This notice explains how we process personal data when you use the Exercise for ADHD website and programme portal (the “Service”). It is intended to align with the UK GDPR, the EU GDPR, and related UK/EU privacy and ePrivacy expectations.
1. Data controller
Insert your organisation’s legal name, registered address, and email address for privacy requests. Where you appoint a data protection officer or EU representative (if applicable), list them here.
2. What we collect
Depending on how you use the Service, we may process:
- Identity and contact: name, email address, optional phone number, programme preferences you submit.
- Health-related programme data: categories you choose during onboarding or check-ins (for example age range, ADHD-related selections, weekly wellbeing ratings, session logs). These may be considered special-category data under GDPR when they concern health; we rely on Article 9 permissions described below.
- Technical data: server logs may include IP address, user agent, and timestamps for security and troubleshooting.
- Marketing preferences: optional consent for promotional emails, including timestamps where we record consent or withdrawal.
3. Purposes and lawful bases (GDPR Articles 6 & 9)
Providing the programme: contract (Art. 6(1)(b)) — running your account, programme sessions, adherence metrics, and operational emails you request (for example reminders).
Health-related inputs you voluntarily provide: explicit consent (Art. 9(2)(a)) and, where applicable, substantial public interest / healthcare purposes as implemented under national law — document the exact Article 9 basis your clinician or legal adviser confirms for your jurisdiction.
Marketing emails: consent (Art. 6(1)(a)); you may withdraw consent at any time via account settings or by contacting us, without affecting the lawfulness of processing before withdrawal.
Security, abuse prevention, legal claims: legitimate interests (Art. 6(1)(f)) or legal obligation (Art. 6(1)(c)) as applicable.
4. Cookies, local storage, and similar technologies
We keep use of non-essential trackers to a minimum. The programme portal stores a session token in the browser’s
local storage (key similar to ea_jwt) so you stay signed in between visits. This is
necessary for the authentication feature you choose to use; it typically lasts until you sign out or the token expires.
We do not use this storage for third-party advertising profiles through this policy version. If you later enable optional analytics or marketing pixels, we will update this notice, record consent where required, and provide granular controls where feasible.
5. International transfers
If personal data is processed outside the UK or EEA (for example via cloud hosting), we use appropriate safeguards such as UK International Data Transfer Agreements / EU Standard Contractual Clauses and supplementary measures as required.
6. Retention
We retain account and programme data only as long as needed for the purposes above, including legal, accounting, or reporting requirements. Marketing consent records may be kept to demonstrate compliance. Specific retention periods should be filled in by the controller (for example: active account + 7 years for relevant health-fitness records where applicable — confirm with your adviser).
7. Your rights
Under UK GDPR / EU GDPR you may have the right to:
- Access your data (including data portability where applicable);
- Rectify inaccurate data;
- Erase data (“right to be forgotten”) where conditions are met;
- Restrict or object to certain processing;
- Withdraw consent for consent-based processing;
- Lodge a complaint with the ICO (UK) or your EU supervisory authority.
The portal offers a JSON export of account-associated data where implemented. For erasure or other requests, contact us using the details in section 1 and describe your request; we may need to verify your identity.
8. Children
The Service is not directed at children without appropriate parental authority or clinical context. If you believe we have collected data from a minor in error, contact us to delete it.
9. Updates
We may update this Privacy Policy. Material changes will be reflected by a new version date; where required we will ask you to confirm acceptance in the portal.
10. Accessibility
We aim for semantic structure, readable contrast, and keyboard-accessible navigation on our public pages. If you need an alternative format of this notice, contact us using the details in section 1.
