Privacy Policy
Effective Date: The date on which you first create an account, click to accept the Agreement, electronically sign the Agreement, or otherwise affirmatively accept the Agreement through a written or electronic process provided or approved by Really Global, whichever occurs first.
Introduction
This Privacy Policy (the “Privacy Policy”) explains how Alden Global Inc., doing business as “Really Global” (“Really Global,” “we,” “us,” or “our”), collects, uses, shares, retains, and otherwise processes information about you in connection with your access to and use of the Really Global Technology Platform. This Privacy Policy is incorporated into and forms part of the agreement that governs your access to and use of the Technology Platform — Really Global’s Terms and Conditions if you use the Technology Platform as a Client, and Really Global’s Technology Platform Terms of Service if you use it as a Company (each, the “Agreement”). By creating an account, clicking “I agree” or a substantially similar acceptance mechanism, accessing or using the Technology Platform, or otherwise affirmatively accepting the Agreement, you acknowledge that you have read, understood, and agree to this Privacy Policy.
In addition to this Privacy Policy, certain processing of your information may be governed by (a) Really Global’s Data Processing Agreement (the “DPA”), which applies where the processing involves personal data subject to the GDPR, UK GDPR, Swiss FADP, or any similar data-protection law; and (b) the Company’s own informed-consent forms, professional disclosure statements, notice of privacy practices, or similar terms that govern the clinical or service relationship between you and the Company.
For purposes of this Privacy Policy, Alden Global Inc., doing business as “Really Global,” is referred to as “Really Global.” The individual accessing or using the Technology Platform as a Client is referred to as “you,” “your,” or the “Client.” If you are accessing or using the Technology Platform on behalf of a minor or another person for whom you have legal authority to act, both you and that person are subject to this Privacy Policy to the maximum extent permitted by applicable law.
This Privacy Policy applies to more than one group of people. Most of it describes the Personal Information of Clients, and except where it says otherwise, references to “you” and “your” are addressed to a Client. It also applies to the individuals behind a Company account, and to individuals a Company names in the information it submits or displays — for example, a person identified on a Company’s profile as supervising that Company’s practice. Section 3 sets out those categories, Section 4 explains why we process them and on what lawful basis, Section 6 describes who we share them with, Section 10 explains how any of those individuals may exercise their rights, including where they hold no account with Really Global, and Section 17 explains how long we keep the information.
1. Definitions
Unless otherwise defined in this Privacy Policy, capitalized terms have the meanings set forth in this Section or in the Agreement. Section references are to this Privacy Policy unless otherwise stated.
“Agreement” has the meaning set forth in the Introduction and includes this Privacy Policy, the Terms and Conditions or the Technology Platform Terms of Service (as applicable to you), the DPA (where applicable), and any additional terms, notices, consents, policies, disclosures, or feature-specific terms incorporated into or accepted under the Agreement.
“Business Associate” has the meaning set forth in 45 CFR § 160.103 of HIPAA.
“Client” means any individual who accesses, books, schedules, communicates with, pays for, receives, requests, or otherwise uses or interacts with services offered by a Company through or in connection with the Technology Platform. Except where this Privacy Policy expressly provides otherwise, references in this Privacy Policy to “you” or “your” refer to the Client.
“Company” refers to the individual, sole proprietor, professional corporation, company, clinic, group, organization, or other legal entity that provides Mental Health Services through or in connection with the Technology Platform pursuant to a separate Technology Platform Terms of Service agreement with Really Global. The Company is solely responsible for the provision of Mental Health Services. At all times, the Company shall exercise overall control of the Mental Health Services provided by the Company and shall retain legal responsibility for the Mental Health Services.
“Company Personnel” means a natural person who creates, operates, administers, or is authorized to access a Company account, or who is identified on a Company’s profile or listing as offering or providing Mental Health Services through that Company.
“Covered Entity” has the meaning set forth in 45 CFR § 160.103 of HIPAA.
“Data Controller” (or “Controller”) has the meaning set forth in Article 4(7) of the GDPR (or the equivalent term under any other Data Protection Law).
“Data Processor” (or “Processor”) has the meaning set forth in Article 4(8) of the GDPR (or the equivalent term under any other Data Protection Law). For purposes of this Privacy Policy, a Data Processor is also any entity engaged by Really Global to process Personal Information on Really Global’s behalf in connection with the Technology Platform.
“Data Protection Law” means, collectively, (a) the GDPR; (b) the UK GDPR; (c) the Swiss FADP; (d) HIPAA; (e) the California Consumer Privacy Act / California Privacy Rights Act (“CCPA/CPRA”); (f) the Washington My Health My Data Act (“WA MHMDA”); (g) the Connecticut Data Privacy Act and the Connecticut Act Concerning Consumer Health Data (“CT CHDA”); (h) the Nevada Consumer Health Data Privacy Act (“NV SB 370”); (i) the Florida Digital Bill of Rights, where applicable; (j) the Children’s Online Privacy Protection Act (“COPPA”); (k) the Brazilian LGPD; (l) Canadian PIPEDA and Quebec Law 25; (m) and any other data-protection or privacy law applicable to the processing of Personal Information through the Technology Platform.
“DPA” has the meaning set forth in the Introduction and refers to the Really Global Data Processing Agreement, as it may be amended or replaced from time to time.
“Effective Date” has the meaning set forth at the top of this Privacy Policy.
“GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (General Data Protection Regulation).
“HIPAA” means, collectively, the administrative simplification provisions of the Health Insurance Portability and Accountability Act of 1996, as amended by the HITECH Act, and the implementing regulations of the U.S. Department of Health and Human Services, including the Privacy Rule, the Security Rule, and the Breach Notification Rule.
“Mental Health Services” means the licensed and non-licensed mental health-related services, including clinical and non-clinical services, that a Company offers, lists, schedules, provides, or makes available through or in connection with the Technology Platform. The term does not, and shall not be construed to, impose any obligation on Really Global to provide, supervise, direct, control, evaluate, or assume responsibility for any such service.
“Named Individual” means a natural person, other than a Client or Company Personnel, whose Personal Information a Company submits to or displays through the Technology Platform as part of the Company’s own profile, listing, or credential information, including a person a Company identifies as supervising its supervised practice. A Named Individual does not hold an account with Really Global and is not a party to the Agreement.
“Personal Information” means any information that relates to an identified or identifiable natural person, as further defined under each applicable Data Protection Law. Personal Information includes Sensitive Personal Information where the applicable Data Protection Law treats certain categories as sensitive.
“Personal Data Breach” has the meaning set forth in Article 4(12) of the GDPR (or the equivalent term under any other Data Protection Law).
“Processing” (and its variants, including “Process”) has the meaning set forth in Article 4(2) of the GDPR (or the equivalent term under any other Data Protection Law) and includes the collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, restriction, erasure, or destruction of Personal Information.
“Sensitive Personal Information” means Personal Information that is treated as sensitive under an applicable Data Protection Law, including, without limitation, mental health information, health information, racial or ethnic origin, religious or philosophical beliefs, sexual orientation, biometric data, precise geolocation, government identifiers, and information about minors.
“Sub-Processor” means any third party engaged by Really Global to process Personal Information on Really Global’s behalf in connection with the Technology Platform.
“Technology Platform” means the websites, mobile applications, software, tools, interfaces, application programming interfaces, databases, documentation, and related technology functionality owned, operated, or made available by Really Global, including any successor or related platform functionality.
“Third Party” means any entity that is not Really Global, a Sub-Processor, or a Company, and is not otherwise specifically identified in the Agreement.
2. Really Global’s Roles and Responsibilities
Really Global plays different roles with respect to different categories of Personal Information processed through the Technology Platform. Understanding these roles helps clarify what Really Global does with your information and what your rights are.
Really Global as Data Controller. With respect to the operation of the Technology Platform itself — including account registration data, platform usage data, transaction and payment metadata, audit and security records, support records, ratings and reviews, and aggregated and de-identified data — Really Global acts as a Data Controller under the GDPR and equivalent Data Protection Laws. As Data Controller, Really Global determines the purposes and means of the processing and is responsible for ensuring that the processing complies with applicable Data Protection Law.
Really Global as Data Processor. With respect to the Mental Health Services content that a Company creates, maintains, or transmits through the Technology Platform — including session recordings, transcripts, session-derived notes, journals, worksheets, assessments, and the substantive content of Company-Client communications occurring within a clinical session — Really Global acts as a Data Processor on the Company’s behalf. The Company, not Really Global, is the entity that creates and owns the clinical content; Really Global hosts and transmits that content on the Company’s behalf in accordance with the DPA (where applicable) and applicable Data Protection Law. Really Global does not process this information in the capacity of a HIPAA Covered Entity.
Really Global’s duties under the Agreement are purely non-clinical and administrative in nature. This Privacy Policy shall in no way be construed to mean or suggest that Really Global is engaged, or permitted to engage, in the practice of medicine, psychology, or any other licensed healthcare activity. Likewise, this Privacy Policy shall in no way be construed to mean or suggest that Really Global is engaged in providing non-licensed services such as health coaching and mentoring.
3. The Personal Information We Process
The Personal Information we process depends on how you interact with the Technology Platform. The categories below describe the types of Personal Information we may process and the role in which we process it.
Account and Profile Information
When you create an account on the Technology Platform, we process information you provide, including your first and last name (which you may select for anonymity reasons but must remain accurate for identity-verification purposes where required), email address, mobile phone number, password (stored in hashed form), age or date of birth (used to determine your eligibility for Mental Health Services under applicable age-of-consent laws), country and, if you are located in the United States, state of residence, language preferences, and emergency contact information you choose to provide. Really Global acts as Data Controller for this category.
Onboarding and Intake Information
If a Company you choose requires an onboarding questionnaire or intake assessment before commencing Mental Health Services, we may process the responses you provide. Some intake content may be Personal Information that we process as a Data Controller (for administrative routing purposes); other intake content provided directly to the Company may be health information that we process as a Data Processor on the Company’s behalf.
Client Interaction and Platform Usage Information
When you visit the Technology Platform, we process technical and behavioral information including pages visited, features used, time spent on pages, errors encountered, type of device and browser, IP address, and similar telemetry. We use third-party identifiers (cookies, web beacons, and similar technologies) consistent with Section 7 (Cookies and Tracking Technologies). Really Global acts as Data Controller for this category.
Transaction and Payment Information
We process information about your transactions on the Technology Platform, including whether a payment for Mental Health Services was completed, the amount, any cancellations, refunds, or discounts, the date and time of the transaction, and the Company involved. Payment instruments (credit card numbers, bank account information, PayPal account identifiers) are processed by the integrated third-party payment processors (currently Stripe and PayPal) on your behalf and on the Company’s behalf, not by Really Global. Really Global processes the transaction metadata necessary to facilitate the booking, refund, and reporting functions of the Technology Platform. Really Global acts as Data Controller for transaction metadata; payment processors act as their own Data Controllers for payment instrument processing.
Affiliate and Referral Program Information
If you participate in, are referred through, or interact with the Affiliate Program, we process information needed to operate it, including affiliate eligibility and attestations; affiliate account identifiers, handles, and links; referral and attribution records; qualifying transaction and commission records; payout status; and fraud, compliance, support, and audit records. If you choose to receive payment, Stripe may collect identity, contact, tax, bank-account, debit-card, or other recipient information directly through Stripe-hosted payout setup. Really Global receives only the recipient and payout information Stripe makes available to operate and reconcile payouts. Really Global acts as Data Controller for its Affiliate Program records. Stripe acts under its own privacy terms for information it collects directly for payout services.
Client Engagement Information
We process information about your engagement with the Technology Platform, including the timing and duration of your logins, the number of messages and live sessions you initiate or participate in, the timing of those interactions, and your use of features such as worksheets, journals, and goal-tracking tools. This category does not include the substantive content of Mental Health Services Information (described below). Really Global acts as Data Controller for engagement metadata.
Mental Health Services Information
When you receive Mental Health Services from a Company through the Technology Platform, the substantive content of those services — including session audio or video recordings, session transcripts, session-derived notes, journals, worksheets, assessments, and the substantive content of Company-Client communications occurring within a clinical session — flows through Really Global’s infrastructure as the Company creates, records, or transmits it. The Company creates and owns this content. Really Global acts as Data Processor for the Company for this category. Really Global does not view, analyze, or use this content for any purpose other than to host and transmit it on the Company’s behalf, except as described in this Privacy Policy or as the Company directs.
Federal Substance Use Disorder Confidentiality. Really Global does not currently make the Technology Platform available to Companies that are “Part 2 programs” within the meaning of 42 CFR § 2.11 and does not currently undertake to act as a “qualified service organization” or enter into a qualified service organization agreement. See Section 15 of this Privacy Policy.
Client Feedback and Platform Experience Information
We process feedback and platform experience information including ratings, reviews, helpful votes, comments, reports, complaints, private feedback, session-availability indicators, cancellation and no-show indicators, Company replies, and similar information you choose to submit. Really Global acts as Data Controller for this category.
Customer Service and Communications
When you contact our Customer Service team, we process the content of your communications with us, your contact information, the support issue, and our response. Really Global acts as Data Controller for this category.
Communications with Companies
Direct messages and communications you exchange with a Company on the Technology Platform outside of a clinical session may include Personal Information. The Company, not Really Global, is the recipient and user of those communications for their professional purposes. Really Global hosts and transmits those communications on the Company’s behalf. Really Global acts as Data Processor for this category.
Identifiers
A unique sequentially-generated identifier is assigned to each Client account. We also process device identifiers and similar technical identifiers used to operate the Technology Platform. Really Global acts as Data Controller for this category.
Aggregated, De-Identified, and Anonymized Data
We may aggregate, de-identify, or anonymize Personal Information we process. Once data is properly aggregated or de-identified under applicable Data Protection Law (including, where applicable, the HIPAA de-identification standard at 45 CFR § 164.514 and the GDPR anonymization standard), it no longer identifies you and may be used for any lawful purpose without temporal limit, including for product improvement, research, benchmarking, and the development of proprietary data assets, models, products, and services. Really Global retains all rights in aggregated and de-identified data as Data Controller.
Company Account, Profile, and Credential Information
When an individual creates or operates a Company account, we process the Personal Information provided in connection with that account, including name, professional or business name, email address, telephone number, password (stored in hashed form), country and, where applicable, state or province, payment-processor account identifiers, and the tax-residency and identification information necessary for platform-operator reporting obligations. We also process the profile, listing, service-description, pricing, availability, and credential information the Company submits, selects, or displays, including the professional licences, registrations, permits, certifications, academic degrees, memberships, and supervision arrangements the Company records, together with the issuing organization, the type of issuing body, the country and region of issue, and the identifiers and dates the Company associates with each. Really Global acts as Data Controller for this category.
Under the Technology Platform Terms of Service, the Company is responsible for the truthfulness, accuracy, completeness, and currency of everything it submits, selects, or displays, and for keeping it up to date. Really Global does not undertake a general duty to verify, monitor, or screen that information, apart from the limited, point-in-time activities of the Verification Program described in Section 6.
Information a Company Provides About a Named Individual
Where a Company records that it practises under supervision, the Technology Platform asks the Company to identify the person supervising it. That is the only circumstance in which we ask a Company for Personal Information about someone who is neither a Client nor Company Personnel, and what follows describes everything we do with it.
What we process. The Named Individual’s name and, where the Company provides one, the professional licence or registration number the Company records for that person. We process no other Personal Information about a Named Individual.
Where it comes from. We obtain this information from the Company, not from the Named Individual. Under the Technology Platform Terms of Service the Company represents that the information is truthful, accurate, complete, current, and not misleading, and confirms that it has told the Named Individual their details will appear on the Company’s public profile and that the Named Individual has agreed. Really Global does not verify that representation and undertakes no duty to do so.
How it is used. The information is displayed on the Company’s public profile on the Technology Platform. We do not use it for any other purpose. We do not use it to evaluate, assess, or form any view about the Named Individual or about the Company, we do not share it with any Third Party for advertising or marketing, and it plays no part in how a Company is ranked, sorted, or displayed.
Why we process it. Where the GDPR, the UK GDPR, or an equivalent Data Protection Law applies, we process this information on the basis of the legitimate interests of Really Global and of the Company (Article 6(1)(f) of the GDPR). Those interests are in operating a marketplace on which a Company can describe its own practice accurately, and in enabling a Company to meet professional-advertising obligations that in some jurisdictions require a person practising under supervision to identify their supervisor in their own printed and electronic materials. We have weighed those interests against the interests, rights, and freedoms of the Named Individual and have limited the processing accordingly: we collect a name and, where the Company provides one, a licence or registration number, and nothing else; we collect it only where the Company confirms that the Named Individual is aware of and has agreed to the publication; we use it for display and for no other purpose; and once it is no longer displayed we keep it only as a record of what was published, as described in Section 17, and erase it if the Named Individual objects.
Your rights if you are a Named Individual. You have the rights described in Section 10, including the right to object to this processing at any time. Because you do not hold an account with us, you may exercise those rights by emailing [email protected]. If you object to the display of your information, we will remove it from the Company’s profile and erase it, and we will tell the Company that we have done so, so that the Company can meet any professional obligation of its own that depends on the disclosure. We will not require you to create an account in order to make a request.
4. Why We Process Your Personal Information
We process your Personal Information for the following purposes. For Personal Information subject to the GDPR or equivalent Data Protection Law that requires a specified lawful basis, the relevant basis is noted in parentheses.
Service Provision
To provide the Technology Platform, facilitate your connection to and bookings with Companies, deliver Mental Health Services through the Technology Platform’s infrastructure, process payments through integrated third-party payment processors, host and transmit Mental Health Services Information on the Company’s behalf, and provide the features and tools you use through the Technology Platform. (Lawful basis: performance of a contract; for Sensitive Personal Information including health information, performance of healthcare services under Article 9(2)(h) of the GDPR and equivalent provisions.)
Account Integrity, Security, and Fraud Prevention
To verify your identity (or your authorized representative’s identity), prevent unauthorized access, detect and respond to security incidents, prevent fraud and misuse, and protect the safety and integrity of the Technology Platform, Companies, other Clients, and Really Global. (Lawful basis: legitimate interests; in some cases, legal obligation.)
Communication
To respond to your inquiries, send you appointment reminders, scheduling notifications, transaction confirmations, account notices, and other service-related communications. We may also, with your consent or where permitted by applicable Data Protection Law, send you marketing communications about Really Global’s features, products, and services. (Lawful basis: performance of a contract for service communications; consent for marketing.)
Trust, Safety, and Platform Integrity
To operate review and feedback features, respond to reports and complaints, prevent platform misuse, enforce platform policies, and improve Technology Platform functionality. When investigating support requests, platform misuse, safety reports, fraud, legal issues, privacy issues, billing issues, or complaints, members of our Customer Support, Trust and Safety, or Legal teams may, with your consent or where otherwise permitted by applicable law and Really Global’s policies, review specific account information or interactions that are not Mental Health Services Information. Such review is for platform support, safety, legal, fraud-prevention, and account-integrity purposes only and is not clinical supervision, peer review, utilization review, professional evaluation of any Company, or any clinical determination by Really Global. We do not access or review the substantive content of Mental Health Services Information (such as session content or clinical notes) except as the Company directs, as required by law, or as set forth in this Privacy Policy. (Lawful basis: legitimate interests; legal obligation for certain investigations.)
Compliance with Legal Obligations
To comply with applicable laws, regulations, court orders, subpoenas, regulatory inquiries, law-enforcement requests, payment-network rules, sanctions, and similar legal obligations. Companies providing Mental Health Services through the Technology Platform have their own professional, ethical, and legal obligations (including record-retention obligations) that are addressed by the Company directly. (Lawful basis: legal obligation.)
Platform Operations, Analytics, and Improvement
To operate, maintain, and improve the Technology Platform, including monitoring usage patterns, analyzing platform performance, identifying issues, prioritizing feature development, conducting research, and managing notifications. (Lawful basis: legitimate interests.)
Safety and Emergency Response
If we have a reasonable basis to believe that you or another individual may be in immediate danger, or if your privacy or safety has been compromised, we may use your Personal Information (including emergency contact information you have provided) to conduct an investigation, contact you, contact your emergency contact, or contact relevant authorities, where legally appropriate and permitted. (Lawful basis: protection of vital interests under Article 6(1)(d) and Article 9(2)(c) of the GDPR; legal obligation where mandatory reporting applies.)
Tax and Regulatory Reporting
To collect and report information about Companies and platform transactions to tax authorities under applicable jurisdiction-specific marketplace and digital-platform reporting regimes (such as OECD DAC7 in the EU, US tax-reporting facilitated by the integrated third-party payment processors, and similar regimes). (Lawful basis: legal obligation.)
Affiliate Program Administration
To determine Affiliate Program eligibility, issue and resolve affiliate links, attribute new accounts, calculate and adjust commissions, administer payout status, prevent fraud and abuse, comply with applicable law, and support program participants. (Lawful basis: performance of a contract; legitimate interests in operating and protecting the Affiliate Program; and legal obligation where applicable.)
Development and Operation of AI and Machine-Learning Systems
To develop, train, test, evaluate, deploy, and operate AI and machine-learning systems as further described in Section 5 (Artificial Intelligence and Machine Learning). (Lawful basis: legitimate interests for platform operational AI uses; consent for any AI training over identifiable Client clinical content, as required by Section 5.)
Company Accounts, Credentials, and Supervision Information
To operate Company accounts, to display Company profiles and listings, and to present the credential and supervision information a Company chooses to display, so that a Company can describe its own practice on the Technology Platform and a Client can read that description before choosing a Company. (Lawful basis: performance of a contract with the Company; and, for Personal Information about a Named Individual, legitimate interests as described in Section 3.)
5. Artificial Intelligence and Machine Learning
Really Global may use artificial intelligence and machine-learning systems in connection with the Technology Platform for purposes including, without limitation, transcription, translation, summarization, search, sorting, ranking, filtering, fraud prevention, account integrity, scheduling assistance, and other administrative and platform-operational functions. These systems are administrative and platform-operational tools designed to support — not to substitute for — a Company’s independent professional judgment.
Really Global may use Platform Records, Transaction and Payment Records, Audit, Access, Support, and Security Records, profile and listing content, ratings and reviews, and aggregated, de-identified, anonymized, statistical, derivative, and benchmark data for the development, training, evaluation, and operation of artificial intelligence and machine-learning systems, in each case subject to applicable Data Protection Law and this Privacy Policy.
Really Global shall not use Client clinical content — including, without limitation, session audio or video recordings, session transcripts, session-derived notes, journals, worksheets, assessments, and the substantive content of Company-Client communications occurring within a clinical session — as training data for the development, fine-tuning, or evaluation of artificial intelligence or machine-learning models, except where (i) both the applicable Company and you have affirmatively opted in through a consent flow expressly identified by Really Global as authorizing such use, (ii) the data has been de-identified or aggregated in accordance with applicable Data Protection Law and this Privacy Policy. You may withdraw any opt-in consent at any time through your account settings; Really Global will honor your withdrawal in accordance with applicable law and its then-current operational practices. Except where applicable law requires otherwise, withdrawal does not require Really Global to remove data that was already lawfully de-identified or aggregated, or to retrain, destroy, or modify a model that was lawfully trained before withdrawal. A legal requirement or legal process may require Really Global to preserve, process, or disclose information, but does not by itself authorize Really Global to use Client clinical content as AI training data. The use of de-identified or aggregated data permitted under this paragraph remains subject to the de-identification standards set by applicable Data Protection Law (including, where applicable, the HIPAA de-identification standard at 45 CFR § 164.514 and the GDPR anonymization standard).
Really Global does not engage in solely automated decision-making that produces legal effects concerning you or similarly significantly affects you in connection with your use of the Technology Platform, except as expressly disclosed to you or as required or permitted by applicable law. Really Global will comply with applicable laws regulating artificial intelligence, including, as applicable, the EU AI Act (Regulation (EU) 2024/1689), and will surface additional transparency notices, consents, or disclosures for specific AI features (such as emotion-recognition features or other higher-risk AI uses) where required by such laws.
Realtime Audio Translation. Where Really Global enables realtime audio translation during a session, audio you speak is processed in real time by artificial intelligence systems (OpenAI Realtime Translation API and Google Gemini Live API; see Section 6) to produce translated audio for the other session participant in their language. Translation is active only when the session participants do not share a session language and only for the duration of the live session. You will be informed that translation is active, consistent with the transparency requirements of the EU AI Act (Regulation (EU) 2024/1689, Article 50) where applicable and equivalent transparency obligations in other jurisdictions. Translation may be declined by you per session before the session begins, and Companies may disable realtime audio translation on their account.
Audio and Video Session Recordings
Audio and Video Session Recordings. Where the Technology Platform records, transmits, or otherwise makes available audio or video content from Mental Health Services sessions (including session recordings, session-derived video clips, or similar audiovisual records), such content may constitute “video tape” or “similar audiovisual material” subject to the federal Video Privacy Protection Act (18 U.S.C. § 2710, the “VPPA”) and analogous state laws. Really Global does not knowingly disclose video-viewing records of identifiable Clients to Third Parties except (i) with the Client’s affirmative opt-in consent at the point of disclosure (in a form that meets VPPA’s informed-written-consent requirements where applicable), (ii) as required by law (including legal process), or (iii) as required for the operation, security, or integrity of the Technology Platform.
6. Who We Share Your Personal Information With
We share your Personal Information only as described in this Section.
With Companies
We share Personal Information necessary for a Company you choose to provide Mental Health Services to you, including your account information, scheduling information, transaction information, and the content of communications and Mental Health Services Information you create or share with the Company.
With Sub-Processors
We engage Sub-Processors to provide infrastructure and services necessary to operate the Technology Platform. As of the Effective Date, our principal Sub-Processors include:
Cloud hosting and infrastructure: Microsoft Azure (cloud hosting, data storage, infrastructure, and security services).
Telephony and live session media infrastructure: Twilio (routing of voice, video, and live session audio between Clients and Companies).
AI realtime audio translation: OpenAI (Realtime Translation API) and Google (Gemini Live API), used to provide live audio translation between Clients and Companies during sessions where the parties do not share a session language.
Payment processing and affiliate payouts: Stripe and PayPal process Client payments through connected payment accounts, with Client payments flowing directly to the applicable Company’s account. Stripe also provides hosted affiliate-recipient onboarding and payout services when an eligible participant chooses to receive payment. Affiliate payouts are separate payments made from Really Global’s own funds. Really Global does not store full payment-card, bank-account, or debit-card credentials. Payment processors may process information under their own privacy terms and legal obligations.
Analytics: Mixpanel and Google Analytics (platform usage analytics; configured to exclude Mental Health Services Information from collection).
Email and messaging: GoHighLevel (transactional and account-related email; we are in the process of migrating from Mailmodo, our prior email-services Sub-Processor).
Calendar integration (Company-side only): Where a Company chooses to do so, the Company may integrate its Google, Microsoft, or Apple calendar with the Technology Platform’s scheduling system through the Provider Portal. This integration enables the Company to manage its availability through its own calendar. Appointment information you book with a Company may flow into the Company’s calendar through this integration. Really Global’s use and transfer of Google user data through this integration complies with the Google API Services User Data Policy, including its Limited Use requirements.
Bot and abuse detection: Standard CAPTCHA and similar abuse-prevention services to protect the Technology Platform from automated abuse.
We maintain a current list of Sub-Processors available upon reasonable request and provided through the Technology Platform. We require each Sub-Processor to enter into a written agreement that imposes data-protection obligations substantially similar to those in this Privacy Policy and applicable Data Protection Law.
With Verification Sources
Where a Company elects to participate in the Verification Program under the Technology Platform Terms of Service, or is required to participate as a condition of a particular Technology Platform feature, we share the Personal Information necessary for that verification with one or more Verification Sources — the independent third-party verification vendors, institutions, agencies, and licensure authorities that review specified documentation, information, or source records. What is shared depends on the verification the Company undertakes and may include identity information, education, training, certifications, licences, supervision arrangements, authorizations, and background-check information. Verification is point-in-time: a Verification Source reviews what is before it as at the date of review and does not monitor afterwards.
This Privacy Policy does not name individual Verification Sources. Really Global may add, remove, change, or substitute a Verification Source, and the Verification Sources engaged from time to time are identified to the Company through the Technology Platform and through the applicable verification workflow. Each Verification Source acts as an independent controller of the information it collects and of any report it produces, and a Company may exercise rights in respect of that report directly with the applicable Verification Source under applicable consumer-reporting, background-check, or Data Protection Law. We do not share Client Personal Information with a Verification Source.
For Legal and Safety Reasons
We may share Personal Information when required or permitted by law, including in response to subpoenas, court orders, regulatory inquiries, law-enforcement requests, or other legal process; to enforce the Agreement; to protect the rights, safety, or property of Really Global, Companies, Clients, or others; to investigate or address fraud, security issues, or violations of the Agreement; or to comply with legal obligations.
In Business Transfers
If Really Global is involved in a merger, acquisition, financing, sale of equity or assets, reorganization, or similar business transaction, your Personal Information may be transferred to the successor or acquirer entity, subject to standard confidentiality protections and applicable Data Protection Law.
With Your Consent
We may share Personal Information for any other purpose with your consent. Where consent is the legal basis, you have the right to withdraw your consent at any time.
What We Do Not Share
We do not sell your Personal Information in the colloquial sense — we are not paid by anyone for your Personal Information. In California, however, the CCPA/CPRA defines “sale” broadly to include certain types of sharing for purposes other than the strict performance of services; please see Section 11 (California Privacy Notice) for the CCPA/CPRA-specific characterization. We do not share Mental Health Services Information (session content, clinical notes, etc.) with Third Parties for advertising, marketing, or any commercial purpose unrelated to providing the Technology Platform.
7. Cookies and Tracking Technologies
We use cookies and similar technologies (including web beacons, pixels, local storage, referral tokens, and similar identifiers) to operate the Technology Platform, remember your preferences, support security and fraud prevention, administer first-party affiliate attribution, and conduct analytics about how the Technology Platform is used. We use a combination of our own cookies, cookies set by our Sub-Processors (including Mixpanel and Google Analytics for analytics), and other technologies.
Affiliate attribution may use first-party links, referral tokens, cookies, local storage, or server-side records to connect an eligible interaction with a later qualifying account event. Where applicable law requires consent for the storage or access method used, Really Global will not use that non-essential method before consent. Browser restrictions, consent choices, deletion, or expiry may prevent attribution, and Really Global does not guarantee that every interaction will be attributed.
You may control your cookie preferences through your browser settings, through the cookie preferences interface made available on the Technology Platform, or through the opt-out mechanisms described in this Privacy Policy. Opting out of certain cookies may affect the functionality of the Technology Platform.
For further information, please see our Cookie Notice, available through the Technology Platform.
Consent Management Platform
Consent Management Platform. Really Global uses CookieYes (https://www.cookieyes.com), a third-party Consent Management Platform, to (i) detect and categorize cookies and similar technologies set on the Technology Platform; (ii) display a geo-targeted consent banner that, for European Economic Area, United Kingdom, and Swiss visitors, requires affirmative opt-in consent before any non-essential cookie or tracker is set, in accordance with the EU ePrivacy Directive (Directive 2002/58/EC, as amended) and equivalent national implementations; (iii) display, for California and other US visitors, the opt-out controls and “Do Not Sell or Share My Personal Information” links required by the CCPA/CPRA and similar US state laws; (iv) automatically block non-essential third-party scripts (including analytics, pixels, and similar trackers) until the visitor has provided the applicable consent; (v) log each visitor’s consent record (consent status, date and time, and where permitted by law a hashed or anonymized identifier such as an anonymized IP address) for compliance and audit purposes; and (vi) allow visitors to withdraw or change their consent at any time through a persistent “cookie preferences” control accessible on the Technology Platform.
Global Privacy Control and Browser Signals
Global Privacy Control and Browser Signals. Really Global, through its CookieYes integration and platform configuration, automatically recognizes and honors the Global Privacy Control (“GPC”) browser signal as a valid opt-out of “sale” and “sharing” of Personal Information for purposes of the CCPA/CPRA and as a valid opt-out of targeted advertising under any other Data Protection Law that recognizes the GPC signal (including the relevant US state comprehensive privacy laws). Really Global also recognizes Do Not Track signals where required by applicable law. This Section, together with our published Cookie Notice, is intended to satisfy the disclosure obligations of the California Online Privacy Protection Act (Cal. Bus. & Prof. Code §§ 22575–22579, “CalOPPA”), including the obligation to describe how Really Global responds to GPC and Do Not Track signals.
8. Data Security
We implement administrative, technical, and organizational measures designed to protect Personal Information against unauthorized access, disclosure, alteration, or destruction. Our measures include:
Encryption: Personal Information is encrypted in transit using industry-standard TLS, and at rest using AES-256 or equivalent encryption where applicable, within our Microsoft Azure infrastructure.
Access controls: Access to Personal Information is restricted to authorized personnel on a need-to-know basis, with role-based access controls and multi-factor authentication for production system access.
Infrastructure: Production systems are deployed in Microsoft Azure with appropriate network segmentation, redundancy, and disaster-recovery configurations.
Monitoring: Security monitoring, logging, and alerting systems detect and respond to potential security incidents.
Personnel: Our personnel are subject to confidentiality obligations and receive appropriate training on data protection and information security.
Sub-Processor management: Sub-Processors are subject to written agreements requiring substantially similar data-protection obligations.
Incident response: We maintain a documented incident-response process for detecting, reporting, and responding to Personal Data Breaches in accordance with the DPA and applicable Data Protection Law.
No system, transmission, or storage method can be guaranteed to be completely secure. You are responsible for taking reasonable steps to protect your account credentials, devices, internet connection, and physical environment when using the Technology Platform. If you believe your account has been compromised, contact us immediately through our customer support page.
We are committed to notifying you of any Personal Data Breach affecting your Personal Information without undue delay, in accordance with applicable Data Protection Law (including, where applicable, GDPR’s 72-hour notification standard and analogous state-law requirements).
9. International Data Transfers
Really Global is based in the United States. We may transfer Personal Information to, store it in, or process it in the United States and other countries, including countries that may not have data-protection laws equivalent to those of your country of residence.
Where we transfer Personal Information subject to the GDPR or UK GDPR from the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses (the “EU SCCs,” Implementing Decision (EU) 2021/914), the UK International Data Transfer Addendum (UK IDTA), the Swiss FADP supplementary measures, or another valid transfer mechanism as further described in the DPA.
Where realtime audio translation is active during a session, audio is processed in real time by OpenAI (United States) and Google (United States) infrastructure as Sub-Processors. International transfers in connection with realtime audio translation are governed by the same transfer mechanisms described above (EU SCCs, UK IDTA, Swiss FADP supplementary measures, and, where applicable, the safeguards described in the DPA). Audio processed for realtime audio translation is transient and not retained by Really Global in identified form; see Section 17.
For further information about international transfers, including a copy of the EU SCCs or UK IDTA we use, please contact us through our customer support page.
10. Your Rights — Universal
Depending on your location and the applicable Data Protection Law, you have rights with respect to your Personal Information. We honor these rights in accordance with the relevant law and the response timelines it requires.
Right of Access
You may request a copy of the Personal Information we hold about you.
Right to Correct
You may request that we correct Personal Information about you that is inaccurate or incomplete.
Right to Delete (Erasure)
You may request that we delete Personal Information about you, subject to legal-retention requirements and other limited exceptions described in this Privacy Policy.
Right to Portability
You may request a copy of certain Personal Information in a structured, commonly used, machine-readable format.
Right to Withdraw Consent
Where we process your Personal Information based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
Right to Object / Opt Out
You may object to certain processing of your Personal Information, including for direct marketing or, in certain cases, for processing based on legitimate interests. You may also opt out of the “sale” or “sharing” of your Personal Information as defined under applicable U.S. state Data Protection Law.
Right Not to Be Subject to Automated Decision-Making
You have the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you. Really Global does not engage in solely automated decision-making of that type in connection with the Technology Platform.
Right to Lodge a Complaint
You have the right to lodge a complaint with the supervisory authority in your country, state, region, or other jurisdiction. See Section 14 (EU/UK/Swiss Privacy Notice) for specific guidance for EU/UK/EEA/Swiss residents.
How to Exercise Your Rights
You may exercise your rights by: – Logging into your account, navigating to Menu > My Account (or Account Settings) > My Personal Information, and using the in-product workflows for access, correction, and deletion; – Contacting us through our customer support page; or – Where applicable, emailing [email protected].
If you do not hold an account with Really Global — for example, because you are a Named Individual whose details a Company has published on its profile — you may exercise your rights by emailing [email protected]. We will not require you to create an account in order to make a request. Because we hold only the limited information the Company has provided about you, we will verify your request using that information together with whatever you provide with your request, and we will not collect additional Personal Information about you in order to verify it beyond what is reasonably necessary to confirm that the request relates to you.
Before fulfilling your request, we will take reasonable steps to verify your identity using the information available to us. We will respond within the timelines required by the applicable Data Protection Law (generally 30 calendar days under the GDPR; 45 calendar days under the CCPA/CPRA; and similar timelines under other state Data Protection Laws). We may extend these timelines where permitted by law and will notify you of any extension.
In some cases, we may decline part or all of your request where the Personal Information is necessary to comply with legal obligations, where another individual’s rights would be infringed, where the information is subject to a litigation hold, or where the information must be retained under the DPA or applicable law. In such cases, we will explain the basis for our decision.
11. California Privacy Notice — CCPA / CPRA
This Section supplements the rest of this Privacy Policy with respect to California residents. It is intended to comply with the California Consumer Privacy Act and California Privacy Rights Act (collectively, “CCPA/CPRA”) and the California “Shine the Light” Law (Civil Code Section 1798.83).
Notice at Collection
At or before the time we collect Personal Information from you, we provide the categories of Personal Information collected, the purposes for which we use it, whether we sell or share it for cross-context behavioral advertising, and how long we retain each category. The categories and purposes are described in Sections 3 and 4 of this Privacy Policy.
Categories of Personal Information Collected
In the preceding 12 months, we may have collected the following categories of Personal Information about California residents (as defined under the CCPA/CPRA):
Identifiers (name, email, phone, account ID, device ID, IP address);
Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e));
Protected classification characteristics (such as age, where you choose to provide it);
Commercial information (transaction records, services purchased);
Internet or other similar network activity (usage data, telemetry);
Geolocation data (approximate location from IP address; precise geolocation is not collected unless you provide an address);
Sensory data (limited; session content is processed as Data Processor on Company’s behalf);
Professional or employment-related information (where applicable to Companies, not to Clients);
Sensitive Personal Information (including health information; mental health information; emergency contact information);
Categories of Sensitive Personal Information We Collect
Categories of Sensitive Personal Information We Collect. The categories of Sensitive Personal Information we may have collected about California residents in the preceding 12 months include, without limitation: (a) health and medical information, including mental health information, treatment status, disability information, and Mental Health Services Information; (b) precise geolocation (only where the Client provides an address or expressly enables a precise-location feature); (c) racial or ethnic origin (only where the Client chooses to provide it, including for purposes of provider matching); (d) sexual orientation (only where the Client chooses to provide it, including for purposes of provider matching); (e) religious or philosophical beliefs (only where the Client chooses to provide it); (f) the contents of mail, email, or text messages between the Client and the Company sent through the Technology Platform, in each case as described in this Privacy Policy; (g) Social Security, driver’s license, state identification card, or passport number (collected only where required for identity verification or government reporting); (h) account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account; and (i) any other category of Sensitive Personal Information designated as such by the CCPA/CPRA. Really Global does not knowingly collect biometric information or genetic data in the ordinary course. Realtime audio translation processes voice as audio in real time for the sole purpose of producing translated speech; it does not extract, generate, or store voiceprint or other biometric identifiers, and Really Global does not use it to identify any individual.
Non-public education information (where applicable, in the limited circumstances FERPA may apply).
Sources of Personal Information
We collect Personal Information from: (a) you directly; (b) your use of the Technology Platform; (c) Companies you choose; (d) Sub-Processors that operate on our behalf; and (e) where applicable, social media or other external platforms you authorize.
Purposes for Collection and Use
The business and commercial purposes for which we collect and use Personal Information are described in Section 4 of this Privacy Policy.
Sharing and Sale
We do not “sell” Personal Information in the colloquial sense and are not paid for Personal Information. The CCPA/CPRA defines “sale” broadly. Subject to your cookie preferences, certain analytics and platform-operational cookies may be considered a “sale” or “sharing” of Personal Information under the CCPA/CPRA. You may opt out of this through the cookie preferences interface on the Technology Platform or by using the Global Privacy Control (GPC) browser signal where supported.
Your CCPA/CPRA Rights
California residents have the following rights: – Right to know what Personal Information we have collected, used, shared, or sold; – Right to correct inaccurate Personal Information; – Right to delete Personal Information, subject to permitted exceptions; – Right to opt out of the sale or sharing of Personal Information for cross-context behavioral advertising; – Right to limit use of Sensitive Personal Information to specific permitted purposes; – Right to non-discrimination for exercising any of these rights.
To exercise your CCPA/CPRA rights, see Section 10 (How to Exercise Your Rights). You may also designate an authorized agent to make a request on your behalf, subject to the verification requirements described above.
Right to Limit Use of Sensitive Personal Information
Right to Limit Use of Sensitive Personal Information. California residents have the right under the CCPA/CPRA to limit Really Global’s use and disclosure of Sensitive Personal Information to the purposes permitted by Cal. Code Regs. tit. 11, § 7027 — that is, to perform the services reasonably expected by the Client, prevent security incidents and malicious or fraudulent activity, resist deceptive or illegal actions, ensure physical safety, perform short-term transient uses (subject to the limits in the regulation), perform services on behalf of the business such as servicing accounts or order fulfillment, and verify or maintain the quality or safety of services that Really Global provides. Really Global does not use Sensitive Personal Information to infer characteristics about Clients, nor for any other purpose that is not described in Section 4 of this Privacy Policy or that is outside the scope of Cal. Code Regs. tit. 11, § 7027. You may exercise this right at any time through the mechanism described in Section 10.
Shine the Light Law
California’s “Shine the Light” law (Civil Code Section 1798.83) permits California residents to request information about disclosures of Personal Information to third parties for those parties’ direct-marketing purposes. We do not share Personal Information with third parties for their direct-marketing purposes. If you would like further information, please contact us through our customer support page.
12. Washington My Health My Data Act (WA MHMDA)
If you are a Washington resident or your Personal Information is otherwise subject to the Washington My Health My Data Act (the “WA MHMDA”), this Section provides additional information and rights specific to “consumer health data” (as defined under the WA MHMDA).
Consumer Health Data We Process
The categories of Personal Information described in Section 3 of this Privacy Policy that may constitute consumer health data under the WA MHMDA include: Account and Profile Information (where it includes health information), Onboarding and Intake Information, Mental Health Services Information, Communications with Companies, certain Client Interaction and Platform Usage Information (where it reveals health status), and any Personal Information that identifies past, present, or future physical or mental health status.
Lawful Basis and Consent
We process your consumer health data on the bases described in Section 4 of this Privacy Policy, including where necessary to provide the Mental Health Services you have requested, where required by law, and otherwise where authorized by you in accordance with the WA MHMDA. We do not sell, share for cross-context behavioral advertising, or use for targeted advertising any of your consumer health data, and we will not collect or share your consumer health data outside of the purposes described in this Privacy Policy without your consent where the WA MHMDA requires it.
Consent for Collection or Sharing; Authorization for Sale
Consent for Collection or Sharing. Where RCW 19.373.030 requires Really Global to obtain consent before collecting or sharing consumer health data, Really Global will obtain that consent before the collection or sharing begins. The consent request will clearly and conspicuously disclose (i) the categories of consumer health data collected or shared; (ii) the purpose of the collection or sharing, including the specific ways the data will be used; (iii) the categories of entities with whom the consumer health data will be shared; and (iv) how the consumer may withdraw consent from future collection or sharing. Consent to share consumer health data will be separate and distinct from consent to collect it. Authorization for Sale. Really Global does not sell consumer health data. If Really Global proposes to sell consumer health data in the future, Really Global will first obtain the separate valid authorization required by RCW 19.373.070 and comply with all other applicable notice and legal requirements before any sale.
WA MHMDA-Specific Rights
In addition to the rights described in Section 10, Washington residents have the following rights under the WA MHMDA: – Right to confirm whether Really Global is processing your consumer health data; – Right to access specific consumer health data; – Right to withdraw consent from collection or sharing of consumer health data; – Right to deletion of consumer health data, subject to the limited exceptions in the WA MHMDA; – Right to appeal a denied request.
Geofencing Restriction
We do not implement geofences around in-person healthcare facilities for the purpose of identifying or tracking consumers seeking healthcare services, or to collect consumer health data, or to send notifications about consumer health data, in violation of RCW 19.373.020(2).
How to Exercise WA MHMDA Rights
See Section 10 (How to Exercise Your Rights). The WA MHMDA also provides a private right of action for violations.
13. Other US State Consumer Health Data and Comprehensive Privacy Laws
This Section provides additional information and rights for residents of other US states whose laws apply to our processing of your Personal Information.
Connecticut Data Privacy Act and Connecticut Act Concerning Consumer Health Data (“CT CHDA”)
Connecticut residents have rights with respect to consumer health data substantially similar to those described in Section 12 for Washington residents, including the right to access, correct, delete, and withdraw consent. We process your consumer health data as described in this Privacy Policy and obtain authorization where the CT CHDA requires it.
Nevada Consumer Health Data Privacy Act (“NV SB 370”)
Nevada residents have rights with respect to consumer health data substantially similar to those described in Section 12 for Washington residents, including the right to confirm, access, delete, and withdraw consent. We obtain authorization where the NV SB 370 requires it.
Colorado, Florida, Virginia, Utah, Connecticut (General), Texas, Oregon, Montana, Tennessee, Indiana, Iowa, Delaware, New Hampshire, New Jersey, and Other US State Privacy Laws
Residents of these and similarly-situated US states have rights with respect to their Personal Information including, depending on the applicable law: – Right to access, correct, and delete Personal Information; – Right to data portability; – Right to opt out of the sale of Personal Information, targeted advertising, or significant profiling; – Right to limit use of sensitive data; – Right to appeal a denied request.
To exercise rights under these laws, please see Section 10 (How to Exercise Your Rights). Where applicable, we will respond within the timelines required by each law (typically 45 days, with permitted extensions).
14. EU / UK / Swiss Privacy Notice — GDPR / UK GDPR / Swiss FADP
This Section provides additional information for residents of the European Economic Area, the United Kingdom, or Switzerland (collectively, “European Residents”). It supplements the rest of this Privacy Policy and should be read together with the DPA, which governs the contractual data-protection arrangement.
Identity of the Controller
For Personal Information described in Section 3 as processed by Really Global as Data Controller, the Controller is Alden Global Inc., d/b/a Really Global, 28 Geary Street, Suite 650 #1031, San Francisco, CA 94108, USA.
Lawful Bases
We process your Personal Information on the bases set forth in Section 4 of this Privacy Policy. For Sensitive Personal Information (Article 9 GDPR data), our lawful bases include: (a) explicit consent (Article 9(2)(a)); (b) provision of healthcare under Article 9(2)(h); (c) protection of vital interests in emergency circumstances under Article 9(2)(c); and (d) the establishment, exercise, or defense of legal claims under Article 9(2)(f), depending on the specific processing activity.
Your GDPR / UK GDPR Rights
European Residents have the following rights: – Right of access (Article 15); – Right to rectification (Article 16); – Right to erasure (Article 17), subject to permitted exceptions; – Right to restriction of processing (Article 18); – Right to data portability (Article 20); – Right to object (Article 21); – Right not to be subject to automated decision-making (Article 22); – Right to withdraw consent (Article 7(3)); – Right to lodge a complaint with the supervisory authority (Article 77).
Right to Lodge a Complaint
If you are located in the European Union or the European Economic Area, you have the right under Article 77 of the GDPR to lodge a complaint with the Supervisory Authority of the Member State in which you reside, work, or where you believe an infringement of the GDPR has taken place. If you are located in the United Kingdom, you have the equivalent right to lodge a complaint with the United Kingdom Information Commissioner’s Office (ICO) at ico.org.uk. If you are located in Switzerland, you may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC).
International Data Transfers
See Section 9 (International Data Transfers) for the transfer mechanisms we use, including the EU SCCs, UK IDTA, and Swiss FADP measures.
Privacy Contact
Really Global maintains an internal Privacy Contact who handles inquiries about this Privacy Policy and Really Global’s processing of Personal Information. To reach our Privacy Contact, please email [email protected] or write to the address above. Really Global has not formally appointed a Data Protection Officer (“DPO”) under Article 37 of the GDPR at this time, because Really Global’s current scale of processing does not meet the mandatory-appointment thresholds set out in Article 37(1). Where applicable Data Protection Law requires Really Global to appoint a formal DPO (for example, where the scale or nature of Really Global’s processing of special categories of personal data crosses the Article 37 thresholds), Really Global will appoint a qualified DPO that meets the independence and expertise requirements of Articles 37 through 39 of the GDPR and any other applicable law. If you believe Really Global is required to have appointed a DPO and has not done so, please contact our Privacy Contact.
EU AI Act
Where applicable, our use of artificial intelligence and machine-learning systems on the Technology Platform complies with the EU AI Act (Regulation (EU) 2024/1689), including its transparency, risk-classification, and oversight requirements. See Section 5 (Artificial Intelligence and Machine Learning) for further information.
Data Protection Impact Assessments
Data Protection Impact Assessments. Where applicable Data Protection Law (including Article 35 of the GDPR, the corresponding provisions of the UK GDPR, and the Swiss FADP) requires a Data Protection Impact Assessment (a “DPIA”) in connection with processing of Personal Information through the Technology Platform — including where the processing is likely to result in a high risk to the rights and freedoms of natural persons — Really Global will (i) where Really Global acts as Data Controller, conduct or cause to be conducted a DPIA that meets the requirements of applicable Data Protection Law, including the criteria set out in Article 35(7); (ii) where Really Global acts as Data Processor, provide the Company (acting as Data Controller) with such reasonable assistance and information as is necessary for the Company to complete its DPIA in accordance with Article 35 and, where required, prior consultation with the supervisory authority under Article 36; and (iii) maintain a record of completed DPIAs and any consultations with supervisory authorities, available to relevant regulators upon lawful request.
14A. India — Digital Personal Data Protection Act, 2023 (DPDPA)
If you are a Data Principal under India’s Digital Personal Data Protection Act, 2023 (the “DPDPA”) and rules and notifications issued under it, you have rights with respect to your Personal Data including: (a) the right to obtain a summary of Personal Data being processed and the identities of any other Data Fiduciaries and Data Processors with whom your Personal Data has been shared; (b) the right to correction, completion, updating, and erasure of your Personal Data; (c) the right to grievance redressal through Really Global; and (d) the right to nominate another individual to exercise your rights in the event of your death or incapacity.
Consent
Consent. Really Global obtains your consent before processing your Personal Data in connection with the Technology Platform, except where processing is permitted on a “legitimate use” basis under Section 7 of the DPDPA. You may withdraw your consent at any time, and Really Global will cease processing your Personal Data for the consented purpose within a reasonable time, except where retention is required by law.
Cross-Border Transfers
Cross-Border Transfers. Really Global may transfer your Personal Data outside India to the United States and other countries in which Really Global, its Sub-Processors, and Companies operate. Such transfers are made in accordance with the cross-border transfer requirements of the DPDPA and any rules or notifications issued by the Government of India under Section 16 of the DPDPA.
Children Under 18
Children Under 18. The DPDPA defines a “child” as an individual below the age of eighteen (18) years and requires verifiable consent of a parent or lawful guardian before processing a child’s Personal Data. Really Global obtains verifiable parental or lawful-guardian consent before processing the Personal Data of any user identified as below eighteen (18) years and resident in India, in addition to and consistent with the consent requirements described in Section 16 of this Privacy Policy.
Grievance Officer
Grievance Officer. To exercise your DPDPA rights or to raise a grievance, contact Really Global at [email protected] or through our customer support page.
15. Non-Covered Entity Posture; Consumer Health Data Framework
Really Global operates a direct-pay marketplace. It does not accept insurance, and it does not conduct the electronic standard transactions — insurance claims, eligibility checks, remittance, and the like — that bring an organization within HIPAA as a “covered entity.” For that reason, Really Global is very likely not a HIPAA covered entity, it does not hold itself out as one, and it does not describe itself or its services as “HIPAA-compliant” or “HIPAA-certified.” Really Global also does not act as a HIPAA Business Associate as a standard matter, and it does not offer a Business Associate Agreement as part of its ordinary terms.
If the Company providing your Mental Health Services is itself a HIPAA covered entity — for example, a provider who separately bills insurance in another practice — that status belongs to the Company, not to Really Global. In that case the Company, not Really Global, is responsible for meeting its own HIPAA obligations and for giving you its own Notice of Privacy Practices.
The fact that HIPAA does not apply to the marketplace does not leave your health information unprotected. Really Global protects it under the privacy laws that do apply — several of which reach further than HIPAA. These include the California Confidentiality of Medical Information Act (Cal. Civ. Code §§ 56–56.37, the “CMIA”), which, following Assembly Bill 2089 (2022), treats a business that offers a “mental health digital service” as a “provider of health care” subject to the CMIA’s confidentiality requirements; the Washington My Health My Data Act (RCW ch. 19.373, “MHMDA”), which protects consumer health data outside HIPAA, requires opt-in consent to collect or share that data and a separate authorization to sell it, and gives consumers a private right of action; the California Consumer Privacy Act and California Privacy Rights Act (Cal. Civ. Code § 1798.100 et seq., “CCPA/CPRA”), which treat information about your health as “sensitive personal information” you can direct us to limit; the EU and UK General Data Protection Regulation, under which health data is “special category” data protected by Article 9; and, because Really Global operates globally, comparable regimes including Canada’s PIPEDA, Brazil’s LGPD, South Africa’s POPIA, and India’s Digital Personal Data Protection Act, 2023. Really Global maintains a standalone Consumer Health Data Privacy Policy written to these regimes.
Rather than rely on a compliance label, Really Global protects your information through measures it can stand behind: encryption in transit, and at rest where applicable; access controls that limit who can see your data; opt-in consent for health data and data minimization; and a firm commitment that Really Global does not sell your personal data and does not share your health data with advertisers.
Federal Trade Commission Health Breach Notification Rule
Federal Trade Commission Health Breach Notification Rule. Where a Company providing Mental Health Services is not a HIPAA Covered Entity or Business Associate but is otherwise subject to the Federal Trade Commission’s Health Breach Notification Rule (16 CFR Part 318, the “FTC HBNR”) as a “vendor of personal health records” or related entity, Really Global supports the Company in (i) determining whether a security event involving unsecured personally identifiable health information has triggered the FTC HBNR’s notification obligations and (ii) providing the notifications required by the FTC HBNR to affected individuals, to the Federal Trade Commission, and (where applicable) to the media, in each case within the timeframes the FTC HBNR specifies. Really Global maintains its incident-response process consistent with these obligations and will cooperate in good faith with any FTC HBNR investigation.
California Confidentiality of Medical Information Act
California Confidentiality of Medical Information Act. Where the Company is subject to the California Confidentiality of Medical Information Act (Cal. Civ. Code §§ 56–56.37, “CMIA”) — for example, as a “provider of health care,” “health care service plan,” “pharmaceutical company,” or “contractor” under the CMIA — Really Global supports the Company’s CMIA obligations through Really Global’s role as the Company’s service provider. Really Global will use and disclose “medical information” (as defined by the CMIA) only as the Company directs and as the CMIA permits, including the requirement that medical information be released only with a valid CMIA-compliant authorization or as otherwise expressly authorized by law.
Federal Substance Use Disorder Confidentiality (42 CFR Part 2)
Federal Substance Use Disorder Confidentiality (42 CFR Part 2). Really Global does not currently make the Technology Platform available to Companies that are “Part 2 programs” within the meaning of 42 CFR § 2.11. Really Global does not currently undertake to act as a “qualified service organization” or enter into a qualified service organization agreement. If Really Global receives information subject to Part 2 despite this restriction, Really Global will handle that information as required by applicable law.
16. Children and Minors
The Technology Platform is intended primarily for use by adults. Access to the Technology Platform and to Mental Health Services is subject to age-eligibility requirements that vary by country and, in the United States, by state. At signup, Really Global determines your eligibility based on your date of birth, your country, and, if you are located in the United States, your state, in accordance with the age-of-consent rules that apply to your jurisdiction.
Limited Track for Minors
If you are below the applicable age of consent for medical or therapy treatment in your jurisdiction, you may still be eligible to access certain features of the Technology Platform on a limited basis, including non-licensed mental health coaching, mentoring, peer support, and similar services. Access to licensed mental healthcare services typically requires the consent of a parent or legal guardian.
Parental and Guardian Consent
Where parental or guardian consent is required by applicable law (including, as applicable, the Children’s Online Privacy Protection Act (COPPA) for US-resident Clients under 13, Article 8 of the GDPR for EU-resident Clients under the applicable national age threshold, the UK Age Appropriate Design Code for UK-resident Clients under 18, the California Age Appropriate Design Code (Cal. Civ. Code §§ 1798.99.28–.40) for California-resident Clients under 18, and similar rules in other jurisdictions), Really Global will request and capture that consent through the Technology Platform before unlocking the relevant features or licensed-provider access for the minor. The parent or guardian providing consent must (i) confirm their legal authority to consent on behalf of the minor and (ii) provide their own identifying and contact information.
India DPDPA. Where the user is resident in India, India’s Digital Personal Data Protection Act, 2023 (“DPDPA”) treats any individual below the age of eighteen (18) years as a “child” and requires verifiable consent of a parent or lawful guardian before processing the child’s Personal Data. See Section 14A for additional DPDPA-specific information.
State-Specific Notification
In certain US states (including, without limitation, Kansas, Massachusetts, and Minnesota), applicable law requires parental notification of minor treatment even where the minor self-consents. Where these rules apply, Really Global will surface the applicable notification requirement through the Technology Platform workflow.
Parents and Guardians Acting on Behalf of a Minor
If you are a parent, legal guardian, or other authorized representative using the Technology Platform on behalf of a minor or another person, you represent that you have the legal authority to do so under applicable law and that you are providing any required consents on that person’s behalf.
COPPA Compliance
If we learn that we have collected Personal Information from a child under 13 (in the United States) or below the applicable age in another jurisdiction without the required parental or guardian consent, we will promptly delete that information. If you believe we may have collected Personal Information from a child without required consent, please contact us through our customer support page.
17. Retention of Personal Information
We retain Personal Information for as long as necessary to fulfill the purposes described in this Privacy Policy, comply with our legal obligations, resolve disputes, enforce our agreements, and perform other lawful purposes. Our retention practices are as follows:
Account Information
We retain Account and Profile Information, Onboarding and Intake Information (other than content that is Mental Health Services Information), and similar account-level data for the duration of your active account and for a reasonable period thereafter to support re-engagement and to comply with legal obligations. After three (3) years of account inactivity (no login activity), we will commence erasure of Personal Information that is not subject to a legal-retention obligation or another permitted exception described below.
Company Account, Credential, and Named Individual Information
We retain Company account, profile, and credential information for the duration of the Company’s active account and for a reasonable period thereafter, on the same basis as Account Information above.
We display Personal Information about a Named Individual for as long as the Company displays it on the Company’s profile. Where the Company removes it, or where the status it relates to changes — for example, where a Company that recorded supervised practice becomes licensed — the information stops being displayed and is kept only as a record of what the Company published, so that we are able to answer a professional, regulatory, or legal inquiry about what appeared on the Company’s profile and to establish, exercise, or defend a legal claim. That record is retained for the duration of the Company’s active account and the period described under Account Information above. It is not displayed, is not used for any other purpose, is not used to evaluate or form any view about the Named Individual or the Company, and is not shared with any Third Party for advertising or marketing.
Where a Named Individual objects to the processing of their Personal Information, or asks us to erase it, we will erase it, subject only to the backup, archive, and disaster-recovery period described below and to any legal-retention obligation or litigation hold.
Mental Health Services Information
Because Really Global acts as Data Processor for Mental Health Services Information, the Company — not Really Global — determines the applicable retention period for that information based on the Company’s own professional, ethical, and legal record-retention obligations. State professional-licensing laws and ethical codes typically require Companies to retain clinical records for a period of years following the conclusion of treatment (frequently 7 years or longer for adults; longer for minors, often until the minor reaches a specified age plus several years). We retain Mental Health Services Information on the Company’s behalf for as long as the Company directs in accordance with the DPA (where applicable) and applicable law.
Realtime Translation Audio
Realtime Translation Audio. Audio processed in real time by translation Sub-Processors (OpenAI Realtime Translation API and Google Gemini Live API; see Section 6) for the sole purpose of producing translated audio during a live session is processed transiently and is not stored by Really Global. Translation provider sessions are terminated at the end of each translated session. By default, no raw audio, no source transcript, and no translated transcript from realtime audio translation is retained by Really Global in identified form. For the avoidance of doubt, aggregated, de-identified, anonymized, statistical, derivative, and benchmark data permitted under Section 5 and the Aggregated and De-Identified Data subsection of this Section 17 remains subject to those provisions.
Transaction and Payment Information
We retain Transaction and Payment Information for as long as required by applicable tax, accounting, and financial regulatory obligations, which is typically a minimum of seven (7) years.
Affiliate Program Records
We retain Affiliate Program acceptance and eligibility records, authoritative referral and attribution records, commission-ledger entries, adjustments, payout records, fraud and compliance records, disputes, and related audit evidence for as long as reasonably necessary to administer the program, meet tax and accounting obligations, resolve disputes, enforce our agreements, and comply with applicable law. Raw click and visit analytics may be retained for a shorter period. Expiration or deletion of an attribution cookie does not erase a valid referral, commission, payout, audit, or legal record that the cookie helped create.
Audit, Security, and Legal-Hold Records
We retain audit logs, access logs, security records, fraud-prevention records, dispute records, and similar records for the periods required or permitted by applicable law, professional or ethical standards, and our internal security and audit practices. These periods may exceed the retention periods for other categories of Personal Information.
Communications and Complaints Records
We retain records of your communications with our Customer Service, Trust and Safety, and Legal teams, including records of your data-subject requests and our responses, for the period required by applicable law, typically a minimum of three (3) years following the resolution of the matter.
Backups, Archives, and Disaster-Recovery Records
Personal Information may persist in encrypted backup, archive, and disaster-recovery systems for a period after deletion from production systems, typically up to ninety (90) days, as part of standard data-resilience practices.
Aggregated and De-Identified Data
We retain aggregated, de-identified, anonymized, statistical, derivative, and benchmark data indefinitely. Once data has been properly aggregated or de-identified, it no longer identifies you and is not subject to the retention limits applicable to identifiable Personal Information.
Erasure Requests
Where you request erasure of your Personal Information and we are required by applicable Data Protection Law to honor that request, we will erase the relevant Personal Information from our production systems without undue delay, and in any event within the timeline required by the applicable law (generally 30 calendar days under the GDPR; 45 calendar days under the CCPA/CPRA; and similar timelines under other state Data Protection Laws). We may decline to erase Personal Information that is necessary to comply with legal obligations, that is the subject of a litigation hold, that must be retained under the DPA, or that is otherwise excepted from the right to erasure under the applicable law.
What we retain after erasure. When we erase content you authored — for example, a review you wrote and its translated copies — we may keep a limited, non-displayed record of the underlying event for fraud prevention, trust and safety, and to establish, exercise, or defend legal claims. This record contains none of the free text you wrote and no direct identifiers; it is limited to an internal reference number, the provider concerned, a numeric rating, an approximate (month-level) date, version numbers, and the outcome of any moderation decision. We keep this limited record for up to 24 months after your erasure request and then delete it, unless a longer period is required to comply with a legal obligation or to establish, exercise, or defend a legal claim.
18. Direct Marketing Communications
We may send you direct-marketing communications about Really Global’s features, products, and services where you have consented to receive them or where applicable law otherwise permits us to do so. You can opt out of marketing communications at any time by: – Clicking the “unsubscribe” link in any marketing email; – Adjusting your communication preferences in your account settings; or – Contacting us through our customer support page.
Opting out of marketing communications does not affect service-related communications (such as appointment reminders, transaction confirmations, account notices, and similar non-marketing messages) that we need to send to operate the Technology Platform and provide the services you have requested.
19. Reporting Illegal Content and DSA Notice (EU Users)
If you are located in the European Union and you wish to report content that appears on the Technology Platform that you believe is illegal under applicable law, you may submit a report through our customer support page or by email to [email protected]. We will review the report in accordance with the EU Digital Services Act (Regulation (EU) 2022/2065) and applicable law. Where we take a content-moderation action affecting an EU recipient, we will provide a statement of reasons in accordance with Article 17 of the Digital Services Act.
20. Cross-Border Operations and International Users
Really Global operates globally and the Technology Platform may be accessed by users located in many countries. Where you are located outside of the United States, your Personal Information may be transferred to, stored in, and processed in the United States and other countries. We rely on appropriate safeguards for international transfers as described in Section 9.
Where the data-protection law of your country requires us to enter into specific agreements, register with local authorities, or implement specific safeguards before processing your Personal Information, we will do so before commencing or continuing processing in your jurisdiction. If you have questions about the data-protection arrangements in your jurisdiction, please contact us through our customer support page.
21. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you through the Technology Platform, by email, by in-product notice, or by another means permitted by applicable law. We encourage you to review this Privacy Policy periodically. Your continued use of the Technology Platform after the effective date of any update constitutes your acceptance of the updated Privacy Policy, to the maximum extent permitted by applicable law.
Where the applicable Data Protection Law requires us to obtain your fresh consent for a material change, we will do so before applying that change to your Personal Information.
22. Contact Us
If you have questions, comments, or concerns about this Privacy Policy or our handling of your Personal Information, please contact us:
Customer support: through the customer support page on the Technology Platform;
Privacy inquiries (including from EU, UK, EEA, and Swiss residents): by email to [email protected];
Legal notices: by email to [email protected];
By postal mail: Alden Global Inc., d/b/a Really Global, Attn: Privacy, 28 Geary Street, Suite 650 #1031, San Francisco, CA 94108, USA.
Last Updated: August 9, 2026
Version 8.18