NoOneToTalk
Privacy Policy
Governing Law: England and Wales
Last Updated: May 2026
Company Details
- Company Name:
- NO ONE TO TALK LTD
- Company Number:
- 15474380
- Registered Office:
- 20 Wenlock Road, London, N1 7GU, England
- Contact Email:
- hello@NoOneToTalk.com
- Data Protection Email:
- privacy@NoOneToTalk.com
- Data Protection Lead:
- Contactable at dpo@NoOneToTalk.com
An independent DPO will be formally designated prior to launch of clinical Services, in line with Art. 37 UK GDPR. - ICO Registration:
- Registration with the UK Information Commissioner's Office is being completed prior to the launch of clinical Services. The registration number will be published here upon issue.
- Jurisdiction:
- England and Wales
Important Notice & Emergency Disclaimer
This platform is not intended for medical emergencies, crisis intervention, or urgent clinical care.
If you are facing a mental health crisis, are contemplating harm to yourself or others, or are experiencing a medical emergency, do not use this platform. You must immediately seek in-person emergency assistance:
- In the United Kingdom (UK): Call 999 or visit the nearest A&E department. You can also contact NHS 111 or your local NHS mental health crisis team.
- International users: Contact your local emergency services (e.g., 911 in the US/Canada, 112 in the EU, or the equivalent number in your country).
NO ONE TO TALK LTD is a technology platform connecting Users with independent Counsellors. We are not a healthcare provider, and the Counsellors are solely responsible for the clinical care and advice provided.
1. Introduction and Scope
1.1 About this Policy
This Privacy Policy (the "Policy") explains how NO ONE TO TALK LTD ("Company", "we", "us", "our") collects, uses, stores, shares, and protects your personal data when you access or use our online platform, websites, and applications (collectively the "Platform"). This Policy should be read alongside our Terms and Conditions of Service.
By accessing or using the Platform, you acknowledge that you have read and understood this Policy. If you do not agree, you must cease use of the Platform immediately.
1.2 Definitions
- Company, We, Us, Our: Refers to NO ONE TO TALK LTD.
- Platform: All online services, software, websites, and applications operated by the Company.
- User, You: Any individual accessing or using the Platform, whether as a registered Member or guest.
- Counsellor (or Practitioner): An independent, self-employed mental health professional providing services to Users via the Platform.
- Personal Data: Any information relating to an identified or identifiable natural person, as defined by the UK GDPR.
- Special Category Data: Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health, or data concerning a natural person's sex life or sexual orientation.
- UK GDPR: The General Data Protection Regulation (Regulation (EU) 2016/679) as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018, read in conjunction with the Data Protection Act 2018.
2. Data Controller and Processor Status
2.1 Company as Controller
For operational and administrative data (e.g., account information, billing, platform logs, IP address, communication metadata), the Company acts as a Data Controller.
2.2 Counsellor as Independent Controller
For clinical notes and therapeutic records directly related to the Services, the Counsellor is the independent Data Controller for the clinical content and must comply with the UK GDPR and the Data Protection Act 2018 regarding your health data.
2.3 Joint Controllers
The Company and the Counsellor may act as Joint Controllers for shared administrative data (e.g., scheduling, session metadata, and communication logs). The specific allocation of responsibilities is defined in a written Joint Controller Agreement between the parties, in accordance with Article 26 UK GDPR.
Essence of the Joint Controller Arrangement (Art. 26(2))
- The Company is responsible for: providing the technological infrastructure, account management, billing, security of the platform, breach notification to the ICO, and responding to general data subject requests concerning administrative data.
- The Counsellor is responsible for: the clinical content of sessions, clinical record-keeping, professional secrecy, and responding to data subject requests concerning clinical data.
- Single point of contact: regardless of the above allocation, you may exercise your rights against either the Company or the Counsellor, and they will route the request to the responsible party. You should address the Company at privacy@NoOneToTalk.com as your default point of contact.
- Full agreement: the full Joint Controller Agreement is available on request to dpo@NoOneToTalk.com.
2.4 Data Protection Lead and Future DPO Designation
At this pre-launch stage, the role of Data Protection Lead is held by the Director of NO ONE TO TALK LTD, contactable at dpo@NoOneToTalk.com. The Data Protection Lead is your point of contact for any matter concerning your personal data and the exercise of your rights under the UK GDPR.
Because, upon launch of clinical Services, we will process Special Category Data (health data) on a regular basis as part of our core activities, NO ONE TO TALK LTD will formally designate an independent Data Protection Officer (DPO) pursuant to Article 37(1)(c) UK GDPR before any therapeutic Services are made available to Users. The DPO's contact details will be published here upon appointment. You will always have the right to contact the DPO directly and confidentially.
2.5 ICO Registration
Most UK organisations that process personal data are required by the Data Protection (Charges and Information) Regulations 2018 to pay a data protection fee to, and be registered with, the UK Information Commissioner's Office (ICO). NO ONE TO TALK LTD is completing this registration ahead of the launch of clinical Services. Our registration number, once issued, will be published in the Company Details section above and verifiable on the ICO public register at ico.org.uk.
3. Information We Collect
3.1 Information You Provide Directly
- Account data: name, email address, password (hashed), date of birth, country of residence, preferred language.
- Profile data: AI-generated avatar, display name, communication preferences.
- Billing data: processed by our PCI-DSS compliant payment provider. We do not store full card numbers on our servers.
- Communications: messages you send to support, feedback, or via in-platform chat.
- Health-related information: any health data you choose to share with your Counsellor during the Services.
3.2 Information Collected Automatically
- Anonymous session ID — a random UUID stored in your browser's
localStorage(not a cookie). You can clear it at any time from your browser settings. - Hashed IP address — your IP is hashed with SHA-256 and an application secret salt before storage. The original IP is never persisted and cannot be recovered from the hash.
- Country — used to show a local crisis helpline: from the Cloudflare country header when present, otherwise from your IP via an on-server GeoIP database when configured, otherwise from your chosen site language. We do not send your IP to external geolocation APIs for this feature.
- Usage analytics — page views, clicks, scroll depth, time on page. Used to understand which content is helpful so we can keep improving the site.
- Device and browser data — user-agent string, screen size, referrer URL.
3.3 Information from Third Parties (Art. 14 UK GDPR)
Where we obtain personal data about you from sources other than yourself, we are required by Article 14 UK GDPR to tell you the categories of data and the source:
- Authentication providers (Google, Apple, Facebook — if and where enabled): we receive your name, email address, profile picture URL (if any), and a unique identifier issued by the provider. We never receive your password.
- Payment processor (e.g., Stripe): we receive transaction status, last four digits of the card, card brand, billing country, and a tokenised reference. We do not receive or store full card numbers.
- Fraud-prevention services: risk scores and signal flags (no raw card or identity data).
- Email delivery providers: bounce status, delivery confirmation, open/click telemetry (only for transactional emails; marketing emails see §5).
- Counsellor referrals: where another counsellor refers you to one of our practitioners, we may receive your name and contact details — only with your prior consent.
3.4 Consequences of Not Providing Data (Art. 13(2)(e))
- Account data and consent to process health data are required to create an account and use the Services. Without them, we cannot provide the Platform to you.
- Billing data is required to process paid subscriptions. Without it, you cannot access paid features.
- Optional fields (e.g., date of birth, preferred language, avatar) are not strictly required. Not providing them will not prevent you from using the Services but may reduce the quality of personalisation.
- Marketing consent is entirely optional. Refusing it has no effect on the Services.
4. Lawful Bases for Processing (UK GDPR)
We process your personal data on one or more of the following lawful bases under Article 6 UK GDPR:
- Contract (Art. 6(1)(b)): processing necessary to perform the Agreement and provide the Services to you (account, authentication, session delivery, payment).
- Legitimate Interests (Art. 6(1)(f)): securing the Platform, preventing fraud and abuse, defending legal claims, and improving our Services via privacy-preserving analytics. We have conducted a Legitimate Interests Assessment (LIA) which balances our interests against your rights and freedoms; a summary is available on request to dpo@NoOneToTalk.com.
- Legal Obligation (Art. 6(1)(c)): complying with tax, accounting, regulatory, and safeguarding obligations under UK law (including HMRC retention rules and ICO obligations).
- Consent (Art. 6(1)(a)): for optional features such as marketing communications and certain non-essential analytics. You may withdraw consent at any time without affecting prior lawful processing.
- Vital Interests (Art. 6(1)(d)): in emergencies where disclosure is necessary to protect the life of you or another person (see §6).
4.1 Special Category Data — Health Data (Article 9 UK GDPR + Schedule 1 DPA 2018)
The Counsellor and the Company process different categories of health-related data on different bases. Both bases under Art. 9 must be read in conjunction with a condition in Schedule 1 of the Data Protection Act 2018 as required by UK law.
A. The Counsellor (clinical data)
- Art. 9(2)(h) UK GDPR — processing necessary for the provision of health or social care or treatment, by or under the responsibility of a professional subject to the obligation of professional secrecy.
- Schedule 1, Part 1, paragraph 2 DPA 2018 — "Health or social care purposes", which requires the processing to be carried out by a health professional or a person who in the circumstances owes a duty of confidentiality equivalent to that of a health professional.
- The Counsellor is bound by the professional secrecy obligations of their regulatory body (BACP, HCPC, NCS, or equivalent), satisfying the Art. 9(3) condition.
B. The Company (platform-level health-related data)
Because NO ONE TO TALK LTD is a technology platform and not itself a healthcare provider, we do not rely on Art. 9(2)(h) for the data we control. Where the Company processes any health-related data (for example metadata indicating that you are using a mental-health service), our lawful basis is:
- Art. 9(2)(a) UK GDPR — your explicit consent, which you provide at account creation by ticking a clearly worded, separate consent box. Consent is freely given, specific, informed, and unambiguous, and may be withdrawn at any time via your account settings or by writing to privacy@NoOneToTalk.com.
- Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. However, withdrawal may make it impossible for us to continue providing the Services to you.
C. Other Special Category Bases
- Art. 9(2)(c) — to protect the vital interests of you or another person where you are physically or legally incapable of giving consent (e.g., serious safeguarding emergency).
- Art. 9(2)(f) — establishment, exercise, or defence of legal claims.
- Each of the above is read with the corresponding condition in Schedule 1 DPA 2018 as applicable.
5. How We Use Your Information
- To create and manage your account and authenticate you.
- To facilitate communication between you and the Counsellor (video, chat, audio).
- To process payments, subscriptions, and refunds.
- To provide customer support and respond to your enquiries.
- To send transactional notifications (e.g., session reminders, account alerts).
- To monitor the technical function and non-clinical content of the Platform (e.g., abuse detection, fraud prevention, system stability).
- To improve the Platform via aggregated, privacy-preserving analytics.
- To comply with legal, regulatory, and safeguarding obligations.
- To send marketing communications — see §5.1 below for our PECR-compliant approach.
5.1 Electronic Marketing (PECR Regulation 22)
Where we send you marketing communications by email or SMS, we comply with the Privacy and Electronic Communications Regulations (PECR), Regulation 22:
- We send marketing only with your prior opt-in consent, given through a ticked-by-you checkbox at sign-up (never pre-ticked).
- Where you have previously purchased a similar service from us, we may rely on the "soft opt-in" exception to send you marketing about similar services, with a clear opt-out in every message.
- Every marketing email contains a working one-click unsubscribe link. SMS marketing includes "STOP" reply instructions.
- You can withdraw marketing consent at any time from your account settings or by writing to privacy@NoOneToTalk.com.
- We do not engage in third-party advertising, behavioural advertising, or sale of your data to advertisers.
6. Confidentiality and Exceptions (Duty of Care)
Subject to the exceptions below, all information you share with your Counsellor is strictly confidential. In compliance with professional ethical guidelines and UK law, confidentiality may be breached without your consent in limited circumstances, including but not limited to:
- Where the Counsellor believes you pose a significant risk of serious harm to yourself or to others (e.g., safeguarding concerns, self-harm, or suicidal intent).
- Where the Counsellor is required by a court order or subpoena to disclose records.
- In cases of suspected abuse or neglect of a child or vulnerable adult.
In such events, the Counsellor will exercise their professional judgment to disclose only the minimum necessary information to the relevant authorities (e.g., police, NHS, social services, or your designated emergency contact).
7. Sharing and Disclosure of Personal Data
We do not sell your personal data. We share personal data only as described below:
- With your Counsellor: the information you choose to share with them, plus the metadata strictly necessary for service delivery (e.g., your display name and session schedule).
- With Sub-Processors: hosting, payment processing, email delivery, video/audio infrastructure, analytics, and fraud prevention, under written Data Processing Agreements (DPAs) compliant with Art. 28 UK GDPR.
- With legal and regulatory authorities: where required by court order, statute, or to protect the vital interests of any person.
- With successors: in connection with a merger, acquisition, or sale of assets, subject to confidentiality protections and a notice to you.
7.1 Our Sub-Processors
We maintain an up-to-date list of all sub-processors that may process your personal data, including their purpose, location, and the transfer safeguards in place. The current list is set out below and may also be requested in full from privacy@NoOneToTalk.com.
| Sub-Processor | Purpose | Location | Transfer Safeguard |
|---|---|---|---|
| Stripe Payments Europe, Ltd | Payment processing, subscription billing, fraud prevention | Ireland (EU) / USA | UK Adequacy + SCC / IDTA |
| Cloudflare, Inc. | CDN, DDoS protection, country detection via CF-IPCountry header | Global edge (EU primary) / USA | UK IDTA / SCC + UK Addendum |
| Amazon Web Services (AWS) — EMEA SARL | Object storage (S3), transactional email delivery (SES), where configured | EU regions (eu-west-1 / eu-west-2) | EU Adequacy + AWS DPA |
| Postmark (ActiveCampaign LLC) | Transactional email delivery (alternative provider) | USA | UK IDTA / SCC + UK Addendum |
| Resend, Inc. | Transactional email delivery (alternative provider) | USA | UK IDTA / SCC + UK Addendum |
| Slack Technologies Limited | Internal operational notifications (waitlist, leads — no clinical content) | Ireland (EU) / USA | EU Adequacy + SCC / UK IDTA |
| Plesk / Web Hosting Provider | Application hosting and database storage | European Union | EU Adequacy (intra-EEA, no transfer) |
| Video/audio session infrastructure | Live counselling sessions (not yet deployed — provider to be confirmed before clinical launch, e.g., Daily.co / Twilio / Zoom for Healthcare) | EU/UK preferred | SCC / UK IDTA + DPA |
First-party analytics are self-hosted on our own infrastructure — no third-party processor is engaged for analytics, advertising, or behavioural tracking.
We will notify Members in advance of any addition or replacement of a sub-processor that involves a material change in data processing, giving you a reasonable opportunity to object before the change takes effect.
8. Cookies, Local Storage, and Tracking Technologies (PECR Regulation 6)
The Privacy and Electronic Communications Regulations (PECR), Regulation 6, applies not only to cookies but to any storage of, or access to, information on a user's device — including localStorage, sessionStorage, and similar technologies. We comply with PECR as follows.
NoOneToTalk runs a privacy-friendly, first-party analytics system — no third-party trackers, no advertising cookies, no fingerprinting, no cross-site tracking.
8.1 Strictly Necessary (no consent required under PECR Reg. 6(4))
- Session cookie — keeps you signed in. Lifespan: session.
- CSRF token — protects against cross-site request forgery. Lifespan: session.
- Locale preference — remembers your chosen language. Lifespan: 1 year.
These are exempt from the consent requirement because they are strictly necessary to provide the service you have requested.
8.2 Analytics (consent-based)
- Anonymous session UUID stored in
localStoragefor usage analytics. Stored only with your consent (or where the analytics is configured to fall within the ICO's narrow analytics exemption). - Hashed IP address (SHA-256 with secret salt) — the original IP is never persisted and cannot be recovered.
- Page views, clicks, scroll depth, time on page — first-party, aggregated, no cross-site tracking.
8.3 Your Choices
Where consent is required, we present a cookie banner on your first visit allowing you to accept, reject, or customise. You can change your preferences at any time via the "Cookie Settings" link in the footer. You can also clear all browser storage from your browser settings.
9. International Data Transfers
As we serve international users and may use international data processors, your data may be transferred outside the UK/EEA. When this occurs, we ensure adequate safeguards are in place, such as:
- Transferring data to countries deemed to provide an adequate level of protection by the UK Government (Adequacy Regulations).
- Implementing legally approved contractual clauses — the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or the European Commission's Standard Contractual Clauses (SCCs) — with all relevant third-party processors.
- Performing Transfer Impact Assessments (TIAs) where required.
10. Data Security
We implement appropriate technical and organisational measures (TOMs) — including encryption in transit (TLS 1.2+) and at rest, access control, network security, and regular security reviews — to protect your personal data, particularly Special Category Data, against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
We conduct due diligence and enter into Data Processing Agreements (DPAs) with all Sub-Processors to ensure they meet UK GDPR compliance standards, especially concerning security and data transfer safeguards.
While we take all reasonable steps, the transmission of information via the internet is never completely secure. Subject to liability that cannot be excluded under UK law, we cannot guarantee the absolute security of your data transmitted to the Platform; any transmission is at your own risk.
10.1 Personal Data Breaches
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware, and we will inform you without undue delay where the breach is likely to result in a high risk to you.
11. Data Retention
- Administrative data — billing, login history, usage logs: retained for as long as your account is active and for a mandatory period thereafter, typically six (6) years, to comply with UK tax, legal, and regulatory obligations.
- Clinical data — Counsellors are legally and professionally mandated to retain clinical notes for specific periods, which may vary by jurisdiction and professional body (e.g., BACP often recommends a minimum of seven (7) years after the final session; some UK contexts require up to 20 years).
- Marketing data — retained until you withdraw consent.
- Anonymised analytics — may be retained indefinitely in aggregated form that cannot be re-identified.
The Right to Erasure (see Section 12) is subject to these legal and professional retention obligations. While we will delete non-mandated administrative data upon request, clinical notes must be retained by the Counsellor for the legally required minimum period.
12. Your UK GDPR Rights (Data Subject Rights)
As a data subject, you have the following rights concerning your personal data:
- Right to be Informed — to know how and why your data is processed (this Policy fulfils that).
- Right of Access (SAR) — to request a copy of the personal data we hold about you.
- Right to Rectification — to have inaccurate data corrected.
- Right to Erasure ("Right to be Forgotten") — to request deletion of your data where there is no legal requirement for us to keep it.
- Right to Restriction of Processing — to limit how your data is used.
- Right to Data Portability — to receive your data in a structured, commonly used, machine-readable format.
- Right to Object — to object to certain types of processing, including direct marketing.
- Rights related to automated decision-making — we do not use automated decision-making that produces legal or similarly significant effects on you.
To exercise any of these rights, contact privacy@NoOneToTalk.com. We will respond within one (1) month, which may be extended by two further months for complex requests (you will be informed within the first month).
12.1 Right to Complain to a Supervisory Authority
You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk, or with the supervisory authority in your country of residence if you are based outside the UK. We would, however, appreciate the chance to address your concerns first.
13. Children's Privacy
The Platform is intended for individuals aged 18 or older. We do not knowingly collect personal data from children under 18. If we become aware that we have collected such data without verifiable parental or guardian consent (where legally permitted), we will delete it promptly. If you believe a child has provided us with personal data, please contact privacy@NoOneToTalk.com.
14. Recording of Sessions
You are strictly prohibited from making any audio, video, or photographic recordings of your therapeutic sessions, whether private or group, without the express, prior written consent of both the Counsellor and the Company. We do not record sessions unless explicitly agreed in writing for a specific clinical or safeguarding purpose.
15. Changes to this Privacy Policy
We reserve the right to update this Policy by posting modifications on the Platform. Where the change is material, we will notify you by email or by an in-platform notice in advance. Unless otherwise specified, all modifications shall be effective upon posting. By continuing to use the Platform after the changes become effective, you agree to be bound by the updated Policy.
16. Governing Law and Dispute Resolution
This Policy shall be governed by and construed in accordance with the laws of England and Wales, without regard to its conflict of law principles. Any dispute arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts of England and Wales, subject to the mandatory consumer-protection provisions of your country of residence if you are a consumer residing outside England and Wales.
17. Contact Information
If you have any questions or concerns regarding this Policy, please contact us:
- Data Protection Email: privacy@NoOneToTalk.com
- General Email: hello@NoOneToTalk.com
- Post: NO ONE TO TALK LTD, 20 Wenlock Road, London, N1 7GU, England
END OF PRIVACY POLICY
Last Updated: May 2026
© 2026 No One To Talk. All rights reserved.
