Our Role
TranqBay is a platform, not a healthcare provider
- •TranqBay is a technology platform that connects individuals with independent, licensed mental-health professionals. TranqBay does not provide clinical or medical care and is not a healthcare provider.
- •The therapists offering services through the platform are independent professionals. They are not employees, agents, or representatives of TranqBay, and they are solely responsible for the care they provide and for their own clinical records.
- •For the clinical content of your sessions, your therapist is the party responsible under applicable health-privacy and professional-confidentiality law. TranqBay processes information to operate the platform, connect you with a therapist, and support your therapist's record-keeping.
Who We Are (Data Controllers)
The TranqBay entity responsible for your information depends on where you are located
- •Nigeria: TranqBay Health Limited, regulated under the Nigeria Data Protection Act (NDPA) 2023 and supervised by the Nigeria Data Protection Commission (NDPC).
- •United Kingdom: TranqBay Ltd (company number 16294223, England and Wales), regulated under the UK GDPR and Data Protection Act 2018 and supervised by the Information Commissioner's Office (ICO).
- •United States: TranqBay LLC (Delaware), subject to HIPAA and applicable state privacy laws.
- •Canada, the European Union, Australia, and other regions: where TranqBay does not have a local entity, TranqBay Ltd (United Kingdom) acts as the data controller. Your local data-protection law and rights still apply (for example, PIPEDA in Canada, the EU GDPR, and the Privacy Act 1988 in Australia), and you may contact your local supervisory authority, such as the Office of the Privacy Commissioner of Canada, your EU Data Protection Authority, or the OAIC.
- •For any data-protection question, or to exercise your rights, you can contact our privacy team at [email protected].
Regulatory Compliance
This policy is designed to comply with multiple data protection regimes including:
- •Nigeria: Nigeria Data Protection Act (NDPA) 2023 and the NDPR
- •United Kingdom: UK GDPR and Data Protection Act 2018
- •Canada: Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws
- •European Union: General Data Protection Regulation (GDPR)
- •United States: Health Insurance Portability and Accountability Act (HIPAA) and applicable state laws
- •Australia: Privacy Act 1988 and the Australian Privacy Principles (APPs)
Information We Collect
Personal Information
- •Name and contact details
- •Date of birth and demographic information
- •Professional credentials (for therapists)
- •Payment information
- •Emergency contact information
- •Government-issued identification (for verification)
- •Insurance information (where applicable)
Health Information
- •Information you choose to share to receive care
- •Session-related notes and documentation produced through the platform
Platform Usage Data
- •IP address and device information
- •Browser type and settings
- •Access times and duration
- •Pages visited and features used
- •Approximate geographic location (as permitted by law)
- •Technical error logs
- •Platform interaction data
- •Third-party calendar metadata (for providers who enable calendar sync)
Session Information
- •Appointment schedules
- •Session metadata
- •Chat messages (where applicable)
- •Scribe transcripts (where enabled; see the Scribe section)
How We Use Your Information
We use your information to:
- •Provide and operate the platform and connect you with a therapist
- •Support clinical documentation (Scribe)
- •Process payments and maintain records
- •Manage scheduling and prevent double bookings (for providers using calendar sync)
- •Keep the platform secure and prevent abuse
- •Respond to emergencies and safeguarding situations
- •Conduct quality assurance and improve our services
- •Send service-related communications
- •Comply with legal and regulatory obligations
Our legal bases include:
- •Performance of our contract with you, to operate the platform and connect you with a therapist
- •Provision of health care (GDPR Article 9(2)(h), and equivalent local provisions), to support clinical documentation, with appropriate safeguards
- •Legal obligation, for tax, accounting, and regulatory compliance
- •Legitimate interests, to keep the platform secure and improve our services
- •Vital interests and protection of health, to respond to emergencies
- •Consent, where required for sensitive information; you can withdraw consent at any time
Scribe (Session Documentation)
What Scribe is
- •Scribe is an optional feature that converts the spoken audio of your session into a written transcript to support your treating clinician's documentation
- •Speech-to-text processing is performed by a vetted processor under a Business Associate Agreement and/or on TranqBay's own secure infrastructure, in each case under confidentiality and security obligations
- •Scribe is provided solely for clinical documentation purposes; it is not used for marketing, advertising, behavioural analytics, or to train any third-party model
What we capture and what we keep
- •Audio is processed in transit only. We do not retain audio recordings. Audio is processed solely to generate text transcripts and is discarded immediately after transcription
- •The resulting text transcript is stored as part of your clinical record on TranqBay infrastructure within the European Union (Frankfurt, eu-central-1) and is subject to the same protections, retention rules, and access controls as other clinical session notes
- •Transcripts may contain special-category health data within the meaning of GDPR Article 9 and Protected Health Information (PHI) within the meaning of HIPAA, and are handled accordingly
Who can access transcripts
- •Your treating clinician, as part of their record-keeping for your care
- •You, the patient, via your data-subject access rights described elsewhere in this policy
- •TranqBay personnel strictly on a least-privilege basis for security, support, legal compliance, or platform operations
- •Where a third-party processor is used, only transiently for the duration of speech-to-text conversion, under contractual confidentiality and Business Associate obligations
Legal basis
- •Nigeria (NDPA 2023): processing of sensitive (health) data is based on your consent, with appropriate safeguards
- •United Kingdom & European Union (UK GDPR / GDPR): Article 6(1)(b) (performance of our service contract with you) and Article 9(2)(h) (provision of health care), with appropriate organisational and technical safeguards; where local professional-secrecy rules apply (for example, § 203 StGB in Germany), any speech-to-text processor is engaged as a confidentiality-bound service provider
- •Canada (PIPEDA and applicable provincial law): processing is based on your meaningful consent within the care relationship, with express consent for sensitive health information
- •United States (HIPAA): use of PHI is consistent with Treatment, Payment, and Health Care Operations purposes, under a Business Associate Agreement with our speech-to-text processor where one is used
- •Australia (Privacy Act 1988): processing of sensitive information is based on your consent and the provision of health services
- •Other jurisdictions: processing is grounded in your service relationship with us and applicable health-care provision exemptions; we apply the higher of local and TranqBay-wide standards
Your choices and rights
- •You may request deletion of transcripts associated with your account via your data-subject rights; clinical-record retention obligations may require us to retain certain records for the minimum period required by law
- •You may opt out of Scribe for future sessions by contacting [email protected] or your clinician; opting out does not affect care delivery, only how the clinician documents the session
- •Where local law requires explicit consent, we will seek that consent before enabling Scribe for your sessions
- •Transcripts are not used for automated decision-making that produces legal or similarly significant effects concerning you
Verification of Therapists
How verification works
- •TranqBay verifies the identity and professional standing of therapists at onboarding
- •TranqBay does not guarantee the accuracy of credentials, does not supervise or direct the clinical services therapists provide, and is not responsible for a therapist's conduct or for credentials that are fraudulent or that change after verification
- •We encourage you to confirm your therapist's registration with the relevant professional body
Third-Party Service Integrations
Google Calendar Integration (For Providers Only)
- •Purpose: We integrate with Google Calendar to help therapists and counselors prevent double bookings and manage their availability
- •What We Access: We access read-only information about calendar names and event times (start/end times) on calendars you choose to sync
- •Scopes Used: calendar.calendars.readonly (to view your calendar list) and calendar.events.readonly (to view event times for availability checking)
- •What We DO NOT Access: We do not read event descriptions, attendees, locations, attachments, or other detailed event content
- •How We Use It: Calendar busy times are used solely to block unavailable time slots from client bookings and prevent scheduling conflicts
- •Data Storage: We store only minimal calendar metadata (calendar IDs, event start/end times) necessary for scheduling purposes
- •Data Retention: Calendar sync data is refreshed regularly and not permanently stored beyond operational needs
- •Your Control: Providers can disconnect their calendar integration at any time from their account settings
- •Provider-Only Feature: Only therapists and counselors can connect their calendars; client data is never accessed through this integration
- •No Data Sharing: Calendar data is never shared with third parties or used for any purpose other than preventing double bookings
Google User Data Policy Compliance
- •TranqBay's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements
- •We limit our use of Google user data to providing and improving our scheduling and availability features
- •We do not transfer Google user data to third parties except as necessary to provide scheduling services to our users
- •We do not use Google user data for serving advertisements or any advertising purposes
- •We do not allow humans to read Google calendar data unless required for security purposes, compliance with applicable law, or with explicit user permission for support purposes
Other Third-Party Service Integrations
- •Payment processors for secure payment processing; we share only the necessary transaction information
- •Video and communication services for sessions; session media is encrypted and not permanently stored by third parties
- •Cloud infrastructure providers for secure hosting and backup, with encryption at rest and in transit
- •Communication services for appointment reminders and platform notifications
- •All third-party services are carefully selected with privacy and security as primary criteria
- •We maintain data processing (and, where applicable, Business Associate) agreements with all third-party service providers
- •Third-party access is limited to the minimum necessary to provide the specific service
Advertising, Data Sales, and AI Training
Our core commitments:
- •We do not sell your personal information
- •We do not use your messages, session content, or health information to train artificial intelligence or machine learning models
- •With your consent, we use advertising and conversion-measurement cookies (Google, Meta, and X) on our public pages to understand which marketing works. We never share your health information, the type of care you seek, or your messages and session content for advertising, and we never use advertising cookies on pages where you receive care
- •We do not sell or share sensitive personal information, including any health information
- •We do not sell or share the information of any user under 18
- •You can withdraw consent to advertising cookies at any time via the cookie banner; for US residents, you can also opt out of any sale or sharing by emailing [email protected]
Categories of information we do not sell:
- •Health information or medical records
- •Biometric information
- •Financial account information
- •Government identifiers
- •Sensitive personal information
- •Information about minors
Your Privacy Rights
United Kingdom & European Union
- •Right to access
- •Right to rectification
- •Right to erasure
- •Right to restrict processing
- •Right to data portability
- •Right to object
- •Right to withdraw consent
- •Right to lodge a complaint with your supervisory authority (the ICO in the UK, or your local Data Protection Authority in the EU)
United States - HIPAA Rights
- •Right to access PHI
- •Right to amend records
- •Right to receive an accounting of disclosures
- •Right to request restrictions
- •Right to confidential communications
- •Right to file a complaint with the U.S. HHS Office for Civil Rights without retaliation
California Residents - CCPA/CPRA Rights
- •Right to know what personal information is collected
- •Right to delete personal information
- •Right to opt out of the sale or sharing of personal information
- •Right to non-discrimination for exercising privacy rights
- •Right to correct inaccurate personal information
- •Right to limit use and disclosure of sensitive personal information
- •Right to data portability
Other US State Residents
- •Virginia residents: rights under VCDPA including access, deletion, and opt-out
- •Colorado residents: rights under CPA including access, correction, deletion, and opt-out
- •Connecticut residents: rights under CTDPA including access, correction, deletion, and opt-out
- •Utah residents: rights under UCPA including access, deletion, and opt-out
- •Additional state-specific rights as applicable under state law
Canadian Users
- •Right to access personal information
- •Right to challenge accuracy and completeness
- •Right to know how information is used and disclosed
- •Right to withdraw consent (subject to legal or contractual limits)
- •Right to request correction of errors
- •Right to file a complaint with the Office of the Privacy Commissioner of Canada
- •Provincial health information rights where applicable
Australian Users
- •Right to access personal information
- •Right to correction of personal information
- •Right to request anonymity or pseudonymity where lawful
- •Right to opt out of direct marketing
- •Right to complain to the Office of the Australian Information Commissioner
- •Right to know if data is disclosed overseas
- •Right to request deletion in certain circumstances
Nigerian Users
- •Right to data access
- •Right to data portability
- •Right to rectification
- •Right to erasure
- •Right to object to processing
- •Right to withdraw consent
- •Right to lodge a complaint with the Nigeria Data Protection Commission (NDPC)
Children's Privacy
TranqBay is for adults
- •TranqBay is intended for users aged 18 and over. By creating an account, you confirm that you are at least 18 years old.
- •We do not knowingly collect or process personal information from anyone under 18.
- •If we become aware that we have collected information from a person under 18 without appropriate authority, we will delete it promptly.
- •If you believe a minor has provided us with personal information, please contact us at [email protected].
Data Security
We implement robust security measures including:
- •Encryption in transit (TLS) and at rest (AES-256)
- •Role-based access on a least-privilege basis, with monitoring and audit logging
- •Internal security reviews and access controls
- •Incident response and breach procedures
Data Retention
We retain data according to regulatory requirements:
- •Session metadata: 30 days
- •Chat messages and treatment-related records: for the duration of care, then as required for clinical record-keeping
- •Scribe transcripts: same retention as clinical notes
- •Medical and clinical records: the minimum period required by applicable local law
- •Payment records: as required for tax and audit purposes
- •Platform usage data: 24 months
International Data Transfers
How we protect international transfers:
- •We use appropriate safeguards, including Standard Contractual Clauses and adequacy decisions where available
- •From the UK, transfers to countries without UK adequacy use the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses
- •From Nigeria, transfers rely on an NDPC adequacy decision, appropriate safeguards, or your consent
- •Your information may be processed outside your home country, including in the European Union and the United States, and may be subject to access by foreign courts or authorities; we remain accountable for it and require comparable protection from our service providers
- •Clinical transcripts are stored within the European Union (Frankfurt)
Data Breach Notification
In the event of a data breach, we will:
- •Notify the relevant supervisory authority within the timeframe required by law, including within 72 hours under the UK GDPR and EU GDPR, and within 72 hours to the NDPC under the Nigeria Data Protection Act where the breach is likely to result in risk to individuals
- •For Canadian users, report to the Office of the Privacy Commissioner and notify affected individuals as soon as feasible where there is a real risk of significant harm, and keep a record of every breach
- •For Australian users, notify the OAIC and affected individuals for eligible breaches under the Notifiable Data Breaches scheme
- •For US users, comply with HIPAA and state-specific breach notification laws
- •Notify affected individuals without undue delay where there is a high risk to them
- •Provide details of the breach, its potential impact, and mitigation measures, and offer appropriate support and remediation
Our incident response includes:
- •Immediate containment and assessment
- •Forensic investigation to determine scope
- •Risk assessment for affected individuals
- •Implementation of additional security measures
- •Documentation and reporting to authorities
- •Post-incident review and improvement
Updates to Privacy Policy
How we handle changes:
- •We may update this policy from time to time
- •For material changes, we will notify you by email or in-platform notice at least 14 days before the changes take effect
- •We maintain a version history
- •Where a change legally requires it, we will request renewed consent before continuing to process your information
Contact Information
How to reach us
- •For any privacy, data-protection, or policy request, email [email protected] (we respond within 1 to 2 business days)
- •To exercise your privacy rights, you can also use our Data Deletion Request page at tranqbay.health/data-deletion
Contact Information
Website:TranqBay.health
Email:[email protected]