Privacy Policy
Effective date: 5 August 2026 · Continuumco Ltd
This policy explains how Continuumco Ltd (company number 15602004) collects, uses, and protects personal data through the Continuum platform. It covers both practitioners who use Continuum professionally and clients who use Continuum as part of their care.
If you have any questions about this policy, contact us at: contact@continuum.ac
1. Who We Are
Continuum is operated by Continuumco Ltd; a company registered in England and Wales (company number 15602004). We are the data controller for personal data processed through the platform.
Registered address: 26 Charlwood Road, London, SW15 1PW
Data protection contact: contact@continuum.ac
2. The Two Types of Users
Continuum is used by two distinct groups of people, each with different data relationships.
Practitioners
Mental health professionals and coaches who use Continuum to support their clients. Practitioners access the platform under a professional agreement with Continuum.
Clients
Individuals introduced to Continuum by their practitioner as part of their care. Clients interact with the platform through a dedicated app.
This policy explains how we handle data for both groups. Where the position differs, we say so clearly.
3. What Data We Collect
3.1 Practitioner Data
When you use Continuum as a practitioner, we collect:
- Account information: name, email address, professional credentials
- Session-related inputs: notes, annotations, tasks, insights and resources
- Usage data: how you interact with the platform, feature usage, login activity
- Communications with Continuum support
3.2 Client Data
When you use Continuum as a client, we collect:
- Account information: name, email address, and basic profile details
- Between-session activity: mood logs, journal entries, task completions, and responses to check-ins
- Assessment responses provided through the app
- Session transcript data, where your practitioner uses the transcription feature and approves the output
- Behavioural patterns derived from your activity in the app
- Usage data: how you interact with the app
Mental health data is special category data under UK GDPR Article 9. We treat it with the highest level of care and apply additional technical and organisational safeguards accordingly.
4. Why We Use Your Data and Our Lawful Basis
4.1 Practitioners
We process practitioner data to:
- Provide and operate the Continuum platform under our agreement with you (lawful basis: contract performance)
- Maintain platform security and prevent misuse (lawful basis: legitimate interests)
- Comply with legal obligations (lawful basis: legal obligation)
4.2 Clients
We process client data to:
- Deliver the Continuum service, including sharing relevant between-session data with your practitioner to support your care (lawful basis: health care provision under Article 9(2)(h), and contract under Article 6(1)(b))
- Generate pre-session summaries and behavioural insights for your practitioner (lawful basis: health care provision)
We do not currently use client data to train or improve our AI tools. If we decide to do so in future, we will update this policy and, where required, seek your consent before any such use begins.
5. AI Training and Platform Improvement
We are continually working to improve Continuum. At present, we do not use your personal data, whether identifiable or anonymised, to train our AI models. If we introduce this in future, we will update this policy first and, where the law requires it, obtain your consent before any such use begins. We will never sell your data or share it with third parties for their own purposes.
6. Data Sharing
6.1 Your Practitioner
Client data is shared with your practitioner as a core part of the service. Your practitioner can see your between-session activity, check-in responses, and any summaries generated by the platform. This is how Continuum works.
6.2 Sub-processors
We use a small number of third-party services to operate the platform. These sub-processors are contractually bound to handle your data only on our instructions and in accordance with UK GDPR. Our current sub-processors include:
- Mistral AI: artificial intelligence and language model processing
- Loops: email communications and notifications
- Clerk: user authentication and account management
- Daily: video session infrastructure
We will update this list as our sub-processors change.
6.3 International Transfers
Some of our sub-processors may process data outside the United Kingdom. Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, such as the UK International Data Transfer Agreement or transfers to countries covered by UK adequacy regulations. We will set out the specific location and safeguards for each sub-processor in this section once confirmed.
6.4 What We Never Do
We do not sell your personal data. We do not share your personal data with third parties for their own marketing or commercial purposes. We do not provide practitioner or client data to insurers, employers, or any other party without your explicit consent or a legal obligation to do so.
7. Data Retention
We retain personal data for as long as necessary to deliver the service and meet our legal obligations.
- Active accounts: data is retained for the duration of your use of the platform
- After account closure: personal data is deleted within 7 years, subject to any legal retention obligations
- Session transcripts: retained for 7 years and then deleted unless you or your practitioner request earlier deletion
If you request deletion of your data, we will action it promptly. In some cases, we may be required to retain certain records for legal or regulatory reasons, and we will tell you if that applies.
8. Security
We take the security of your data seriously, particularly given the sensitive nature of mental health information. Our measures include:
- Encryption of data in transit and at rest
- Access controls limiting who within Continuum can access personal data
- Regular review of our security practices
- Contractual security obligations on all sub-processors
No system is completely immune to risk. In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the ICO as required by law.
9. Your Rights
Under UK GDPR, you have the following rights in relation to your personal data:
- Right of access: you can request a copy of the personal data we hold about you
- Right to rectification: you can ask us to correct inaccurate data
- Right to erasure: you can ask us to delete your data, subject to legal retention obligations
- Right to restriction: you can ask us to limit how we use your data in certain circumstances
- Right to data portability: you can request your data in a portable format
- Right to object: you can object to processing based on legitimate interests
To exercise any of these rights, contact us at contact@continuum.ac. We will respond within one month.
If you are a client and wish to raise a concern about how your data is handled, you can also speak to your practitioner, who introduced you to the platform.
10. Complaints
If you are unhappy with how we have handled your data, you have the right to complain to the Information Commissioner’s Office (ICO).
ICO website: ico.org.uk
ICO helpline: 0303 123 1113
We would always prefer to resolve concerns directly first. Please contact us at contact@continuum.ac before escalating to the ICO and we will do our best to address your concern promptly.
11. Changes to This Policy
We will update this policy as the platform develops. Where changes are material, we will notify you by email or through the platform before they take effect.
The current version and effective date are shown at the top of this document.
12. Contact
Continuumco Ltd
Company number: 15602004
Email: contact@continuum.ac
Website: www.continuum.ac
