Who we are
ViaCara Ltd connects people in private mental health and wellbeing care with the practitioners who fit them. This notice describes how we handle data about practitioners. It is distinct from the client privacy policy because the data flows and lawful bases are different.
- Company number: 17138185 (England and Wales)
- Registered office: 66 Paul Street, London, EC2A 4NA, United Kingdom
- ICO registration: ZC116531
- Data protection contact: dataprotection@viacara.com
We are the data controller for the practitioner-side data described below. Where we make introductions to clients, you remain the independent data controller for everything that flows inside the therapeutic, coaching or counselling relationship that follows.
Which laws apply
ViaCara is a UK-based service and we process practitioner data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
We introduce practitioners to clients in the United Kingdom and the Channel Islands. We do not yet target the European Union or the European Economic Area, and we do not recruit practitioners there. If you use ViaCara from there, we process your personal data under UK GDPR as set out below. When we begin to actively serve the EU or EEA, we will also comply with the EU General Data Protection Regulation (EU GDPR, Regulation 2016/679) and appoint a representative under Article 27 of the EU GDPR. Until then, you can contact us at the data protection contact above.
If you use ViaCara from anywhere in the Bailiwick of Guernsey, which includes Alderney, Sark and Herm, we process your personal data under the Data Protection (Bailiwick of Guernsey) Law, 2017, regulated by the Office of the Data Protection Authority (ODPA). If you use ViaCara from Jersey, we process your personal data under the Data Protection (Jersey) Law 2018, regulated by the Jersey Office of the Information Commissioner (JOIC). Both laws give you the same rights set out in this notice.
How we discover and contact you
We add practitioners to our platform through four paths. Each path has its own legal basis.
1. You came to us directly
You signed up via /app/join, accepted an existing practitioner's referral link, or arrived from one of our paid acquisition campaigns and submitted the form. In every case the data we hold about you exists because you provided it knowingly. Legal basis: Article 6(1)(a) consent.
2. You were introduced by another practitioner
A practitioner already on the platform referred you to us. We hold your contact details because the introducing practitioner shared them with the legitimate expectation that you might want to hear from us. Legal basis: Article 6(1)(f) legitimate interest in growing a trusted practitioner network through warm referrals.
3. We discovered you on a public professional register
We curate a directory of practitioners by sourcing from publicly available professional information: professional register entries (such as the BACP, NCPS, UKCP and similar), company registry records for registered practices, and professional networking. We use this information to decide whether your practice is a fit for the platform and to send you a single, opt-out-respecting introduction.
We perform a company registry check before sending any cold electronic communication: Companies House for a UK practice, the Guernsey Registry for a Guernsey practice, the JFSC registry for a Jersey practice. We only send to a practice registered as a company there (which the Privacy and Electronic Communications Regulations 2003, and Guernsey's equivalent Ordinance, treat as a "corporate subscriber"). We verify the practice's company registry number to confirm its status. Sole-trader practitioners are never sent unsolicited electronic marketing, on any island, whether or not local law requires that; we wait until you come to us instead.
Every first cold message to a Guernsey or Jersey practice states your right to object to further contact, explicitly and separately from anything else in the message, and how to exercise it. This follows the Data Protection (Bailiwick of Guernsey) Law, 2017 section 17, and the Data Protection (Jersey) Law 2018 Article 36.
Legal basis: Article 6(1)(f) legitimate interest, balanced against your rights under a documented Legitimate Interests Assessment. At this discovery and outreach stage we never process special-category data (UK GDPR Article 9) about you. That changes only if you choose to join and share something personal during onboarding, which we describe in "Your working style and lived experience" below.
4. We saw your advert in a public place or online
You displayed a flyer, poster, leaflet or business card on a public noticeboard, in a shop window or on a community board, advertising your practice to people who are looking for a practitioner. A member of our team photographed it. We keep the details you printed on it, the place and the date we saw it, and the photograph itself. Where your advert names a website or a professional body, we also read the contact details you publish there. We follow your own website, the pages it links to and the register entry for the number you printed, and no further.
The same applies when you advertise your practice online: your own website, a directory listing or a public social media post. A member of our team read the page, or a search tool we run read it and a member of our team reviewed what it found. We keep the details it states, its address and the date we read it. There is no photograph. If your website or a search result shows your professional networking profile, we keep only its address. We follow that page, the pages it links to and the register entry for any number it shows, and no further.
We treat the advert as what it is: an invitation to be contacted about your practice, published by you for that purpose. That makes contact foreseeable, and it is why we can tell you exactly where we saw you. It is not consent, so the Companies House rule above applies here in full. A sole-trader practitioner who advertises on a noticeboard is still an individual subscriber, and we still send them no unsolicited electronic marketing.
We email a sole trader we met, spoke to or talked with online only when they asked, and we record when and how. Asking can happen in person, by phone, on a video call, by email, in a direct message or in a comment addressed to us. A like, a follow or a general comment is not asking.
Because these details did not come from you directly, the first message we send names the advert or the page, where we saw it and the date, and links to this notice.
We record what your advert states, never what it implies about you. If your advert is displayed at a place of worship, a clinic or a school, we do not name that place back to you, because naming it would suggest something about you or your clients that you did not say.
Legal basis: Article 6(1)(f) legitimate interest, balanced under the same documented Legitimate Interests Assessment as route 3, and with the same Article 9 position: no special-category data at the discovery and outreach stage.
What we collect and why
| Data | Purpose | Source |
|---|---|---|
| Name, professional title, town and country | Contact and routing | You, the introducing practitioner, the public register, your printed advert, or the page where you advertise your practice |
| Email address | To send introductions, invitations and operational mail | You, the public register, your printed advert, the page where you advertise your practice, or the website either names |
| Practice trading name and company registry number (if registered) | To confirm registered-company status before any cold contact | Companies House Public Data API (UK); Guernsey Registry public search (Guernsey); manual JFSC registry search (Jersey) |
| Professional register entry URL | To verify accreditation and contact you in context | Public register |
| Service type, approach and who each service sees (individuals, couples, families or groups) | To route introductions to people you can actually help | You |
| Practice website URL (optional) | Profile pre-fill at your request | You |
| Courses and training you name on your public pages (course, provider, year and whether it is complete) | To support the approaches on your profile, once you confirm each course | Your own public pages, at your request |
| Certificates, transcripts and CPD records you upload, and the courses read from them | To show the training behind your profile, once you confirm each course | You |
| Courses you add without a certificate | To shape your onboarding conversation. They stay private | You |
| Your professional indemnity insurance schedule or certificate, its file name, its text and what we read from it (the policyholder, insurer, policy number, policy dates, limit per claim and what the policy covers) | To check that you hold the cover our terms require before we introduce you to clients | You, and Companies House when the policy is in your company's name |
| The health insurers and employee assistance programmes (EAPs) you are registered with, the services each registration covers and any limit on it, your provider number, the evidence of your registration and the record of our check | To check each registration before it can show on your profile or bring you clients who use that programme | You, and the programme when we confirm a registration with it |
| The venue where you see clients in person, and its access details | To show clients how to get there and whether they can get in | You, the venue's own public pages and our team |
| Your home address, if you see clients at home | To measure how far away you are. Clients only see your town | You |
| Onboarding profile data once you join | Display to clients during the introduction step | You |
| Subscription, credit balance and billing data | To run the commercial relationship | You and our payment processor |
| Introduction history (accept / decline / outcome) | Your booking and response history in our ranking: how often an introduction led to a first session and how often you answered an availability request before it ran out | Generated by your platform activity |
| Bookings clients make with you (the client, the date, the time, the length, the format and the outcome) | To run the booking and to hold the record of it in case either side raises a dispute, and to work out how much of your availability is still free, for ranking | Generated by your platform activity |
| Outreach event log (sends, deliveries, bounces, opens, clicks, signups, unsubscribes, complaints) | Deliverability hygiene, audit trail for ICO scrutiny | Generated by our systems |
| Contact details you printed on your advert, or published on the page where you advertise your practice or the website either names (phone, email, website, social handles) | To identify your practice and to reach you on a route that is open to us | Your printed advert, the page and the website either names |
| Where and when we saw your advert or page | To tell you honestly why we are writing, and to date the record | Our photograph of the advert, including its camera location data, or the address of the page |
| The photograph of your advert | The record of what you published and where, held with the prospect row | Our photograph of the advert |
| Feedback you send from the app: your note, the page you sent it from and, if something had just gone wrong, the reference number of that error | To fix what went wrong and improve the platform. An AI language model sorts each note, and any note you add to a star rating, by type, such as a fault, a feature idea or a question, and notes its tone. We ask for your consent each time you send, and ask you to leave out details about your clients | You, and your browser adds the page and the error reference |
| A screenshot of the page, if you add one to your feedback | To see what went wrong on that page | Your browser, when you tap to add it |
| Referral link activity (aggregate visits and link-preview fetches per referral code, by calendar day) | To show you how your own invite link is performing | Generated by visits to your link. We briefly check the browser type only to tell a person from an automatic preview robot, then discard it: we store no IP address, browser detail or other visitor identifier |
| Your IP address when you use the join form, its town suggestions or account recovery | To stop one address from overloading the service or trying many guesses | Generated by your connection |
Lawful bases
| Purpose | Lawful basis |
|---|---|
| Maintaining the practitioner directory | Article 6(1)(f) legitimate interest, with the LIA on file |
| Recording a practice we saw advertised in a public place or online | Article 6(1)(f) legitimate interest, with the LIA on file |
| Sending you the initial introduction (corporate subscribers only) | Article 6(1)(f) legitimate interest plus PECR Reg 22 corporate-subscriber permission |
| Sending the initial cold introduction to a Guernsey or Jersey practice | Article 6(1)(f) legitimate interest, with notice of the right to object given explicitly and separately at first contact |
| Sending you an invitation you asked us to send | Article 6(1)(a) consent plus your prior consent under PECR Reg 22(2) |
| Sending operational invitations and onboarding once you engage | Article 6(1)(a) consent (you replied or submitted) |
| Checking your professional indemnity insurance | Article 6(1)(b) performance of a contract |
| Keeping an insurance document we verified after it stops backing our check | Article 6(1)(f) legitimate interest |
| Checking your insurer and EAP registrations | Article 6(1)(b) performance of a contract |
| Keeping the record of a registration we verified after it ends | Article 6(1)(f) legitimate interest |
| Running the commercial relationship after you join | Article 6(1)(b) performance of a contract |
| Keeping lived experience, health, disability, neurodivergence, faith, sexuality or ethnicity you choose to share | Article 9(2)(a) explicit consent, asked for separately when you start onboarding |
| Reviewing your onboarding conversation, if you say yes at the end | Article 6(1)(a) consent and Article 9(2)(a) explicit consent |
| Sorting a note you send, or add to a star rating, by type and tone | Article 6(1)(a) consent and Article 9(2)(a) explicit consent for any detail about your own health |
| Keeping a screenshot you add to your feedback | Article 6(1)(a) consent and Article 9(2)(a) explicit consent |
| Showing lifestyle interests you choose to share on your profile | Article 6(1)(a) consent |
| Marketing email you asked for (the updates switch on the join form, or the switch in your account) | Article 6(1)(a) consent, and PECR regulation 22(2). Every marketing email has a one-click way to stop |
| Confirming a declared registration number with your named professional body | Article 6(1)(f) legitimate interest in directory accuracy |
| Keeping the record of each introduction that employment agency law requires | Article 6(1)(c) legal obligation |
| Telling a client we introduced to you in the last three months that we suspended your profile or could no longer confirm your registration | Article 6(1)(c) legal obligation |
| Maintaining suppression and deliverability records after you opt out | Article 6(1)(c) legal obligation under PECR |
| Keeping the record of a booked session to answer a later dispute | Article 6(1)(f) legitimate interest |
| Improving the platform | Article 6(1)(f) legitimate interest |
| Keeping health-related evidence for a legal claim | Article 9(2)(f) establishing, exercising or defending a legal claim |
| Showing you how your referral link is performing | Article 6(1)(f) legitimate interest |
| Protecting the service from misuse and abuse by limiting the requests from one IP address | Article 6(1)(f) legitimate interest |
Your working style and lived experience
When you join, onboarding includes a short conversation by voice or text so we can understand how you actually work. From the words you use, we keep five measures of your relational style and a "voice signature" of your phrasing and self-described approach, which we use to write each client-facing profile summary in your own voice. We do not analyse pitch, pace, pauses or other vocal characteristics. If you speak, we turn the audio into text as you talk. We keep the text understanding and the signature drawn from it. We keep the conversation itself only if you agree at the end, as below.
If, and only if, you choose to mention something personal you have lived through (your own grief, addiction, a health condition, neurodivergence or a disability), we treat that as special-category data under UK GDPR Article 9 and process it on the basis of your explicit consent (Article 9(2)(a)). We ask for it once, separately from the terms, when you start onboarding, and again separately if you agree to a review of your onboarding conversation. The same consent covers any disability, neurodivergence, faith, sexuality or ethnicity you record on your profile. If you say no, we keep none of these, and nothing else about your profile changes. We record which wording you agreed to and when.
We use lived experience only to connect you with clients facing something you understand first-hand, or a related health condition. Clients see no details, at most an anonymous note that you know what they face, or a related condition, first-hand. Our team can see them when checking profiles. You can review, edit or remove any of this from your dashboard at any time. You can also withdraw your Article 9 consent at any time from your account page. We then delete all of these details from your profile and your onboarding records. Introductions already made keep their record, and the withdrawal does not affect anything we did beforehand.
The conversation may also ask what you enjoy outside work. If you share interests (a dog, long walks, a book on the go), we keep them as simple categories from a fixed list. Up to three appear on your profile, named, so clients can see the person behind the professional.
These interests are ordinary personal data, not special-category data. We process them under your consent (Article 6(1)(a)), and explain before the conversation that interests can appear on your profile. You can remove any interest during onboarding, and review, edit or remove them from your dashboard at any time.
Reviewing your onboarding conversation
At the end of the conversation, we ask whether our team may review it. Nothing is kept unless you tap yes. Saying no changes nothing about your profile.
If you say yes, we take out personal details before we save a copy. Anything you lived through, any health detail, anyone else you mention and anything that identifies you becomes a short marker.
A small, named team can read the copy for 30 days, and each visit is recorded.
We may use its shape to write a made-up practitioner for testing. It gets a new name, new details and new words, and a team member checks it. Once approved, it no longer relates to you.
We rely on your consent and, because a conversation can touch on health or lived experience, your explicit consent (Article 9(2)(a)). You can withdraw from your dashboard at any time, and we delete the copy straight away.
Every conversation also records a few measures with no words in them. They include reply times, the order of topics and any step that failed. They carry no name, and we delete them within 90 days.
Screenshots with your feedback
When you send feedback from the app, you can add a screenshot of the page you are on. We take it only when you tap to add one, and you see it before you send. The first tap on send then shows what the screenshot holds, and a second tap sends it.
A page can show details about you or your clients, so we treat a screenshot as special-category data. We rely on your consent and your explicit consent (Article 9(2)(a)). The screenshot is kept in EU object storage. Only the ViaCara team can open it, and each opening is recorded. The email we receive about your feedback links to our feedback list, never to the image.
We delete it 30 days after you send it, or when you close your account. To have it deleted sooner, send us a note from the Feedback panel or write to the data protection contact at the top of this notice.
Researching your public professional presence
When you tell us where your practice is listed (a directory page, your own site, a professional register entry), we use that starting point to research your public professional presence on the open web. We follow the links you have published yourself (your own site, your directory listings, your register entry) before looking anywhere else, and we keep only the structured fields you review and edit on the review screen. When a professional-body badge appears on your own site, this can include reading the registration number it displays so you can confirm it. We also read the courses and training you name, and keep each one as its own entry for you to confirm or remove. We store the source URL and a short verbatim excerpt for each field we extract, never the raw page content.
We process this under your consent (Article 6(1)(a)). Anything you have not already published yourself is not researched: we never infer protected characteristics from names, photos or locations, and any faith, sexuality or ethnicity fields on your profile come only from what you have self-identified on your own public pages, which we keep only if you gave the Article 9 consent described above. If a site blocks automated access we ask you to paste the text instead.
When we cannot confirm a declared registration number automatically against the body's own public register, a member of our team may write to the professional body you named to ask them to confirm your name and number against their records. We only ever contact the specific body you declared, never a general directory, and we ask nothing beyond that one confirmation. We process this under our legitimate interest in keeping the directory accurate and trustworthy for the clients who rely on it (Article 6(1)(f)).
Your training and certificates
If you upload a certificate, transcript or CPD record, an EU-based document-reading service reads the courses from it. You check each course before we keep it.
Only courses with a certificate or a listing on your own pages appear on your profile. Clients see each one by its title. A course you add yourself stays private.
The courses you confirm shape one or two questions in your onboarding conversation. You can skip them.
Only our team can open a document you upload, such as a certificate or an insurance schedule.
We read and show your courses to perform our contract with you (Article 6(1)(b)). After a document stops backing a course on your profile, we keep it under our legitimate interest (Article 6(1)(f)), so we can show what supported the course if anyone questions it.
Your insurance
You upload your current professional indemnity insurance schedule or certificate. An EU-based document-reading service reads its text: the policyholder name, the insurer, the policy number, the policy dates, the limit per claim and what the policy covers. Our systems compare what it read with what our terms require.
When something is missing or falls short, we tell you what it is and which document clears it. A schedule, its policy wording and its certificate count together. If the policy is in your company's name, we check the public Companies House register to confirm you are one of its officers.
We introduce you to clients only while a verified policy is in date. We email you 30 days and 7 days before it ends. When it ends, we stop until your renewal is checked.
We check your insurance to perform our contract with you (Article 6(1)(b)). After the policy ends, a newer one replaces it or you close your account, we keep the verified document under our legitimate interest (Article 6(1)(f)), so we can show that we checked it if anyone questions it.
Your insurer and EAP registrations
You can tell us which health insurers and employee assistance programmes (EAPs) you are registered with, and which of your services each registration covers. A registration stays private until we check it.
We check it with the programme's own public directory or portal, or with the programme directly. We may ask you for a letter or email the programme sent you. We never ask you for a client's record. Your provider number and your evidence stay private. Only a registration we verified can show to clients.
We check your registrations to perform our contract with you (Article 6(1)(b)). After a verified registration ends, or you close your account, we keep its record under our legitimate interest (Article 6(1)(f)), so we can show that we checked it if anyone questions it.
Where you see clients in person
If you see clients in person, you tell us where. A shared venue, such as therapy rooms, has one record. Every professional who works there shares it.
We check a venue's details once. Each detail keeps its source, who checked it and when. We withdraw an access detail from clients when it is due for checking again.
Our research tool reads a venue's own public pages. We send it only the venue's name, address, postcode and operator. We never send it a web address you gave us.
We keep each detail with its web address and a short quote from the page. Our team checks every detail before clients see it. We hold photographs only with the venue operator's written permission.
When you type an address, we suggest addresses. Our servers send what you type to a map service in the EU, which keeps its logs for about two weeks. Your browser never contacts it for suggestions. We keep only the address you choose. The town field on the join form works the same way: our servers send what you type to that map service while you type, and once more when you submit the form if you did not choose a suggestion, so that we know which country your town is in. We keep only the town you enter or choose, and that country.
We show each venue on a map. When someone views a venue, their browser loads the map from that same map service in the EU. So the service sees their connection details, such as their IP address and the page they are on. We make no map of a home. Your own map service opens only when you choose "Get directions".
A venue's details are not personal data unless its operator trades in their own name. Then we hold that name and any quote that names them. We rely on our legitimate interest in accurate venue details for clients (Article 6(1)(f)).
If you run a venue, we tell you what we hold about you the first time we contact you. You can ask us to remove your name. The building's details stay, because they are not about you.
If you see clients in your own home, that address stays private to you. Clients only see your town. We never add it to a shared venue record, and our research tool never looks it up. Address suggestions work the same way for your home, and we never make a map of it.
To show clients how far away you are, we send a mapping service only the first half of your postcode. It identifies a postal district, not your home.
Your profile photos
When you upload a headshot or an environment photo we run an automatic check on it: a quality pass (lighting, focus, whether the face is clearly visible) and a safety pass (that it is a genuine photo and shows no other identifiable people). From a headshot we also note broad, apparent details, an approximate age range and apparent gender presentation, for two narrow purposes: to offer to complete a profile detail you left blank, and to flag an obvious discrepancy with what you told us so a person can check it. We never infer your ethnicity, race or nationality from a photo, and we never use any of these observations to override what you have told us: your own declared details always take precedence, and anything we observe is shown to you, never applied silently. The original photo is kept in EU object storage; cropped versions for display are generated on request.
Automated activation
Once your registration is verified (see above), your professional indemnity insurance is verified and in date (see "Your insurance") and neither of your photos is flagged in the safety check (see above), your profile goes live automatically. No person makes the go-live decision itself: we re-check each condition the moment one changes, and activate your profile the moment all three are met.
Going live is a significant decision taken by automated processing, so the UK GDPR requires safeguards around it. Under Articles 22A to 22C of the UK GDPR you have the right to be told about the decision, to make representations about it and to contest it, and the right to obtain human intervention. If you want a person to look at your activation rather than the automated check, write to the data protection contact at the top of this notice and we will review it by hand.
How to opt out
Every outreach email carries a one-click unsubscribe link. Clicking it writes a permanent suppression keyed on your email address. If we found your practice through its website and hold no email address for you, we key the suppression on your website address instead. We will not contact you again, and a future re-import from another register will see the suppression and skip you. You can also write to the data protection contact at the top of this notice and we will action your request manually. We never share suppression evidence with third parties.
Suppression is permanent unless you ask us to revoke it (for example by signing up at /app/join yourself). Revocation is recorded with evidence so the audit trail stays intact.
If you later want to leave the platform after onboarding, you can request account deletion at any time. Profile data is removed, and so is the data we generate when we rank and connect you to clients, where it is not part of a booking record. Some records stay: billing records, a minimal closed account record and the other records the retention table below lists.
Booking records also stay, and we will itemise anything we keep. We hold them for six years after the session is completed or cancelled. That is in case either side raises a dispute.
Closing your account is one act, and we cannot undo it. Your profile, your working style, your voice signature, your photos and your contact details are erased. Nobody at ViaCara can restore them.
We keep the closed account record described below, and nothing in it rebuilds the profile. If you return to ViaCara later, you import your profile again from scratch. The practitioner terms set out what closure does to your subscription, your credits and your bookings.
Sub-processors
We use the same set of carefully chosen service providers across the platform. The full list is in the client privacy policy. It does not vary by audience. Core hosting and database storage are in the EU (Frankfurt). Companies House lookups go to the UK government's Public Data API, and Guernsey Registry lookups go to its public search service; a Jersey registry check is a manual search, not an automated lookup. The search service we use to find practitioners' own public websites reads those pages as a separate controller and receives no personal data from us. All sub-processors are engaged under written data processing agreements that meet Article 28 requirements.
Retention
| Data | Retention |
|---|---|
| Prospect rows (cold-discovered, never engaged) | Retained while the source register is still publicly listing you, deleted on a periodic sweep when the source removes you |
| Prospect rows sourced from a printed advert or a page advertising your practice, never engaged | Six months from the date we saw the advert or read the page, then deleted along with any photograph. An advert carries no register listing for us to re-check, so we use a fixed period instead |
| Lead and active practitioner data | Retained while your account is active, deleted on request. An account you stop using is not retained indefinitely: see the inactive accounts row below. The records in the rows below stay for the periods they give |
| Your working style, voice signature, lived experience and interests | Part of your active practitioner data above |
| Training documents you upload | Kept for six years after the last course they back stops showing on your profile, so we can show what supports it. A document that backs a course stays if you close your account, and the six years start then. A document that backs no course on your profile is deleted 30 days after you upload it |
| Insurance documents you upload | A document we verified is kept for six years after the policy ends or a newer one replaces it, so we can show that we checked it. It stays if you close your account, and the six years start then. A document we never verified is deleted when you remove it, or 30 days after you upload it |
| Insurer and EAP registrations you add | A registration we verified is kept for six years after it ends, so we can show that we checked it. It stays if you close your account: closing ends any registration still open, and its six years start then. A registration we never verified is deleted 30 days after it is rejected or you remove it |
| Booking records | Kept for six years after the session is completed or cancelled, in case either side raises a dispute. They stay if you close your account |
| Booking documents | The intake form, contract and invoice files stored for a booking are kept for six years after the session is completed or cancelled, in case either side raises a dispute. They stay if you close your account |
| Inactive accounts | An account with no activity for six years is closed and reduced to the closed account record below. We give at least thirty days' notice first |
| Closed account record | The name you used, your registration details and the closure date are kept for six years after your practitioner account closes. Everything else is erased. It stays if you delete your account, because it is the evidence the closure happened |
| Record that you asked for an invitation | Kept for six years from the date we recorded it, so we can show the invitation was one you asked for. Asking us to stop ends the contact and leaves this record in place. It stays if you close your account |
| Outreach event log | 24 months from the event date, then deleted |
| Venue details and the evidence behind them | While professionals work there, and for 12 months after the last one leaves |
| What we found when researching a venue | 90 days after our team has checked it |
| A check on whether an address is a venue we already list | 90 days after our team decides |
| Suppression records | Kept for as long as we could otherwise contact you again, so that a future import cannot undo your opt-out. They stay if you delete your account |
| Marketing consent and its withdrawal | Held until withdrawn; the withdrawal is kept as evidence |
| Marketing delivery log | 24 months, then deleted |
| Quality review records (no raw text), such as photo checks and profile link clicks | Deleted within 90 days |
| A reviewed copy of your onboarding conversation, if you said yes | Deleted 30 days after you agreed, or straight away if you withdraw |
| Measures from your onboarding conversation, with no words in them | Deleted within 90 days |
| A made-up practitioner written from that copy, before a team member approves it | Deleted within 30 days, or straight away if you withdraw |
| Feedback you send from the app | Deleted twelve months after you send it, or when you close your account |
| A note you add to a star rating | Deleted twelve months after you send it, or when you close your account. The star rating stays |
| A screenshot you add to your feedback | Deleted 30 days after you send it, when you close your account, or sooner if you ask |
| Live update delivery copies | Eligible for deletion after one day. An hourly cleanup removes expired copies |
| Record of an introduction | The first name of each client we introduced you to, and when. Employment agency law requires us to keep it for one year after your last introduction. It stays if you close your account |
| Record of a notice to a client | Which client we told, when and why. Kept for one year after your last introduction, like the record of an introduction. It stays if you close your account |
| Billing records | Kept for six years from the end of the financial year they belong to, as UK tax and accounting law require. They stay if you close your account |
| Phone verification codes | A record of each code we send is deleted within 30 days. We never store the code itself in readable form |
| Security record of sign-ins and account changes | Each event is kept for six years, then deleted. It stays if you delete your account, so we can investigate suspicious activity |
| Record of a data rights request | Kept for three years after our final response. It stays if you close your account, because it is the evidence we answered you |
| Dispute records | Where a dispute is raised, the related evidence is kept for six years after it is resolved or closed. They stay if you close your account |
| Referral link activity | 24 months from the day it was recorded, then deleted |
| IP addresses counted to limit misuse | Kept with a one-minute count, then deleted within two weeks |
Cookies and browser storage
ViaCara does not use tracking cookies or advertising cookies. We use the cookies and browser storage below.
| Name | Purpose | Retention |
|---|---|---|
hanko cookie | Our sign-in service sets this first-party cookie. It keeps you signed in | 12 hours |
_viacara_session cookie | Protects form submissions and carries short-lived app notices. It does not keep you signed in | Your current browser session |
vc_nav_search_opener browser storage | Carries your site-search query to a conversation when no search result fits | Until the home page opens the conversation, or you close the browser tab |
vc-theme browser storage | Remembers your light or dark theme choice | Until you change the choice or clear this site's data |
Each item supports a feature you request. Schedule A1 paragraph 4 covers automatic authentication, security and saved website choices.
These uses are strictly necessary under that clause. PECR Regulation 6 therefore does not require consent. We do not show a consent banner.
None of these items tracks you across other websites.
Our analytics service counts page visits and button presses on our site and in your account. In your account, it receives only the kind of page, the button name and the website you came from. It never receives which record or person the page is about.
Our analytics service is cookieless, uses no persistent identifiers and collects no personal data. It does not write to browser storage.
Your rights
You have the same rights as any data subject under UK GDPR: access, correction, deletion, restriction, portability, objection, and the right to withdraw consent. To exercise any of them, write to the data protection contact at the top of this notice. We respond within one calendar month.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you are unhappy with how we handle your data. If you are resident in the Bailiwick of Guernsey, including Alderney and Sark, you may lodge a complaint with the ODPA. If you are resident in Jersey, you may lodge a complaint with the JOIC.
Changes to this notice
We update this page when our practices change. Material changes are communicated by email to active practitioners. Inactive prospects are not emailed about policy changes. That would itself be unsolicited contact.
Last updated: October 2026
This notice is written in plain language and is periodically reviewed for accuracy.