Last updated: 11 July 2026
| Who this document applies to Individuals who browse, register, contact a therapist, make a booking or pay for therapy-related services through the Wellbeing Rooms platform or the Wellbeing Rooms website. |
1. Who we are
Wellbeing Rooms is a trading name and digital service operated by Purely Nordic Ltd, a company registered in England and Wales under company number 11865119, whose registered office is at 107 Sherland Road, Twickenham TW1 4HB, United Kingdom. In these Client Terms, “Wellbeing Rooms”, “we”, “us” and “our” mean Purely Nordic Ltd trading as Wellbeing Rooms.
Website: https://wellbeingrooms.com/ | Contact: hello@wellbeingrooms.com
2. The platform and the separate therapy contract
• Wellbeing Rooms provides a digital marketplace and related technology, which may include therapist profiles, discovery and search, availability, booking, calendar, messaging, payment collection, refunds, reviews, promotional listings and access to rooms or venue partners.
• Wellbeing Rooms is not a therapist, psychotherapist, counsellor, psychologist, psychiatrist, medical practitioner, healthcare provider, mental-health provider, clinic, hospital, care provider, insurer, crisis service, emergency service or professional regulator. We do not diagnose, assess, prescribe, treat, triage or provide clinical supervision.
• Therapy and related professional services are supplied by the independent therapist, practitioner or clinic identified in the listing and booking confirmation (the “Therapist”). Your contract for those services is directly with the Therapist (the “Therapy Contract”).
• The Therapist is not our employee, worker, partner, clinical subcontractor or representative. A limited appointment to collect payment does not change that independent status.
• Our contract with you concerns only the platform and any separate room-access or administration service expressly described as supplied by us.
3. Not an emergency or crisis service
Do not use the platform, booking notes, reviews, contact form or messages for an emergency, urgent clinical risk, suicidal crisis, self-harm risk, risk of harm to another person, severe psychiatric symptoms, safeguarding emergency or urgent medical need. We do not monitor communications continuously or provide crisis intervention.
If there is immediate danger in the United Kingdom, call 999 or attend Accident & Emergency. For urgent non-emergency NHS assistance, use NHS 111. Samaritans can be contacted on 116 123. Outside the United Kingdom, contact the local emergency number and appropriate local crisis service.
4. Eligibility and acceptance
• The platform is intended for adults aged 18 or over. You must not create an account or make a booking for a person under 18 unless a specific service has been expressly approved by Wellbeing Rooms and the Therapist and all required parental, guardian, safeguarding and legal arrangements are in place.
• You agree to these Client Terms when you tick an acceptance box, register, make a booking or payment, or continue using the platform after clear notice of them. The Refund and Cancellation Policy and booking-specific information form part of your contract with us.
• The Privacy Policy is a notice explaining our use of personal information. A general acceptance of these terms is not consent to every type of data processing or marketing.
• You must provide accurate, current information and keep your account secure. Tell us promptly through the Contact page if you suspect unauthorised access.
5. Choosing a Therapist
• You are responsible for deciding whether a Therapist appears suitable. Review their qualifications, registration or professional membership, insurance, experience, approach, location, fee, availability, cancellation terms and any other matter important to you.
• We may check identity, credentials, professional membership or insurance information supplied by a Therapist. These checks are administrative and do not amount to clinical endorsement, supervision or a guarantee of continuing validity, competence, suitability or outcome.
• Search position may reflect relevance, availability, location, profile completeness, user preferences, platform performance and commercial features. Paid profile promotion will be identified where required. Ranking is not a clinical recommendation.
• The Therapist alone decides whether they can accept you, whether a service is clinically appropriate, and whether online or in-person work is suitable and lawful.
6. Bookings and the Therapy Contract
• A booking is confirmed only when the platform or Therapist issues confirmation. A pending request does not guarantee an appointment.
• The booking confirmation identifies the Therapist, service, date, time, duration, location or online method, total price and applicable cancellation information. Check it promptly and report errors.
• The Therapist may require separate informed-consent, clinical, confidentiality or privacy terms. If those terms conflict with these Client Terms, these Client Terms govern the platform relationship and the Therapist’s terms govern the Therapy Contract, unless mandatory law requires otherwise.
• A recurring booking reserves future appointments only as confirmed. Each appointment remains subject to the cancellation rules applying to that appointment.
7. Prices, payments and collection agency
• Therapists normally set their own Therapy Fees. The total amount payable, including mandatory taxes and any client-facing platform or booking charge, will be displayed before you place an order. We will not add an undisclosed mandatory fee after the point at which you commit to pay.
• Where we use a third-party payment processor to collect a Therapy Fee, we do so as the Therapist’s disclosed collection agent unless checkout expressly states another arrangement. Payment through our approved payment process discharges the corresponding amount you owe the Therapist.
• Payments may be processed by an independent payment service provider under its own terms and privacy notice. We do not normally receive or store full payment-card details.
• We may refuse, cancel, reverse or hold a transaction where payment or identity checks fail, a booking is unavailable, a refund is due, or we reasonably suspect fraud, chargeback abuse, illegality, sanctions risk, security risk or breach of these terms.
• You must not use a chargeback to avoid a valid fee. Contact us first so that the issue can be investigated. This does not remove any lawful right to contact your card issuer.
8. Cancellations, refunds and statutory cancellation rights
The Refund and Cancellation Policy applies. In summary, a client who cancels at least 48 hours before the scheduled start time qualifies for a full refund of the affected session payment. A cancellation made less than 48 hours before the scheduled start time, or a failure to attend, does not qualify for an automatic refund; any discretionary refund must be agreed with the Therapist and administered through the platform where applicable.
If you are a consumer with a statutory cancellation right for a distance contract, those rights remain unaffected. Where you expressly request a service to begin during a statutory cancellation period, you may have to pay for services supplied before cancellation and may lose the right to cancel once the service has been fully performed, provided the legally required request and acknowledgement were obtained.
9. Online sessions, rooms and locations
• For an online session, you are responsible for a private and safe environment, a compatible device, a reliable connection and any software or access link reasonably required. Do not attend while driving or in another unsafe setting.
• For an in-person session, follow the venue’s access, safety, conduct, confidentiality and departure requirements. Arrive and leave within the booked times.
• A room made available by us or a venue partner is an administrative facility only. It does not make us the provider of therapy. Venue common areas may be managed by third parties under their own notices.
• If a room or platform feature becomes unavailable, we may offer a reasonable alternative, online session, rescheduling, credit or refund in accordance with the Refund and Cancellation Policy.
10. Sensitive information and clinical records
• Do not enter or upload therapy notes, detailed medical histories, diagnoses, treatment plans, medication records, trauma narratives, abuse or crime reports, safeguarding records, genetic or biometric data, detailed sexual history, session recordings, crisis information or any other highly sensitive material through general profile, booking, review, support or messaging fields.
• Use any optional matching field only for concise, high-level preferences needed to identify a potentially suitable Therapist. Clinical information should be provided directly to the Therapist using the Therapist’s designated secure process.
• Searching for or booking therapy can itself reveal or imply information about wellbeing or health. We remain responsible for protecting personal information we receive as explained in the Privacy Policy; this clause does not transfer our legal data-protection duties to you.
• Do not provide another person’s sensitive information unless you have a lawful basis and it is strictly necessary for an approved purpose.
11. Messages, reviews and user content
• User content must be lawful, accurate, relevant, respectful and non-defamatory. It must not disclose confidential therapy content or another person’s personal information without lawful authority.
• Reviews must reflect a genuine experience. You must not submit or commission a fake review, manipulate ratings, offer undisclosed incentives for a positive review, or threaten a review to obtain money or another benefit.
• You grant us a non-exclusive, worldwide, royalty-free licence to host, reproduce, format, moderate, investigate, remove and display your content only as reasonably needed to operate, secure, improve and promote the platform and comply with law. You retain ownership of your content.
• We may remove, restrict or preserve content; suspend related functionality; or report content where we reasonably believe it is illegal, harmful, fraudulent, unsafe or contrary to these terms. Suspected illegal content can be reported through the Contact page.
12. Acceptable use
You must not:
• use the platform unlawfully, fraudulently, maliciously, deceptively or unethically;
• harass, threaten, exploit, discriminate against, impersonate or endanger another person;
• attempt unauthorised access, introduce malware, scrape data, interfere with security, reverse engineer protected software or overload the service;
• use contact details for spam, unrelated marketing, stalking or off-platform fraud;
• circumvent payment or booking controls in breach of these terms;
• record a session without the prior informed and lawful consent of every participant; or
• use the platform for emergency clinical communications, illegal content or any activity that could expose users, Therapists, staff, venues or the public to harm.
13. Suspension, cancellation and termination
We may refuse registration, restrict functionality, cancel a booking, remove content, suspend or close an account, or permanently prevent use where we reasonably suspect fraud, unlawful or unethical conduct, harassment, safety or safeguarding risk, payment abuse, security risk, repeated breach, false information, fee circumvention, serious reputational harm, or a risk to users, Therapists, staff, venues or the public. We may act without advance notice where prompt action is reasonably necessary.
Where appropriate and lawful, we will explain a material restriction and provide a route to contact us. Termination does not affect accrued payment, refund, evidence-preservation, complaint, liability or enforcement rights.
14. Complaints and professional concerns
• Platform, booking, payment, content or room complaints should be submitted through the Contact page. Include the booking reference and enough information for us to investigate.
• Clinical care, professional conduct, confidentiality, safeguarding, treatment, records or Therapist behaviour should normally be raised with the Therapist or clinic and, where appropriate, the relevant professional body, insurer, regulator, safeguarding authority or court.
• We do not adjudicate clinical negligence or professional misconduct, but may investigate platform issues, preserve evidence, share information lawfully and take safety or account action.
• A complaint about our handling of personal information is dealt with under the Privacy Policy. We will provide an electronic route, acknowledge a data-protection complaint within 30 days and respond without undue delay.
15. Platform availability and third parties
• We provide the platform with reasonable care and skill, but do not guarantee uninterrupted or error-free operation, a particular number of Therapists, a booking, a therapy outcome, or compatibility with every device or third-party service.
• The platform may link to or depend on third-party payment, video, email, mapping, analytics, venue or identity services. We are not responsible for an independent third party’s acts or omissions, except to the extent the law makes us responsible for our selection, instructions or use of that party.
• General website content is not medical, therapeutic, psychiatric, crisis, legal, tax, financial or other professional advice from Wellbeing Rooms.
16. Liability
Nothing in these Client Terms excludes or restricts liability for death or personal injury caused by negligence; fraud or fraudulent misrepresentation; breach of statutory consumer rights that cannot be excluded; liability under data-protection law that cannot lawfully be limited; or any other liability that cannot lawfully be excluded or limited.
Wellbeing Rooms is not liable for the Therapist’s independent clinical services, acts or omissions, professional negligence, suitability decisions, safeguarding decisions, records, confidentiality obligations, advice or outcomes, except to the extent loss is directly caused by our own breach of duty and cannot lawfully be excluded.
If you are a consumer, we are responsible for foreseeable loss or damage caused by our breach of these Client Terms or failure to use reasonable care and skill. We are not responsible for loss that was not foreseeable, business loss, or loss caused by information or instructions you failed to provide, your equipment or connection, or circumstances outside our reasonable control.
Subject to the first paragraph of this clause and only to the maximum extent permitted by law, our total aggregate liability for claims concerning the platform, a booking, payment administration or room access is limited to the greater of: (a) £100; and (b) the Wellbeing Rooms service fees actually retained in respect of your bookings during the three calendar months immediately before the first written complaint giving rise to the claim. If this limit is unfair or unenforceable in a particular case, it applies only to the extent permitted by law.
No director, founder, shareholder, employee, officer or contractor of Wellbeing Rooms assumes personal liability to you merely because of their role. The protected persons referred to in this clause may enforce the protections intended for them under the Contracts (Rights of Third Parties) Act 1999.
17. Individual claims
To the maximum extent permitted by applicable law, a dispute between you and Wellbeing Rooms should be brought on an individual basis and not as a contractual class, collective or representative claim. This clause does not remove any mandatory right to bring or participate in group litigation, a representative action, regulatory process, ombudsman or court procedure where applicable law or a court permits it.
18. Changes to the platform or these terms
We may change features and these Client Terms. We will give reasonable advance notice of a material adverse change where required or reasonably practicable. Immediate changes may be made for law, safety, security, fraud prevention, payment-system or urgent operational reasons. The version accepted when a confirmed booking was made normally governs that booking, unless mandatory law or an urgent protective change requires otherwise.
19. General legal terms
• We may transfer our rights and obligations as part of a reorganisation, financing, sale or transfer of the platform, provided this does not reduce mandatory consumer rights. You may not transfer your account or booking without consent.
• If a provision is invalid or unenforceable, the remaining provisions continue and the affected provision applies to the maximum lawful extent.
• Delay in enforcing a right is not a waiver. These Client Terms do not create a partnership, joint venture or fiduciary relationship.
• Electronic notices may be sent through the account, booking flow, website or contact details you provide. Keep those details current.
20. Law and courts
These Client Terms are governed by the law of England and Wales. A consumer retains any mandatory protection of the country in which they habitually reside. A consumer may bring proceedings in the courts permitted by applicable consumer law, including the courts of their UK place of residence where applicable. A business user submits to the exclusive jurisdiction of the courts of England and Wales.
21. Contact
Contact us by email at: hello@wellbeingrooms.com. Legal notices may also be posted to: Wellbeing Rooms, 107 Sherland Road, Twickenham TW1 4HB, United Kingdom, marked “Legal”.
Privacy Policy
Last updated: 11 July 2026
| Who this document applies to Clients, prospective clients, Therapists, provider personnel, website visitors, account holders, room partners, suppliers and other people whose personal information is processed through the Wellbeing Rooms platform. |
1. Controller and contact details
The controller is Purely Nordic Ltd trading as Wellbeing Rooms, company number 11865119, of 107 Sherland Road, Twickenham TW1 4HB, United Kingdom.
Privacy enquiries and data-protection complaints can be submitted electronically at https://wellbeingrooms.com/contact-page/ or by post to the registered address marked “Privacy”.
You may complain to the UK Information Commissioner’s Office (ICO). We ask that you contact us first so we can investigate. We will acknowledge a data-protection complaint within 30 days and respond without undue delay.
2. Our role and scope
Wellbeing Rooms is a digital marketplace and technology provider, not a therapist or healthcare provider. Therapists are independent controllers for their clinical records, therapy content, safeguarding records and professional communications outside the platform. This Privacy Policy covers our platform processing, not a Therapist’s separate clinical processing.
3. Data-minimisation and sensitive information
• The platform is not designed to store therapy notes, diagnoses, treatment plans, detailed medical records, safeguarding files or session recordings.
• Do not put detailed clinical or highly sensitive information into general booking, message, review, support or profile fields. Use the secure process designated by the Therapist for clinical information.
• The fact that a person searches for or books therapy, selected issue categories, accessibility needs or matching preferences may reveal or imply health or other sensitive information. We treat such information with additional safeguards.
4. Personal information we collect
| Category | Examples |
| Identity and contact | Name, username, email, telephone, postal address where needed, age confirmation, account identifiers and authentication information. |
| Account and booking | Therapist viewed or selected, appointment time, duration, location or online option, availability, booking status, cancellations, attendance status, high-level preferences and booking references. |
| Provider and professional | Profile, image, biography, qualifications, professional membership or registration, insurance, identity and bank verification, tax status, fees, availability, complaints and platform-performance information. |
| Payment and transaction | Amounts, currency, receipts, refunds, chargebacks, payout records, processor tokens, limited card metadata, invoices, fraud and risk signals. We do not normally store full card details. |
| Communications and content | Platform messages, contact forms, support tickets, emails, complaints, reviews, feedback, surveys and administrative records. |
| Technical and usage | IP address, device and browser information, operating system, logs, security events, cookie identifiers, page interactions, approximate location and analytics data. |
| Marketing | Communication preferences, consents, opt-outs, campaign interactions and referral source. |
| Room, access and safety | Room bookings, access records, incident and damage reports, and venue CCTV or access information where a venue separately provides notice. |
| Limited special-category data | High-level wellbeing or therapy preferences, issue categories, accessibility information and information inherently revealed by seeking or booking therapy. We do not seek clinical records. |
5. How we collect information
• Directly from you when you browse, register, create a listing, search, book, pay, communicate, review, request support or use a room.
• From a Therapist, client, clinic, venue, professional body, insurer, payment provider, identity or fraud provider, supplier or public register where relevant to verification, booking, payment, safety or legal compliance.
• Automatically from devices, cookies, logs and similar technologies.
6. Purposes and lawful bases
| Purpose | Typical basis |
| Provide accounts, listings, search, booking, calendars and communications | Contract; legitimate interests in operating and securing the marketplace. |
| Process payments, payouts, refunds, accounting and chargebacks | Contract; legitimate interests; legal obligations for tax, accounting, fraud and records. |
| Verify Providers and manage platform safety | Legitimate interests in trust, fraud prevention, quality and safety; legal obligations where applicable. |
| Handle support, complaints, disputes, safety incidents and legal claims | Contract; legitimate interests; legal obligation; vital interests in rare emergencies; establishment, exercise or defence of legal claims where sensitive data is involved. |
| Use optional health or wellbeing preferences for matching or booking | Article 6 contract or consent as appropriate; explicit consent under Article 9 where required, or another lawful Article 9 condition in exceptional circumstances. |
| Send booking, payment, security and legal service messages | Contract; legitimate interests; legal obligation. |
| Marketing and promotions | Consent where required by PECR or local law; lawful soft opt-in where available; legitimate interests for permitted business-to-business communications. Opt-out is always available. |
| Analytics, development, security and fraud prevention | Legitimate interests; consent for non-essential cookies or tracking where required. |
| Comply with law and protect rights | Legal obligation; legitimate interests; legal claims; recognised legitimate interests where applicable under UK law. |
7. Special-category and consumer health data
Where an identified or identifiable person’s use of the platform reveals health, sexual life, sexual orientation, racial or ethnic origin, religion or another protected category, we apply an Article 6 lawful basis and an Article 9 condition. For optional high-level therapy preferences, the usual Article 9 condition is explicit consent. Consent can be withdrawn prospectively, although we may retain information where another lawful ground applies, including legal claims, fraud prevention, safeguarding or legal duties.
We do not use therapy search, matching or booking information for targeted advertising. We prohibit the routine disclosure of those fields to advertising providers. The separate United States Consumer Health Data Privacy Notice applies where relevant.
8. Sharing personal information
We may share the minimum necessary information with:
• Therapists and clinics you contact or book, and clients who need Provider profile, availability, fee and booking information;
• payment processors, banks, fraud-prevention, identity-verification, accounting and tax providers;
• website hosting, marketplace, booking, calendar, video, messaging, email, SMS, customer-support, security, analytics and other technology suppliers;
• room partners, landlords and venue operators for access, safety, incidents and bookings;
• professional advisers, auditors, insurers, finance providers, investors, purchasers or successor businesses under confidentiality and due-diligence safeguards; and
• professional bodies, regulators, safeguarding authorities, tax authorities, courts, law enforcement and public bodies where disclosure is required or lawful.
We do not sell personal information for money. Some non-health cookie or advertising disclosures may be treated as “sale”, “sharing” or targeted advertising under certain US laws; where applicable, we provide required controls. We do not sell Consumer Health Data.
9. International transfers
We are based in the United Kingdom and may use suppliers or interact with users in other countries. Where a restricted transfer occurs, we use a lawful mechanism such as UK adequacy regulations, an EU adequacy decision, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, EU Standard Contractual Clauses, the UK Extension or EU-US Data Privacy Framework where applicable, or another permitted safeguard. We assess supplementary measures where required.
10. Retention
| Record | Typical period |
| Account and contract records | While active and generally up to 6 years after closure or the end of the relationship. |
| Booking, payment, payout and tax records | Generally 6 years after the relevant financial period, or longer where legally required. |
| Provider verification and insurance | While listed and generally up to 6 years after delisting, subject to complaints or legal claims. |
| High-level matching preferences | Only as long as needed for matching or booking and ordinarily no longer than 12 months after last relevant use, unless retained by the user or needed for a claim or legal duty. |
| Routine platform messages and support | Normally up to 3 years after last activity; complaint, dispute, safeguarding and legal records may be kept up to 6 years or longer if necessary. |
| Security and technical logs | Usually 12 to 24 months, or longer where required to investigate security, fraud or abuse. |
| Marketing preferences | Until opt-out and afterwards as a suppression record so the opt-out can be honoured. |
| Backups | Until overwritten or securely retired under the applicable backup cycle, subject to isolation and restricted use. |
These are maximum or typical periods, not promises to retain every record for the full period. We may delete or anonymise earlier and may retain longer for legal claims, fraud, safeguarding, regulatory investigation, litigation hold or another legal requirement.
11. Security
We use measures proportionate to risk, including access controls, least-privilege permissions, confidentiality duties, secure hosting, encryption in transit, encryption at rest where supported, multi-factor authentication for appropriate administrative access, logging, monitoring, backups, supplier diligence, testing and incident response. No internet service can guarantee absolute security. Keep credentials confidential and report suspected compromise promptly.
12. Your rights
Depending on applicable law, you may have rights to access, correction, erasure, restriction, objection, portability, withdrawal of consent, objection to direct marketing and complaint. We may verify identity and may limit a request where law permits, including for another person’s rights, legal claims, tax records, fraud prevention, safety or security.
For a Therapist’s clinical records, contact the Therapist directly. We will forward a request where appropriate but may not control those records.
13. Data-protection complaints procedure
• Submit the complaint electronically at https://wellbeingrooms.com/contact-page/ or by post marked “Privacy”.
• Explain the concern, the information involved, relevant dates and the remedy sought. Do not include unnecessary clinical detail.
• We will acknowledge the complaint within 30 days, investigate appropriately, keep you informed where needed and communicate the outcome without undue delay.
• You may complain to the ICO at any time. Contacting us first may allow faster resolution.
14. Cookies and similar technologies
• Necessary technologies support login, security, fraud prevention, preferences, bookings and core functions and may operate without consent where law permits.
• We request consent for non-essential analytics, advertising or tracking where required. The cookie banner or settings centre identifies available choices and applicable providers.
• Do not configure advertising tags to receive therapy search terms, issue categories, booking details or other Consumer Health Data. Withdrawing cookie consent does not affect earlier lawful processing.
15. Marketing
We send marketing only where lawful. You can opt out through an unsubscribe facility, account setting or the Contact page. Service messages about accounts, bookings, payments, safety, security and legal updates are not marketing and may still be sent.
16. Automated decisions and ranking
We may use automated tools to rank search results, detect fraud, prioritise support or identify security risk. We do not intend to make a solely automated decision producing a legal or similarly significant effect using special-category data. Where applicable law gives a right to human review, you may request it through the Contact page.
17. Children
The platform is intended for adults. We do not knowingly offer ordinary account or booking services directly to children. If a specifically approved service for a minor is introduced, we will implement age-appropriate design, consent, safeguarding and privacy measures before collection.
18. Non-UK users and representatives
The platform is operated from the United Kingdom. Access from another country does not mean that every service is lawfully available there. Where the EU GDPR or another law requires a local representative, additional notice or registration because we actively offer services in that jurisdiction, the relevant details will be displayed before or when that offering begins.
19. Changes
We may update this policy to reflect law, technology or service changes. We will provide reasonable notice of a material change where required. The current version is displayed on the website.
United States Consumer Health Data Privacy Notice
Last updated: 11 July 2026
| Who this document applies to US residents where a state consumer-health-data law applies to Wellbeing Rooms. This notice supplements the Privacy Policy and concerns Consumer Health Data outside HIPAA. |
1. Scope and definitions
“Consumer Health Data” means personal information that identifies, is linked or is reasonably linkable to a consumer and identifies or permits an inference about physical or mental health status, as defined by applicable US state law. It may include seeking or booking psychotherapy, selected therapy concerns, accessibility needs, location linked to a therapy service, and related account or transaction information.
This notice does not apply to information governed by HIPAA or another statutory exemption. Wellbeing Rooms is not a HIPAA covered entity or business associate unless it signs a separate Business Associate Agreement. A US Provider must not submit protected health information where a Business Associate Agreement is required but has not been signed.
2. Consumer Health Data we collect
• Account identity and contact details associated with a therapy search, enquiry or booking.
• Therapist viewed or selected, issue or matching category, session method, date, time, duration and booking status.
• Accessibility or high-level wellbeing information voluntarily provided for the requested service.
• Technical, location and usage data where it is used to identify or infer a health-related interaction.
We do not design the platform to collect therapy notes, diagnoses, treatment plans, detailed medical histories, session transcripts or safeguarding records.
3. Sources and purposes
We collect Consumer Health Data directly from consumers, Providers, devices and suppliers involved in the requested service. We use it only to provide requested search, matching, booking, payment, communications, support, security, fraud prevention, legal compliance and dispute-resolution functions, or for another purpose disclosed with required consent.
4. Collection and sharing choices
• We collect Consumer Health Data with affirmative consent where required, or to the extent necessary to provide a product or service the consumer requested where the law permits.
• We share it only with the selected Provider and necessary service providers, payment or security suppliers, venues, advisers or authorities for the disclosed purpose and lawful operation.
• We do not sell Consumer Health Data. We do not use it for cross-context behavioural advertising or precise geofencing around mental-health facilities.
• We will obtain separate authorisation before any sale if future lawfully permitted activity were to constitute a sale.
5. Recipients
Recipient categories are: the Therapist or clinic selected by the consumer; payment, fraud, identity and security providers; booking, hosting, communication and support processors; venue partners where an in-person booking requires access information; advisers and insurers; and authorities where legally required. A current list of material processor categories is available on request.
6. Consumer rights
Subject to applicable law, a consumer may request confirmation of collection, access, a list of third parties or affiliates receiving Consumer Health Data, correction, deletion, withdrawal of consent, and appeal of a refused request. Deletion may require us to notify processors or other recipients, subject to legal exceptions.
Requests and appeals can be submitted at https://wellbeingrooms.com/contact-page/. We will verify the request using information proportionate to its sensitivity. We will not unlawfully discriminate against a person for exercising a right.
7. Security and retention
We use administrative, technical and physical safeguards appropriate to the volume and sensitivity of Consumer Health Data and restrict access to people and suppliers who need it for the disclosed purpose. We retain it only as described in the Privacy Policy and delete or anonymise it when no longer required, subject to legal, security, fraud, tax and claims exceptions.
8. Processors
A processor may handle Consumer Health Data only under binding instructions that limit processing to the disclosed service, require confidentiality and reasonable security, prohibit sale and unauthorised combination or reuse, require assistance with consumer rights and deletion, and require notification of incidents. The Data Processing Agreement contains the applicable processor terms.
9. Changes and contact
We will not collect, use or share an additional category of Consumer Health Data or use it for an additional purpose without the disclosure and consent required by applicable law. Material changes will be shown by an updated date and notice where required.
Contact: https://wellbeingrooms.com/contact-page/. Postal address: Wellbeing Rooms, 107 Sherland Road, Twickenham TW1 4HB, United Kingdom, marked “US Health Privacy”.
Data Processing Agreement and Data Sharing Terms
Last updated: 11 July 2026
| Who this document applies to Wellbeing Rooms and each Provider that accepts the Therapist and Provider Terms. This document allocates controller and processor roles and includes UK GDPR, EU GDPR and relevant US processor terms. |
1. Parties and definitions
This Data Processing Agreement (“DPA”) is between Purely Nordic Ltd trading as Wellbeing Rooms (“Wellbeing Rooms”) and the Provider accepting the Provider Terms (“Provider”). It forms part of the Provider Terms.
“Data Protection Law” means the UK GDPR as amended, the Data Protection Act 2018, PECR, the Data (Use and Access) Act 2025, EU GDPR and ePrivacy law where applicable, and applicable US federal or state privacy, security and consumer-health-data law. Terms such as controller, processor, personal data, processing, special-category data and personal data breach have their statutory meanings.
2. Role allocation
| Role | Processing |
| Wellbeing Rooms as independent controller | Accounts, identity and Provider verification, listings and ranking, platform security, fraud prevention, payments and payout records, refunds, support, complaints, analytics, marketing, legal compliance and business records. |
| Provider as independent controller | Client acceptance and suitability, Therapy Contract, clinical communications, therapy content, notes and records, safeguarding, supervision, professional complaints, Provider marketing and professional or legal duties. |
| Wellbeing Rooms as processor for Provider | Only where Wellbeing Rooms processes personal data solely on Provider’s documented instruction to deliver configured booking, calendar, administrative communication or similar Provider-directed functions and not for Wellbeing Rooms’ own controller purposes. |
| Provider as processor for Wellbeing Rooms | Only where Provider handles platform data solely on Wellbeing Rooms’ documented instruction, which is expected to be limited and incidental. |
| Independent controller sharing | Where booking or contact information is disclosed and each party then determines its own lawful purpose and means. The parties are not joint controllers unless they expressly agree an Article 26 arrangement. |
3. Each party’s controller obligations
• Comply with Data Protection Law, process fairly and transparently, use an appropriate lawful basis and Article 9 condition where required, and provide an accurate privacy notice.
• Collect and share only data necessary for lawful purposes; maintain records, retention controls, staff confidentiality, training and appropriate technical and organisational measures.
• Respond to rights requests and complaints for processing it controls and cooperate where a request spans both parties.
• Do not use general platform fields for clinical notes, treatment records, detailed medical histories, diagnoses, safeguarding files, trauma narratives or session recordings.
• Provider must not market to a client using platform data without a lawful basis and any required consent.
4. Documented instructions
Where Wellbeing Rooms is processor, Provider instructs it to process Provider Personal Data only to operate the configured marketplace, booking, calendar, payment-allocation, communication, support and security services described in the Provider Terms, this DPA and Provider’s lawful platform settings or written instructions.
If an instruction appears unlawful, Wellbeing Rooms may suspend it and inform Provider unless prohibited by law. Wellbeing Rooms may process the same data as controller for its separate lawful purposes described in the Privacy Policy; that controller processing is outside this processor clause.
5. Confidentiality and personnel
Each processor must ensure that authorised personnel are bound by confidentiality, receive appropriate privacy and security instruction, and access personal data only on a need-to-know and least-privilege basis.
6. Security measures
Taking account of the nature, scope, context and risk, each processor must implement appropriate measures. Wellbeing Rooms’ measures include, as applicable:
• role-based access control and least privilege;
• appropriate authentication and administrative multi-factor authentication;
• encryption in transit and encryption at rest where supported;
• secure hosting, backup, recovery, vulnerability and patch management;
• logging, monitoring, malware protection and incident response;
• supplier diligence and contractual controls;
• data minimisation, retention and secure deletion processes; and
• periodic review of privacy and security controls.
7. Subprocessors
Provider gives general written authorisation for Wellbeing Rooms to use subprocessors for hosting, infrastructure, databases, payments, fraud and identity checks, booking, calendars, video, messaging, email, SMS, support, analytics, security, accounting, legal, insurance and venue-access systems.
Wellbeing Rooms will impose materially equivalent data-protection obligations and remains responsible to the extent required by law. We will make current material subprocessor information available on request and give reasonable notice of a material new subprocessor where required. Provider may object on reasonable data-protection grounds; the parties will seek a practical solution, which may include disabling the affected feature or termination if no solution is available.
8. Data-subject rights, DPIAs and regulator assistance
Taking account of the processing and information available, a processor will provide reasonable assistance with access, correction, deletion, restriction, objection, portability, consent withdrawal, complaints, DPIAs and regulator consultation. The controller remains responsible for the response and legal decision. Additional assistance beyond ordinary service may be charged at reasonable cost unless required because of the processor’s breach.
9. Personal data breaches
A processor must notify the relevant controller without undue delay after becoming aware of a personal data breach affecting data processed for that controller. An initial notice may be incomplete and should, where known, describe the nature of the breach, categories and approximate number of people and records, likely consequences, containment and remediation, and a contact point.
The parties will cooperate on investigation, evidence preservation, risk assessment, notifications and remediation. Neither party will make a misleading public statement or identify the other as responsible without a proper basis; this does not restrict a disclosure required by law.
10. Deletion and return
At the end of processor services, the processor will delete or return personal data as the controller reasonably requests, unless law requires or permits retention. Data may remain temporarily in protected backups and may be retained for security, fraud, accounting, legal claims or the processor’s separate controller purposes, with access restricted to those purposes.
11. Compliance information and audit
A processor will provide information reasonably necessary to demonstrate compliance with applicable processor obligations. Audits must be proportionate, protect other users and security, and ordinarily use certifications, reports, questionnaires or remote review. On-site inspection may occur where legally required or reasonably necessary after a serious incident, on reasonable notice, no more than once annually absent cause, and at the requesting party’s cost unless a material breach is found.
12. Independent-controller data sharing
• The disclosing party must have a lawful basis and provide required transparency. The receiving party becomes responsible for its own use upon receipt.
• Booking and contact data may be shared with the selected Provider to decide whether to enter and perform the Therapy Contract. Provider must not use it for an incompatible purpose.
• Each party must use secure transfer methods, minimise access, keep records and notify the other of an incident or rights request that materially affects shared data.
• Nothing requires disclosure that would breach confidentiality, privilege, safeguarding restrictions or law.
13. International transfers
A party initiating a restricted transfer must ensure that it is covered by adequacy, an approved certification framework, appropriate safeguards or a lawful exception. Appropriate safeguards may include the EU Standard Contractual Clauses, the UK Addendum, the UK International Data Transfer Agreement and a transfer risk assessment with supplementary measures.
The United Kingdom currently benefits from EU adequacy for relevant EU-to-UK transfers. If adequacy ceases or does not cover a transfer, the parties will implement another lawful mechanism without undue delay. Provider must not access or transfer platform data from an unapproved country in a way that creates an unlawful restricted transfer.
14. United States service-provider and contractor terms
Where Wellbeing Rooms or Provider acts as a service provider, contractor or processor under an applicable US state privacy law, the processor:
• processes personal information only for the specific business purposes in this DPA and documented instructions;
• must not sell or share it, retain, use or disclose it outside the direct business relationship, or use it for another commercial purpose except as expressly permitted by law;
• must not combine it with information from another source except where the law expressly permits;
• must provide the same level of privacy protection required by applicable law and implement reasonable security;
• must notify the controller if it determines it can no longer meet its obligations;
• must allow the controller to take reasonable steps to stop and remediate unauthorised use;
• must assist consumer requests, risk assessments, cybersecurity audits and compliance where required; and
• must impose equivalent terms on subcontractors.
15. US Consumer Health Data
Where a processor handles Consumer Health Data under Washington’s My Health My Data Act or a similar law, the binding instructions are limited to providing the service requested by the consumer and the purposes disclosed in the United States Consumer Health Data Privacy Notice. The processor must not sell, geofence, use for targeted advertising, or process outside those instructions; must support access, withdrawal and deletion; and must maintain reasonable administrative, technical and physical security.
16. HIPAA
The platform is not designed as a HIPAA service and Wellbeing Rooms does not act as a HIPAA business associate unless it signs a separate Business Associate Agreement. A Provider must not submit PHI or ePHI where a Business Associate Agreement is legally required but absent. If a signed Business Associate Agreement conflicts with this DPA on HIPAA matters, that agreement prevails for the relevant PHI.
17. Processing details
| Item | Details |
| Subject matter | Operation of the marketplace, profiles, discovery, bookings, calendars, payment allocation, communications, support, verification, complaints, room access and security. |
| Duration | During the Provider relationship and applicable post-termination retention. |
| Nature | Collection, recording, organisation, storage, retrieval, consultation, use, transmission, restriction, deletion, anonymisation and destruction. |
| Purposes | Deliver platform functions, manage bookings and payments, enable communications, verify Providers, prevent fraud, maintain security, resolve disputes and comply with law. |
| Data subjects | Clients, prospective clients, Providers, clinic personnel, room partners, support contacts, website users and business contacts. |
| Personal data | Identity, contact, account, profile, qualification, booking, availability, payment, transaction, communication, technical, usage, marketing, verification, room-access, support and complaint data. |
| Sensitive data | Limited high-level therapy or wellbeing preferences, accessibility needs, professional disciplinary information where relevant, and data inherently revealed by seeking or booking therapy. No routine clinical records. |
| Frequency | Continuous or event-driven while the platform is used. |
18. Liability, precedence and duration
The liability and indemnity provisions in the Provider Terms apply to this DPA, except to the extent Data Protection Law prohibits limitation. If this DPA conflicts with the Provider Terms on data-protection matters, this DPA prevails. Mandatory transfer clauses or a signed Business Associate Agreement prevail for their subject matter.
This DPA begins when Provider accepts the Provider Terms and continues while either party processes personal data connected with the platform or retains data subject to surviving obligations.
19. Law and contact
This DPA is governed by the law of England and Wales, without displacing mandatory rights or transfer-clause law. The courts of England and Wales have exclusive jurisdiction except where mandatory law provides otherwise.
Data-protection communications: https://wellbeingrooms.com/contact-page/. Postal address: Wellbeing Rooms, 107 Sherland Road, Twickenham TW1 4HB, United Kingdom, marked “Privacy”.
