Privacy Policy

Last updated: April 18, 2026

Introduction

Mindwell Therapy Collective ("we," "us," "our," or "Company") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our services.

Please read this Privacy Policy carefully. If you do not agree with our policies and practices, please do not use our services. By accessing and using Mindwell Therapy Collective, you acknowledge that you have read, understood, and agree to be bound by all the provisions of this Privacy Policy.

1. Information We Collect

Information You Provide Directly

We collect information you voluntarily provide when you:

  • Create an account or register for our services
  • Complete booking forms or intake questionnaires
  • Contact us via email, phone, or contact forms
  • Participate in surveys or feedback requests
  • Make payments for therapy sessions

This may include your name, email address, phone number, postal address, date of birth, health information, payment details, and any other information you choose to provide.

Information Collected Automatically

When you visit our website, we automatically collect certain information about your device and browsing activity, including:

  • IP address and device identifiers
  • Browser type and version
  • Operating system
  • Pages visited and time spent on pages
  • Referral source and links clicked
  • Approximate geographic location

Sensitive Health Information

As a therapy provider, we may collect sensitive health and personal information including mental health history, treatment notes, and other personal details. This information is collected only with your explicit consent and is subject to the highest level of protection under applicable privacy laws.

2. Legal Basis for Processing

For Canadian Residents (PIPEDA): We process your personal information based on your consent, the performance of our contractual obligations to provide therapy services, and our legitimate business interests including client safety and regulatory compliance.

For EU/EEA Residents (GDPR): We process your personal information based on:

  • Your explicit consent for health-related data processing
  • Performance of the contract to provide therapy services
  • Compliance with legal obligations
  • Legitimate interests in operating and improving our services
  • Protection of vital interests and safety

You have the right to withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Providing therapy services and clinical care
  • Scheduling appointments and sending appointment reminders
  • Processing payments and billing
  • Communicating with you about your account and services
  • Responding to your inquiries and requests
  • Improving our website, services, and user experience
  • Conducting research and analytics
  • Complying with legal obligations and regulations
  • Protecting against fraud, abuse, and security threats
  • Marketing and promotional communications (with consent)
  • Maintaining clinical records as required by law

4. Data Retention

We retain your personal information for as long as necessary to provide our services and fulfill the purposes outlined in this Privacy Policy. Retention periods vary depending on the type of information:

  • Clinical Records: Retained for a minimum of 7 years following the last date of service, in accordance with professional standards and legal requirements
  • Account Information: Retained for the duration of your account and 3 years after closure
  • Billing Records: Retained for 7 years for tax and regulatory compliance
  • Marketing Data: Retained until you unsubscribe or request deletion
  • Website Analytics: Retained for up to 24 months

When information is no longer needed, it is securely deleted or anonymized. In some cases, we may retain information if required by law or to protect our legal interests.

5. Your Privacy Rights

For All Users

You have the right to:

  • Access the personal information we hold about you
  • Request correction or update of inaccurate information
  • Request deletion of your personal information
  • Withdraw consent to processing at any time
  • Lodge a complaint with the relevant privacy authority

For EU/EEA Residents (GDPR Rights)

In addition to the rights listed above, you have the right to:

  • Data portability: receive your data in a structured, commonly used format
  • Restrict processing of your information
  • Object to processing for marketing purposes
  • Request human review of automated decision-making
  • Lodge a complaint with your local data protection authority

For Canadian Residents (PIPEDA Rights)

Under the Personal Information Protection and Electronic Documents Act (PIPEDA), you have the right to:

  • Access your personal information held by us
  • Request correction of inaccurate or incomplete information
  • Know why your information is being collected and used
  • Opt-out of non-essential collection, use, or disclosure
  • Lodge a complaint with the Office of the Privacy Commissioner of Canada

To exercise any of these rights, please contact us using the information provided in the Contact Us section below.

6. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience on our website. Cookies are small files stored on your device that help us recognize you and remember your preferences.

Types of Cookies We Use:

  • Essential Cookies: Required for website functionality and security
  • Analytics Cookies: Help us understand how visitors use our website
  • Preference Cookies: Remember your preferences and settings
  • Marketing Cookies: Used to deliver targeted advertising (with consent)

You can control cookie preferences through your browser settings. Most browsers allow you to refuse cookies or alert you when cookies are being sent. However, blocking essential cookies may affect website functionality.

7. Data Security

We implement comprehensive technical, administrative, and physical safeguards to protect your personal information against unauthorized access, alteration, disclosure, or destruction. Our security measures include:

  • Encryption of data in transit using SSL/TLS protocols
  • Encryption of sensitive data at rest
  • Secure authentication mechanisms and access controls
  • Regular security audits and vulnerability assessments
  • Employee training on data protection and privacy
  • Restricted access to personal information on a need-to-know basis
  • Secure disposal procedures for physical and digital records

While we strive to protect your information using reasonable security measures, no method of transmission over the internet is completely secure. We cannot guarantee absolute security, and you use our services at your own risk.

8. Third-Party Disclosure

We do not sell or rent your personal information to third parties. We may share your information with trusted service providers and partners only when necessary to:

  • Provide you with therapy services and administrative support
  • Process payments through secure payment processors
  • Host and maintain our website and systems
  • Conduct analytics and improve our services
  • Comply with legal obligations and court orders
  • Protect against fraud and ensure security
  • With your explicit consent for other purposes

All third-party service providers are contractually obligated to protect your information and use it only for the specified purposes. We do not authorize them to use or disclose your information for other purposes.

9. Compliance with Privacy Laws

PIPEDA Compliance (Canada)

Mindwell Therapy Collective complies with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation including the Personal Health Information Protection Act (PHIPA) in Ontario. We collect, use, and disclose personal information in accordance with PIPEDA's principles of fairness, accuracy, accountability, and confidentiality. You have the right to access, correct, or request deletion of your information, and to lodge complaints with the Office of the Privacy Commissioner of Canada.

GDPR Compliance (EU/EEA)

For individuals in the European Union and European Economic Area, we comply with the General Data Protection Regulation (GDPR). We process personal information based on lawful grounds including your explicit consent, performance of contracts, compliance with legal obligations, and legitimate interests. You have the rights described in Section 5 of this Privacy Policy, including the right to lodge complaints with your local data protection authority. Our Data Protection Officer and additional information about GDPR compliance are available upon request.

Healthcare Privacy Standards

As a therapy provider, we comply with applicable health privacy regulations and professional standards of conduct. We maintain strict confidentiality of health information except where disclosure is required or permitted by law, or with your informed consent.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, and other factors. We will notify you of material changes by posting the updated Privacy Policy on our website and updating the "Last updated" date.

Your continued use of our services following the posting of a revised Privacy Policy means you accept and agree to the changes. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

11. Contact Us

If you have questions about this Privacy Policy, would like to exercise your privacy rights, or wish to make a complaint regarding our privacy practices, please contact us:

Mindwell Therapy Collective

Privacy Officer

Mailing Address:

Mindwell Therapy Collective
Privacy Requests
Toronto, Ontario
Canada

We aim to respond to all privacy requests within 30 days. For PIPEDA complaints, you may also contact the Office of the Privacy Commissioner of Canada at 1-800-282-1376 or www.priv.gc.ca.

This Privacy Policy is effective as of April 18, 2026, and applies to all information collected through our website and services provided by Mindwell Therapy Collective.