Faresay
Therapy, matched.

Faresay — UK Business Overview

Confidential Faresay Ltd·25 June 2026

One-page context for advisers. Preparatory material — not legal advice. UK launch scope only; US plans and the future "find clients" marketplace add-on are deliberately excluded from this document. Supersedes the marketplace overview (uk-business-overview.md) for the current direction. Last updated: [PLACEHOLDER: date]

What Faresay is

Faresay is a B2B SaaS "practice portal" — software that UK therapists subscribe to in order to run their own private practice. The platform gives the therapist the tools to manage their own clients, scheduling, secure video sessions, card payments, and appointment reminders, on web and phone. The therapist delivers the clinical work and owns the relationship; Faresay provides the software, nothing more.

  • What it is: practice-management software sold to independent UK therapists to run their own private practice.
  • What it is not: not a two-sided marketplace; not a healthcare provider; not a care intermediary arranging or matching care; not an employer of the therapists; not a crisis service; and not the data controller of the clinical record (the therapist is).

How it works

  1. A therapist subscribes to Faresay (a monthly SaaS plan).
  2. The therapist adds their own clients and manages their own diary, notes, and reminders.
  3. Therapist and client meet over secure video booked through the portal.
  4. Clients pay the therapist by card through the platform (via Stripe); the therapist sets their own fee and keeps it.

Faresay is the toolset behind all of this. Clinical responsibility, crisis and safeguarding, and the client relationship sit with the therapist, who is the practitioner and the controller of the clinical record.

Who the customer is

The customer is the therapist — a business or sole trader — not the client. Therapists are independent, UK-registered mental-health professionals (e.g. BACP / UKCP / NCS / BPS, or statutory registration where relevant) who carry their own professional indemnity insurance. Faresay verifies their registration before the account goes live. The therapist's clients are the therapist's own clients throughout.

Revenue model (directional)

Revenue is a monthly subscription fee paid by the therapist, plus a small commission on card payments processed through the platform. To be explicit: this is a recurring software subscription, not a 15% marketplace fee — Faresay does not take a share of the clinician's professional fee in the old marketplace sense. The commission covers the cost and convenience of in-platform card processing only.

Item Value Note
Subscription tiers ~Free / £29 / £79 per month Directional / launch pricing — [PLACEHOLDER: confirm pricing]
Payment commission Small % of card payments Via Stripe; not a fee-split of the professional fee
Customer The therapist (business / sole trader) Not the client
Therapist status Independent, self-employed Not employed by Faresay
Stage Pre-launch (UK) [PLACEHOLDER: confirm entity] — Companies House + counsel in progress

Data-protection posture (one line)

The therapist is the data controller of their clients' (special-category, mental-health) data; Faresay is a data processor acting on the therapist's documented instructions, which requires an Article 28 Data Processing Agreement (DPA) with every therapist.

Confirming the processor characterisation and getting a signable Article 28 DPA in place with every therapist — this is what lets Faresay process real client data lawfully and what keeps clinical and controller responsibility with the therapist. See pp-uk-legal-brief.md for the specific questions to put to counsel.

Faresay
Therapy, matched.

Faresay — UK Legal Brief & Questions

Confidential Faresay Ltd·25 June 2026

Read this before the lawyer meeting. The model has pivoted from a B2C care marketplace to a B2B SaaS practice portal (model-comparison.md). That changes Faresay's legal role fundamentally, so the questions to ask counsel change too. This supersedes the marketplace brief (uk-legal-regulatory-brief.md) for the current direction — bring both: the marketplace one stays relevant for the future "find clients" add-on. Preparatory material, not legal advice. Last updated: [PLACEHOLDER: date]


The one change that reframes the whole conversation

Marketplace: Faresay arranged care, owned the client, was the data controller, and carried care-intermediary + crisis liability close to home.

Practice portal: Faresay sells software to therapists. The therapist owns the client and the clinical record and is the data controller; Faresay is a data processor acting on the therapist's instructions. Clinical and crisis responsibility sit with the therapist. Faresay is a tool, one step removed from care.

Almost every legal question below flows from that single shift. Lead the meeting with it.

Priority questions for counsel (tonight)

  1. Role confirmation. Confirm Faresay is a processor of therapists' client data and the therapist is the controller. Where does Faresay remain a controller in its own right (therapist account data, billing, product analytics)? Get the dual role mapped cleanly.

  2. DPA with every therapist (the central instrument). We need an Article 28 Data Processing Agreement signed with each therapist before real client data is processed. Ask counsel to produce/review a standard DPA template covering: documented-instructions only, confidentiality, Art 32 security, sub-processor flow-down (Clerk, Daily.co, Resend, Neon), international transfers (IDTA/SCCs for any non-UK leg), breach notification to the controller, assistance with DSARs/DPIAs, and deletion/return on termination.

  3. The "managed / accountless client" feature. Therapists can add clients who never log in, and the therapist asserts consent on their behalf. Confirm this is lawful as processor acting on the controller's documented instruction, and that the DPA + the therapist's own lawful basis cover it.

  4. Contracts — what replaces what. The primary contract becomes a B2B SaaS subscription agreement with the therapist (replacing the marketplace therapist/contractor agreement). Does Faresay still need any client-facing terms, given the client now contracts with the therapist, not Faresay? What minimal platform notice does the end-client need?

  5. Liability shift + residual platform duties. Clinical care, duty of care, crisis and safeguarding move to the therapist (controller/provider). What residual obligations stay with Faresay as the tool — crisis signposting in the UI, what to do if the platform itself surfaces risk, acceptable-use/abuse, and the limitation-of-liability wording for SaaS terms?

  6. CQC / regulated activity. As a pure software tool (not arranging or providing care), confirm Faresay is outside CQC registration — and what facts would tip it back in (e.g. the marketplace add-on, or doing anything clinical).

  7. Payments / fee characterisation. Revenue = subscription (SaaS) + a small commission on client→therapist payments via Stripe Connect (therapist sets the price and owns the client). Is the commission clean now (vs the marketplace fee-split concern), or does it still need careful characterisation? Any issue charging both a subscription and a commission ("pay twice")?

  8. Cross-border — does the portal dissolve the problem? This was the marketplace's biggest blocker (a UK therapist treating a client physically abroad). Under the portal, the therapist decides whom they can lawfully treat and where — it's their licensure question, not Faresay's, because Faresay is just the tool. Confirm Faresay-as-software isn't liable for where a therapist's client sits, and what (if any) terms put that responsibility squarely on the therapist.

  9. The future marketplace add-on (gate it). When we later switch on "find clients" matching, Faresay re-enters intermediary/controller territory for those introductions only. Confirm we can run the portal as processor-only now and treat the add-on as a separate, later legal workstream.

  10. B2B vs consumer + housekeeping. Customer is now a therapist (business/sole trader) → largely B2B, lighter consumer-law exposure on the core sale (confirm). Plus: ICO registration, the DPO trigger (large-scale special-category processing, even as processor), and ASA/advertising for the new B2B claims and any "verified therapist" / efficacy language.

What's deferred or changed from the marketplace brief

  • Per-corridor cross-border licensure → becomes the therapist's responsibility under the portal (revisit only for the marketplace add-on).
  • Care-intermediary / controller crisis liabilityshifts to the therapist.
  • Therapist employment / worker status → far less central (the therapist is now a customer, not supply Faresay directs). Revisit only if/when marketplace supply recruitment restarts.
  • Consumer-contract / 14-day cancellation mechanics → recedes (B2B sale), but the therapist's own clients remain consumers — the therapist's responsibility.

Still relevant, unchanged

  • The high security bar for special-category data (Art 32) — non-negotiable either model.
  • UK GDPR + DPA 2018 + ICO.
  • Data residency (EU/UK) and the US sub-processors (Clerk/Daily/Resend) needing transfer mechanisms.

Bring to the meeting

  • model-comparison.md (so counsel sees the pivot and the hybrid plan).
  • This brief + uk-legal-regulatory-brief.md (for the add-on/future).
  • The single ask to walk out with: a DPA template we can sign with design-partner therapists, so the validation pilot (pp-validation-plan.md) can process real client data lawfully.

Linked documents

  • model-comparison.md · therapist-portal-pivot.md · pp-validation-plan.md · uk-legal-regulatory-brief.md (marketplace/future) · pp-risk-register.md
Faresay
Therapy, matched.

Terms of Service (SaaS)

DRAFT — for professional sign-off Faresay Ltd·25 June 2026

⚠️ DRAFT v0.1 — for UK legal counsel review. NOT legal advice. Counsel must finalise before use. Last updated: [PLACEHOLDER: date]

Faresay Practice Portal — Subscription Terms of Service (United Kingdom)

These Subscription Terms of Service ("Terms") govern your subscription to and use of the Faresay practice portal — software that a mental-health professional subscribes to in order to run their own private practice (together with our website, applications, APIs, and related services, the "Service"). The Service is operated by [PLACEHOLDER: registered entity name], a company registered in England & Wales with company number [PLACEHOLDER: company number] and registered office at [PLACEHOLDER: registered address] ("Faresay", "we", "us", "our").

These Terms are a business-to-business (B2B) software-as-a-service (SaaS) agreement between Faresay and you, the professional or practice that subscribes to the Service (the "Customer", "you", "your"). Please read them carefully. By creating an account, subscribing, or using the Service, you agree to be bound by them.

⚠️ COUNSEL — Confirm the UK operating entity details (registered name, number, address) and that the B2B characterisation is correct: the Customer is a therapist/practice (a business or sole trader), not a consumer, and not the therapist's client.


1. The Service and Faresay's role

1.1 Faresay is software. The Service is a practice-management software platform that helps an independent mental-health professional run their own private practice. It provides tools to manage clients, schedule and book appointments, hold secure video sessions, take card payments, send reminders and notifications, and keep practice records.

1.2 Faresay is NOT a care provider. Faresay does not provide clinical, therapy, counselling, medical, or healthcare services, does not arrange or supply care, is not a healthcare provider or practice, and is not an intermediary between you and your clients. Faresay does not practise, supervise, direct, or control the clinical judgement of any Customer.

1.3 You run your own practice. The Service is a tool you use to operate your practice. The clinical relationship, the client relationship, and the clinical record are between you and your client — Faresay is not a party to either. Your clients are your clients, not Faresay's. See Section 5.

1.4 You are the data controller. In respect of your clients' personal data (including special-category health data), you are the data controller and Faresay is your data processor, acting only on your documented instructions. The processing terms are set out in the Data Processing Agreement (pp-dpa.md), which forms part of these Terms, and our Privacy Policy (pp-privacy-policy.md). See Section 8.

⚠️ COUNSEL — This software/processor (not provider/controller) characterisation is the foundation of Faresay's liability and regulatory position (see pp-uk-legal-brief.md). Confirm the wording matches what the Service actually does and does not control, and that it supports the position that Faresay is outside CQC registration as a pure software tool.

1.5 Not an emergency or crisis service. The Service is practice-management software for scheduled, non-urgent care delivered by you. It is not an emergency service, crisis line, or monitored channel, and Faresay does not monitor client communications or bookings for emergencies. Responsibility for crisis handling, risk management, and safeguarding rests with you as the clinician (Section 5).


2. Eligibility

2.1 Who may subscribe. To subscribe to and use the Service to deliver care, you must be a mental-health professional who is appropriately registered and entitled to practise in the United Kingdom, namely a current member of an appropriate UK professional body or a PSA-accredited register (for example BACP, UKCP, NCS (National Counselling & Psychotherapy Society), or BPS) or, where your title or profession is statutorily regulated, holding the relevant statutory registration.

2.2 Good standing. You must hold and maintain at all times that registration in good standing, with a valid, current, and unrestricted entitlement to practise, and you must hold your own professional indemnity insurance (Section 5.5). You must notify us promptly if your registration, entitlement, or insurance lapses, is suspended, restricted, or revoked.

2.3 Business use. You confirm that you are subscribing in the course of a business (as a sole trader, partnership, or company) and not as a consumer, and that any individual accepting these Terms is authorised to bind the Customer.

⚠️ COUNSEL / ⚠️ CLINICAL — Confirm the acceptable registers and minimum-membership criteria per profession, how protected titles are handled, and what verification (if any) Faresay performs at sign-up versus relying on the Customer's warranty. See pp-uk-legal-brief.md.


3. Accounts

3.1 To use the Service you must create an account and provide accurate, current, and complete information, and keep it up to date.

3.2 You are responsible for safeguarding your login credentials and for all activity under your account, including activity by any colleagues, associates, or staff you authorise. Notify us promptly at [PLACEHOLDER: security/support contact] if you suspect unauthorised use.

3.3 You may not share your account, register using false information, or allow any person who is not eligible under Section 2 to deliver care through your account.


4. Subscription plans and fees

4.1 Subscription plans. The Service is offered on monthly subscription plans. Indicative launch tiers are:

  • Free — [PLACEHOLDER: feature limits, e.g. capped active clients / no card payments];
  • [PLACEHOLDER: plan name] — £29 per month — [PLACEHOLDER: features];
  • [PLACEHOLDER: plan name] — £79 per month — [PLACEHOLDER: features].

⚠️ PRICING IS DIRECTIONAL / LAUNCH-ONLY. The tiers and prices above are indicative and subject to change. [PLACEHOLDER: confirm final tiers, prices, feature splits, VAT treatment, and any annual-billing option.]

4.2 Card-payment commission. Where you use the Service to take card payments from your clients, Faresay charges a small commission on each card payment processed, in addition to your subscription fee and in addition to the underlying payment-processor (Stripe) fees. The commission rate is [PLACEHOLDER: e.g. X% + £Y per transaction], disclosed in-product before you enable payments.

4.3 This is not a marketplace fee. The commission in clause 4.2 is a fee for the payment-processing facility within the software. It is not a marketplace fee, a referral fee, an introduction fee, or any share, split, or cut of your professional or clinical fee. You set your own fees, own your clients, and receive your fees less only the processor fees and this commission.

⚠️ COUNSEL — Confirm the commission characterisation is sound, consistent with professional-body guidance, and clearly presented. Confirm there is no issue charging both a subscription and a per-transaction commission, and confirm the VAT treatment of the subscription and the commission. See pp-uk-legal-brief.md.

4.4 Billing. Subscription fees are billed monthly in advance and commission is collected per transaction, via our payment provider Stripe. By subscribing and enabling payments, you authorise us (and Stripe) to charge the applicable fees, and you agree to Stripe's terms. You are responsible for completing Stripe's onboarding (including any KYC steps).

4.5 Changes to fees. We may change subscription prices, plan features, or the commission rate on [PLACEHOLDER: e.g. 30 days'] notice. If you do not accept a change, you may cancel under Section 9 before it takes effect.

4.6 Taxes. Prices are stated [PLACEHOLDER: inclusive / exclusive] of VAT. You are responsible for any taxes arising from your own practice income and from your use of the Service.

4.7 Non-payment. If a subscription payment fails, we may suspend paid features after reasonable notice until payment is made, without affecting your right to export your data (Section 9.3).


5. Your responsibilities

You acknowledge and agree that, as the professional running your own practice, you (and not Faresay) are responsible for the following:

5.1 The client relationship and the clinical record. You own the relationship with each of your clients and you own, create, maintain, retain, and secure the clinical record, in accordance with applicable law and your professional standards. Faresay merely stores and processes that data on your instructions as your processor (Section 8).

5.2 Clinical care. All assessment, diagnosis, treatment, advice, professional judgement, and the suitability, quality, and safety of care are yours alone. You must practise only within your scope of competence and registration, and refer or decline where care falls outside it (including where in-person or higher-acuity care is indicated).

5.3 Data controller duties. As controller of your clients' personal data, you are responsible for: establishing a lawful basis and an Article 9 condition for processing special-category health data; obtaining and documenting client consent (including consent to remote/online delivery and to any client who you add without their own login, where you assert consent on their behalf); providing privacy information to your clients; and handling your clients' data-subject rights. Faresay will assist you as set out in the DPA.

5.4 Crisis and safeguarding. You are responsible for crisis handling, risk assessment, escalation, safeguarding, and signposting clients to appropriate UK services (for example 999, NHS 111, the Samaritans on 116 123, or SHOUT by texting 85258). The Service does not perform these functions for you.

5.5 Insurance and professional compliance. You must hold and maintain your own professional indemnity insurance appropriate to your practice, and comply with your professional body's standards, your registration conditions, and all applicable law (including, where you treat a client located outside the UK, your own licensure position for that client — that is your responsibility, not Faresay's).

5.6 Accurate use. You must keep your account and any client-facing content accurate and not misleading, and not make false or guaranteed-outcome claims.

⚠️ COUNSEL / ⚠️ CLINICAL — Confirm this allocation of clinical, consent, lawful-basis, crisis, and licensure responsibility to the Customer is complete and aligns with pp-uk-legal-brief.md, the DPA (pp-dpa.md), and professional-body standards. Confirm the cross-border position (Customer decides whom they can lawfully treat and where).


6. Acceptable use

6.1 You agree to use the Service only for lawful purposes and in accordance with these Terms. You must not:

  • (a) use the Service for any emergency or crisis-monitoring purpose (Section 1.5);
  • (b) allow any ineligible person to deliver care through your account (Section 2);
  • (c) upload unlawful content, or content you have no lawful basis to process;
  • (d) attempt to gain unauthorised access to the Service, interfere with its operation, introduce malicious code, or scrape, harvest, or reverse-engineer it (except to the extent that restriction is unlawful);
  • (e) use the Service to infringe the rights of any person, or to harass, abuse, or harm any person;
  • (f) resell, sublicense, or provide the Service to third parties as a service bureau except as expressly permitted; or
  • (g) use the Service in breach of any applicable law or your professional obligations.

6.2 We may suspend or restrict access for breach of this Section, acting reasonably and, where practicable, on notice (Section 9.2).


7. Intellectual property; your data

7.1 Faresay owns the software. Faresay (and its licensors) own all rights in the Service, including all software, designs, text, graphics, logos, trademarks, and Faresay-created content. "Faresay" and our logos are our trademarks. We grant you a limited, non-exclusive, non-transferable, revocable licence to access and use the Service to run your practice for the duration of your subscription, in accordance with these Terms. No other rights are granted.

7.2 You own your data. As between you and Faresay, you retain all ownership of your account content, your practice data, and your clients' data (including the clinical record) that you put into or generate through the Service ("Customer Data"). You grant Faresay only the limited licence necessary to host, store, process, and transmit Customer Data so as to provide the Service to you and as instructed in the DPA. We claim no ownership of, and will not use, Customer Data for any other purpose.

7.3 Feedback. If you give us feedback or suggestions, we may use them without restriction or obligation to you.


8. Data protection

8.1 In respect of your clients' and your practice's personal data processed through the Service, you are the controller and Faresay is the processor. Faresay processes that personal data only on your documented instructions and in accordance with the Data Processing Agreement (pp-dpa.md), which is incorporated into and forms part of these Terms.

8.2 In respect of your account, billing, and product-usage data, Faresay acts as an independent controller for the limited purposes of operating, billing, securing, and improving the Service, as described in our Privacy Policy (pp-privacy-policy.md).

8.3 Both parties will comply with the UK GDPR and the Data Protection Act 2018. You acknowledge that client clinical data is special-category (health) data requiring an appropriate lawful basis, an Article 9 condition, and a high standard of security, and that establishing those bases is your responsibility as controller (Section 5.3).

⚠️ COUNSEL / DPO — Confirm the controller (Faresay, for account/billing/analytics) versus processor (Faresay, for client data) split is mapped cleanly, the DPA is signed before real client data is processed, and ICO-registration / DPO-trigger questions are addressed. See pp-uk-legal-brief.md.


9. Term, cancellation, and your data on exit

9.1 Term. These Terms apply from when you first accept them and continue for as long as you have an account. Paid plans renew automatically each month until cancelled.

9.2 Cancellation by you. You may cancel at any time through your account or by contacting us. Cancellation takes effect at the end of the then-current paid month; we do not, as standard, refund the unused part of a month [PLACEHOLDER: confirm pro-rata / no-refund policy]. On cancellation you may downgrade to the Free plan (if available) or close your account.

9.3 Your data on termination. On cancellation or termination, you may export and keep your Customer Data. We will make Customer Data available for export for [PLACEHOLDER: e.g. 30 days] after termination, after which we will delete or return it in accordance with the DPA (pp-dpa.md). You remain responsible, as controller, for retaining the clinical record for the period your professional standards require — exporting it before deletion is your responsibility.

9.4 Suspension or termination by us. We may suspend or terminate your access, on reasonable notice where practicable, if (a) you materially breach these Terms (including Sections 2, 5, or 6) and fail to remedy a remediable breach within [PLACEHOLDER: cure period]; (b) you lose the registration, entitlement, or insurance required by Section 2/5.5; (c) we are required to do so by law; (d) your use poses a risk to others or to the Service; or (e) we discontinue the Service or a material feature on reasonable notice.

9.5 Survival. Sections that by their nature should survive (including 1, 4 (accrued fees), 7, 8, 10, 11, 12, and 13) survive termination.

⚠️ COUNSEL / ⚠️ CLINICAL — Termination must not cut off care or records in a clinically unsafe way. Confirm the data-export window and that the Customer is clearly responsible for continuity of care and record retention.


10. Warranties and disclaimers

10.1 Software "as is". To the fullest extent permitted by law, the Service is provided "as is" and "as available", without warranties of any kind, express, implied, or statutory, except as set out in clause 10.4. We do not warrant that the Service will be uninterrupted, error-free, secure, or free of harmful components, or that any defect will be corrected.

10.2 No clinical warranty. Because Faresay does not provide care, we make no representation or warranty as to the suitability, safety, quality, or outcome of any care you deliver using the Service. The Service is a tool; clinical responsibility is yours (Section 5).

10.3 No reliance for clinical decisions. Any templates, prompts, reminders, or informational content in the Service are conveniences only and are not clinical advice. You must apply your own professional judgement.

10.4 Non-excludable terms. Nothing in these Terms excludes or limits any term or liability that cannot lawfully be excluded or limited. Where the Service is supplied to you, it will be supplied with reasonable care and skill.

⚠️ COUNSEL — Confirm the "as is" disclaimer and the non-excludable-terms carve-out are correctly framed for a B2B supply (Unfair Contract Terms Act 1977 reasonableness applies).


11. Limitation of liability

11.1 Non-excludable liability. Nothing in these Terms limits or excludes liability that cannot lawfully be limited or excluded, including liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or any other liability that cannot lawfully be limited.

11.2 Excluded losses. Subject to clause 11.1, Faresay will not be liable for any indirect or consequential loss, or for loss of profits, revenue, goodwill, anticipated savings, or loss of or damage to data (save for our obligation to maintain reasonable backups), however arising.

11.3 Liability cap. Subject to clauses 11.1 and 11.2, Faresay's total aggregate liability arising out of or relating to these Terms or the Service in any 12-month period is limited to the total subscription and commission fees you paid to Faresay in the 12 months before the event giving rise to the claim [PLACEHOLDER: confirm cap basis and any floor].

11.4 No liability for care or controller duties. Faresay is not liable for the care you provide, your clinical decisions, or your discharge of your duties as data controller (lawful basis, consent, crisis, safeguarding, retention), all of which are your sole responsibility (Section 5).

⚠️ COUNSEL — Set the cap and confirm the exclusions and cap are reasonable and enforceable in a B2B context (UCTA 1977), and reconcile with the indemnity (Section 12) and the DPA liability allocation.


12. Indemnity

12.1 To the fullest extent permitted by law, you agree to indemnify Faresay and its officers, employees, and agents against claims, liabilities, losses, and reasonable costs (including legal fees) arising out of or relating to (a) the care you provide (or fail to provide) using the Service, including any clinical negligence or breach of professional duty; (b) your breach of these Terms or the DPA; (c) your breach of your duties as data controller or of data-protection law; or (d) any claim that you lacked the required registration, entitlement, insurance, or lawful basis.

⚠️ COUNSEL — Confirm scope, any mutual indemnity, and the interaction with the limitation of liability, the DPA, and the Customer's professional indemnity insurance.


13. General

13.1 Governing law and jurisdiction. These Terms and any dispute arising out of them are governed by the laws of England & Wales, and the courts of England & Wales have exclusive jurisdiction. [PLACEHOLDER: confirm position for Customers established in Scotland / Northern Ireland.]

13.2 Changes to these Terms. We may update these Terms from time to time. We will give reasonable notice of material changes (for example by email or in-product) before they take effect. Continued use after the effective date constitutes acceptance; if you do not agree, you may cancel under Section 9.

13.3 Entire agreement. These Terms, together with the DPA (pp-dpa.md) and Privacy Policy (pp-privacy-policy.md) incorporated by reference, are the entire agreement between you and Faresay regarding the Service and supersede prior agreements on that subject. This does not exclude liability for fraudulent misrepresentation.

13.4 Severability. If any provision is unenforceable, the remainder stays in effect and the provision is modified to the minimum extent necessary.

13.5 No waiver. A failure to enforce any provision is not a waiver of it.

13.6 Assignment. You may not assign these Terms without our consent. We may assign in connection with a merger, acquisition, or sale of assets, subject to applicable law.

13.7 No partnership/agency. Nothing in these Terms creates any partnership, joint venture, agency, or employment relationship between you and Faresay.

13.8 Force majeure. We are not liable for any failure or delay caused by events beyond our reasonable control.

13.9 Notices. We may give notices by email or through the Service. You may contact us as set out in Section 14.

13.10 Third-party rights. Except as expressly stated, no third party has rights to enforce these Terms under the Contracts (Rights of Third Parties) Act 1999. [PLACEHOLDER: confirm.]


14. Contact

  • Entity: [PLACEHOLDER: registered entity name]
  • Address: [PLACEHOLDER: registered address]
  • Email: [PLACEHOLDER: contact email, e.g. support@ / legal@]

For client emergencies, do not contact us — see Section 1.5 and your own crisis procedures.


End of draft. ⚠️ This document is a v0.1 first draft for UK legal counsel review and is not legal advice. Counsel must finalise before use.

Faresay
Therapy, matched.

Privacy Policy

DRAFT — for professional sign-off Faresay Ltd·25 June 2026

⚠️ DRAFT v0.1 — for professional sign-off by legal/privacy counsel. NOT legal advice. Counsel must finalise before use. Last updated: [PLACEHOLDER: date]

Faresay Privacy Policy (UK)

Faresay is a B2B SaaS practice portal for therapists. We provide software that an independent therapist uses to run their practice — managing their own client list, scheduling and conducting video sessions, taking payments, and keeping notes. Our customer is the therapist.

This Privacy Policy explains how Faresay handles personal data in the situations where Faresay itself is the data controller — principally, the data we hold about therapists (our customers) and website visitors. It also explains, in plain terms, where Faresay is instead a processor acting on a therapist's behalf, and where you should go in that case.

Two data-protection roles — please read Section 1 carefully. For a therapist's own account, billing, usage and support data, Faresay is the controller and this policy applies. For a therapist's clients' data (including mental-health information), Faresay is a processor acting on the therapist's instructions under a Data Processing Agreement — the therapist is the controller of that data, and a client should refer to their therapist's own privacy notice, not this one.

This policy should be read alongside our Security & Data Protection Policy and, for therapists, the Data Processing Agreement and the SaaS subscription terms. Preparatory material — see also the UK Legal Brief.


1. Who we are & our two data-protection roles ⚠️ COUNSEL

Faresay ("Faresay", "we", "us", "our") provides a practice-portal software product to independent, UK-registered mental-health professionals ("therapists", "clinicians", "you" where you are our customer).

  • Controller legal entity: [PLACEHOLDER: registered controller legal name]
  • Registered address: [PLACEHOLDER: registered address]
  • Company registration number: [PLACEHOLDER: company number]
  • ICO registration number: [PLACEHOLDER: ICO registration number]
  • Privacy contact: privacy@faresay.com
  • Data Protection Officer (if/when appointed): [PLACEHOLDER: DPO name and contact] — see Section 12 and the Security & Data Protection Policy

Faresay holds two distinct data-protection roles, and it matters which one applies to a given piece of data:

1.1 Where Faresay is the CONTROLLER (this policy)

Faresay is the controller of the data it processes for its own business purposes — that is, the data about the therapist (our customer) and about visitors to our website. This includes: - therapist account and identity data; - billing and subscription data; - usage and analytics data about how the portal and website are used; - support and communications data; and - marketing data (where applicable).

Sections 3–14 of this policy describe how we handle that controller data.

1.2 Where Faresay is a PROCESSOR (the therapist is the controller)

When a therapist uses the portal to manage their clients — adding clients, holding intake and session information, conducting sessions, recording notes — Faresay processes that client data on the therapist's documented instructions. For that client data:

  • the therapist is the controller;
  • Faresay is a processor, governed by a Data Processing Agreement (DPA) under UK GDPR Article 28 (see pp-dpa.md); and
  • much of that data is special-category mental-health data (UK GDPR Article 9), which we protect to a correspondingly high standard.

If you are a client of a therapist who uses Faresay: this policy is not the right document for you. Faresay does not decide why or how your data is used — your therapist does. Please refer to your therapist's own privacy notice for information about how your data is handled, and contact your therapist to exercise your rights. Faresay will assist your therapist in responding, as required under the DPA.

⚠️ COUNSEL — confirm the controller / processor mapping above, the precise boundary between Faresay's controller data and the therapist's client data, and that the DPA and SaaS terms reflect these roles consistently. Faresay must not be described as the controller of client clinical data.


2. Scope

This policy applies to Faresay's services as offered in the United Kingdom.

  • Faresay's processing of personal data as a controller is governed by the UK GDPR and the Data Protection Act 2018 (DPA 2018), and regulated by the Information Commissioner's Office (ICO).
  • Faresay is registered with the ICO and pays the applicable data-protection fee (see Section 1).

This policy covers our website and the practice-portal application (together, the "Portal") insofar as Faresay acts as controller. It does not govern the therapist's processing of their clients' data (Section 1.2), and it does not cover third-party websites or services we link to, which have their own privacy practices.


3. What data we collect (as controller)

We collect the following categories of personal data about therapists and visitors, for which we are the controller.

3.1 Therapist account & identity data

  • Name, email address, telephone number, username and password (stored hashed) — authentication is provided via Clerk (Section 5).
  • Practice / business name and details (the therapist is typically a sole trader or small business).
  • Professional identity and registration details with a relevant professional body (e.g. BACP, UKCP, NCPS, HCPC, BPS or another PSA-accredited register), and any verification information.
  • Profile and configuration information the therapist provides about their practice.

3.2 Billing & subscription data

  • Subscription plan, billing details and transaction history for the therapist's monthly subscription.
  • Records relating to the small card commission we charge on client→therapist payments processed through the Portal.
  • Payment is processed by a third-party payment provider; we do not store full card numbers on our own systems. [PLACEHOLDER: confirm exactly what billing data Faresay stores vs. the payment processor.]

3.3 Usage & analytics data

  • Pages/screens viewed, features used, and timestamps within the Portal and website.
  • Technical data: IP address, device identifiers, browser type, operating system, and log data.
  • Website analytics via Plausible — a cookieless, privacy-focused analytics tool (see Section 10).

3.4 Support & communications data

  • Messages you send to us (support requests, enquiries) and our responses.
  • Feedback, survey responses, and onboarding correspondence.

3.5 Marketing data (where applicable)

  • Contact details and preferences for product updates and marketing communications, where you have opted in or where we may lawfully contact you.

We collect this information directly from you (the therapist), automatically through use of the Portal and website, and in some cases from third parties (e.g. our authentication, payment and email providers).

Not covered here: a therapist's clients' personal data (intake, session, clinical-note and mental-health information). Faresay processes that only as a processor on the therapist's instructions under the DPA — see Section 1.2.


4. How and why we use your data, with lawful bases (as controller)

The table below summarises our main purposes and the lawful bases we rely on under UK GDPR for the controller data described in Section 3. Note that, as controller, Faresay does not rely on these bases to process clients' special-category data — that processing sits with the therapist as controller.

⚠️ COUNSEL — the lawful bases below are a first draft and must be confirmed.

# Purpose Data used UK GDPR Art 6 basis
1 Create and manage the therapist's account Account/identity Contract (Art 6(1)(b))
2 Provide, operate and support the Portal as a SaaS service Account, usage, support Contract (Art 6(1)(b))
3 Process the subscription and the card commission Billing, account Contract (Art 6(1)(b)) / Legal obligation (tax/accounting)
4 Provide customer support and respond to enquiries Communications, account Contract / Legitimate interests (Art 6(1)(f))
5 Verify professional registration / eligibility to use the Portal Account/identity, verification Legitimate interests / Legal obligation ⚠️ COUNSEL
6 Security, fraud prevention, and protecting the Portal Usage, account Legitimate interests / Legal obligation
7 Product analytics, service improvement (aggregated where possible) Usage (minimised) Legitimate interests
8 Marketing communications (where permitted) Account, marketing Consent / Legitimate interests (with opt-out)
9 Legal compliance, regulatory and dispute handling As needed Legal obligation / Legitimate interests / Art 9(2)(f) for legal claims where relevant

Where we rely on legitimate interests, we balance our interests against your rights and only proceed where appropriate. Where we rely on consent (e.g. some marketing), you can withdraw it at any time without affecting prior processing.


5. How we share your data (as controller)

We share controller personal data only as described below. Each of these providers acts as a processor or sub-processor for Faresay's controller data under a written contract (Article 28 terms), and is also listed in our Security & Data Protection Policy.

Provider Role Used for
Clerk (US) Sub-processor Authentication / identity for therapist accounts
Daily (US) Sub-processor Video session delivery within the Portal
Resend (US) Sub-processor Transactional and account email
Neon (US/EU) Sub-processor Application database / data storage
[PLACEHOLDER: payment provider] Independent processor / controller Payment processing, subscription billing, commission
Plausible Processor Cookieless website analytics

[PLACEHOLDER: maintain a current sub-processor list / link.]

We may also disclose data where necessary to comply with law, respond to lawful requests, enforce our terms, prevent fraud, or protect rights and safety. If Faresay is involved in a merger, acquisition, financing or sale of assets, personal data may be transferred as part of that transaction, subject to appropriate confidentiality and continued protection.

We do not sell your personal information.

For a therapist's clients' data, sharing is governed by the DPA — Faresay shares it only on the therapist's documented instructions and with the sub-processors listed there.

⚠️ COUNSEL — confirm disclosures match actual data flows and that no health-related data is exposed via website analytics or trackers (note: Plausible is cookieless and does not track individuals across sites).


6. International data transfers ⚠️ COUNSEL

Faresay's preferred residency for personal data is UK or EU regions. However, several of our sub-processors are US-based (notably Clerk, Daily and Resend; Neon offers UK/EU regions which we select where available). Where personal data is transferred outside the UK, we put in place an appropriate safeguard, which may include:

  • the UK International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses (SCCs) with the UK Addendum;
  • reliance on an adequacy decision / the UK Extension to the EU–US Data Privacy Framework, where applicable; or
  • other lawful transfer mechanisms,

each supported, where required, by a transfer risk assessment (TRA).

⚠️ COUNSEL — finalise the transfer mechanism for each data flow (Clerk, Daily, Resend, Neon and the payment provider), confirm current adequacy / DPF status, select UK/EU hosting regions where available, and ensure the same mechanisms flow down through the DPA for client data.


7. Data retention ⚠️ COUNSEL

We keep controller personal data only for as long as necessary for the purposes in this policy, and to meet legal, regulatory, accounting and dispute-resolution requirements.

  • Therapist account & identity data: [PLACEHOLDER: retention period — typically while the account is active plus a defined wind-down period]
  • Billing & subscription data: [PLACEHOLDER: retention period, typically driven by tax/accounting law — commonly 6 years]
  • Usage, analytics & log data: [PLACEHOLDER: retention period]
  • Support & communications data: [PLACEHOLDER: retention period]
  • Marketing data: until opt-out / [PLACEHOLDER: period]

When controller data is no longer required, we securely delete or anonymise it.

Retention of a therapist's clients' data is governed by the DPA and the therapist's own clinical-records obligations — Faresay returns or deletes that data on the therapist's instruction or on termination, as the controller directs.

⚠️ COUNSEL — finalise the full retention schedule and reconcile controller retention with the DPA's deletion/return obligations.


8. Security

We implement technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse or alteration, with enhanced controls for the special-category client data we process. These are described in our Security & Data Protection Policy, which this policy incorporates by reference.

No system can be guaranteed 100% secure, but we maintain a security bar appropriate to the sensitivity of the data on the Portal.


9. Your rights (as a therapist / data subject of controller data)

Where Faresay is the controller of your data, and subject to applicable law, you have the right to: - access the personal data we hold about you (a subject access request / DSAR); - request rectification of inaccurate data; - request erasure in certain circumstances; - restrict or object to certain processing; - data portability; - withdraw consent at any time where processing is based on consent; and - not be subject to solely automated decisions with legal/similarly significant effects.

To exercise these rights, contact privacy@faresay.com. We respond within the timeframes required by law — generally within one month (extendable in limited circumstances).

If you are a client of a therapist: to exercise rights over your data, contact your therapist (the controller), not Faresay. Faresay will assist the therapist in responding, as required by the DPA.


10. Cookies & analytics

We aim to keep tracking minimal.

  • Strictly necessary cookies are required for the Portal to function (e.g. authentication/session via Clerk, security).
  • Analytics: we use Plausible, a privacy-focused, cookieless analytics tool. Plausible does not use cookies, does not collect personal data for cross-site tracking, and does not require a consent banner for analytics in the way cookie-based trackers do.
  • We do not use advertising trackers or sell analytics data.

⚠️ COUNSEL — confirm the cookie inventory (including any set by Clerk) and that any non-essential cookies have an appropriate consent mechanism under PECR. [PLACEHOLDER: link to detailed cookie notice if required.]


11. Automated decision-making

Faresay does not make decisions producing legal or similarly significant effects about you based solely on automated processing without human involvement. Clinical decisions are made by the therapist, not by Faresay.

⚠️ COUNSEL — confirm this remains accurate as features evolve.


12. Data breaches

We maintain procedures to detect, investigate and respond to personal-data breaches.

  • For controller data (therapist/visitor), where a breach is likely to result in a risk to rights and freedoms, we notify the ICO without undue delay and, where feasible, within 72 hours (UK GDPR Art 33), and notify affected individuals where there is a high risk (Art 34).
  • For a therapist's client data, where Faresay is the processor, we notify the controller (the therapist) without undue delay so they can meet their own notification obligations.

Our incident-response approach is detailed in the Security & Data Protection Policy.


13. How to complain ⚠️ COUNSEL

If you have a concern about how Faresay handles your controller data, please contact us first at privacy@faresay.com so we can try to resolve it.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) — https://ico.org.uk.

Concerns about how a therapist handles client data should be raised with the therapist (the controller) in the first instance; the client retains their right to complain to the ICO.

If you need urgent help. This policy is about data protection, not crisis support. If you or someone else is in immediate danger, call 999. For mental-health support you can also contact the Samaritans on 116 123, NHS 111, or the SHOUT text service by texting 85258.


14. Contact & updates

Privacy / data-protection contact: privacy@faresay.com — [PLACEHOLDER: postal address] Data Protection Officer (if appointed): [PLACEHOLDER: DPO name and contact]

We may update this Privacy Policy from time to time. We will post the updated version with a revised "Last updated" date and, where changes are material, take additional steps to notify you as required by law.


This is a DRAFT document prepared for professional sign-off by qualified UK legal/privacy counsel. It is not legal advice and must be reviewed and finalised before publication or use. Resolve all [PLACEHOLDER: …] items and ⚠️ flags first.

Faresay
Therapy, matched.

Data Processing Agreement (Art 28)

DRAFT — for professional sign-off Faresay Ltd·25 June 2026

⚠️ DRAFT v0.1 — for UK legal counsel review. NOT legal advice. Counsel must finalise before use. Last updated: [PLACEHOLDER: date]

Faresay Practice Portal — Data Processing Agreement (UK GDPR, Article 28)

This Data Processing Agreement (the "DPA") forms part of, and is incorporated into, the Faresay Practice Portal Subscription Terms of Service (pp-terms-of-service.md) (the "Agreement") between Faresay and the Customer. It sets out the terms on which Faresay processes personal data on the Customer's behalf in connection with the Service, as required by Article 28 of the UK GDPR.

In this DPA:

  • "Controller" means the Customer — the mental-health professional or practice that subscribes to the Service and determines the purposes and means of processing its clients' personal data.
  • "Processor" means Faresay — [PLACEHOLDER: registered entity name], company number [PLACEHOLDER], registered office [PLACEHOLDER] — which processes that personal data on the Controller's behalf.
  • "Client Personal Data" means personal data of the Controller's clients (and other individuals whose data the Controller processes through the Service) that Faresay processes on the Controller's behalf.
  • "Data Protection Law" means the UK GDPR, the Data Protection Act 2018, and any other applicable UK data-protection law, together with guidance and codes issued by the Information Commissioner's Office (ICO).
  • "Sub-processor" means any third party engaged by Faresay to process Client Personal Data.
  • Terms such as "personal data", "processing", "data subject", "controller", "processor", "special category data", and "personal data breach" have the meanings given in the UK GDPR.

Where the Controller and Faresay roles differ for account, billing, and product-usage data (for which Faresay is an independent controller), that processing is governed by the Privacy Policy (pp-privacy-policy.md), not this DPA.

⚠️ COUNSEL / DPO — Confirm the controller/processor mapping, that this DPA is executed before any real Client Personal Data is processed, and that it meets all Article 28(3) requirements. See pp-uk-legal-brief.md.


1. Roles and scope

1.1 The parties agree that, in respect of Client Personal Data, the Controller is the Customer and the Processor is Faresay. Faresay processes Client Personal Data only to provide the Service and only as a processor on the Controller's behalf.

1.2 The Controller is responsible for establishing a lawful basis (and, for special-category data, an Article 9 condition) for the processing, for the lawfulness of its instructions, and for the rights and freedoms of data subjects. Faresay does not determine the purposes or essential means of processing Client Personal Data.

1.3 This DPA applies for as long as Faresay processes Client Personal Data on the Controller's behalf (the "Term"), and survives termination of the Agreement to the extent Faresay retains any Client Personal Data.


2. Details of processing (Article 28(3) and Annex A)

The required particulars are set out in Annex A and summarised here:

2.1 Subject-matter: the provision of the Faresay practice-portal Service to the Controller.

2.2 Duration: the Term (clause 1.3) — for as long as the Controller subscribes and until deletion or return under Section 11.

2.3 Nature and purpose: hosting, storage, organisation, retrieval, transmission, and processing of Client Personal Data to enable the Controller to manage clients, schedule appointments, deliver secure video sessions, take card payments, send reminders/notifications, and keep practice records.

2.4 Types of personal data: including client identity and contact details, appointment and scheduling data, communications/notes the Controller records, billing and payment metadata, and — critically — special-category health data (information relating to the client's mental and physical health and care).

2.5 Categories of data subjects: the Controller's clients (including clients added by the Controller who do not themselves log in, where the Controller asserts a lawful basis on their behalf), and other individuals whose data the Controller chooses to process through the Service (for example client emergency contacts).


3. Processing only on documented instructions

3.1 Faresay will process Client Personal Data only on the documented instructions of the Controller, including with regard to international transfers, unless required to do otherwise by UK law (in which case Faresay will inform the Controller of that legal requirement before processing, unless the law prohibits it on important grounds of public interest).

3.2 The Controller's instructions are: (a) the Agreement and this DPA; (b) the Controller's use and configuration of the Service; and (c) any further written instructions agreed by the parties. Faresay will not use Client Personal Data for its own purposes.

3.3 Faresay will inform the Controller without undue delay if, in its opinion, an instruction infringes Data Protection Law (without obligation to provide legal advice).


4. Confidentiality

4.1 Faresay will ensure that persons authorised to process Client Personal Data are bound by an appropriate duty of confidentiality (contractual or statutory) and process the data only as necessary to perform Faresay's obligations.

4.2 Faresay will limit access to Client Personal Data to personnel who need it to provide the Service, and will ensure they are trained on their data-protection and confidentiality obligations.


5. Security (Article 32)

5.1 Faresay will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking account of the special-category nature of the data, including as appropriate:

  • encryption of Client Personal Data in transit and at rest;
  • measures to ensure ongoing confidentiality, integrity, availability, and resilience of processing systems;
  • the ability to restore availability and access in a timely manner after an incident (backups and recovery);
  • access controls, authentication, logging, and least-privilege principles; and
  • a process for regularly testing and evaluating the effectiveness of these measures.

5.2 The current security measures are described in Annex B and in the Security & Data Protection Policy (pp-security-data-protection-policy.md). Faresay may update them provided the level of security is not materially reduced.

⚠️ COUNSEL — The Article 32 measures for special-category health data are a high bar and non-negotiable. Confirm Annex B reflects the actual implemented controls (encryption, residency, access control, backups, pen-testing) before use.


6. Sub-processors

6.1 General authorisation. The Controller provides general written authorisation for Faresay to engage Sub-processors to process Client Personal Data, subject to this Section. The Sub-processors authorised at the date of this DPA are listed in Annex C:

Sub-processor Purpose Location Transfer mechanism (if outside UK)
Clerk Authentication / identity & account management [PLACEHOLDER: e.g. US] UK IDTA / UK Addendum to SCCs [PLACEHOLDER: confirm]
Daily.co Secure video sessions [PLACEHOLDER: e.g. US] UK IDTA / UK Addendum to SCCs [PLACEHOLDER: confirm]
Resend Transactional email (reminders/notifications) [PLACEHOLDER: e.g. US] UK IDTA / UK Addendum to SCCs [PLACEHOLDER: confirm]
Neon Database hosting (practice/client data) [PLACEHOLDER: confirm EU/UK region] [PLACEHOLDER: confirm region; IDTA only if non-UK]
Stripe Card-payment processing [PLACEHOLDER] [PLACEHOLDER: note Stripe may act as an independent controller for payments — confirm]

⚠️ COUNSEL — Confirm each Sub-processor's processing region and the correct transfer mechanism for any non-UK leg, and confirm Stripe's role (processor vs independent controller for payment data) is correctly characterised and carved out where appropriate.

6.2 Flow-down. Faresay will impose on each Sub-processor, by written contract, data-protection obligations no less protective than those in this DPA, in particular the Article 28(3) and Article 32 requirements. Faresay remains fully liable to the Controller for any Sub-processor's failure to fulfil its data-protection obligations.

6.3 Change notice. Faresay will give the Controller prior notice (at least [PLACEHOLDER: e.g. 14 days']) of any intended addition or replacement of a Sub-processor, giving the Controller the opportunity to object on reasonable data-protection grounds. If the Controller objects and the parties cannot resolve the objection, the Controller may terminate the affected Service in accordance with the Agreement.


7. International transfers

7.1 Faresay will not transfer Client Personal Data outside the United Kingdom except in accordance with the Controller's instructions (clause 3.1) and a valid transfer mechanism under Data Protection Law, namely an adequacy regulation, the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or another lawful mechanism, together with any transfer risk assessment and supplementary measures required.

7.2 Where Faresay engages a non-UK Sub-processor (Annex C), Faresay will ensure an appropriate transfer mechanism is in place for that transfer.

7.3 The Controller authorises the transfers described in Annex C on the basis of the mechanisms stated there, as updated under Section 6.

⚠️ COUNSEL — Confirm the transfer mechanism and any transfer risk assessment for each non-UK Sub-processor (Clerk, Daily.co, Resend, and Neon if non-UK). Prefer UK/EU data residency for Neon where possible.


8. Assistance to the Controller

8.1 Data-subject requests. Taking account of the nature of the processing, Faresay will assist the Controller by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability, objection). If Faresay receives such a request directly from a data subject, it will not respond except on the Controller's instruction, and will promptly notify the Controller.

8.2 Other Article 28(3)(f) assistance. Taking account of the nature of processing and the information available to it, Faresay will assist the Controller in ensuring compliance with its obligations under Articles 32–36 of the UK GDPR, including: security of processing; personal-data breach notification and communication; data protection impact assessments (DPIAs); and prior consultation with, and other queries from, the ICO or any other regulator.

8.3 Faresay may charge a reasonable fee for assistance that goes materially beyond what is required to provide the Service, on prior notice.


9. Personal-data breach notification

9.1 Faresay will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Client Personal Data, and in any event within [PLACEHOLDER: e.g. 48 hours] of becoming aware.

9.2 The notification will, to the extent known, describe: the nature of the breach (including categories and approximate numbers of data subjects and records affected); the likely consequences; the measures taken or proposed to address it and mitigate its effects; and a contact point for further information. Faresay will provide further information in phases as it becomes available.

9.3 The Controller, as controller, is responsible for any notification to the ICO and to affected data subjects required under Articles 33–34 of the UK GDPR. Faresay will provide reasonable assistance (clause 8.2).


10. Audit and records

10.1 Faresay will make available to the Controller all information reasonably necessary to demonstrate compliance with the obligations in Article 28 and this DPA.

10.2 Faresay will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to: reasonable prior notice (at least [PLACEHOLDER: e.g. 30 days] except where required sooner by the ICO); frequency of no more than [PLACEHOLDER: e.g. once per year] except where required by a regulator or following a breach; conduct during business hours, with minimal disruption and appropriate confidentiality; and the Controller bearing its own costs. Faresay may satisfy audit requests by providing current third-party certifications or audit reports (for example SOC 2 / ISO 27001) where these reasonably address the request.

10.3 Faresay will maintain records of processing carried out on behalf of the Controller as required by Article 30(2).


11. Deletion or return on termination

11.1 On termination or expiry of the Agreement, Faresay will, at the Controller's choice, delete or return all Client Personal Data, and delete existing copies, unless UK law requires continued storage.

11.2 The Controller may export its Client Personal Data through the Service during the Term and for [PLACEHOLDER: e.g. 30 days] after termination. After that export window, Faresay will delete Client Personal Data within [PLACEHOLDER: e.g. a further 30 days], subject to clause 11.1.

11.3 Faresay may retain Client Personal Data to the extent, and for the period, required by UK law, and will continue to protect it under this DPA for so long as it is retained.

⚠️ COUNSEL / ⚠️ CLINICAL — The Controller remains responsible for retaining the clinical record for its professional retention period; confirm the export window gives the Controller sufficient time to take its records before deletion.


12. Liability

12.1 Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement (pp-terms-of-service.md, Section 11), except to the extent Data Protection Law requires otherwise.

12.2 Liability as between the parties reflects each party's role: the Controller is responsible for the lawfulness of the processing, its instructions, lawful basis, consent, and data-subject rights; Faresay is responsible for processing in accordance with this DPA and Data Protection Law obligations applicable to processors. Each party will indemnify the other for losses arising from its own breach of this DPA or of Data Protection Law applicable to its role, subject to clause 12.1.

⚠️ COUNSEL — Confirm the per-role liability/indemnity split and its interaction with Article 82 UK GDPR (which can make either party liable to data subjects regardless of contractual allocation) and with the Agreement's liability cap.


13. General

13.1 This DPA forms part of the Agreement. In the event of conflict between this DPA and the rest of the Agreement on a data-protection matter, this DPA prevails. In the event of conflict between this DPA and an applicable Standard Contractual Clauses / IDTA mechanism, that mechanism prevails to the extent of the conflict.

13.2 This DPA is governed by the laws of England & Wales, and the courts of England & Wales have exclusive jurisdiction, consistent with the Agreement.

13.3 Faresay may update this DPA on reasonable notice to reflect changes in Data Protection Law, regulatory guidance, or Sub-processors, provided no update materially reduces the protection of Client Personal Data.


Annex A — Details of processing

  • Controller: the Customer (mental-health professional / practice) — [PLACEHOLDER: captured at onboarding].
  • Processor: Faresay — [PLACEHOLDER: registered entity].
  • Subject-matter: provision of the Faresay practice-portal Service.
  • Duration: the Term (clause 1.3).
  • Nature and purpose: practice management — client records, scheduling, secure video, card payments, reminders/notifications.
  • Types of personal data: identity and contact details; appointment/scheduling data; client communications and notes; billing/payment metadata; special-category health data.
  • Categories of data subjects: the Controller's clients (including non-logging-in clients), and related individuals (e.g. emergency contacts).

⚠️ COUNSEL — Finalise Annex A against the actual data captured in the Service.

Annex B — Technical and organisational security measures (Article 32)

[PLACEHOLDER: summarise the implemented controls — encryption in transit/at rest, data residency, access control and authentication, logging and monitoring, backups and recovery, vulnerability management and penetration testing, personnel training, incident response. Cross-reference pp-security-data-protection-policy.md.]

Annex C — Authorised Sub-processors

As listed in clause 6.1. [PLACEHOLDER: maintain a current, dated Sub-processor list, with purpose, location, and transfer mechanism for each — Clerk, Daily.co, Resend, Neon, Stripe.]


End of draft. ⚠️ This document is a v0.1 first draft for UK legal counsel review and is not legal advice. Counsel must finalise before use.

Faresay
Therapy, matched.

Security & Data Protection Policy

DRAFT — for professional sign-off Faresay Ltd·25 June 2026

⚠️ DRAFT v0.1 — for professional sign-off by security + legal review. NOT legal advice. Must be validated before use. Last updated: [PLACEHOLDER: date]

Faresay UK Security & Data Protection Policy

Faresay is a B2B SaaS practice portal: software that an independent therapist uses to run their practice. Because the Portal handles mental-health information — among the most sensitive categories of personal data that exist — Faresay applies a correspondingly high standard of security and data protection across its people, processes and technology.

This policy sets out the controls Faresay maintains to protect the confidentiality, integrity and availability of the data it processes. It supports Faresay's obligations under the UK GDPR (in particular Article 32 — Security of processing) and the Data Protection Act 2018 (DPA 2018). Client clinical data is special-category health data under Article 9 UK GDPR; Faresay is registered with the Information Commissioner's Office (ICO).

Read alongside the Privacy Policy, the Data Processing Agreement, and the UK Legal Brief. This is an internal operational policy; controller-facing commitments live in the Privacy Policy and the DPA.

⚠️ SECURITY / COUNSEL — overarching honesty note. This is a first draft. Faresay is bootstrapped and early-stage; several controls below describe a target state, not a control that is fully implemented today. Each such item is flagged with ⚠️. Counsel and a security specialist must validate the controller/processor analysis, the UK/EU data-residency and transfer model, the DPO assessment, and all breach-notification obligations before this policy is relied upon. Do not represent target-state controls as live.


1. Purpose & scope

1.1 Purpose

This policy defines how Faresay protects the data it processes, establishes accountability for security and data protection, and demonstrates — for UK GDPR Article 32 — that Faresay implements appropriate technical and organisational measures (TOMs) proportionate to the risk to individuals.

1.2 Scope

This policy applies to: - All Faresay personnel: founders, employees, contractors, and any worker with access to Faresay systems or data. - All Faresay information systems: the practice-portal application, supporting infrastructure, code repositories, administrative tooling, and corporate accounts. - All data Faresay processes — both data for which Faresay is the controller (therapist account, billing, usage, support data) and data for which Faresay is a processor (therapist's client data, including special-category mental-health data). - Sub-processors that process Faresay data on Faresay's behalf (Section 5).

1.3 The controller / processor split ⚠️ COUNSEL

Faresay's customer is the therapist. Faresay holds two roles:

  • Faresay is the CONTROLLER of data about its customer and visitors: therapist account/identity, billing/subscription, usage/analytics, and support data.
  • Faresay is a PROCESSOR of the therapist's clients' data (intake, session, clinical notes, mental-health information). The therapist is the controller of that client data; Faresay processes it only on the therapist's documented instructions under an Article 28 Data Processing Agreement (see pp-dpa.md).

This split determines which obligations in this policy fall on Faresay as controller versus on the therapist as controller (with Faresay assisting as processor). ⚠️ COUNSEL — confirm the mapping; Faresay must not be treated as controller of client clinical data.


2. Data classification

Class Examples Faresay's role Handling baseline
Class 1 — Highest: client mental-health / special-category data The fact a person is a client; intake/assessment; session content; clinical notes; safeguarding/crisis information; messages relating to care. Processor (therapist is controller) Strict least-privilege; encryption in transit and at rest; full audit logging; never in non-production; processor breach regime (notify controller — Section 8).
Class 2 — Confidential Therapist account & identity; authentication data; billing data; professional registration/verification; security configuration. Controller RBAC; encryption in transit and at rest; logged access.
Class 3 — Internal Internal documents, non-sensitive operational data. Controller Access limited to personnel; standard controls.
Class 4 — Public Marketing pages; therapist profile data the therapist agrees to publish. Mixed Integrity controls; no confidentiality requirement.

Notes: - Even the bare fact that an individual is a client of a therapist on Faresay is Class 1 special-category data. - For Class 1 data, the therapist (controller) sets the lawful basis and permitted uses; Faresay processes only on documented instructions under the DPA. - Payment card data: Faresay uses a PCI-DSS-compliant payment processor so Faresay does not store raw card data. [PLACEHOLDER: payment processor]. ⚠️ SECURITY — confirm cardholder-data flows and PCI scope.


3. Governance, roles & responsibilities

3.1 Accountability

Faresay's leadership (founder/management) is ultimately accountable for information security and data protection and for approving this policy.

3.2 Key roles

  • Security Lead — [PLACEHOLDER: named individual]. Owns this policy, risk treatment, vendor security review, incident response, and the security roadmap. In an early-stage bootstrapped company this is initially a founder; ⚠️ SECURITY — confirm whether a fractional/virtual CISO or external advisor is engaged.
  • Data Protection point of contact — [PLACEHOLDER: named individual]. Owns DPIAs, records of processing (UK GDPR Art 30), data-subject-rights assistance, and the ICO relationship.
  • All personnel — follow this policy, complete training, report incidents promptly, protect credentials and devices.

3.3 DPO assessment ⚠️ COUNSEL

Faresay processes special-category health data on a large scale as a processor. This is a strong trigger for the mandatory appointment of a Data Protection Officer (DPO) under UK GDPR Article 37(1)(c), which can apply to processors as well as controllers where core activities consist of large-scale special-category processing.

  • ⚠️ COUNSEL — formally assess whether a statutory DPO is required. Given Faresay's core activity is processing therapists' clients' mental-health data at scale, the assessment is likely to conclude a DPO is required.
  • If required: appoint a DPO, document the appointment and their independence, publish their contact details, and notify the ICO. ⚠️ — target state; not yet appointed.
  • Record the assessment and its outcome whatever the conclusion (accountability under Art 5(2)).

3.4 Review

Security risks are tracked in the risk register. Material decisions, exceptions and accepted risks are recorded with an owner and review date.


4. Article 32 technical & organisational measures

This section sets out Faresay's TOMs for UK GDPR Article 32. It is a planning aid, not a confirmation of compliance. ⚠️ items are target-state.

4.1 Access control (Art 32(1)(b))

  • Least privilege — minimum access for the role; admin access is the exception, justified and time-bound.
  • RBAC — access granted by role wherever the platform supports it.
  • Need-to-know for Class 1 — access to client mental-health data restricted to roles with genuine operational need and logged.
  • MFA required for all administrative and production access, code repositories (GitHub), the hosting/database provider (Neon), authentication provider (Clerk), DNS, and email.
  • Separation of duties — production access, deployment rights and security administration separated where headcount allows. ⚠️ SECURITY — document compensating controls given small team size.
  • Joiner/mover/leaver — access provisioned by role on a documented request; reviewed on role change; revoked promptly on departure (target: same business day; immediately for involuntary departures); periodic access reviews ([PLACEHOLDER: quarterly]). ⚠️ — target state.

4.2 Encryption (Art 32(1)(a))

  • In transitTLS 1.2+/1.3 enforced for all connections; HTTP→HTTPS redirect; HSTS. Edge/TLS via [PLACEHOLDER: Vercel/Cloudflare]; backend, API and database connections (Neon) also encrypted.
  • At rest — Class 1 and Class 2 data encrypted at rest with strong, industry-standard algorithms (e.g. AES-256) via the database/storage provider (Neon); backups encrypted at rest.
  • Key management — API keys, database credentials and secrets held in a platform secrets/environment-variable store, never committed to source control; access restricted and logged; rotation on a defined schedule and on suspected compromise. ⚠️ SECURITY — define rotation cadence and ownership.

4.3 Confidentiality, integrity, availability & resilience (Art 32(1)(b)–(c))

  • Access control, RBAC, MFA — Section 4.1.
  • Audit logging — access to and changes affecting Class 1 and Class 2 data logged with identity, timestamp and action (accountability, Art 5(2)). ⚠️ SECURITY — confirm logging covers reads of client data, not just writes.
  • No sensitive data in logs — Class 1 content and secrets must never be written to application logs.
  • Backups & DR — regular encrypted backups with restore testing; defined RPO/RTO [PLACEHOLDER]; documented recovery procedure. ⚠️ — target state for formal RPO/RTO and restore testing.

4.4 Data residency (Art 32 + transfers)

  • Preferred residency: UK or EU regions for all personal data, especially Class 1. Neon offers UK/EU regions — these must be selected and verified for the production database.
  • US sub-processors — Clerk, Daily and Resend are US-based; transfers handled per Section 5.2.
  • ⚠️ SECURITY — maintain a data-flow map showing where each data class is stored, processed and transmitted, including sub-processor location and the transfer mechanism relied on.

4.5 Secure development & testing (Art 32(1)(d))

  • Secure-by-design; DPIA completed for the large-scale special-category processing (Art 35) — ⚠️ COUNSEL, target state.
  • Code in version control (GitHub); changes via peer-reviewed pull requests; protected main branch; secret scanning; dependency scanning (Dependabot/equivalent); OWASP Top 10 protections; environment separation with no production Class 1 data in non-production.
  • ⚠️ SECURITY — formalise SAST/DAST and independent penetration testing as the team matures.

5. Sub-processors & Article 28 terms ⚠️ COUNSEL

5.1 Sub-processor register

Faresay maintains a register of all sub-processors, the data classes they handle, and their locations. [PLACEHOLDER: link.]

Sub-processor Location Purpose Data class
Clerk US Authentication / identity for therapist accounts Class 2 (therapist account)
Daily US Video session delivery Class 1 (client session, in transit)
Resend US Transactional / account email Class 2 (therapist), incidental Class 1
Neon US / EU (select EU/UK region) Application database & storage Class 1 & Class 2
[PLACEHOLDER: payment provider] [PLACEHOLDER] Subscription billing + card commission Class 2 (billing)

5.2 Article 28 DPAs and transfer mechanisms ⚠️ COUNSEL

  • A Data Processing Agreement compliant with UK GDPR Article 28 is required with every sub-processor that handles personal data, including the Art 28(3) terms: processing only on documented instructions, confidentiality, Art 32 security, sub-processor controls and flow-down, assistance with data-subject rights and breaches, and deletion/return of data on termination.
  • These terms must flow down from the DPA Faresay signs with each therapist (Faresay as processor) to each sub-processor (Faresay's sub-processors) — see pp-dpa.md.
  • For non-UK sub-processors (Clerk, Daily, Resend, and Neon where a non-UK/EU region is used), a UK transfer mechanism — IDTA, or SCCs with the UK Addendum, plus a transfer risk assessment — is required in addition to the DPA before any personal data is shared.
  • ⚠️ SECURITY / COUNSEL — confirm a signed DPA and a valid transfer mechanism are in place for each provider before transmitting Class 1/Class 2 data. Do not transmit Class 1 data to any provider without both. ⚠️ — several of these are target state today.

6. Logging, monitoring & vulnerability management

  • Audit & monitoring — infrastructure, authentication and application logs collected and reviewed; alerting on suspicious activity (failed-login spikes, privilege changes). [PLACEHOLDER: tooling]. ⚠️ — target state for centralised monitoring/alerting.
  • Log retention — [PLACEHOLDER: period, aligned with storage-limitation and ICO guidance]. ⚠️ COUNSEL.
  • Patch management — OS, dependencies and platform components kept current; critical vulnerabilities remediated on an SLA (target: [PLACEHOLDER: critical within 7 days]).
  • Penetration testing — independent test before scaled launch and at least annually / on major change. [PLACEHOLDER: provider/cadence]. ⚠️ SECURITY — not yet performed.
  • Coordinated disclosure — vulnerability reporting channel ([PLACEHOLDER: security@faresay.com]) and triage process.

7. Personnel & physical security

  • Background checks — pre-engagement screening proportionate to role and access to Class 1 data, subject to UK law (e.g. DBS where appropriate). ⚠️ COUNSEL — confirm lawful basis and limits.
  • Confidentiality agreements — all personnel with access to Class 1/Class 2 data sign confidentiality / NDA terms.
  • Training — security and data-protection training at onboarding and at least annually (phishing, UK GDPR fundamentals, handling mental-health data). ⚠️ — target state for formal annual programme.
  • Endpoint security — full-disk encryption, screen lock, current OS/security updates, reputable endpoint protection; lost/stolen devices reported immediately.
  • Remote-first — Faresay relies on cloud-hosted infrastructure; physical data-centre security is inherited from providers (Neon, and the hosting/edge provider) and evidenced via their certifications (SOC 2 / ISO 27001).
  • Acceptable use — systems used only for authorised purposes; no credential sharing; no exporting Class 1 data outside approved systems; no use of unapproved tools (including AI/LLM tools) on Class 1/Class 2 data without authorisation. ⚠️ SECURITY — define an approved-tools list.

8. Incident response & breach notification ⚠️ COUNSEL

8.1 Incident response

  • Documented process: detection, triage, containment, eradication, recovery, notification, post-incident review. ⚠️ — target state for the fully documented runbook.
  • All personnel must report suspected incidents immediately to the Security Lead. [PLACEHOLDER: channel.]
  • Incidents are logged and assessed for severity and for whether a notifiable personal-data breach has occurred.

8.2 Breach notification — role-dependent

The notification path depends on Faresay's role for the affected data:

  • Faresay's own controller data (therapist account, billing, usage, support): where a breach is likely to result in a risk to rights and freedoms, Faresay notifies the ICO without undue delay and, where feasible, within 72 hours (UK GDPR Art 33), and notifies affected individuals where there is a high risk (Art 34).
  • Therapist's client data (Faresay as processor): Faresay notifies the controller — the therapist — without undue delay after becoming aware (UK GDPR Art 33(2)), with the information the therapist needs to meet their ICO and data-subject obligations. Faresay does not notify the ICO directly for client data; that is the therapist-controller's duty, which Faresay assists.

A record of all personal-data breaches (facts, effects, remedial action) is maintained whether or not notified.

⚠️ COUNSEL — confirm the notification routing above, the contractual timelines for processor→controller notification in the DPA, and the contact details/escalation path.


9. Data retention, minimisation & secure disposal

  • Minimisation — Faresay collects and retains only the data necessary for the purposes in the Privacy Policy and the DPA.
  • Controller data retained per a defined retention schedule (Privacy Policy Section 7). [PLACEHOLDER: schedule.]
  • Client (processor) data retained only as long as the therapist (controller) instructs; returned or deleted on the controller's instruction or on termination, per the DPA.
  • Secure disposal — data securely deleted/anonymised at end of retention; providers' certified-destruction processes relied upon; backups age out per backup retention policy.
  • ⚠️ COUNSEL / CLINICAL — reconcile retention with UK GDPR storage limitation (Art 5(1)(e)) and the therapist's clinical-records retention rules, which differ.

10. Alignment to a recognised framework (future goal)

As a bootstrapped, early-stage company, formal certification is a future goal, not a current state. Candidate frameworks: - Cyber Essentials / Cyber Essentials Plus — UK government-backed baseline; pragmatic early target. - ISO/IEC 27001 — recognised ISMS certification; strong signal for UK healthtech and therapist trust. - SOC 2 (Type II) — where partner due diligence demands it.

⚠️ SECURITY — agree the target framework and a realistic roadmap (likely Cyber Essentials early, ISO 27001 as the company scales).


11. Policy review

  • Reviewed at least annually and after any major change to systems, processing, regulation, or following a significant incident.
  • The Security Lead owns the review; the Data Protection point of contact and counsel review data-protection aspects.
Version Date Author Notes
v0.1 (DRAFT) [PLACEHOLDER: date] [PLACEHOLDER: author] Initial practice-portal draft (controller/processor split) for security + legal sign-off.

End of draft. ⚠️ This v0.1 draft must be validated by qualified security and legal professionals, with all [PLACEHOLDER: …] items resolved and ⚠️ target-state controls either implemented or honestly disclosed, before it is relied upon or published. Not legal advice.

Faresay
Therapy, matched.

Clinical Governance Policy

DRAFT — for professional sign-off Faresay Ltd·25 June 2026

⚠️ DRAFT v0.1 (Practice Portal) — for clinical advisor + UK legal review. NOT clinical or legal advice. Must be validated by a UK-qualified clinical lead (⚠️ CLINICAL) and counsel (⚠️ COUNSEL) before use. Last updated: [PLACEHOLDER: date]

Faresay Practice Portal — Clinical Governance Position

Read the pivot first. Faresay is now B2B SaaS software (a practice portal sold to therapists), not a care marketplace. See pp-uk-legal-brief.md and model-comparison.md. Under this model the therapist is the provider, the data controller, and holds clinical responsibility for their own clients. Faresay does not provide care, does not direct clinical decisions, and does not control the clinical relationship. This document is therefore deliberately short: it defines Faresay's narrow role and the clinical-governance responsibilities therapists must carry as a condition of using the software.

This document replaces the marketplace Clinical Governance Policy (uk-clinical-governance-policy.md) for the practice-portal direction. The marketplace version remains relevant only for a possible future "find clients" add-on, which would re-open provider/intermediary questions (see pp-uk-legal-brief.md §9).


1. The boundary that must not be crossed

1.1 Faresay supplies software tools to independent, registered mental-health professionals so they can run their own practice (scheduling, video, messaging, records storage, payments). The therapist delivers the clinical service, owns the clinical relationship, exercises clinical judgement, and holds the clinical record.

1.2 Faresay must stay "software, not provider." Faresay does not, and must not appear to: - provide, arrange, or coordinate clinical care; - make or direct clinical decisions about any individual client; - set treatment standards, override clinical judgement, or supervise therapists clinically; - control or own the clinical relationship or the clinical record.

⚠️ COUNSEL — This boundary is load-bearing. If Faresay is treated in substance or appearance as the provider or controller of clinical care, it risks: (a) being pulled into CQC regulated-activity registration; (b) acquiring a clinical duty of care and crisis/safeguarding liability; and (c) losing its clean processor characterisation under UK GDPR. Counsel must review this document and the product to confirm nothing makes Faresay the provider or controller of care rather than a tool one step removed. See pp-uk-legal-brief.md §5–§6.

1.3 ⚠️ CLINICAL — Even as a software vendor, Faresay should take an advisor's view (via a qualified clinical/safeguarding advisor) on whether the product's design creates foreseeable clinical risk (e.g. how crisis signposting and records are handled). That advisory input does not make Faresay the clinical provider; it is product-safety diligence.


2. Faresay's limited role

Faresay's clinical-governance footprint is confined to three things:

2.1 Provide the software

2.1.1 Faresay provides and maintains the portal tooling to an appropriate security standard (UK GDPR Art 32; see pp-uk-legal-brief.md and the Security & Data Protection Policy). Faresay processes client data only on the therapist's documented instructions as a processor under an Article 28 DPA. Faresay does not hold or control the clinical record; the therapist does.

2.2 Verify professional registration

2.2.1 As a condition of access, Faresay verifies that each therapist holds a current, valid, unrestricted registration or accredited-register membership with a relevant UK professional body — e.g. HCPC (practitioner psychologists), or a PSA-accredited register such as BACP, UKCP, or NCPS/NCS (counsellors/psychotherapists), as applicable.

2.2.2 Verification is a gate to using the software, not a clinical assessment of fitness to treat any particular client. Faresay records the registering body, registration/membership number, type and standing, and issue/expiry dates, and re-checks standing on a defined cadence. [PLACEHOLDER: verification method and cadence — e.g. primary-source check against the regulator/register, at onboarding and at least annually.]

⚠️ COUNSEL / ⚠️ CLINICAL — "Therapist"/"counsellor" are not statutorily protected titles in the UK. Confirm the minimum acceptable registers/accreditations, whether unaccredited counsellors are admitted, and what (if any) identity/DBS checks are appropriate for a software customer (lighter than a marketplace supplier — Faresay is not placing this person with clients). Confirm this verification does not imply Faresay vouches for clinical quality in a way that creates a duty of care.

2.3 Stay out of clinical care

2.3.1 Faresay does not screen clients, does not assess suitability, does not make referral or crisis decisions, and does not direct treatment. Those are the therapist's responsibilities (Section 3) and, for crisis/safeguarding, are governed by pp-crisis-safeguarding-policy.md.


3. Therapist responsibilities (condition of use)

As a term of using the Faresay practice portal, each therapist warrants that they — as the provider, controller, and clinically responsible professional for their own clients — maintain the following. These obligations sit in the B2B SaaS subscription agreement and DPA (see pp-uk-legal-brief.md §2, §4).

3.1 Own clinical governance

3.1.1 The therapist is responsible for the quality, safety, and ethics of their own clinical service, and for compliance with the standards of their professional body. Faresay sets no clinical standard above the therapist's own professional obligations.

3.2 Supervision and CPD

3.2.1 The therapist maintains clinical supervision and continuing professional development as required by their professional body, and can evidence this. Faresay does not supervise and is not the therapist's clinical supervisor.

3.3 Scope of practice

3.3.1 The therapist works only within their competence, training, and registration/accreditation, and only with client populations and presentations they are competent to treat — referring or signposting elsewhere where a client's needs fall outside their scope or outside what can be safely delivered remotely. ⚠️ CLINICAL — confirm any product-side prompts that help (but do not direct) the therapist here.

3.4.1 The therapist obtains and documents the client's informed consent to treatment, including the limits of remote delivery, confidentiality and its limits (safeguarding disclosures), how records are kept, fees, and what to do in a crisis (see pp-crisis-safeguarding-policy.md). Consent to clinical treatment (the therapist's responsibility) is distinct from any consent/lawful basis for data processing, which the therapist (as controller) is responsible for and which the DPA supports.

3.5 Record-keeping standards

3.5.1 The therapist is the controller and custodian of the clinical record. They keep records that are accurate, contemporaneous, adequate, secure, and retained for the period required by their professional body and UK law, then securely disposed of. Faresay's storage tooling is a processor service operated on the therapist's instructions; it does not transfer record ownership or responsibility to Faresay. [PLACEHOLDER: retention periods — set by the therapist per their discipline; confirm what the product stores and under what DPA terms.] ⚠️ COUNSEL.

3.6 Professional-body compliance and indemnity

3.6.1 The therapist remains bound by, and complies with, the ethical and practice standards of the body that registers/accredits them (BACP / UKCP / NCS / BPS / HCPC, as applicable), including standards for remote delivery, and holds their own professional indemnity insurance appropriate to their practice. Where this document and a therapist's professional standards ever appear to conflict, the therapist follows their professional and legal obligations.

3.7 Crisis and safeguarding

3.7.1 The therapist owns crisis management and safeguarding for their own clients. This is governed by pp-crisis-safeguarding-policy.md, which forms part of these terms.


4. Roles at a glance

⚠️ CLINICAL / ⚠️ COUNSEL — Indicative; confirm the split keeps Faresay as a tool, not a provider/controller of care.

Area Therapist (provider / controller) Faresay (software vendor / processor)
Clinical decisions for clients Owns / accountable None
Clinical standards, supervision, CPD Owns / maintains None (does not supervise)
Scope of practice / suitability Owns May provide neutral product prompts only
Informed consent Obtains & documents Provides tooling
Clinical record Owns / controls / retains Provides secure storage (processor)
Professional-body compliance & indemnity Owns Verifies registration as access gate
Crisis & safeguarding Owns (see pp-crisis-safeguarding-policy.md) Signposting + lawful data-sharing mechanism only
Software security & availability Uses securely Owns (Art 32)

  • pp-uk-legal-brief.md — practice-portal legal brief (processor role, DPA, liability shift).
  • pp-crisis-safeguarding-policy.md — crisis & safeguarding (therapist-owned; Faresay limited role).
  • model-comparison.md · therapist-portal-pivot.md · pp-risk-register.md.
  • B2B SaaS subscription agreement + Article 28 DPA (the instruments that bind therapists to Sections 2–3). [PLACEHOLDER: links once drafted.]
  • uk-clinical-governance-policy.md — superseded marketplace version (retain for possible future "find clients" add-on only).

End of DRAFT v0.1 (Practice Portal). ⚠️ Validate with a UK-qualified clinical lead and counsel before use. Do not let any clause make Faresay the provider or controller of clinical care.

Faresay
Therapy, matched.

Crisis & Safeguarding Policy

DRAFT — for professional sign-off Faresay Ltd·25 June 2026

⚠️ DRAFT v0.1 (Practice Portal) — for clinical/safeguarding advisor + UK legal review. NOT clinical or legal advice. Must be validated by a qualified clinical/safeguarding lead (⚠️ CLINICAL) and counsel (⚠️ COUNSEL) before use. Last updated: [PLACEHOLDER: date]

Faresay Practice Portal — Crisis & Safeguarding Position

Read the pivot first. Faresay is now B2B SaaS software sold to therapists, not a care marketplace. See pp-uk-legal-brief.md. Under this model the therapist is the provider and the data controller, and therefore owns crisis management and safeguarding for their own clients. Faresay's role is narrow: it is not a crisis service, it surfaces UK crisis signposting in the product, it provides a lawful mechanism for emergency data-sharing, and it requires therapists to hold their own crisis and safeguarding protocols as a term of use.

This document replaces the marketplace Crisis & Safeguarding Policy (uk-crisis-safeguarding-policy.md) for the practice-portal direction. It applies to Faresay's UK operations and assumes an adults-only therapist client base. Where it and another Faresay document conflict on a safety-critical point, the more protective interpretation applies pending resolution.

⚠️ CLINICAL — Structural first draft. Faresay does not set clinical thresholds; therapists do, within their own protocols and professional standards. The product-side items (signposting wording, data-sharing mechanism) must still be reviewed by a qualified clinical/safeguarding advisor and counsel before operational use.


1. Where responsibility sits

1.1 The therapist owns crisis and safeguarding. As the provider, controller, and clinically responsible professional for their own clients, the therapist is responsible for identifying, assessing, responding to, escalating, documenting, and learning from any risk to a client's safety or the safety of others. Nothing in this document transfers clinical or safeguarding responsibility for any client to Faresay or makes Faresay a healthcare or crisis provider.

1.2 UK frameworks apply to the therapist, not Faresay. Statutory and professional safeguarding, public-interest-disclosure, and reporting duties — for example under the Children Act 1989 / 2004 and Working Together to Safeguard Children (and devolved equivalents), the Care Act 2014 (England) / Adult Support and Protection (Scotland) Act 2007 / Social Services and Well-being (Wales) Act 2014 and the Northern Ireland adult-safeguarding framework, together with the therapist's professional-body guidance (BACP / UKCP / NCS / BPS / HCPC) — fall on the therapist as the provider. ⚠️ COUNSEL / ⚠️ CLINICAL — confirm framework applicability per UK nation and that Faresay-as-software carries no provider-level safeguarding duty.

1.3 Faresay is software, not a provider. Faresay does not screen clients, does not assess risk, does not make crisis or referral decisions, and does not supervise the therapist's clinical judgement. Its role is limited to Sections 2–4. ⚠️ COUNSEL — confirm this preserves Faresay's processor characterisation and keeps it outside CQC regulated activity (see pp-uk-legal-brief.md §5–§6).


2. Faresay is not a crisis service

2.1 Core statement. Faresay and the portal are not an emergency service, crisis line, or suicide-prevention service. Communications through the portal are not monitored in real time for emergencies. The product is for non-urgent, scheduled use by a therapist and their clients.

2.2 How it is surfaced. This message, and the crisis signposting in Section 3, should appear clearly in the product — at minimum in client-facing surfaces (e.g. a standing message in the client interface) and in the platform notice the end-client sees. The therapist also reinforces it as part of their own informed-consent and contracting with the client (see pp-clinical-governance-policy.md §3.4). ⚠️ CLINICAL / ⚠️ COUNSEL — confirm placement and wording, and keep it synchronised with the SaaS platform notice / terms.

2.3 What this does not do. The "not a crisis service" statement governs expectations of the software's availability and monitoring. It does not switch off the therapist's professional duty of care during an active treatment relationship, nor their safeguarding and disclosure duties.


3. UK crisis signposting in the product

3.1 The portal displays standard UK crisis resources in the surfaces described in §2.2. ⚠️ COUNSEL / ⚠️ CLINICAL — verify and keep synchronised with the platform notice/terms:

United Kingdom - 999 — for any life-threatening emergency. - NHS 111 — for urgent (non-life-threatening) NHS help, including the NHS 111 urgent mental health option in many areas. - Samaritans — free on 116 123 (24 hours a day). - SHOUT — free 24/7 crisis text support: text 85258. - [PLACEHOLDER: nation/region-specific urgent mental health lines, confirmed before publication.]

3.2 If a client is outside the UK, they should be directed to local emergency services. ⚠️ CLINICAL — the therapist decides whom they can lawfully treat and where; signposting is generic.


4. Emergency data-sharing mechanism

4.1 In a life-at-risk emergency, the therapist (as controller), or Faresay acting on the therapist's instruction, may need to share limited personal data (e.g. identity, contact details, location if held, nature of risk) with emergency services or relevant authorities without prior consent to protect the vital interests of the client or another person.

4.2 Faresay provides the mechanism and lawful basis support for this — i.e. the product allows the necessary minimum data to be retrieved/shared, and the DPA and Privacy/Security policies reflect the carve-out. Faresay does not decide when to invoke it; that is the therapist's clinical and lawful judgement.

⚠️ COUNSEL — Confirm the lawful basis for emergency sharing (UK GDPR vital-interests / substantial-public-interest / legal-obligation conditions for special-category data), the minimum-necessary principle, logging/auditability, and how the carve-out reads against the DPA, Privacy Policy, and Security & Data Protection Policy. Confirm any precise-location capture is justified and assessed in the DPIA.


5. Therapist must hold their own crisis & safeguarding protocols (condition of use)

5.1 As a term of using the portal, each therapist warrants that they maintain and follow their own crisis and safeguarding protocols, appropriate to their practice and professional standards, including: - (a) risk screening at intake and ongoing reassessment of suicidality, self-harm, risk to others, domestic abuse, child and adult-at-risk safeguarding, and other acute presentations; - (b) an escalation pathway for imminent, elevated, and lower-level risk, including directing clients to emergency services (§3) and contacting authorities where their duties and lawful basis permit; - (c) confidentiality and public-interest-disclosure judgement (the UK has no statutory "duty to warn"; disclosure is permissive and proportionate) and safeguarding-referral routes to local-authority children's services / adult social care per the client's UK nation; - (d) suitability/exclusion judgement — declining or referring on presentations unsuitable for remote, non-real-time delivery, handled to avoid clinical abandonment; - (e) contemporaneous documentation of risk, decisions, disclosures, and actions in the clinical record they own; and - (f) their own professional indemnity insurance and CPD/competence in risk management.

⚠️ CLINICAL / ⚠️ COUNSEL — Faresay does not author these protocols or set the thresholds; it requires that the therapist has them. Confirm the contractual warranty wording (SaaS agreement) and whether Faresay should provide a non-binding reference template without thereby appearing to direct care.


6. Faresay's limited supporting role

6.1 Faresay does not provide clinical care, does not supervise therapists' clinical judgement, and is not a substitute for emergency services. If the platform itself were ever to surface a risk signal (e.g. a product feature flags content), Faresay's response is a non-clinical, product-safety/governance one — routing to the therapist and to its own legal/notification obligations — not a clinical intervention. ⚠️ CLINICAL / ⚠️ COUNSEL — any automated detection on sensitive mental-health content carries clinical, false-positive/negative, privacy, and liability risk and must be confirmed before building; default position is no real-time monitoring (§2.1).

6.2 Faresay may keep a minimal, secure governance log of any incident reported to it (for its own legal/learning obligations), distinct from the therapist's clinical record, consistent with the controller/processor split. ⚠️ COUNSEL — confirm what Faresay records vs the therapist, access controls, and retention.


7. Review

7.1 Reviewed at least annually, and after any material change in UK law or professional guidance. Crisis resources kept synchronised with the platform notice/terms. Owner: [PLACEHOLDER]. Next review: [PLACEHOLDER: date].


  • pp-uk-legal-brief.md — practice-portal legal brief (processor role, liability shift to therapist, emergency data-sharing).
  • pp-clinical-governance-policy.md — Faresay's limited role + therapist clinical-governance responsibilities.
  • model-comparison.md · therapist-portal-pivot.md · pp-risk-register.md.
  • B2B SaaS subscription agreement + Article 28 DPA (bind the therapist to Section 5). [PLACEHOLDER: links once drafted.]
  • uk-crisis-safeguarding-policy.md — superseded marketplace version (retain for possible future "find clients" add-on only).

End of DRAFT v0.1 (Practice Portal). ⚠️ Not for operational use. Validate with a qualified clinical/safeguarding lead and counsel. Do not let any clause make Faresay the provider or controller of crisis/safeguarding care.