Counsellor Privacy Policy
This policy applies to counsellors and mental health professionals registered on Manovedh.
Last updated: June 30, 2026
1. About This Policy
This Privacy Policy explains how Manovedh ("we", "our", "us") collects, uses, stores, and protects your personal data as a registered counsellor, in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act 2023) and the Information Technology (Reasonable Security Practices and Procedures) Rules, 2011. It works alongside the Counsellor Participation & Professional Agreement, which governs your role and obligations on the platform.
2. Data We Collect From You
When you register and use the platform as a counsellor, we collect:
- Your full name, email address, and mobile number
- Date of birth, gender, and address
- Professional details: qualification, profession, specialization, and experience
- Your professional registration number and practising certificate (PDF)
- Verification status and records of the review of your credentials
- Session documentation, notes, and communications created through the platform
Sensitive registration information such as your certificate and professional details is stored in encrypted form and is accessible only to Manovedh's verification and clinical governance teams.
3. How We Use Your Data
We use your data to:
- Verify your professional credentials and eligibility to register
- Maintain your counsellor profile and match you appropriately to patient referrals
- Facilitate counselling sessions, session notes, and patient–counsellor communication
- Carry out quality assurance and platform audits
- Notify you of crisis escalations, sessions, and platform updates
- Meet legal, regulatory, and clinical record-keeping obligations
4. Legal Basis for Processing
We process your personal data based on your explicit consent, provided by registering on the platform and agreeing to these policies, and where necessary to perform the professional agreement and comply with applicable law. You may withdraw consent or update your data at any time.
5. Patient Data You Access
When a patient is referred to you, you are granted access only to:
- The patient's screening result summary (condition indicators and confidence scores)
- Risk level flagged by the system (Low / Moderate / High / Critical)
- Session notes from the current interaction
- Any previous session summaries the patient has consented to share with you
You will NOT have access to raw audio, video, or images of the patient, nor the patient's full personal details unless they have explicitly consented to share them.
All patient data shared with you remains governed by the DPDP Act 2023. You are bound by the same data protection obligations as the platform itself, and may not use or disclose patient data outside the platform except as described in the professional agreement.
6. Storage, Retention & Deletion
- Registration data and credentials: retained for the duration of your registration plus a reasonable post-termination period to meet audit and record-keeping requirements
- Session notes and documentation: retained for 5 years in line with standard clinical record-keeping requirements
- Support and verification records: retained as required by applicable law
- Live audio and video streams used for screening are processed in near real time and are not made available to counsellors
You may request deletion of your data at any time. Certain records may need to be retained where required by law even after a deletion request.
7. Your Rights Under DPDP Act 2023
- Right to Access: Request a copy of your personal data
- Right to Correction: Update inaccurate or incomplete data
- Right to Erasure: Request deletion of your data
- Right to Withdraw Consent: Withdraw consent at any time
- Right to Data Portability: Receive your data in a machine-readable format
- Right to Grievance Redressal: File a complaint with our Data Protection Officer
- Right to Breach Notification: Be informed of any data breach affecting your data
8. Data Sharing & Disclosures
We do not sell your personal data. Your data may be shared with:
- Manovedh's clinical governance and verification teams, for audit and quality assurance
- Third-party service providers who host and secure the platform, contractually bound to comply with DPDP Act 2023
- Regulatory or law-enforcement authorities where legally required
- The patient, for records they have consented to access (such as session notes)
9. Data Security
We implement the following security measures:
- Encrypted data transmission via HTTPS/TLS
- Strong password hashing and role-based access control
- Sensitive fields encrypted at rest
- Audit logging of all data access events
- Content Security Policy (CSP) headers
- Regular security reviews and breach response procedures
10. Breach Notification
If a data breach affects your personal data, we will notify you and the relevant authority as required by the DPDP Act 2023, and advise on any steps you should take.
11. Contact & Grievance Redressal
- Data Protection Officer: dpo@mindspace.in
- Counsellor Support: counsellors@mindspace.in
- Clinical Governance: clinical@mindspace.in
Response time: Within 30 days. If your grievance is not resolved to your satisfaction, you may escalate to the Data Protection Board of India.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated to you via email or through the platform.
Manovedh