Legal

Privacy Policy

Mindcarter provides psychological and organisational consulting services. That means we handle information about your mental health — some of the most sensitive data there is. This policy explains exactly what we collect, who can see it, and what control you have over it.

Last updated — 27 September 2026

01

Who we are

Mindcarter ("Mindcarter", "we", "us", "our") is an organisational psychology consulting practice based in Thiruvananthapuram, Kerala, India. We provide therapy and counselling, psychometric assessments, executive coaching and corporate wellness programmes, both directly to individuals and through employer-sponsored Corporate Counselling programmes.

Under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025, Mindcarter is the Data Fiduciary for the personal data described in this policy. If you use our website or portals, you are a Data Principal. We also handle your information in line with the Information Technology Act, 2000 and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), which classify mental-health information and medical records as sensitive personal data or information.

Mindcarter

Module No. A, Tejaswini, Technopark, Thiruvananthapuram, Kerala, India

Email: info@mindcarter.com
Phone: +91 75940 71071

02

Scope of this policy

This policy covers:

  • Our public website, including enquiry and contact forms.
  • The client portal, where you book sessions, keep a wellness journal, manage your profile and message support.
  • The psychologist portal used by our clinicians.
  • The Corporate Counselling dashboard used by employers who sponsor our programmes.
  • Email and phone communication connected with the services above.

It does not cover third-party websites we link to. Those have their own privacy policies and we are not responsible for them.

03

What we collect

We collect only what the service needs. Different categories are treated with different levels of protection — the clinical categories are the most tightly restricted.

CategoryWhat it includesHow we get it
Account detailsName, email address, phone number, password (stored only as a one-way bcrypt hash), profile photo, account role and status.You provide it at sign-up, or your employer provides your name and work email when adding you to a Corporate Counselling roster.
Google sign-in dataYour Google account identifier, name and email, if you choose to sign in with Google.From Google, with your permission, at the moment you sign in.
Profile detailsDate of birth, emergency contact name, number and relationship to you, preferred language, and your notification preferences.You provide these when completing your portal profile.
Health and clinical dataThe primary concern you tell us about, wellness journal entries (including mood ratings from 1 to 5, tags and free text), notes your clinician writes about your sessions, assessment-related information, and the clinical categories/tags attached to your record.You write journal entries yourself; your clinician writes session notes.
Booking and session dataSession date, time, duration, type, mode (video, in person or phone), status, fee amount, cancellation reason and refund status, meeting links, and which clinicians make up your care team.Generated when you book, reschedule or attend a session.
Support dataSupport tickets you raise and the messages in those threads.You provide it when contacting support.
Technical and security dataIP address, browser user-agent string, session tokens (stored as hashes), one-time verification codes (stored as hashes) and password-reset tokens.Collected automatically when you sign in and use the site, to keep your account secure.
Employment data (Corporate Counselling only)Your employer's name, your work email, department and job title.Provided by your employer when they add you to their roster.

We do not collect government identity numbers such as Aadhaar or PAN through this website, and we do not run behavioural advertising or sell data to anyone, ever.

04

Why we use it

  • To deliver care. Scheduling sessions, matching you with a clinician, letting your clinician prepare for and record sessions, and supporting continuity of care across your care team.
  • To run your account. Creating and securing your login, verifying your email, resetting passwords, and keeping you signed in.
  • To communicate with you. Booking confirmations, reschedule and cancellation notices, session reminders, verification codes and service updates. These are transactional messages tied to your care — not marketing.
  • To handle payments and records. Recording session fees, refunds and the financial records we are required to keep.
  • To keep the service safe. Detecting suspicious sign-ins and preventing abuse.
  • To report programme usage to employers — strictly limited to the information described in the Corporate Counselling section below.
  • To meet legal obligations, including record-keeping and responding to lawful orders.

06

Clinical confidentiality

What you discuss in a session stays between you and your clinician. Access inside Mindcarter is restricted by role, and the system is built to enforce it:

  • Your clinician can see your profile, your bookings, the journal entries you submit for review and their own session notes for you.
  • Session notes written by your clinician are visible only to that clinician. They are not shown to anyone else at Mindcarter and are not displayed in your portal.
  • Your employer never sees clinical content of any kind. See the next section.

We break confidentiality only where the law requires or permits it — for example, where there is a serious and imminent risk to your life or safety or to someone else's, where a court or competent authority lawfully orders disclosure, or in a medical emergency. This reflects our obligations under the Mental Healthcare Act, 2017, which gives you a right to confidentiality in respect of your mental health care and treatment.

07

Corporate Counselling — what your employer sees

If your employer sponsors your access to Mindcarter, they receive a dashboard to measure the programme. We are deliberately specific about its limits, because this is the question employees ask most.

Your employer can see

Who is on their roster (name, work email, department, job title), whether an employee has activated their account, and how many sessions each employee has booked or completed, including aggregate utilisation figures for the organisation.

Your employer can never see

What is discussed in a session, clinical notes, your wellness journal entries, your mood ratings, assessment results, your stated concerns, or which psychologist you are seeing. Those stay strictly between you and your clinician.

Session counts are attributed to named employees, so your employer can tell that you used the programme and how often — but never anything about the content of your care. If you would prefer your employer not to see your participation at all, you can book with us privately instead of through the corporate programme.

08

Who we share data with

We do not sell your personal data and we do not share it for advertising. We share it only with service providers who process it on our instructions under contract, and only as far as needed:

WhoWhat they processWhy
Our cloud hosting and database providersAll application dataTo host the website, the portals and the database that stores your records.
Resend (email delivery)Your name, email address and the contents of transactional emailsTo deliver verification codes, booking confirmations, reminders and password resets.
GoogleYour Google account identifier and email if you use Google sign-in; session date, time and title if your clinician has connected Google CalendarTo authenticate you, and to create the calendar event and Google Meet link for a video session.
Your employerRoster and session-count data onlyTo administer a sponsored Corporate Counselling programme, as limited above.
Professional and legal advisers, auditors and authoritiesOnly what is strictly necessaryWhere we are required to comply with law, a court order, or a lawful request from a government agency.

Calendar entries created for video sessions carry the session time and a neutral title. Clinical details are never written into a calendar event.

09

Where data is stored

Our infrastructure providers may store or process data on servers located outside India. The DPDP Act permits transfer of personal data outside India except to territories the Central Government restricts by notification; we will comply with any such restriction if it applies to our providers, and will relocate data where legally required.

Wherever your data sits, it remains subject to this policy and to contractual security obligations on the provider.

10

How we protect data

  • Passwords are stored only as bcrypt hashes — we cannot read your password, and neither can our staff.
  • Sessions use signed, expiring tokens; only a hash of each token is stored, and sessions can be revoked immediately.
  • One-time verification codes and password-reset tokens are stored as hashes, never in plain text, and expire after a short window.
  • Third-party calendar credentials are encrypted at rest with AES-256-GCM.
  • Traffic between your browser and our servers is encrypted in transit over HTTPS.
  • Access to clinical records is restricted by role and enforced on the server, not just hidden in the interface.

These measures are intended to meet the "reasonable security practices and procedures" standard under Section 43A of the Information Technology Act, 2000 and the security safeguard obligations of the DPDP Act. No system is perfectly secure, and we cannot guarantee absolute security — but we will tell you if something goes wrong, as described below.

11

How long we keep data

We keep personal data only as long as it is needed for the purpose it was collected for, and erase it when you withdraw consent or the purpose is no longer served — unless retention is required by law.

  • Clinical records, including session notes, are retained for the period required for continuity of care and by applicable professional and legal record-keeping obligations.
  • Booking and financial records are retained for the period required by tax and accounting law.
  • Authentication data — session rows, verification codes and reset tokens — is short-lived and cleared after expiry.
  • Corporate roster entries for employees who leave a programme are retained in a removed state so historical utilisation figures stay accurate, and can be erased on request.

12

Your rights as a Data Principal

Under the DPDP Act you have the right to:

  • Access — obtain a summary of the personal data we hold about you and how we process it, and the identities of those we have shared it with.
  • Correction and completion — have inaccurate or incomplete data corrected, completed or updated. You can edit most profile fields yourself in the portal.
  • Erasure — have your personal data erased where it is no longer needed and no law requires us to keep it.
  • Grievance redressal — a readily available means of raising a complaint with us, described below.
  • Nomination — nominate another individual to exercise your rights on your behalf if you die or become incapacitated.
  • Withdraw consent — at any time, as easily as you gave it.

You also have the right, under the Mental Healthcare Act, 2017, to access your own mental health records, subject to the limited exceptions in that Act.

To exercise any of these rights, email info@mindcarter.com from the address registered on your account. We may ask you to verify your identity before acting, and we will respond within the timelines set out under the DPDP Rules.

The Act also requires you to exercise these rights in good faith: not to impersonate anyone, not to suppress material information, and not to file false or frivolous complaints.

13

Children's data

Our website and portals are intended for adults. Under the DPDP Act, a child is anyone under 18 years of age. We do not knowingly create accounts for children through this website without verifiable consent from a parent or lawful guardian, and we do not carry out tracking, behavioural monitoring or targeted advertising directed at children.

Where Mindcarter provides services to a minor, consent is obtained from the parent or lawful guardian through our intake process rather than through online self-signup. If you believe a child has registered without that consent, contact us and we will erase the account.

14

Cookies

We use a small number of cookies, mainly to keep you signed in. The first time you visit we ask whether you accept non-essential cookies, and we remember your answer. Full details are in our Cookie Policy.

15

Data breaches

If a personal data breach occurs, we will notify each affected Data Principal and the Data Protection Board of India in the manner and within the timelines required by the DPDP Rules, 2025. Our notice to you will describe the nature and extent of the breach, its likely consequences, the measures we have taken, and what you can do to protect yourself.

16

Changes to this policy

We may update this policy as our services or the law change. The "last updated" date at the top always reflects the current version. If a change materially affects how we handle your data, we will notify you by email or through the portal before it takes effect, and where the law requires it, ask for fresh consent.

17

Grievance redressal

If you have a question or complaint about how we handle your data, contact our Grievance Officer. We will acknowledge your complaint and respond within the period prescribed under the DPDP Rules, 2025.

Grievance Officer

Mindcarter
Module No. A, Tejaswini, Technopark, Thiruvananthapuram, Kerala, India
Email: info@mindcarter.com
Phone: +91 75940 71071

If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India established under the DPDP Act.