Your privacy is important to us at ProblemShared. We respect your privacy regarding any information we may collect from you across our website.
This Privacy Notice (this “Notice”) explains how we collect, use, store, and protect your personal data.
Please read this Notice together with our User Terms & Conditions. They set out the types of data we process, how we handle that data, and your rights over it.
This Notice is intended for adults; if you are the parent or guardian of a child who uses our services, please share our Children’s Privacy Notice with them and make sure they understand the information it contains.
This Notice is divided into clear sections. You can use the index to go straight to any section. You can also download a full copy here.
We are ProblemShared, which is the trading name of Teledoctor Limited, a company registered in England with company number 10410380. Our registered address is 16 High Holborn, London, England, WC1V 6BX. In this Notice, “ProblemShared”, “we”, “us” or “our” all refer to ProblemShared.
We provide mind and mental health (including neurodiversity) assessment and post-diagnostic services and support (the “Services”). These Services are delivered by qualified healthcare professionals (our “Practitioners”). Most Services are delivered through our digital platform, which includes components provided by third-party partners (together the “Platform”). These partners also process your personal data on our behalf and in line with this Notice. Some elements of our Services may also be delivered in-person.
This Notice explains how we collect, use, and protect your personal data when you use our Platform or access our Services. This may include special category data, such as information about your mental or physical health.
ProblemShared is generally the data controller of the personal data covered by this Notice. In some cases, ProblemShared may act as a joint controller or processor for certain personal data. In these situations, we and the relevant organisation determine our respective responsibilities in line with data protection law, and further information will be provided at the point of referral. We are responsible for making sure that your personal data is handled safely, lawfully, and transparently, in line with applicable data protection laws (“Data Protection Legislation”). This legislation sets out the rules for how we collect, use, store, and share your personal data. It includes, without limitation:
We have appointed a Data Protection Officer (“DPO”) who is responsible for answering questions in relation to this Notice. If you have any questions about this Notice or wish to exercise your legal rights under the Data Protection Legislation, please contact our DPO (dpo@problemshared.net).
Personal data is any information that can identify you, either directly or indirectly. We may collect this information when you sign up or enrol on our Platform, when a referring partner organisation or another third party provides it for you under their own privacy notice, or automatically when you use the Platform.
We may collect, use, store and transfer different kinds of personal data about you, which we have grouped together as follows:
Employment data: We may collect information such as your job title and employer details from corporate contacts for the purposes of managing business relationships, client communication and marketing, and delivering our Services, including where these are provided in an occupational health context.
Where our Services involve face-to-face interaction and/or live video sessions, we may process additional personal data such as audio data, visual data, behavioural data, and any special category information disclosed or visible during the session. However, we only record or store video or audio from our sessions if you have agreed to this.
It is important that the information we hold about you is accurate, current, and complete. Please let us know if any of your information changes or needs updating.
We use different methods to collect data from and about you including through:
Legal basis
The law requires us to have a legal basis for collecting, using, and sharing your personal data. Before you receive any Services from us, you will be asked to accept our User Terms and Conditions and this Notice. These explain the legal bases on which we rely when processing your data. These are:
Purposes for which we will use your personal data
We will use your information only where the law allows. Below, we explain how we may use each type of your personal data, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.
| Purposes of processing | Types of individuals | Types of personal data | Legal basis and retention period |
|---|---|---|---|
| Providing healthcare to patients | Patients | Identity data Contact data Financial data Transaction data Medical data Profile data | Performance of a contract Provision of health and social care Personal data retained for seven (7) years after care has ceased. Health and clinical records (medical data) typically retained for 20 years after the last contact, or until a child’s 25th birthday, whichever is later. |
| Providing training and professional development services to referring organisations | Staff at referring organisations | Identity data Contact data Employment data | Performance of a contract Records relating to training provided to staff at referring organisations will be retained for up to 6 years following completion of the training. |
| Training and improving our services: Using session recordings to support staff training and enhance the quality of our care | Patients who have provided consent | Identity data Contact data Medical data Audio data Video data Behavioural data Special category data | Consent Provision of health and social care Health and clinical records (medical data) typically retained for 20 years after the last contact, or until a child’s 25th birthday, whichever is later. |
Processing and delivering your payments including: (a) manage payments, fees and charges; or (b) collect and recover money owed to us. | Private/self-pay patients | Identity data Contact data Financial data Transaction data | Performance of a contract Personal data – seven (7) years |
Managing our relationship with you, which will include: (a) notifying you about changes to our terms or Notice; (b) dealing with your requests, complaints and queries; or (c) responding to enquiries or registrations of interest. | All patients and prospective patients | Identity data Contact data | Performance of a contract (including steps taken at your request before entering into a contract) Personal data – seven (7) years. If you register your interest with our Services as a self-pay patient, but do not proceed with our Services, we keep your information only for as long as needed to manage your enquiry and any follow-up. |
| Developing and maintaining client relationships: Carrying out direct marketing activities | All patients, business partners | Identity data Contact data Communication data Engagement data Employment data | Consent Legitimate interest (to develop and maintain relationships with clients and stakeholders, including promoting and improving our services and supporting business growth) Retention periods for data collected for marketing purposes may vary. Records of patients’ opt-ins and consents will be retained indefinitely, unless consent is withdrawn. Other marketing data will be kept for up to 36 months. |
| Looking after your wellbeing in emergencies: Using information from emergency contacts to support you if an urgent situation arises | Emergency contacts of patients | Identity data Contact data | Legitimate interest (ensuring client safety and wellbeing during care delivery, including the ability to respond appropriately in emergency or safeguarding situations) Personal data – seven (7) years |
| Supporting safe and accurate assessments: Using information from informants (e.g., parents, teachers, or carers) to give Practitioners a fuller picture | Informant identified by the patient (e.g. family members, carers, teachers, or other third parties) who provides information to support the patient’s assessment or care. | Identity data Contact data Medical data shared about the patient to support assessment or care (e.g., observations, concerns, context). | Legitimate interest (to record who provided input and ensure accountability and context in the assessment process) Kept for the same duration as the patient’s record if it forms part of that record. 7 years if stored separately for admin/legal purposes. |
| Running and protecting our business: Administering our platform and website, including troubleshooting, testing, maintenance, support, reporting, and hosting data | All Platform users | Technical data | Legitimate interest (to operate, manage, and secure our digital infrastructure and ensure the integrity, availability, and performance of our website and services) Retention periods vary per cookie. Most data is retained for 4 months, but analytical cookies (used to understand how visitors interact with the website) are retained for 1 year 1 month 4 days. |
| Improving our services: Using information about how services are used to generate insights, monitor quality, and develop improvements to patient care | Patients, website users | All categories of data as outlined in section 2. | Legitimate interest (To help us understand and improve our services for patients) Personal data retained for seven (7) years after care has ceased. Health and clinical records (medical data) typically retained for 20 years after the last contact, or until a child’s 25th birthday, whichever is later. |
| Complying with laws and regulations: Meeting legal obligations, defending or exercising our rights, or acting in the vital interests of a patient | All patients | All categories of data collected (where necessary) | Legal obligation (Article 6(1)(c) and 9(2)(f)) Vital interests (Article 6(1)(d) and 9(2)(c)) Personal data retained for seven (7) years after care has ceased. Health and clinical records (medical data) typically retained for 20 years after the last contact, or until a child’s 25th birthday, whichever is later. |
Marketing
If you have signed up or opted in to receive marketing communications from us, we may:
Cookies
To find out more about the cookies we use and how to change your preferences, click on the 'Consent Preferences' widget at the bottom left of your screen. You can also view our full Cookie Policy here.
Practitioners’ obligations
The Practitioner you see in your session or who is involved in your care or assessment must follow and comply with all Data Protection Legislation.
All Practitioners are trained on data privacy and are contractually required to follow our internal data handling, information governance, and privacy policies.
We may share your personal data where necessary with the parties set out below.
When we share any information with them, we always make sure it is allowed by law. All third-party companies we use must follow data protection rules. They can only use your personal information to help us and cannot use it for their own purposes.
Most of your information is stored and used in the UK on secure servers, including NHS-approved systems. Some companies that help us are based in the EU. When this happens, we make sure your information is fully protected according to the Data Protection Legislation.
We take care to keep your personal information safe. We have strong security measures to stop your information from being lost, seen by the wrong people, changed, or shared without permission. These include:
We also limit access to your personal information. Only employees, contractors, or other trusted people who need to see it can use it. They must follow our instructions and keep your information confidential.
Our systems meet the NHS Data Security and Protection Toolkit standards (with an “exceed” rating). Our web application is also tested every year by independent security experts.
No internet system is completely safe, but we have strong procedures to deal with any suspected data breaches. If the law requires it, we will tell you and the ICO about any breach.
How long we keep information depends on the type of information and the purpose for which it was collected. Health and clinical records (special category data) are kept in line with the NHS Records Management Code of Practice: typically for 20 years after the last contact, or until a child’s 25th birthday, whichever is later. This ensures you get the right care and we meet our medico-legal obligations.
AI-assisted outputs that have been reviewed and validated by the Practitioner form part of your clinical record and are therefore retained for the same period as your clinical records. Other AI-assisted data that does not form part of your clinical record is retained only for as long as necessary for the purposes for which it is used.
We keep things like administrative, engagement, financial, and technical records, for seven (7) years after care or treatment has ended. This aligns with the Limitation Act 1980 and helps us meet our legal, contractual, and audit requirements. Retention periods for the data we collect for marketing purposes may vary. Records of patients’ opt-ins and consent will be kept indefinitely, unless consent is withdrawn. Other marketing data will be retained for up to 36 months.
We regularly check our retention schedules to make sure they follow current guidance. When your information is no longer needed, we make sure it is securely deleted.
You have several rights about the information we hold about you. To exercise any of these rights, or to withdraw your consent to us using your information in ways you previously agreed to, please email our DPO (DPO@problemshared.net).
You have the right to:
| Right | Meaning |
|---|---|
| Access (Article 15 UK GDPR) | You can ask for a copy of the information we hold about you. |
| Rectification (Article 16 UK GDPR) | If any of your information is wrong, you can ask us to fix it. We may check the new information to make sure it is correct. |
| Erasure (Article 17 UK GDPR) | You can ask us to delete your information if we do not need it anymore, if you have objected to how we use it, or if we have used it wrongly. Sometimes, we must keep information for legal reasons. If this happens, we will explain when you make your request. |
| Restriction (Article 18 UK GDPR) | You can ask us to stop using your information in some situations, but we might need to keep it. This can happen if: You are checking that your information is correct We are using your information wrongly, but you want us to stop instead of delete it You need the information for a legal claim You have objected to our use, and we are checking if we have stronger reasons to continue |
| Portability (Article 20 UK GDPR) | You can ask for your information in a format that can be easily transferred to another company. |
| Objection (Article 21 UK GDPR) | You can object to how we use your information when we rely on a legal duty or our legitimate interests. |
No fee usually required
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, if your request is clearly unreasonable, repeated a lot, or too difficult, we may charge a small fee or, in some cases, refuse your request.
What we may need from you
We may ask for some information to make sure you are who you say you are. This helps us keep your personal information safe and make sure it is not given to the wrong person. Sometimes we may also ask you for more information to help us respond more quickly to your request.
Time limit to respond
We normally answer all requests within one month, however, if your request is very complicated or you have made many requests, it might take longer. If this happens, we will tell you and keep you updated.
Under Article 15 of the UK GDPR, you have the right to submit a Data Subject Access Request (“DSAR”) to get confirmation as to whether we process personal data relating to you. If we do, you can ask for a copy of it together with information required by law.
How to make a request
You can ask us by using this link or by post addressed to: ProblemShared, 16 High Holborn, London, WC1V 6BX.
To help us find your information quickly, please state that you are making a “Data Subject Access Request” and, if you can, say exactly what information you want.
Verification of identity
To keep your information safe, we may need to check who you are. If someone else is asking for your information, we may ask for proof that they have your permission, such as written consent or a power of attorney.
Timeframe
We will acknowledge your request quickly and try to respond within one calendar month of receipt. If your request is very complicated or you have made many requests, this period may be extended by up to two additional months. If this is necessary, we will tell you within the first month.
Exemptions
Sometimes, we cannot give all the information. This could happen if giving it would:
If we do not give you some information, we will explain why whenever we can.
Fees
You will not usually be charged for making a DSAR. If your request is clearly unreasonable, repeated many times, or too difficult, we may charge a small fee or refuse your request.
How we will provide the data
Information will normally be provided in a secure electronic format unless you request otherwise. If we cannot provide your data electronically, we will agree another method with you.
You have the right to make a complaint to the ICO (www.ico.org.uk). They can be contacted at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, telephone: 0303 123 1113.
Before doing so, please make sure you have first made your complaint to us or asked us for clarification if there is something you do not understand. You can find more guidance on our complaints procedure here [Complaints & concerns | ProblemShared], and our complaints form here [Complaints Form].
If you apply for a job with us, we collect and process personal data (including, but not limited to, your name, contact details, address details, CV, and employment history) based on our legitimate interest in managing the recruitment process. None of this data will comprise sensitive category data unless you choose to share these with us as part of your job application.
This data is stored securely on the Platform and retained for up to 6 months if you are not hired, after which only minimal information (e.g. your name, role applied for) is kept for HR and legal purposes.
For your rights in relation to your personal data, please see section 9 of this Notice.
This Notice serves to inform adults who use our services (or are responsible for children who use our services) about how we handle their personal data. If you are the parent or guardian of a child who uses our services, please share our Children’s Privacy Notice with them.
We keep this Notice under regular review. This version was last updated on 8 September 2026. Historic versions can be obtained by contacting us at help@problemshared.net.
It is important that your information is correct and up to date. Please tell us if anything changes, like your address or email, while you are using our services.
Our website may have links to other websites, apps, or plug-ins. If you click on these links, the other websites may collect or share information about you. We do not control these websites and are not responsible for their privacy rules. When you leave our website, we recommend that you read the privacy notice of the website you visit.