Explicit Consent to the Processing of Special-Category Personal Data

Version 1.2. The current version is published in the app.

Effective from 9 September 2026.

This Consent concerns information about the User’s psychological state, health, private life and DBT practice in WisemindApp. The current registration screen accepts it together with the Terms of Use and Privacy Policy through one checkbox: there is no version of the Service that operates without processing this data.

1. Controller

Digital Vanguard LLC
Date of incorporation: 8 January 2026

Registration number: 56381280

Tax identification number: 08313488

Address: Premises 239, 2/2 Anastas Mikoyan Street, Yerevan, Republic of Armenia

Email: [email protected]

Additional email: [email protected]

Referred to below as the “Controller”.

The contact details of the Controller’s representatives in the EEA and United Kingdom, and any Data Protection Officer, must match the Privacy Policy.

2. Data Subject and Identification Method

2.1. The data subject is the adult User giving this Consent.

2.2. Consent is linked to the account and the acceptance log. The log retains:

The User can view the Consent recorded in this way within the Service under “More” → “Account” → “What you agreed to”.

2.3. If applicable law requires written consent to contain additional identifying details, an address, identity-document details or a particular form of electronic signature, the Controller must obtain those details and signature before the relevant processing begins. An ordinary tick-box is not a substitute for a mandatory form.

3. Choice and Age

3.1. The User confirms that they are at least 18, act freely and in their own interests, and understand this Consent.

3.2. The User may decline Consent. Because the diary card, worksheets, state tracking and safety plan are fundamental to the Service, an account is not created without this Consent; an existing account is deleted following withdrawal. The present registration design uses one checkbox to accept this Consent, the Terms of Use and the Privacy Policy because there is no version of the Service that operates without this processing. The decision required for EEA and UK consent design is identified above and in section 14.

3.3. This Consent is intended to be specific, informed, explicit and unambiguous. It does not cover advertising, sale of data, training of artificial-intelligence models or any purpose not listed below.

3.4. For Users to whom the GDPR or UK GDPR applies, this Consent is intended to constitute EXPLICIT CONSENT to the processing of health data and other special-category personal data under Article 9(2)(a) GDPR or UK GDPR, together with consent under Article 6(1)(a). Contract administration that is objectively necessary to provide the requested Service may additionally rely on Article 6(1)(b), but that basis does not replace the Article 9 condition. Consent concerns the health and psychological-state data listed in section 4 and is separate in purpose from consent to any other processing. It may be withdrawn at any time using the methods in section 12, as easily as it is given once the required separate consent control has been implemented.

4. Data Covered

The User consents to the processing of the following data entered by the User or generated through use of the features:

  1. emotional and psychological state, mood and changes in state;
  2. impulses, urges, intensity of experiences and target behaviours;
  3. diary card, skill records and DBT practice history;
  4. worksheet answers, free-text fields and exercise results;
  5. assigned and completed homework and comments;
  6. safety plan, including warning signs, distractions, reasons for living and safety measures;
  7. names, relationships and contact details of people added by the User to the safety plan;
  8. selected emergency and psychological-support numbers;
  9. the fact, time, recipient, status and withdrawal of an “I’m overwhelmed” alert;
  10. connection with a Therapist and history of granting and withdrawing access;
  11. Therapist notes about the Client, if the feature is used;
  12. information about assignment completion, session attendance and DBT Group participation to the extent that it reveals psychological practice;
  13. technical identifiers required for secure storage, access controls and confirmation of actions involving the data above.

These fields may contain health data, information about mental health, private and family life, and other special-category or sensitive personal data.

5. Purposes of Processing

The Controller processes the data only to:

  1. maintain an electronic diary card and DBT practice history;
  2. save and display worksheets, skills, exercises and homework;
  3. provide the User with tools for observing their own state;
  4. create and use a personal safety plan;
  5. send an alert to a connected Therapist following a separate action by the User;
  6. give a particular Therapist access to permitted records following a separate expression of the User’s choice;
  7. operate a DBT Group without disclosing individual health records to participants;
  8. maintain security, prevent unauthorised access, and evidence grants and withdrawals of access;
  9. provide technical support and correct an error following a request by the User;
  10. evaluate how the Service performs using product analytics, including the fact that crisis features were used, without transferring the content of records;
  11. comply with mandatory law and establish, exercise or defend legal claims, strictly to the extent necessary.

Ordinary processing for purposes 1–10 relies on the explicit consent described in clause 3.4. Processing that is strictly necessary for legal claims may rely on Article 9(2)(f) GDPR or UK GDPR rather than consent, and an exceptional disclosure necessary to protect vital interests may rely on Article 9(2)(c) only where its legal conditions are met. These exceptions are not used to avoid obtaining consent for the Service’s ordinary features.

6. Processing Operations and Methods

6.1. The Controller may carry out the following operations: collection, receipt, recording, organisation, accumulation, storage, correction, updating, retrieval, matching, use, provision of access, transfer to authorised providers, blocking, restriction, anonymisation, deletion and destruction.

6.2. Processing is automated using information systems and, where necessary, involves an authorised member of staff for support, security, incident investigation or compliance with a lawful requirement.

6.3. Clinical content must not intentionally be placed in advertising or analytics systems or general technical logs. A crisis-path event may itself reveal health information even without clinical text; such events are transferred to product analytics only as the fact of use described in clause 9.5, and that processing is authorised by purpose 10 of section 5 and by this Consent.

7. Therapist Access

7.1. This Consent allows the Controller to store the data within the Service but does not automatically grant any Therapist access.

7.2. Access for a particular Therapist is granted through a separate, verifiable action by the User. The log records the Therapist, the time of granting access, the version of the notice and the time of withdrawal.

7.3. While access is active, the Therapist may read the records made available by the Service, including the diary card, worksheets, target behaviour information, assignments and safety plan. The Therapist cannot alter entries on the User’s behalf.

7.4. Membership of a DBT Group does not give trainers or participants access to individual health information. Such access arises only from a separate Client–Therapist connection.

7.5. The User may withdraw a particular Therapist’s access at any time in settings. Withdrawal stops future access through the Service but cannot technically delete copies that the Therapist lawfully created outside the Service before withdrawal. The Therapist is responsible for such external copies.

8. Crisis Alert

8.1. The User decides whether to send an “I’m overwhelmed” alert to a connected Therapist.

8.2. An email or push notification may contain the User’s name or pseudonym, the fact that an alert was sent or withdrawn, the time and a link to a protected area of the Service. The text of the diary card, worksheets and safety plan is not included in the message.

8.3. The User understands that sending an alert does not guarantee delivery, reading, a response or help. WisemindApp is not an emergency service and does not automatically call one.

8.4. An unanswered alert ceases to be shown as active after 24 hours. A notification of a crisis event may be retained for up to 180 days, as described in the Privacy Policy.

9. Authorised Providers and Recipients

9.1. The Controller may use the providers listed in the Privacy Policy for technical processing: Supabase for the database, authentication and storage in the principal Frankfurt, Germany region; Vercel for hosting and server functions, with processing potentially in the United States; Resend for service emails; Sentry for technical error reports in the European Union; and Amplitude and Google Analytics for analytics. Amplitude and Google Analytics must not receive clinical content or the content of special-category records. Polar Software acts as merchant of record for international subscription sales, and Boosty processes payments made through its platform; they receive payment metadata, not the clinical content covered by this Consent.

9.2. Providers receive only the data needed for hosting, storage, authentication, email delivery, security, technical support, analytics as strictly described in the Privacy Policy, or payment processing.

9.3. Before processing begins, the Controller must enter into the necessary controller–processor agreements, limit provider purposes, and satisfy international-transfer requirements.

9.4. Special-category data may be disclosed to a public authority without consent only where and to the extent expressly required by applicable law, or exceptionally to protect life where the law permits that disclosure.

9.5. The Controller uses product analytics to evaluate how the Service performs, including the fact that crisis features were used (the “I’m overwhelmed” screen, the safety plan, contacting support services), linked to an internal account identifier. The content of records, scale values and clinical indicators are not transferred to analytics.

10. International Transfers

10.1. The principal database may be hosted in Frankfurt, Germany. Individual providers may process technical or User data in the United States and other countries. The Controller is established in Armenia and may access data there.

10.2. For a restricted transfer from the EEA, the Controller must use an applicable adequacy decision or another valid Chapter V GDPR safeguard, such as the European Commission’s Standard Contractual Clauses where appropriate, together with a transfer impact assessment and supplementary measures where required. For a restricted transfer from the United Kingdom, it must use UK adequacy regulations or an appropriate safeguard such as the UK International Data Transfer Agreement or UK Addendum, together with a transfer risk assessment/data protection test and supplementary measures where required.

10.3. For Russian citizens, this Consent does not disapply requirements on primary collection using a database in Russia or prior notifications. The Controller must not begin the relevant processing solely on foreign infrastructure until those requirements have been met.

11. Duration and Retention

11.1. Consent takes effect when validly confirmed and continues until it is withdrawn or the account is finally deleted, unless the purpose ends earlier.

11.2. Following an account-deletion request, the account is deactivated for 30 calendar days. During that period, the User may cancel deletion using a dedicated button.

11.3. Following final deletion, special-category data is deleted or irreversibly anonymised except for the minimum information that must be retained by law, to evidence Consent, for security or for a particular legal dispute.

11.4. If the database provider Supabase creates backups under the project’s active plan, deleted data may remain in an isolated copy until scheduled overwriting — normally for up to 7, 14 or 30 days depending on the plan. It is not used in ordinary operations.

11.5. The record of the fact, version and time of giving and withdrawing Consent is retained for as long as necessary to establish which version applied at a particular time and for any mandatory legal period. The record does not contain clinical text.

11.6. In the mobile app, an encrypted offline copy of the safety plan and skill-library texts is stored only on the User’s device. It is deleted when the User signs out, signs in to a different account, requests account deletion, or uninstalls the app. Loss of connectivity and session expiry do not delete it. Full details are in the Privacy Policy.

12. Withdrawal of Consent

12.1. The User may withdraw Consent:

12.2. The User should identify the account email address in the request. The Controller may request proof of identity so that data is not deleted at the request of an unauthorised person.

12.3. Following a valid withdrawal, the Controller stops processing based solely on Consent and destroys the relevant data within the period required by applicable law. Under Armenian law, withdrawal of valid written or electronically signed consent results in destruction within ten working days unless the law or an agreement permits an exception.

12.4. Withdrawal does not affect the lawfulness of processing before withdrawal and does not require deletion of information that the Controller must or may retain on another lawful basis to a limited extent.

12.5. Following withdrawal, the features listed in clause 3.2 are unavailable.

13. User Rights

Where the GDPR or UK GDPR applies, the User may request access to and a copy of personal data, rectification, erasure, restriction, and data portability where applicable; object to processing based on legitimate interests; withdraw consent at any time; and lodge a complaint with a competent supervisory authority or seek a judicial remedy. These rights are subject to the conditions and exceptions in the applicable law. The full procedure is in the Privacy Policy.

Requests may be sent to [email protected]. The Controller responds without undue delay and, for GDPR/UK GDPR requests, within one month. The period may be extended by up to two further months where permitted because of complexity or the number of requests; the User will be told within the first month and given the reason. The Controller may request reasonable proof of identity.

14. Electronic Confirmation

14.1. In the current registration flow, Consent is confirmed by a box that is not pre-ticked. The same box also accepts the Terms of Use and acknowledges the Privacy Policy because the Service cannot operate without all three documents. For EEA and UK Users, the explicit health-data consent must be presented as a separate and clearly distinguishable affirmative action; acknowledging a privacy notice is not consent.

14.2. The current confirmation process is:

  1. before ticking the box, the User can open the full text of each of the three documents from the registration screen without losing entered information;
  2. the box is not pre-ticked; if the form returns an error, the previous selection is retained so that the User does not have to tick it again;
  3. when the account is created, the consent type, accepted version, account address, account identifier, date and time are recorded in the log;
  4. the User can view accepted versions in the Service under “More” → “Account” → “What you agreed to” and open the texts there;
  5. a material change to purposes, data categories or recipients triggers a request for fresh confirmation.

14.3. The Service does not use a separate action after email verification, record an IP address for this purpose, or apply an electronic signature. This is insufficient in a jurisdiction that requires written consent containing prescribed details or a particular electronic signature; the Controller must not offer the Service in such a jurisdiction until the required form is implemented.

15. User Confirmation

By using the separate explicit-consent control at registration, the User states:

I am at least 18. I have read this Consent and understand the special categories and purposes of processing. I explicitly consent to Digital Vanguard LLC processing the listed health and psychological-state data in the ways described, and I know how to withdraw my consent. I understand that WisemindApp is not a medical or emergency service and that access for a particular Therapist is granted separately.

16. Contact

Withdrawal of Consent and processing enquiries: [email protected].

Controller’s postal address: Premises 239, 2/2 Anastas Mikoyan Street, Yerevan, Republic of Armenia.

© 2026 Digital Vanguard LLC