Accountable access. We keep append-only records of who accessed sensitive information and when.
- Deletion that means it. Where information can be deleted, we destroy the encryption key that protects it, making the content unrecoverable from the live system. A copy of the encrypted content may remain in an automated backup for up to 7 days, after which it ages out. If we ever restore from a backup, we re-apply every deletion made since that backup was taken before the system returns to service.
- Independent review. Before any real participant information enters the system, our security is independently reviewed by an expert who is not involved in building it.
We are building toward ISO 27001 and NEN 7510 (the Dutch healthcare information-security standard).
If a security breach occurs that puts your rights at risk, we will tell you and notify the relevant supervisory authority as the law requires.
10. If you are a practitioner
This section is for practitioners using Integrate. We are the data controller for your account and for the information you provide to us about yourself.
10.1 What we hold about you
Your name, email address, country, organisation and role; any professional registration details you provide; your sign-in and usage records; and any reflective notes or community profile you create. Reflective notes are encrypted with a practice-level key and are intended to be about your own practice, not about identifiable participants. Our legal basis is the contract we have with you, and our legitimate interests in running and securing the platform.
10.2 Google Calendar
If you choose to connect your Google Calendar, we use Google's OAuth service so that you sign in with Google and grant Integrate specific, limited permissions. We do not see your Google password.
- What we access: your calendar's availability (free/busy times), so that sessions can be scheduled around your existing commitments; and the ability to create, update and remove the Integrate session events we place in your calendar.
- What we do with it: scheduling sessions and keeping them in sync between Integrate and your calendar. Nothing else.
- What we store: the access tokens Google gives us, stored encrypted, and the identifiers of the events we create. We do not copy the contents of your other calendar events into Integrate.
- Who sees it: no one outside Integrate. We do not sell, share or transfer Google user data to third parties, we do not use it for advertising, and we do not use it to train or improve any AI or machine-learning model.
- Disconnecting: you can disconnect at any time from your Integrate settings or from your Google account permissions page. When you disconnect, we delete the tokens and stop all access.
Integrate's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
10.3 Your obligations
As a controller for your participants' care information, you have your own duties under data protection law. The Data Processing Agreement between us sets out how we support you in meeting them.
11. Professional secrecy
Practitioners bound by professional secrecy — for example Dutch practitioners under Article 7:457 BW and the Wet BIG, or UK regulated professionals under their professional standards — can share your information only in strictly defined circumstances. Where your practitioner is not bound by such an obligation, they are still bound by the confidentiality obligations in their agreement with us, and your information is protected by the safeguards in this policy.
12. Your rights
12.1 Rights under data protection law
You have the right to:
- Know what information we hold about you and receive a copy (Art. 15).
- Correct information that is wrong (Art. 16).
- Delete information, in the circumstances the law allows (Art. 17). See section 12.3.
- Restrict or object to how your information is used (Arts. 18, 21).
- Receive your information in a reusable format (Art. 20), where processing is based on contract or consent.
- Withdraw consent at any time, where processing relies on it, without affecting anything done before.
- Complain to us or to a supervisory authority — see section 14.
12.2 Additional rights if your practitioner is bound by Dutch healthcare law (WGBO)
- Inspect and obtain a copy of your record (Art. 7:456 BW). Exercise this with your practitioner directly.
- Add a statement to your record (Art. 7:455 BW) if you disagree with something recorded.
- Request destruction (Art. 7:455 BW), subject to the statutory retention period described in section 12.3.
12.3 An honest note on deletion
If your practitioner is bound by a statutory record-keeping duty — for example the Dutch WGBO's 20-year retention — neither we nor your practitioner can delete your care record on request during that period. A legal obligation overrides the right to erasure (Art. 17(3)(b)).
If your practitioner relies on your explicit consent, no such obligation applies. You have a normal right to erasure, subject to the usual exceptions (for example, if we must keep information to meet another legal obligation or to defend a legal claim).
We will always explain clearly which applies to you, and which information can and cannot be deleted.
Where information can be deleted, we destroy the encryption key that protects it. The content is then unrecoverable from the live system. An encrypted copy may remain in an automated backup for up to 7 days, and if we ever restore from a backup we re-apply every deletion first.
To exercise any right: email privacy@joinintegrate.com or speak to your practitioner. We will respond within one month.
13. Children
Integrate is for adults aged 18 and over. We do not knowingly provide the service to anyone under 18.
14. Complaints and supervisory authorities
We would appreciate the chance to put things right first. Email privacy@joinintegrate.com. We will acknowledge your complaint within 30 days, look into it without undue delay, and tell you the outcome and what we have done.
You also have the right to complain to a supervisory authority:
UK — Information Commissioner's Office (ICO): Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF | www.ico.org.uk | 0303 123 1113
EU/EEA: the supervisory authority in the Member State where you live or work. For the Netherlands: Autoriteit Persoonsgegevens (AP), Hoge Nieuwstraat 8, 2514 EL Den Haag | www.autoriteitpersoonsgegevens.nl. For complaints about healthcare data handling by Dutch practitioners, you may also contact the Inspectie Gezondheidszorg en Jeugd (IGJ).
15. Cookies and similar technologies
We use only what is necessary to sign you in and keep your session secure. We do not use advertising or third-party tracking cookies.
16. Changes to this policy
If we make a significant change, we will tell you directly — by email or in-platform notification — rather than quietly updating this page. This version reflects our closed pilot; we expect to revise it as the service develops.
17. Contact us
With Integrate Ltd 469a Roman Road, London, England, E3 5LX privacy@joinintegrate.com
