PRIVACY POLICY

Mentle Health

Privacy Policy

Effective: November 11, 2025 | v1.0

1. About This Policy

Mentle Health ('Company', 'we', 'us', or 'our') operates a digital men's mental health platform accessible via mobile application and website, collectively the 'Platform'.

This Privacy Policy explains how we collect, use, store, share, and protect your personal data. It also sets out your rights as a user.

By creating an account or using the Platform, you consent to the data practices described in this Policy. If you do not agree, please discontinue use of the Platform immediately.

2. Definitions

Personal Data

Any information relating to an identified or identifiable natural person, including name, email, health data, and device identifiers.

Sensitive Personal Data (SPD)

Health records, mental health history, session notes, biometric data, and financial data, as defined under SPDI Rules 2011 and DPDP Act 2023.

Data Fiduciary

Mentle Health, as the entity that determines the purposes and means of processing your data, equivalent to 'data controller' under GDPR.

Data Principal

You, the individual user whose personal data is being processed.

Processing

Any operation on personal data including collection, storage, use, disclosure, or deletion.

3. Data We Collect

3.1 Data You Provide Directly

  • Registration data: name, date of birth, email address, phone number, gender identity.
  • Health and wellness data: mood logs, journal entries, symptom check-ins, mental health assessments.
  • Session data: audio/video recordings of therapy sessions, only with explicit consent, and session notes.
  • Payment data: billing details processed via PCI-DSS compliant payment gateways; we do not store card numbers.
  • Communications: messages, feedback, support queries.

3.2 Data Collected Automatically

  • Device data: device type, OS, app version, unique device identifiers (UDID/IDFA/GAID).
  • Usage data: features accessed, session duration, clickstream data.
  • Log data: IP address, timestamps, crash reports.
  • Location data: approximate location derived from IP, not GPS, unless you grant location permission.

3.3 Data From Third Parties

  • Therapist-provided clinical notes and assessments.
  • Payment gateway transaction references.
  • App store analytics, anonymised and aggregated only.

4. Purposes of Processing & Legal Basis

PurposeLegal Basis (India)Legal Basis (EU/GDPR)
Providing therapy and wellness servicesConsent + ContractArt. 6(1)(b) - Contract
Processing mental health dataExplicit Consent (DPDP/MHCA)Art. 9(2)(a) - Explicit Consent
Payment processingContract performanceArt. 6(1)(b) - Contract
Platform safety and crisis interventionLegitimate interest / vital interestsArt. 6(1)(d) - Vital Interests
Product improvement (anonymised)Legitimate interestArt. 6(1)(f) - Legitimate Interest
Legal compliance and auditLegal obligationArt. 6(1)(c) - Legal Obligation
Marketing (opt-in only)ConsentArt. 6(1)(a) - Consent

5. Data Sharing & Disclosure

5.1 With Therapists

Your session data and health records are shared with the therapist assigned to you on the Platform, strictly for the purpose of providing therapeutic services.

5.2 With Service Providers

We engage third-party processors, including cloud storage, payment gateways, and analytics providers, under Data Processing Agreements that restrict them to processing your data only on our instructions.

5.3 Legal Disclosure

We may disclose data where required by Indian law, court order, or a competent authority. We will notify you where legally permissible before complying with such requests.

5.4 Crisis Situations

If we reasonably believe a user is at imminent risk of self-harm or harm to others, we may share necessary information with emergency services without prior consent, consistent with our obligations under the MHCA 2017 and Telemedicine Practice Guidelines 2020.

5.5 We Never Sell Your Data

Mentle Health does not sell, rent, or trade your personal data to advertisers or any third party for commercial purposes.

6. Data Retention

  • Therapy session notes and clinical records: 7 years from last session, minimum, as recommended under MHCA 2017 guidelines.
  • Account data: for the duration of your account, plus 3 years after deletion for legal compliance.
  • Payment records: 8 years, as required under Indian tax laws.
  • Marketing data: until you withdraw consent.
  • Anonymised analytics data: indefinitely.

7. Data Security

We implement the following safeguards:

  • AES-256 encryption for data at rest; TLS 1.3 for data in transit.
  • Role-based access control: therapists can only access their own clients' data.
  • Multi-factor authentication for all practitioner accounts.
  • Regular third-party penetration testing and vulnerability assessments.
  • Data localisation: all personal data of Indian users is stored on servers physically located in India.
  • Data breach notification: we will notify affected users and the Data Protection Board of India within 72 hours of becoming aware of a breach, as required under DPDP Rules 2025.

8. Your Rights

8.1 Rights Under DPDP Act 2023 (Indian Users)

  • Right to access: obtain a summary of personal data held and how it is being processed.
  • Right to correction: correct inaccurate or incomplete personal data.
  • Right to erasure: request deletion of your data, subject to legal retention requirements.
  • Right to grievance redressal: raise complaints with our Grievance Officer.
  • Right to nominate: nominate a person to exercise rights on your behalf in case of incapacity or death.

8.2 Additional Rights Under GDPR (EU/EEA Users)

  • Right to data portability: receive your data in a structured, machine-readable format.
  • Right to object: object to processing based on legitimate interests.
  • Right to restrict processing: request we limit how your data is used.
  • Right to lodge a complaint with your national supervisory authority.

8.3 Additional Rights Under CCPA (California Users)

  • Right to know what personal information is collected and how it is used.
  • Right to opt-out of any sale of personal information; we do not sell.
  • Right to non-discrimination for exercising your rights.

9. Cookies & Tracking

Our web platform uses cookies and similar technologies for authentication, security, and analytics. You may control cookie preferences through your browser settings. We do not use third-party advertising cookies.

10. Children's Privacy

The Platform is strictly intended for users aged 18 and above. We do not knowingly collect data from minors. If we discover that a minor has provided data without parental consent, we will delete it immediately.

11. International Data Transfers

If your data is transferred outside India, for example for global analytics tools, we ensure equivalent protections via Standard Contractual Clauses (SCCs) under GDPR and comply with data localisation obligations under DPDP Rules 2025 for Indian users' sensitive personal data.

12. Changes to This Policy

We may update this Policy. Material changes will be notified via email and in-app notification at least 15 days before they take effect. Continued use of the Platform after the effective date constitutes acceptance of the revised Policy.