Skip to main content

Privacy Policy

Last updated June 2026

Who we are

Formulate is operated by Formulate Tools Ltd, a company registered in England & Wales (Company No. 17065550), registered address 11 Chantry Close, TW16 7TH.

Formulate is a platform of interactive clinical psychology tools and worksheets for use by qualified healthcare professionals. For data protection queries, contact formulatetools@outlook.com.

What data we collect

Therapist account data

Email address, full name, organisation name (optional), subscription status, and usage data (which worksheets accessed, when, and frequency).

Client label data

Pseudonymised client labels (initials or case codes) assigned by the therapist. The platform validates client labels to reject obvious identifiers (such as emails, phone numbers, NHS/NI numbers, dates of birth and postcodes) and warns therapists against using names. Therapists remain responsible for not entering identifiable information.

Worksheet response data

Clinical content entered by clients via homework links. This data is pseudonymous. Only the assigning therapist can view response data. Formulate does not access, review, analyse, or use response data for any purpose other than storage and display to the therapist.

Technical data

IP addresses (for security), device and browser information (for compatibility), and cookies. We set strictly necessary cookies (authentication and session) without consent. Optional analytics and advertising cookies — including the Meta Pixel and Vercel Web Analytics — are set only if you accept them. See “Cookies” below.

Legal basis for processing

Data typeLegal basis
Therapist account dataContract (Art. 6(1)(b))
Subscription/payment dataContract (Art. 6(1)(b))
Usage analyticsLegitimate interests (Art. 6(1)(f))
Client labelsLegitimate interests (Art. 6(1)(f))
Worksheet responsesLegitimate interests as processor (Art. 6(1)(f))
Audit logsLegal obligation (Art. 6(1)(c)) + Legitimate interests

Special category data

Worksheet response data may constitute health data under Article 9. Our legal basis is Article 9(2)(h) — processing necessary for health care provision under a health professional's responsibility.

Data sharing

We use the sub-processors listed in our Data Processing Agreement — including Supabase (database, UK), Stripe (payments), Resend (transactional email), Anthropic (AI worksheet generation, on PII-stripped input only), Vercel (hosting) and Sentry (error monitoring). With your consent, we also load analytics and advertising tools (the Meta Pixel and Vercel Web Analytics). We do NOT sell your data, share clinical response data with third parties for their own purposes, use clinical data for advertising, or train AI models on worksheet responses.

Where we store your data

Your account and clinical data are stored in the UK (Supabase, AWS eu-west-2, London). Some sub-processors operate outside the UK (see our DPA for the full list and the safeguards that cover those transfers).

Data retention

Active account data is retained while the account is active plus 90 days after deletion request. Worksheet responses are retained while the therapeutic relationship is active. Therapists can permanently delete client data at any time via the GDPR erasure function. Audit logs are retained for 7 years.

Your rights

Under UK GDPR, you have the right to access, rectify, erase, restrict processing of, and port your data, and to object to processing. Contact formulatetools@outlook.com. We will respond within 30 days.

Client rights

Clients who complete homework worksheets can exercise their rights by contacting their therapist. The therapist can delete all data associated with a client using the platform's GDPR erasure function.

Cookies

Formulate uses strictly necessary cookies for authentication and session management; no consent is required for these under UK PECR. With your consent, we also use optional analytics and advertising cookies — currently the Meta Pixel (advertising-performance measurement) and Vercel Web Analytics (aggregate usage) — which may set additional cookies. We request your consent before any analytics or advertising cookies are set, and you can accept or decline them via the cookie banner displayed on your first visit.