Privacy Policy

Your trust is our priority. Learn how we protect your sensitive mental health data.

At StayUnfiltered, we recognize that mental health data requires the highest level of protection. This policy outlines our commitment to safeguarding your sensitive information in compliance with GDPR and India's Digital Personal Data Protection Act (DPDP) 2023.

Last Updated: August 18, 2025

Introduction

StayUnfiltered is a mental health and wellness provider offering EAP programs, webinars, workshops, and one-on-one sessions. We are committed to protecting your privacy and safeguarding your personal information in compliance with GDPR (for EU/UK individuals) and India's DPDP Act 2023.

Commitment to Privacy and Confidentiality

We prioritize strict confidentiality for all client information. Industry guidelines mandate explicit confidentiality: EAP providers must give users clear statements about confidentiality and protect client information with "appropriate levels of security".

Our Compliance Framework:

  • GDPR compliance for EU/UK individuals
  • DPDP Act 2023 compliance for India
  • Lawful, purpose-limited processing of data
  • Implementation of security safeguards
  • Support for data subject rights

Data We Collect

We collect only the personal data needed to provide our services and improve your overall experience. This includes:

Identifiers & Contacts

  • Name
  • Email address
  • Phone number
  • Employment details (if relevant)

Health & Wellness Data

  • Health history
  • Dietary preferences
  • Mental health status
  • Well-being information

Usage & Location Data

  • Website/app usage
  • Service preferences
  • Survey responses
  • Feedback data
  • Approximate location — fetched automatically to provide region-specific packages and pricing based on your local currency. We do not use your location for tracking, marketing, or any unrelated purposes.

How We Use Your Data

Your data is used strictly to deliver, personalize, and improve our services, and for necessary administrative purposes.

Service Delivery

  • Providing EAP programs and webinars
  • Scheduling and conducting sessions
  • Facilitating workshops

Personalization & Improvement

  • Tailoring advice based on health data
  • Personalizing care based on dietary information
  • Improving services through anonymized analytics
  • Displaying packages and pricing according to your location and currency for a seamless experience

Communication

  • Sending appointment reminders
  • Requesting feedback (with consent)
  • Providing service updates

Administrative Purposes

  • Billing and payment processing
  • Account management
  • Legal compliance

Cookies & Tracking Technologies

Our website and mobile platforms use cookies and similar tracking technologies for functionality and analytics.

Our Cookie Categories:

Essential

Required for basic functionality

Preferences

Remember your settings

Analytics

Help us improve our services

Marketing

Used only with your consent

Consent Notice: In compliance with GDPR and related EU laws, we obtain user consent before setting any non-essential cookies. You can withdraw your consent at any time.

Data Sharing & Disclosure

We do not sell personal data. We share user data only in limited, controlled circumstances.

With Employers

Only with consent for EAP coordination purposes. We share minimal necessary information.

With Service Providers

Trusted partners under strict contracts for hosting, analytics, and support services.

Legal Obligations

When required by law or to protect our rights, property, or safety.

No Third-Party Marketing

We never share your data with third parties for marketing purposes without your explicit consent.

Data Security Measures

We implement strong technical and organizational safeguards to protect personal data.

Technical Safeguards

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Secure hosting with Vercel (ISO 27001 certified)
  • Secure hosting with Hostinger
  • Regular security audits and vulnerability scans

Organizational Safeguards

  • Access restricted to authorized staff only
  • Comprehensive staff training on data protection
  • Strict confidentiality agreements
  • Regular security awareness programs

Incident Response

We have a comprehensive incident response plan to address potential data breaches. In the unlikely event of a breach, we will notify affected users and relevant authorities within 72 hours as required by GDPR and DPDP regulations.

Data Retention

We retain personal data only as long as necessary to fulfill its intended purpose.

Active Data

We retain data during active engagement with our services. This includes:
  • Duration of EAP program participation
  • Active therapy sessions
  • Ongoing workshop enrollment

Post-Service Retention

After service completion, we retain data only as required:
  • For legal or regulatory requirements
  • For financial record keeping (7 years)
  • For dispute resolution purposes

Data Disposal

Once retention periods expire, we securely delete or anonymize your personal data using industry-standard data destruction methods that prevent reconstruction.

Compliance with GDPR & DPDP

StayUnfiltered is fully compliant with GDPR and India's DPDP Act (2023). We adhere to all applicable requirements for data protection.

GDPR Compliance

  • Lawful basis for processing
  • Data subject rights implementation
  • Data Protection Impact Assessments
  • Appointment of EU representative

DPDP 2023 Compliance

  • Consent-based processing
  • Purpose limitation
  • Data minimization
  • Appointment of Data Protection Officer

Core Principles

LawfulnessTransparencyPurpose LimitationData MinimizationAccuracyStorage LimitationSecurityAccountability

Your Privacy Rights

Under GDPR and DPDP, you have the following rights regarding your personal data:

Access Rights

Request access to the personal information we hold about you at any time.

Correction Rights

Request correction of inaccurate or incomplete personal information.

Deletion Rights

Request deletion of your personal data when it's no longer necessary for our services ("Right to be Forgotten").

Data Portability

Request a copy of your data in a structured, commonly used format.

Objection Rights

Object to certain types of processing, such as direct marketing.

Restriction Rights

Request restriction of processing in certain circumstances.

Exercising Your Rights

To exercise any of these rights, please contact our Data Protection Officer at stay.unfiltered.2025@gmail.com. We will respond to your request within 30 days as required by law.

Summary of Key Practices

Strict Confidentiality

All client information is treated with the highest level of confidentiality in accordance with industry standards.

GDPR/DPDP Compliance

Full compliance with GDPR for EU/UK individuals and India's DPDP Act 2023.

Security First

Implementation of robust security measures including encryption and certified hosting.

Transparency

Clear privacy notices and consent practices so you understand how your data is used.

User Control

You remain in full control of your personal data with multiple rights to manage it.

Contact Our Privacy Team

If you have questions about this privacy policy or wish to exercise your privacy rights, please contact our Data Protection Officer:

Phone

+91-79923 27474

Registered Office

Flat No. 1151, Tower - G ,

11th Avenue, Gaur City 2 ,

Greater Noida , Uttar Pradesh 201009

We typically respond to privacy inquiries within 48 business hours. For urgent matters regarding data security, please include "URGENT" in your subject line.