Privacy Policy

Dynamic Running Therapy (DRT)

Effective Date: June 1, 2026 | Last Updated: May 26, 2026

  1. About This Policy

    This Privacy Policy explains how Dynamic Running Therapy (referred to in this Policy as “DRT,” “we,” “us,” or “our”) collects, uses, shares, and protects your personal information when you download, install, register for, or use the Dynamic Running Therapy mobile application (the “App”) and any other DRT activities or websites expressly referenced herein. It also describes the choices and rights you have regarding your personal information.

    DRT is a self-guided wellness application that combines movement (such as walking or running), mindfulness prompts, and reflective questions designed to support your general well-being. The App is not a medical device, is not intended to diagnose, treat, cure, or prevent any illness or disease, and does not provide medical, psychological, or psychotherapy services. If you are experiencing a mental health crisis or have a medical concern, please contact a qualified healthcare professional or your local emergency services. By using the App, you acknowledge and accept that it is not a substitute for professional healthcare advice. For more information on our liability limitations, please refer to our Terms and Conditions, which include a liability cap.

    We have written this Policy to comply with privacy laws in the regions where the App is available, including the United States (with state-specific addenda below), the European Economic Area (including Ireland), the United Kingdom, Canada, South Africa, Australia, and New Zealand. Sections 16 through 23 of this Policy contain jurisdiction-specific disclosures that supplement, and where applicable override, the general provisions.

    By downloading, installing, accessing, or using the App, you confirm that you have read and understood this Policy. If you do not agree with this Policy, please do not use the App.

    A current copy of this Policy is available on our website at Dynamic Running Therapy Privacy Policy, and from within the App at any time. We recommend that you save or print a copy for your records.

    By downloading, installing, accessing, or using the App, you confirm that you have read, understood, and agree to the Terms and Conditions, including the liability limitations and disclaimers. You must check the box indicating your acceptance of these terms before proceeding to use the App.

  2. Who We Are and How to Contact Us

    The data controller responsible for your personal information under applicable law is:

    Dynamic Running Therapy LLC
    38 Davis Hill Rd,
    Weston,
    CT 06883,
    USA

    info@dynamicrunningtherapy.com

    For questions about this Policy, to exercise any of your privacy rights, or to submit a privacy complaint, please contact us at the email address above. We aim to respond to privacy inquiries within thirty (30) days, and within the shorter response times required by specific laws referenced in the jurisdiction-specific sections below.

    For privacy-related matters, you may also contact our designated Data Protection Officer at dpo@dynamicrunningtherapy.co.uk. Our designated Data Protection Officer, as required under GDPR Article 37, may be contacted regarding matters involving special categories of data processing at dpo@dynamicrunningtherapy.co.uk.

  3. Information We Collect

    We collect personal information from and about you in three ways: (a) information you provide to us directly; (b) information we collect automatically when you use the App; and (c) information we receive from third parties.

    1. Information You Provide to Us

      When you create an account or use the App, you may provide us with:

      1. Account information: your name, email address, password, date of birth (used to confirm you meet the minimum age requirement applicable in your jurisdiction), and country of residence. We do not knowingly collect data from individuals under the applicable minimum age. If we discover that we have collected personal information from a minor without parental consent where required, we will delete that information promptly.
      2. Profile information: optional information you choose to add, such as a display name, profile photo, fitness level, or wellness goals.
      3. Reflection and journal content: written responses to the App’s reflective prompts, mood logs, free-text journal entries, and any other content you choose to record within the App.
      4. Communications: any messages, feedback, or support requests you send to us, including the contents of those communications and the contact information you provide.
      5. Survey responses: if you choose to take part in optional research, feedback, or product surveys we may run from time to time.
    2. Information We Collect Automatically

      When you use the App, we and the service providers acting on our behalf automatically collect certain information, which may include:

      1. Usage data: which features you use, the date and length of your sessions, the audio content you play, and how you interact with the App.
      2. Device data: device model, operating system and version, language settings, time zone, mobile network information, advertising or app identifiers issued by Apple or Google (used solely for analytics purposes), and a unique installation identifier.
      3. Diagnostics: crash logs, performance data, and error reports.
      4. Location data: with your permission through your device settings, the App may access your device’s GPS location during an active running or walking session in order to calculate your route, distance, pace, and time. You can switch this off at any time in your device settings, although doing so will limit certain features.
      5. Health and fitness data: if you choose to connect Apple Health (HealthKit) or Google Fit, the App will access only the categories of data you authorize, such as steps, distance, heart rate, or active energy. You can revoke this access at any time through the relevant device setting.
    3. Information from Third Parties

      We may receive limited information about you from third parties, such as the Apple App Store, the Google Play Store, payment processors handling in-app purchases, and analytics or crash-reporting providers. We do not receive financial card details from Apple or Google; they handle payment processing directly and only share with us the information necessary to manage your subscription, such as a transaction reference and subscription status.

    4. Sensitive Information

      Some of the information you provide through the App, such as journal entries describing your feelings, mental state, or well-being, and any health or fitness data you connect, may constitute sensitive personal information under applicable privacy laws. We afford this information heightened protection and process it solely for the following purposes:

      1. providing, operating, and maintaining the App’s core features that you have requested, including delivering personalized exercises, prompts, and session tracking;
      2. complying with our legal and regulatory obligations; and
      3. establishing, exercising, or defending legal claims.

      We do not use sensitive personal information for product analytics, advertising, profiling, or any purpose unrelated to the direct provision of the App’s features to you, except that anonymized or de-identified data may be used for product improvement.

      We do not sell or share sensitive personal information for cross-context behavioral advertising, and we do not use such information to infer characteristics about you for any purpose unrelated to the App.

      Specifically, we do not use HealthKit data for advertising purposes or sell it to third parties, in compliance with Apple’s HealthKit guidelines.

  4. How We Use Your Information

    We use the personal information we collect to:

    1. Provide, operate, and maintain the App, including authenticating you, syncing your data across your devices, and delivering the content and features you request.
    2. Personalize your experience, such as remembering your settings, suggesting relevant exercises, and tailoring reflective prompts.
    3. Process subscriptions and any other transactions you make through the App (handled by Apple or Google, as applicable).
    4. Communicate with you about your account, customer-support requests, technical notices, security alerts, and changes to this Policy.
    5. Improve and develop the App, including by analyzing usage patterns, testing new features, and fixing bugs.
    6. Maintain the security and integrity of the App, prevent fraud and abuse, and enforce our Terms and Conditions.
    7. Comply with our legal and regulatory obligations, including responding to lawful requests from public authorities, and to establish, exercise, or defend legal claims.
    8. Where permitted by law, send you information about new App features, content, or wellness resources. For existing customers, we may rely on legitimate interests to send you marketing communications, unless you opt out. You can unsubscribe at any time. In jurisdictions where consent is required, we will obtain your consent before sending marketing communications, and you can withdraw your consent at any time.

    We will not use your personal information for any purpose that is incompatible with the purposes described in this Policy unless we obtain your consent or are otherwise permitted to do so by law.

  5. Legal Bases for Processing (Users in the EEA, the United Kingdom, and Switzerland)

    If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, we process your personal information only when we have a legal basis to do so under Article 6 of the General Data Protection Regulation, Regulation (EU) 2016/679 (the “GDPR”), and the corresponding provision of the United Kingdom’s retained version of the GDPR (the “UK GDPR”). The legal bases we rely on are:

    1. Performance of a contract (GDPR art. 6(1)(b)): to provide the App and the services you have signed up for, and to take steps at your request before entering into a contract.
    2. Compliance with a legal obligation (GDPR art. 6(1)(c)): where we are required to process information to meet a legal duty.
    3. Legitimate interests (GDPR art. 6(1)(f)): where it is in our legitimate interest to do so, balanced against your rights. Examples include keeping the App secure, preventing fraud, analyzing aggregated usage to improve the App, and corresponding with you in response to questions. We conduct documented Legitimate Interests Assessments (LIAs) to ensure that our interests are balanced against your rights.
    4. Consent (GDPR art. 6(1)(a)): where you have given consent, for example to enable optional analytics, to send you marketing communications, or to access optional device features such as location or HealthKit.

    Where we process special categories of personal data (Article 9 GDPR), including any health-related information you share with us, we rely on your explicit consent (GDPR art. 9(2)(a)) and a condition under Schedule 1 of the Data Protection Act 2018, such as paragraph 1, which relates to processing with consent. You have the right to withdraw your consent at any time without affecting the lawfulness of any processing carried out before withdrawal.

  6. How We Share Your Information

    We share your personal information only as set out in this Policy. We may share it with:

    1. Service providers and processors: companies that help us run the App, such as cloud hosting, analytics, customer support, payment processing (Apple and Google), email delivery, and crash-reporting providers. They process your information only on our instructions and under written contracts that require them to protect it. A current list of these service providers and processors is available at https://dynamicrunningtherapy.co.uk/?s=subprocessors.
    2. Apple and Google: as needed to distribute the App, process in-app purchases, and provide platform services such as Apple Sign In, HealthKit, or Google Fit.
    3. Legal, safety, and compliance recipients: courts, law-enforcement bodies, regulators, and other public authorities where we are required to do so by law or where disclosure is necessary to protect the rights, property, or safety of you, us, or others.
    4. Professional advisers: our lawyers, accountants, auditors, and insurers, where reasonably necessary for the running of our business.
    5. Successors in business: if we sell, merge, restructure, or otherwise transfer all or part of our business, your personal information may be transferred to the successor entity as part of that transaction. We will notify you and apply this Policy or seek your consent if the new entity intends to process your information differently.
    6. With your consent or at your direction: where you have agreed to or asked for the disclosure.
    7. No sale of personal information; no targeted advertising without consent: we do not sell your personal information for money. We do not share your personal information for cross-context behavioral advertising or targeted advertising without your explicit consent. We do not allow third-party advertising networks to track you through the App without your consent.
  7. International Data Transfers

    We are based in London, United Kingdom, and the service providers we use may be located in other countries, including the United States, the United Kingdom, the European Economic Area, and other regions. When we transfer personal information across borders, we put in place safeguards required by law, including:

    1. Transfers to countries that have received an adequacy decision from the European Commission or the UK government.
    2. Standard contractual clauses approved by the European Commission and the UK’s International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses, supplemented where necessary by additional technical and organizational measures. If these mechanisms are invalidated or become unavailable, we reserve the right to use alternative lawful transfer mechanisms without a material change to this Policy. We will notify you of any such changes to the transfer mechanisms.
    3. For South African data subjects, transfers permitted under section 72 of the Protection of Personal Information Act, 4 of 2013 (“POPIA”).
    4. For Australian users, transfers compliant with Australian Privacy Principle 8 under the Privacy Act 1988.
    5. For New Zealand users, transfers consistent with Information Privacy Principle 12 of the Privacy Act 2020.

    You can ask us for a copy of the safeguards we rely on by contacting us at the email address in Section 2.

  8. How Long We Keep Your Information

    We keep your personal information only for as long as we need it for the purposes described in this Policy or for as long as the law requires. In general:

    1. Account data is kept for as long as your account is active.
    2. Reflection, journal, and session content is kept for as long as your account is active, or until you delete it within the App.
    3. Subscription and transaction records are kept for the period required by tax, accounting, and consumer-protection law (typically six to seven years from the end of the relevant financial year, depending on jurisdiction).
    4. Diagnostic logs are kept in identifiable form for approximately ninety (90) days, after which they are aggregated or deleted, unless retention is required for security, legal, or specific operational reasons such as system maintenance or troubleshooting. Any extended retention for operational reasons will be reviewed periodically to ensure compliance with applicable data protection laws.
    5. If you ask us to delete your account, we will do so within thirty (30) days, except where we are required or permitted by law to keep certain information, for example, to comply with a legal hold or to defend a legal claim. Once the legal hold or claim is resolved, we will delete the retained data within a maximum of ninety (90) days. You may also request deletion of specific personal data, such as journal entries, session history, or health and fitness data, without deleting your entire account by contacting us at the email address in Section 2 or by using the data deletion feature within the App. We will action such requests within thirty (30) days, subject to the same legal exceptions described above.
  9. How We Protect Your Information

    We use technical and organizational measures designed to protect your personal information against accidental loss and unauthorized access, use, alteration, or disclosure. These measures include encryption of personal information in transit and at rest using AES-256 and TLS 1.2 or higher, access controls and authentication for our staff, regular review of our security practices, and contractual obligations on our service providers.

    No method of transmission over the internet or storage on a mobile device is completely secure. While we work hard to protect your information, we cannot guarantee absolute security. You are responsible for keeping your login credentials confidential.

    If a breach of security affecting your personal information occurs, we will notify you and the relevant regulators where required by law, including under Article 33 and 34 of the GDPR and the UK GDPR, the Federal Trade Commission’s Health Breach Notification Rule (16 C.F.R. Part 318), section 22 of POPIA, Part IIIC of the Australian Privacy Act 1988, and Part 6 of the New Zealand Privacy Act 2020. We will establish internal breach response timelines and escalation procedures to ensure compliance with these obligations.

  10. Your Rights

    Depending on where you live, you have certain rights in relation to your personal information. The general rights described in this Section 10 apply to all users where the relevant law permits. The jurisdiction-specific sections (16 through 23) explain additional or different rights and how to exercise them.

    You generally have the right to:

    1. Access the personal information we hold about you and receive a copy of it.
    2. Have inaccurate or incomplete personal information corrected.
    3. Have your personal information deleted in certain circumstances.
    4. Object to or restrict our processing of your personal information in certain circumstances.
    5. Withdraw consent where we rely on consent to process your information.
    6. Receive your personal information in a portable, machine-readable format and ask us to transmit it to another controller where this is technically feasible.
    7. File a complaint with the data protection authority in the country where you live or work.

    To exercise any of these rights, contact us at the email address in Section 2. We may verify your identity before responding to your request. We reserve the right to charge a reasonable fee or decline requests that are manifestly unfounded or excessive, to the extent permitted under GDPR art. 12(5). A published fee schedule is available upon request. We will not discriminate or retaliate against you for exercising any privacy right.

  11. Children’s Privacy

    The App is not directed to children under the age of sixteen (16), and we do not knowingly collect personal information from anyone under that age. In some jurisdictions, including parts of the European Economic Area, the minimum age at which a person can consent to the processing of their information without parental authorization is lower (as low as thirteen (13) under GDPR art. 8(1)). Regardless of any lower local age limit, we apply a minimum age of sixteen (16) for use of the App. We enforce this policy through age verification mechanisms to ensure compliance.

    If we learn that we have collected personal information from a person under the age of sixteen (16) without verifiable parental consent, we will delete that information promptly. If you believe a child has provided personal information to us, please contact us at the email address in Section 2.

    For users in the United States, our practices are also designed to comply with the Children’s Online Privacy Protection Act, 15 U.S.C. §§ 6501-6506, and the FTC’s implementing regulations at 16 C.F.R. Part 312 (“COPPA”).

  12. Third-Party Services

    The App relies on a small number of third-party services to function. These include categories such as app store platforms, cloud hosting, analytics, crash-reporting, and email and communications providers. A current list of specific providers is maintained on our website and can be accessed via a link in this Policy.

    1. Apple App Store, Apple Sign In, and HealthKit (Apple Inc.).
    2. Google Play Store and Google Fit (Google LLC).
    3. Cloud hosting provider GoDaddy Europe Limited via Amazon Web Services.
    4. Analytics and crash-reporting provider Firebase Crashlytics.
    5. Email and communications provider GoDaddy Europe Limited.

    Each of these providers has its own privacy notice, which governs its processing of your information for its own purposes. We encourage you to read those notices.

    We do not control how third parties process information they collect directly from your device through their software development kits (SDKs) or operating-system features, although we contractually require our processors to act only on our instructions when they process information on our behalf, pursuant to written data processing agreements that comply with Article 28 of the GDPR (and the equivalent provision of the UK GDPR) and other applicable data protection laws.

    DRT disclaims liability for any unauthorized data processing by third-party SDKs, except where required by applicable law.

  13. Changes to This Policy

    We may update this Policy from time to time. When we make material changes, we will notify you through the App or by email before the changes take effect, and we will update the “Last Updated” date at the top of this Policy.

    Where a change materially affects the purposes for which we process your personal information or the legal basis on which we rely, we will seek your affirmative consent before applying the change to your information.

    For all other changes, your continued use of the App after the effective date of the updated Policy means you accept the changes. Non-material changes are those that do not affect your rights or the legal basis for processing your information. If you do not agree with any non-material changes, you should stop using the App and may delete your account.

  14. Definitions

    In this Policy:

    1. “Personal information” means information that identifies, relates to, or could reasonably be linked with you. The exact definition varies between the laws referenced in this Policy. Where a specific law’s definition applies, for example, the GDPR’s definition of “personal data” or the CCPA’s definition of “personal information,” we use it for that jurisdiction’s section.
    2. “Processing” means any operation performed on personal information, such as collection, recording, storage, use, disclosure, or deletion.
    3. “Service provider,” “processor,” and “operator” all refer to third parties who process personal information on our behalf, under our instructions, and pursuant to written contracts.
  15. Apple App Store and Google Play Disclosures

    In addition to this Policy, the App’s Apple App Store listing displays Apple’s “App Privacy” labels, and its Google Play listing displays Google’s “Data Safety” disclosures. The labels summarize the data we collect and how it is used in the format required by the relevant platform.

    We endeavor to keep those labels accurate and consistent with this Policy. If you identify an inconsistency, please notify us using the contact information in Section 2 so that we may investigate and correct it.

  16. United States: Additional Disclosures

    This Section 16 applies to users located in the United States and is in addition to the rest of this Policy.

    1. FTC Health Breach Notification Rule

      DRT operates the App as a “vendor of personal health records” within the meaning of the Federal Trade Commission’s Health Breach Notification Rule, 16 C.F.R. Part 318. Under that Rule, a “personal health record” (“PHR”) is an electronic record of identifiable health information that has the technical capacity to draw information from multiple sources and that is managed, shared, and controlled by or primarily for the individual. 16 C.F.R. § 318.2. The Rule applies to mobile applications that track health information such as fitness, mental health, sleep, and related categories.

      If a breach of security affects unsecured PHR identifiable health information, we will notify each affected U.S. user, the Federal Trade Commission, and, where 500 or more residents of any State are affected, prominent media outlets, in accordance with 16 C.F.R. §§ 318.3 through 318.6. Notification will be sent without unreasonable delay and in any event within sixty (60) days after the breach is discovered by a responsible officer, unless a law enforcement agency determines that notification would impede a criminal investigation, in which case notification may be delayed as permitted under 16 C.F.R. § 318.4(b).

    2. No HIPAA-Covered Relationship

      DRT is not a “covered entity” or a “business associate” as those terms are defined under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), 42 U.S.C. § 1320d et seq., and its implementing regulations at 45 C.F.R. Parts 160 and 164.

      The App is a direct-to-consumer wellness tool. Information you provide through the App is not “protected health information” under HIPAA and is not protected by the HIPAA Privacy or Security Rules. We protect your information through the safeguards described in this Policy and the laws referenced below.

      Users must not submit information they believe to be protected health information, and DRT disclaims any liability for any protected health information submitted in violation of this provision.

    3. Federal Trade Commission Act

      We are subject to Section 5 of the Federal Trade Commission Act, 15 U.S.C. § 45, which prohibits unfair or deceptive acts or practices in or affecting commerce. We will not make materially false or misleading statements about our privacy practices, and we will honor the commitments in this Policy, as amended from time to time. In the event of material amendments to this Policy, we will provide notice to affected users in accordance with applicable legal requirements.

    4. Health-Specific State Laws

      In addition to the comprehensive state privacy laws covered in Section 16.5 below, certain U.S. states have enacted laws specifically directed at consumer health information. We comply with the following where they apply, as well as other applicable state health data laws:

      1. Washington My Health My Data Act: Wash. Rev. Code (RCW) ch. 19.373. Consumers whose data is collected in Washington may confirm whether we collect, share, or sell their consumer health data, access that data including a list of third parties with which it has been shared or sold, withdraw consent, and request deletion. RCW 19.373.040. Requests may be submitted to the contact email in Section 2.
      2. Nevada Consumer Health Data Privacy Law: Nev. Rev. Stat. ch. 603A (as amended by 2023 Nev. Stats. ch. 567, SB 370). Nevada consumers have similar rights to access, withdraw consent, and request deletion of consumer health data.
      3. Connecticut Data Privacy Act: Conn. Gen. Stat. § 42-515 et seq., which expanded protections for “consumer health data” effective 1 July 2023.
    5. Comprehensive State Privacy Laws

      Residents of states with comprehensive consumer privacy laws have rights regarding their personal information. The states currently in scope include California (see Section 17 below), Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia, among others (subject to applicability thresholds, such as a minimum of 500 residents or specific revenue criteria).

      These rights generally include, but are not limited to:

      1. The right to confirm whether we process your personal information and to access it.
      2. The right to correct inaccuracies.
      3. The right to delete personal information.
      4. The right to receive your personal information in a portable format.
      5. The right to opt out of targeted advertising, sales of personal information, and profiling that produces legal or similarly significant effects (we do not engage in any of these activities, but the opt-out is available as a precaution).
      6. The right to appeal a denial of any of the above requests.

      To exercise these rights, contact us at the email address in Section 2. We will verify your identity before responding and will respond within forty-five (45) days unless an extension is permitted by law.

      We reserve the right to decline requests that are excessive, repetitive, or manifestly unfounded, and we may limit the frequency of requests to twice per 12-month period, to the extent permitted by applicable law.

  17. California: Your CCPA and CPRA Rights

    This Section 17 applies to “consumers” as defined in the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (the “CCPA”), Cal. Civ. Code §§ 1798.100 et seq.

    1. Categories of Personal Information We Collect

      In the past twelve (12) months, we have collected the following categories of personal information about California consumers, drawn from the categories at Cal. Civ. Code § 1798.140(v):

      1. Identifiers (such as name, email address, account identifier, device identifier, IP address).
      2. Customer records (account profile data, contact details).
      3. Commercial information (subscription status, transaction records via Apple or Google).
      4. Internet or other network activity (App usage data, interaction logs).
      5. Geolocation data (during active sessions, with your permission).
      6. Audio, electronic, or similar information (in-app audio playback events, support communications).
      7. Health and fitness data (if you connect HealthKit or Google Fit, and any well-being-related information you choose to enter in the App).
      8. Inferences drawn from the above (limited to in-app personalization, such as suggested exercises or prompts).

      We collect this information from the sources described in Section 3 of this Policy, use it for the purposes described in Section 4, and share it with the categories of recipients described in Section 6.

    2. Sensitive Personal Information

      Some of the categories above include “sensitive personal information” as defined in Cal. Civ. Code § 1798.140(ae), in particular health information and precise geolocation. We use sensitive personal information for the purposes described in Cal. Civ. Code § 1798.121(a) and the implementing regulations of the California Privacy Protection Agency, including but not limited to providing the App and its features as you have requested, security, fraud prevention, and legal compliance.

      We do not use or disclose sensitive personal information to infer characteristics about you for any other purpose or to third parties for non-operational purposes. You have the right to limit our use of sensitive personal information by contacting us at the email address in Section 2.

    3. “Do Not Sell or Share My Personal Information”

      We do not sell your personal information, and we do not share your personal information for cross-context behavioral advertising, as those terms are defined in Cal. Civ. Code § 1798.140(ad) and (ah).

      No opt-out is required to stop sales or sharing of your personal information because we do not engage in those activities. We honor Global Privacy Control (GPC) signals where technically feasible.

      If you would still like to exercise an opt-out as a precaution, you may do so by emailing us at the address in Section 2 with the subject line “Do Not Sell or Share My Personal Information.” This representation is current as of the effective date and subject to future Policy updates, which will be communicated to you in advance.

    4. Your CCPA Rights

      California consumers have the following rights:

      1. Right to know. Cal. Civ. Code § 1798.110 and § 1798.115. To request the categories and specific pieces of personal information we have collected, the sources, the purposes, and the third parties to whom we have disclosed it.
      2. Right to delete. Cal. Civ. Code § 1798.105. To request deletion of personal information we have collected from you, subject to certain exceptions.
      3. Right to correct. Cal. Civ. Code § 1798.106. To request correction of inaccurate personal information.
      4. Right to opt out of sale or sharing. Cal. Civ. Code § 1798.120 (see Section 17.3 above).
      5. Right to limit use and disclosure of sensitive personal information. Cal. Civ. Code § 1798.121.
      6. Right of no retaliation. Cal. Civ. Code § 1798.125. We will not deny services, charge different prices, or provide a different level of service because you have exercised any CCPA right.

      To submit a verifiable consumer request, contact us at the email address in Section 2. We will confirm receipt within ten (10) business days and respond within forty-five (45) calendar days, extendable by an additional forty-five (45) days where reasonably necessary and with notice to you. Cal. Civ. Code § 1798.130(a)(2).

      You may also designate an authorized agent to make a request on your behalf. We will require written permission from you, which must include a signed authorization, and may verify your identity directly.

    5. California “Shine the Light” Law

      California Civil Code § 1798.83 permits California residents to request information regarding the disclosure of personal information to third parties for the third parties’ direct marketing purposes. We do not disclose personal information to third parties for their own direct marketing purposes, thereby fully satisfying the requirements of § 1798.83.

  18. European Economic Area (including Ireland): Your GDPR Rights

    If you are located in the European Economic Area, this Section 18 applies to you. The General Data Protection Regulation, Regulation (EU) 2016/679 (the “GDPR”), applies to our processing of your personal data. The legal bases on which we rely are set out in Section 5 of this Policy. Section 6 of this Policy describes the recipients of your personal data, and Section 7 describes our international data transfer safeguards.

    1. Your GDPR Rights

      Under the GDPR, you have the following rights:

      1. Right of access. GDPR art. 15. To obtain confirmation of whether we process personal data about you, and a copy of that data.
      2. Right to rectification. GDPR art. 16. To have inaccurate or incomplete personal data corrected.
      3. Right to erasure (“right to be forgotten”). GDPR art. 17. This right is subject to exceptions where retention of data is necessary for compliance with legal obligations or for the establishment, exercise, or defense of legal claims, as outlined in GDPR art. 17(3).
      4. Right to restrict processing. GDPR art. 18.
      5. Right to data portability. GDPR art. 20.
      6. Right to object. GDPR art. 21. Including an absolute right to object to processing for direct marketing.
      7. Rights related to automated decision-making and profiling. GDPR art. 22. We do not subject you to decisions that have legal or similarly significant effects based solely on automated processing.
      8. Right to withdraw consent. GDPR art. 7(3). Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.

      To exercise any of these rights, contact us at the email address in Section 2. We will respond within one (1) month of receiving your request, extendable by a further two (2) months where necessary, in which case we will tell you why. GDPR art. 12(3). We reserve the right to charge a reasonable fee or refuse requests that are manifestly unfounded or excessive, as permitted by GDPR art. 12(5).

    2. Right to Lodge a Complaint

      You have the right to file a complaint with a supervisory authority in the EU Member State where you live, work, or where you believe an infringement has occurred. GDPR art. 77.

      Before doing so, we encourage you to contact us directly at the email address in Section 2 to allow us the opportunity to address your concerns. A list of supervisory authorities is available from the European Data Protection Board. Notable authorities include:

      1. Ireland: Data Protection Commission (DPC), 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland. Website: www.dataprotection.ie.
      2. Germany: Federal Commissioner for Data Protection and Freedom of Information (BfDI) at the federal level, and the data protection authority of the relevant Land.
      3. France: Commission nationale de l’informatique et des libertés (CNIL).
      4. Netherlands: Autoriteit Persoonsgegevens (AP).
    3. Children’s Consent under GDPR Article 8

      For users in the EEA, we apply a minimum age for use of the App that aligns with the age of digital consent in each Member State, ranging from thirteen (13) to sixteen (16) years. We will implement an age verification mechanism to ensure compliance with GDPR Article 8. Where you are a parent or guardian and become aware that your child has used the App without your authorization, contact us at the email in Section 2 and we will delete the account and associated personal data.

  19. United Kingdom: Your UK GDPR Rights

    If you are located in the United Kingdom, the UK General Data Protection Regulation (the “UK GDPR”) and the Data Protection Act 2018 apply to our processing of your personal data. Your rights mirror those described in Section 18 above, subject to UK-specific derogations and the UK’s data protection framework. We reserve the right under UK GDPR Art. 12(5) to refuse or charge a reasonable fee for excessive or unfounded requests. Additionally, specific carve-outs apply to data retention and health data as per UK regulations.

    You have the right to lodge a complaint with the Information Commissioner’s Office (ICO):

    Information Commissioner’s Office
    Wycliffe House, Water Lane,
    Wilmslow, Cheshire SK9 5AF,
    United Kingdom

    Helpline: 0303 123 1113
    Website: https://ico.org.uk

    Where we transfer personal data from the United Kingdom to a country that is not subject to a UK adequacy regulation, we use the UK’s International Data Transfer Agreement or, where the UK Addendum to the EU Standard Contractual Clauses is applicable, the UK Addendum, supplemented by additional safeguards where necessary.

  20. Canada: Your PIPEDA Rights

    If you are located in Canada, our processing of your personal information is subject to the Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5 (“PIPEDA”), and, where applicable, substantially similar provincial laws including Quebec’s Act respecting the protection of personal information in the private sector, CQLR c. P-39.1 (“Law 25”), British Columbia’s Personal Information Protection Act, S.B.C. 2003, c. 63, and Alberta’s Personal Information Protection Act, S.A. 2003, c. P-6.5. In the event of a conflict between PIPEDA and provincial laws, the stricter law will apply.

    You have the right to:

    1. Access the personal information we hold about you and request information about how it is used and disclosed.
    2. Challenge the accuracy and completeness of the information and have it amended as appropriate.
    3. Withdraw consent at any time, subject to legal and contractual restrictions and reasonable notice.
    4. In Quebec, request data portability and object to the use of your information for automated decision-making. Quebec Law 25 (Bill 64) requires Privacy Impact Assessments for projects involving personal information, particularly in digital health. We commit to conducting such assessments as required by law, with defined triggers and timelines.

    You may also direct privacy complaints to the Office of the Privacy Commissioner of Canada at 30 Victoria Street, Gatineau, Quebec K1A 1H3, or to your provincial Information and Privacy Commissioner.

    If a privacy breach creates a real risk of significant harm, we will report the breach to the relevant Privacy Commissioner and notify affected individuals as required by section 10.1 of PIPEDA and corresponding provincial legislation.

    We will respond to access requests within thirty (30) days of receipt, with the possibility of extending this period by an additional thirty (30) days if necessary, in accordance with PIPEDA s. 8(3).

  21. South Africa: Your POPIA Rights

    If you are located in South Africa, our processing of your personal information is subject to the Protection of Personal Information Act, 4 of 2013 (“POPIA”). For the purposes of POPIA, we act as the “responsible party” and any service providers we use act as “operators.” The Information Officer for DRT can be contacted at the email address in Section 2.

    Under POPIA, you have the right to:

    1. Be notified that your personal information is being collected (section 18 of POPIA).
    2. Request access to your personal information (section 23). We will respond within twenty (20) days of receiving your request, extendable by a further period as necessary, in accordance with PAIA timelines.
    3. Request the correction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or unlawfully obtained (section 24).
    4. Object, on reasonable grounds, to the processing of your personal information (section 11(3)).
    5. Object to the processing of your personal information for direct marketing (section 11(3) and section 69).
    6. Not be subject, generally, to a decision based solely on automated processing that significantly affects you (section 71).
    7. Submit a complaint to the Information Regulator regarding any alleged interference with the protection of your personal information (section 74).

    The Information Regulator (South Africa) can be contacted at JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001, by email at enquiries@inforegulator.org.za, or via www.inforegulator.org.za.

    Where a compromise of your personal information occurs that may give rise to a risk of harm, we will notify the Information Regulator and you as required by section 22 of POPIA within 72 hours of becoming aware of the breach.

  22. Australia: Your Privacy Act Rights

    If you are located in Australia, our processing of your personal information is subject to the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles (“APPs”) set out in Schedule 1 to that Act.

    You have the right to:

    1. Be informed about how we handle your personal information (APP 1, APP 5).
    2. Request access to your personal information (APP 12).
    3. Request correction of your personal information (APP 13).
    4. Opt out of receiving direct marketing communications (APP 7).
    5. Deal with us anonymously or by pseudonym where it is lawful and practicable to do so (APP 2).

    Some information you provide through the App is “sensitive information” under section 6 of the Privacy Act 1988, including health information. We collect sensitive information only with your consent and use it only for the purpose for which it was collected, or for a directly related secondary purpose that you would reasonably expect, as permitted by APP 6. Consent is obtained through an in-app acknowledgment mechanism, where users must actively agree to the collection and use of their sensitive information before proceeding.

    You can make a complaint about how we handle your personal information by contacting us at the email in Section 2. We will respond to your complaint within thirty (30) days of receipt. If you are not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at GPO Box 5288, Sydney NSW 2001, by phone on 1300 363 992, or via www.oaic.gov.au.

    Where an eligible data breach occurs, we will notify affected individuals and the OAIC as required by Part IIIC of the Privacy Act 1988 (the Notifiable Data Breaches scheme).

  23. New Zealand: Your Privacy Act 2020 Rights

    If you are located in New Zealand, our processing of your personal information is subject to the Privacy Act 2020 and the thirteen Information Privacy Principles (“IPPs”) set out in section 22 of that Act. In the event of a privacy breach that is likely to cause serious harm, we will notify the affected individuals and the Office of the Privacy Commissioner within the time required by applicable law.

    You have the right to:

    1. Receive confirmation that we hold personal information about you and access to that information (IPP 6, Privacy Act 2020 s 22).
    2. Request correction of personal information (IPP 7).
    3. Have your personal information protected by reasonable security safeguards (IPP 5).
    4. Be informed of the purposes for which we collect your personal information (IPP 3).
    5. Have your personal information collected only by lawful and fair means (IPP 4).
    6. Have your personal information used and disclosed only for the purposes for which it was collected, or as otherwise permitted under IPPs 10 and 11.

    Where we disclose your personal information to a person or entity outside New Zealand, we do so in accordance with IPP 12 of the Privacy Act 2020, which requires that the recipient is subject to comparable privacy safeguards or that you have authorized the disclosure after being informed that comparable safeguards may not apply.

    For transfers to countries without comparable privacy safeguards, we use lawful and appropriate transfer mechanisms to ensure adequate protection of your personal information. In the event that a transfer mechanism is invalidated due to regulatory changes, we will promptly implement alternative measures to maintain the protection of your personal information.

    If you have a complaint about how we handle your personal information, contact us at the email in Section 2. We will acknowledge receipt of your complaint within 5 business days and aim to resolve it within 20 business days.

    You may also complain to the Office of the Privacy Commissioner, PO Box 10094, The Terrace, Wellington 6143, by phone on 0800 803 909, or via www.privacy.org.nz.

    Where a privacy breach occurs that it is reasonable to believe has caused, or has a risk of causing, serious harm to an affected individual, we will notify the Privacy Commissioner and the affected individuals as soon as practicable, as required by Part 6 of the Privacy Act 2020.

Ready to move forward? No pressure. Just take the first step.

MENTAL HEALTH PROGRAMS

Choose from our different programs and sit, walk or run your way through the sessions

SESSIONS

Listen to sessions how and when you want to

MOOD DIARY

Regularly update your MOOD DIARY with your thoughts and feelings

MAP YOUR RUN

Track Step Count, Distance, Duration, and Pace