CBT Flow

Privacy Policy

Version v1.0-temp · Effective 12 July 2026

Last updated 12 July 2026

Version: v1.0-temp · Last updated: 13 July 2026 · Effective: from the date this version is published at cbtflow.com/legal/privacy

1. Who we are

CBT Flow is operated by Digita1 OÜ, Estonian registry code 17003669, VAT number EE102745881, registered at Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia.

Digita1 OÜ is the controller for the personal data described in this policy except where we expressly explain that we process Practice-controlled data on a Practice's behalf. You can contact us at:

We have paid the UK data protection fee to the Information Commissioner's Office (ICO); our registration reference will be added to this page when the ICO issues it.

We are not required to appoint a statutory Data Protection Officer. Our internal Privacy Lead is Paulius Alionis, reachable via privacy@cbtflow.com.

Digita1 OÜ has no UK establishment. We are appointing a UK representative under Article 27 UK GDPR; the representative's name and contact details will be published on this page as soon as the appointment is confirmed.

2. Scope and our different privacy roles

This policy applies to visitors to the public CBT Flow website, prospective and current therapist/practice customers, authorised users, people who contact support, and business contacts. Launch customers are UK-established therapists and practices.

It does not replace the separate Client Privacy Notice for therapy clients using the Client app.

CBT Flow has different roles depending on the purpose:

  • Practice-controlled clinical data: the therapist or practice normally decides why and how its clients' records are used. It is controller and Digita1 OÜ processes those records on its behalf under the Data Processing Agreement (DPA).
  • CBT Flow-controlled data: Digita1 OÜ is controller for defined purposes such as website operation, enquiries, customer accounts, subscriptions, security, support administration, legal compliance and its own payment administration.
  • Other organisations: Stripe and some other recipients may act as separate or independent controllers for their own legal, payment, fraud or service purposes.

If you are a therapy client asking about your clinical record, contact your therapist or practice first. We will assist them where we act as processor. We remain directly responsible for data we control ourselves.

3. Information we process

Depending on how you interact with us, we may process:

  • identity and contact information, such as name, email, telephone number and correspondence address;
  • professional and practice information, including practice identity, role, authority, professional details and UK establishment information;
  • account and authentication information, user ID, login events, permissions and preferences;
  • subscription and commercial information, plan, entitlement, billing status, invoices and transaction references;
  • Stripe Connect payment-administration information: onboarding and account status, transaction, payout, refund, dispute and application-fee records. Stripe collects identity, bank and know-your-customer verification information directly through its own hosted onboarding; we receive the resulting account status rather than the underlying verification documents;
  • enquiries, support messages, feedback and complaint records;
  • website, device and security information, such as IP address, browser/device details, page requests, timestamps, diagnostic events and security signals;
  • consent and marketing-preference records;
  • records of accepted legal terms, version, account, authority and time;
  • information required for fraud prevention, legal claims, regulatory enquiries and compliance; and
  • public-site analytics data, where you have consented (see section 7).

Please do not send client clinical information through public website forms or ordinary marketing channels. If that happens accidentally, contact privacy@cbtflow.com and we will handle and minimise it appropriately.

4. Purposes, roles and lawful bases

PurposeData/sourceRoleLawful basis
Respond to enquiries and take pre-contract stepsContact, practice details and correspondence from youControllerSteps at your request before a contract; legitimate interests where the enquiry is on behalf of an entity
Create and administer accountsIdentity, professional/practice, authentication and permissionsControllerContract; legitimate interests for entity-authorised users
Supply and bill subscriptionsPlan, billing, invoice and payment statusControllerContract; legal obligation for tax/accounting records
Administer Stripe Connect payment facilitationPractice, connected-account status, payment/refund/dispute/application-fee recordsController for our own fee and compliance records; processor where we handle Practice-controlled data on instructionContract; legitimate interests; legal obligation
Provide support and manage complaintsContact, account, correspondence and necessary diagnostic dataController; processor if reviewing Practice-controlled data on instructionContract; legitimate interests; legal obligation where applicable
Secure the Site and Platform; prevent misuse and fraudDevice, logs, access, security and transaction signalsControllerLegitimate interests; legal obligation where applicable
Keep contract and acceptance evidence; establish or defend claimsIdentity, authority, versions, timestamps and relevant communicationsControllerLegitimate interests; legal obligation
Send essential service communicationsAccount and contact detailsControllerContract; legitimate interests
Send marketing to eligible contactsContact, preferences, relationship and campaign recordControllerConsent or, where lawfully available, the soft opt-in for similar services; you can opt out at any time
Measure public-site useConsent state, online identifiers and eventsControllerConsent
Measure advertising conversions (if advertising tools are enabled in future)Consent state, online identifiers and non-sensitive public commercial eventsControllerConsent
Meet privacy, regulatory and legal dutiesRequests, complaints, investigations and compliance evidenceControllerLegal obligation; legitimate interests

We do not use therapist or client data to train general-purpose AI models. Any future clinical-data AI processing requires separate approval, risk assessment, contracts and notice. We do not make autonomous treatment decisions.

5. Clinical and special-category data

Therapist workspaces may contain mental-health and other special-category data. For that clinical-record processing, the Practice normally determines its Article 6 basis and Article 9 condition and CBT Flow acts on its instructions under the DPA.

Our own controller purposes are designed not to require clinical information. Where special-category data unavoidably reaches a controller purpose — for example if you include health information in a support message or a legal claim requires it — we handle it only as strictly necessary, minimise it, and rely on the applicable condition (such as the establishment, exercise or defence of legal claims).

Public-site analytics must not receive clinical content, health information, client identifiers, therapist–client relationships, measures, payment-page activity or URLs/query strings that reveal sensitive information.

6. Payments and Stripe

Digita1 OÜ uses Stripe for CBT Flow subscription billing. For therapy payments, the Practice supplies the therapy and uses a UK Stripe Express connected account: client payments are created as destination charges on behalf of the Practice, with an application fee to CBT Flow.

Stripe collects and uses information under its own terms and privacy information for purposes including payment processing, identity verification, fraud prevention and legal compliance, and acts as an independent controller for those purposes. Payment card details are collected by Stripe through its hosted payment components; we do not receive or store full card numbers.

7. Marketing and tracking

We distinguish service messages from marketing. Marketing messages include an unsubscribe route, and you may change preferences at any time.

Our public marketing website uses Google Tag Manager to deliver measurement tags, and Google Analytics to understand aggregate site use. Analytics runs only after you consent through the cookie bar. We may later add advertising tools (Google Ads conversion tracking and Meta Pixel); they will run only with a separate advertising consent and updated disclosure in the Cookie Notice.

These tools are not used on authenticated therapist or client areas, clinical workflows, payment pages, measures or other sensitive surfaces.

See the Cookie Notice at cbtflow.com/legal/cookies for categories, choices and how to change your mind. Google consent signals, where used, communicate your choice; they do not replace it.

8. Who receives information

Information may be received by:

  • infrastructure, hosting, authentication, communication and support suppliers acting on our instructions — our current suppliers are listed at cbtflow.com/legal/subprocessors;
  • Stripe and payment participants for subscription and connected-payment purposes;
  • Google, for public-site analytics after your consent;
  • professional advisers, insurers, auditors and prospective transaction advisers under appropriate duties;
  • regulators, courts, law enforcement and other bodies where lawfully required; and
  • a successor in a merger, reorganisation or sale, subject to applicable safeguards.

We do not sell personal data.

9. International transfers

Digita1 OÜ is established in Estonia. Our primary application database and storage are hosted in the European Economic Area (Ireland region). Transfers between the UK and the EEA are covered by the applicable adequacy arrangements.

Some suppliers or their support personnel may process information outside the UK or EEA. Where a restricted transfer occurs, we use a lawful transfer route — an adequacy decision or regulations, the EU Standard Contractual Clauses with the UK Addendum or the UK International Data Transfer Agreement, as applicable — together with a transfer risk assessment where required. The supplier list at cbtflow.com/legal/subprocessors records the location and transfer route per supplier.

10. Retention

We retain personal data only for as long as needed for the relevant purpose, including legal, tax, security and claims requirements.

DataRetention
Active account and subscription administrationFor the life of the account/subscription, then only as needed for closure, claims and the records below
Tax, billing, application-fee and payment ledger recordsFor statutory accounting periods (under Estonian law, generally seven years)
Legal-term acceptance and authority evidenceFor the contract plus the period during which a legal claim could be brought
Enquiries, support and complaintsUntil resolved, then as needed for service quality, security and claims
Security and diagnostic logsShort, risk-based periods that vary by log type
Marketing preferences and suppressionWhile marketing is active, plus a minimal suppression record to honour opt-out
Cookie consent recordsWhile the consent remains relevant and afterwards as evidence of compliance
Practice-controlled client records after cancellation/non-conversion30-day return/export window, then deletion under the DPA standing instruction; one documented extension and legal holds may apply; backups expire through the documented backup lifecycle

We do not retain inactive clinical workspaces indefinitely by default. We retain separately only the controller records we legally or operationally need, and minimise any clinical content in them.

11. Your rights

Subject to legal conditions and exceptions, you may ask us to:

  • give you access to personal data we control about you;
  • correct inaccurate information;
  • erase information;
  • restrict processing;
  • provide portable data;
  • stop processing based on legitimate interests;
  • stop direct marketing; or
  • record withdrawal of consent without affecting earlier lawful processing.

Email privacy@cbtflow.com. We may need proportionate information to verify identity and authority.

If your request concerns a Practice-controlled clinical record, we will normally route it to the Practice and assist. A parent, guardian or other third party does not receive automatic access to a client's information; the Practice assesses authority, confidentiality, safeguarding and the client's rights before any disclosure.

12. Complaints

Send a privacy complaint to privacy@cbtflow.com. We will acknowledge your complaint within 30 days, investigate it appropriately, keep you informed and tell you the outcome.

You may also complain to:

  • the UK Information Commissioner's Office at ico.org.uk; or
  • the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) at aki.ee.

You may also have a right to complain to another competent data protection authority where you live or work.

13. Security

We use technical and organisational measures designed for the sensitivity of the information processed, including access controls, encryption in transit, provider-managed encryption at rest, logging and regular backups. No system is completely secure, and we do not make absolute security promises. More detail is on our security page at cbtflow.com/security and in the DPA's security annex.

Contact security@cbtflow.com to report a security concern. Do not include unnecessary clinical information.

14. Required information, automated decisions and changes

Some account, practice and billing information is needed to enter into or perform the contract. Without it, we may be unable to create an account, verify eligibility, provide a plan or administer payments.

We do not make decisions producing legal or similarly significant effects about website visitors or therapist customers solely by automated means. Automated plan rules (such as the Flow Solo active-client limit) apply plan eligibility, and you can always contact support about their effect.

We may update this policy when processing, law or suppliers change. Material changes will be communicated through an appropriate channel. This page shows the current version and effective date; earlier versions are available on request via privacy@cbtflow.com.