Faresay
Therapy, matched.

Security & Data Protection Policy

DRAFT — for professional sign-off Faresay Ltd·25 June 2026

⚠️ DRAFT v0.1 — for professional sign-off by security + legal review. NOT legal advice. Must be validated before use. Last updated: [PLACEHOLDER: date]

Faresay UK Security & Data Protection Policy

Faresay is a B2B SaaS practice portal: software that an independent therapist uses to run their practice. Because the Portal handles mental-health information — among the most sensitive categories of personal data that exist — Faresay applies a correspondingly high standard of security and data protection across its people, processes and technology.

This policy sets out the controls Faresay maintains to protect the confidentiality, integrity and availability of the data it processes. It supports Faresay's obligations under the UK GDPR (in particular Article 32 — Security of processing) and the Data Protection Act 2018 (DPA 2018). Client clinical data is special-category health data under Article 9 UK GDPR; Faresay is registered with the Information Commissioner's Office (ICO).

Read alongside the Privacy Policy, the Data Processing Agreement, and the UK Legal Brief. This is an internal operational policy; controller-facing commitments live in the Privacy Policy and the DPA.

⚠️ SECURITY / COUNSEL — overarching honesty note. This is a first draft. Faresay is bootstrapped and early-stage; several controls below describe a target state, not a control that is fully implemented today. Each such item is flagged with ⚠️. Counsel and a security specialist must validate the controller/processor analysis, the UK/EU data-residency and transfer model, the DPO assessment, and all breach-notification obligations before this policy is relied upon. Do not represent target-state controls as live.


1. Purpose & scope

1.1 Purpose

This policy defines how Faresay protects the data it processes, establishes accountability for security and data protection, and demonstrates — for UK GDPR Article 32 — that Faresay implements appropriate technical and organisational measures (TOMs) proportionate to the risk to individuals.

1.2 Scope

This policy applies to: - All Faresay personnel: founders, employees, contractors, and any worker with access to Faresay systems or data. - All Faresay information systems: the practice-portal application, supporting infrastructure, code repositories, administrative tooling, and corporate accounts. - All data Faresay processes — both data for which Faresay is the controller (therapist account, billing, usage, support data) and data for which Faresay is a processor (therapist's client data, including special-category mental-health data). - Sub-processors that process Faresay data on Faresay's behalf (Section 5).

1.3 The controller / processor split ⚠️ COUNSEL

Faresay's customer is the therapist. Faresay holds two roles:

This split determines which obligations in this policy fall on Faresay as controller versus on the therapist as controller (with Faresay assisting as processor). ⚠️ COUNSEL — confirm the mapping; Faresay must not be treated as controller of client clinical data.


2. Data classification

Class Examples Faresay's role Handling baseline
Class 1 — Highest: client mental-health / special-category data The fact a person is a client; intake/assessment; session content; clinical notes; safeguarding/crisis information; messages relating to care. Processor (therapist is controller) Strict least-privilege; encryption in transit and at rest; full audit logging; never in non-production; processor breach regime (notify controller — Section 8).
Class 2 — Confidential Therapist account & identity; authentication data; billing data; professional registration/verification; security configuration. Controller RBAC; encryption in transit and at rest; logged access.
Class 3 — Internal Internal documents, non-sensitive operational data. Controller Access limited to personnel; standard controls.
Class 4 — Public Marketing pages; therapist profile data the therapist agrees to publish. Mixed Integrity controls; no confidentiality requirement.

Notes: - Even the bare fact that an individual is a client of a therapist on Faresay is Class 1 special-category data. - For Class 1 data, the therapist (controller) sets the lawful basis and permitted uses; Faresay processes only on documented instructions under the DPA. - Payment card data: Faresay uses a PCI-DSS-compliant payment processor so Faresay does not store raw card data. [PLACEHOLDER: payment processor]. ⚠️ SECURITY — confirm cardholder-data flows and PCI scope.


3. Governance, roles & responsibilities

3.1 Accountability

Faresay's leadership (founder/management) is ultimately accountable for information security and data protection and for approving this policy.

3.2 Key roles

3.3 DPO assessment ⚠️ COUNSEL

Faresay processes special-category health data on a large scale as a processor. This is a strong trigger for the mandatory appointment of a Data Protection Officer (DPO) under UK GDPR Article 37(1)(c), which can apply to processors as well as controllers where core activities consist of large-scale special-category processing.

3.4 Review

Security risks are tracked in the risk register. Material decisions, exceptions and accepted risks are recorded with an owner and review date.


4. Article 32 technical & organisational measures

This section sets out Faresay's TOMs for UK GDPR Article 32. It is a planning aid, not a confirmation of compliance. ⚠️ items are target-state.

4.1 Access control (Art 32(1)(b))

4.2 Encryption (Art 32(1)(a))

4.3 Confidentiality, integrity, availability & resilience (Art 32(1)(b)–(c))

4.4 Data residency (Art 32 + transfers)

4.5 Secure development & testing (Art 32(1)(d))


5. Sub-processors & Article 28 terms ⚠️ COUNSEL

5.1 Sub-processor register

Faresay maintains a register of all sub-processors, the data classes they handle, and their locations. [PLACEHOLDER: link.]

Sub-processor Location Purpose Data class
Clerk US Authentication / identity for therapist accounts Class 2 (therapist account)
Daily US Video session delivery Class 1 (client session, in transit)
Resend US Transactional / account email Class 2 (therapist), incidental Class 1
Neon US / EU (select EU/UK region) Application database & storage Class 1 & Class 2
[PLACEHOLDER: payment provider] [PLACEHOLDER] Subscription billing + card commission Class 2 (billing)

5.2 Article 28 DPAs and transfer mechanisms ⚠️ COUNSEL


6. Logging, monitoring & vulnerability management


7. Personnel & physical security


8. Incident response & breach notification ⚠️ COUNSEL

8.1 Incident response

8.2 Breach notification — role-dependent

The notification path depends on Faresay's role for the affected data:

A record of all personal-data breaches (facts, effects, remedial action) is maintained whether or not notified.

⚠️ COUNSEL — confirm the notification routing above, the contractual timelines for processor→controller notification in the DPA, and the contact details/escalation path.


9. Data retention, minimisation & secure disposal


10. Alignment to a recognised framework (future goal)

As a bootstrapped, early-stage company, formal certification is a future goal, not a current state. Candidate frameworks: - Cyber Essentials / Cyber Essentials Plus — UK government-backed baseline; pragmatic early target. - ISO/IEC 27001 — recognised ISMS certification; strong signal for UK healthtech and therapist trust. - SOC 2 (Type II) — where partner due diligence demands it.

⚠️ SECURITY — agree the target framework and a realistic roadmap (likely Cyber Essentials early, ISO 27001 as the company scales).


11. Policy review

Version Date Author Notes
v0.1 (DRAFT) [PLACEHOLDER: date] [PLACEHOLDER: author] Initial practice-portal draft (controller/processor split) for security + legal sign-off.

End of draft. ⚠️ This v0.1 draft must be validated by qualified security and legal professionals, with all [PLACEHOLDER: …] items resolved and ⚠️ target-state controls either implemented or honestly disclosed, before it is relied upon or published. Not legal advice.