Legal
Privacy Policy
Last updated: 1 September 2026. This policy is maintained by BYOU and explains how we handle personal data on the BYOU website, the BYOU iOS app and the BYOU Android app.
1. Who we are
BYOU ("BYOU", "we", "us") operates the BYOU website at byou-app.com, the BYOU client app and the BYOU expert (partner) app. For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, BYOU is the data controller for the personal data described in this policy.
You can reach us about any privacy matter at info@byouimpact.org.
Experts who deliver sessions through BYOU act as independent providers and are separate controllers for the professional records they keep about their own clients. This policy covers BYOU's own processing.
2. Personal data we collect
Account data. Name, email address, password credentials, country, language and, for experts, professional details, qualifications and verification documents.
Booking and transaction data. Sessions booked, session type, expert selected, payments made, referral codes, invoices and payment status. Card details are processed by our payment provider and are not stored by BYOU.
Content you provide. Messages, intake answers, reviews, support requests and any information you choose to share with us or with an expert.
Technical data. IP address, device and browser type, operating system, referring URL, pages viewed and timestamps, collected through logs and analytics.
Marketing and referral data. Newsletter subscriptions, communication preferences, referral and affiliate link identifiers, and campaign parameters (such as utm tags) that tell us how you found BYOU.
Session data. Session date, duration, attendance and, where a session is delivered by video, the connection metadata needed to run the call. We do not record sessions unless both you and the expert explicitly agree in advance.
Business account data. If your employer sponsors your access, we process your work email, department or team where provided, and your booking history.
Some information you share with an expert may concern your health or wellbeing. Where such data qualifies as a special category of personal data, we process it only with your explicit consent or where another lawful basis under Article 9 GDPR applies.
3. Why we use your data and our legal bases
To provide the service (creating your account, matching you with experts, processing bookings and payments, enabling sessions) - performance of a contract, Article 6(1)(b) GDPR.
To operate, secure and improve the platform (fraud prevention, debugging, analytics, service quality) - our legitimate interests, Article 6(1)(f) GDPR.
To verify experts and maintain the standard of our network - performance of a contract and legitimate interests.
To send service messages such as booking confirmations and account notices - performance of a contract.
To send marketing such as newsletters or product updates - your consent, which you can withdraw at any time, or legitimate interests where permitted by law.
To meet legal obligations including tax, accounting and responding to lawful requests - Article 6(1)(c) GDPR.
5. How long we keep data
We keep personal data only as long as needed for the purposes described above. Account data is retained for as long as your account is active and for a reasonable period afterwards to handle disputes and legal claims. Transaction and invoicing records are retained for the period required by applicable tax and accounting law. Marketing data is kept until you unsubscribe. When data is no longer needed, we delete or anonymise it.
6. Security
We apply technical and organisational measures appropriate to the risk, including encryption of data in transit, access controls on our systems, role-based permissions for administrators and regular review of our infrastructure. No online service can guarantee absolute security, and you are responsible for keeping your account credentials confidential.
If a personal data breach is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority without undue delay and, where the law requires it, we inform affected users directly.
8. Android app and Google Play
The BYOU Android app is distributed through Google Play. When you install or use the Android app, Google processes certain information as the operator of Google Play and Google Play Services. This is governed by Google's own privacy policy, which we encourage you to read.
Android permissions. The app may request access to your camera and microphone so you can join video sessions, to your calendar so we can add bookings, and to notifications so we can send booking reminders and account updates. You can grant or revoke these permissions at any time in your Android device settings.
Push notifications. We use Firebase Cloud Messaging to deliver push notifications. Firebase may process a device token to route messages to your phone. You can turn off notifications in your device settings or in the app.
In-app purchases. Session payments on Android are processed through Google Play Billing. Google handles the payment and provides us with transaction details such as the purchase identifier, status and timestamp. We do not receive or store your full payment card details.
Device data. We collect technical information needed to run the app securely, including your device model, Android version, app version and a device identifier. We use this for troubleshooting, fraud prevention and improving performance.
Local storage. Some data, such as login tokens and app preferences, is stored locally on your device to keep you signed in and improve your experience. You can clear this data through your device settings or by uninstalling the app.
9. iOS app and the App Store
The BYOU client and expert apps are also distributed through the Apple App Store. Apple processes download, purchase and crash information as an independent controller under its own privacy policy.
App tracking. We do not track you across apps or websites owned by other companies for advertising purposes. If that ever changes, we will ask for your permission through Apple's App Tracking Transparency prompt first.
In-app purchases. Sessions paid for inside the iOS app are handled by Apple's in-app purchase system. We receive the transaction status and identifier, not your payment card details.
Apple permissions. Camera, microphone, notifications, calendar and photo access are requested only when a feature needs them, and can be changed at any time in iOS settings.
10. Wellbeing and health information
BYOU is a marketplace that connects you with independent wellbeing professionals. We are not a medical provider, and the platform is not a substitute for medical care or emergency services. If you are in crisis, contact your local emergency number or a crisis line.
Intake answers, goals and notes you share with an expert are visible to that expert. BYOU staff access this content only where strictly necessary, for example to investigate a safety report, a payment dispute or a technical fault, and always under confidentiality obligations.
Experts keep their own professional records under their own legal and professional duties, including any applicable healthcare or professional confidentiality rules. For those records the expert is the controller and you should ask them for their privacy notice.
11. Matching, profiling and AI features
We use your stated preferences, category selections, language and location to suggest relevant experts and content. This is profiling in a limited sense, but it does not produce legal or similarly significant effects for you, and a human decision is never replaced by an algorithm in the booking process.
We do not make decisions based solely on automated processing within the meaning of Article 22 GDPR. Automated checks may flag suspected fraud or abuse, but a person reviews the outcome before any account is suspended.
Where we use AI features to support search, summaries or support responses, we do not use your personal content to train third-party foundation models.
12. Employer and business accounts
If your organisation sponsors BYOU sessions for its people, your employer is a separate controller for the employee data it shares with us and for its own decision to offer the programme. Your employer receives aggregated, de-identified usage reporting only. Your employer does not receive the identity of the expert you booked, your intake answers, your session content or any individual health information.
13. Your rights
Subject to applicable law, you have the right to access your personal data, to rectify inaccurate data, to erasure, to restrict or object to processing, to data portability, and to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. You also have the right to object to direct marketing at any time.
To exercise a right, email info@byouimpact.org. We respond within one month, and may extend this by two further months for complex requests. You may also lodge a complaint with your local data protection authority.
14. United States state privacy rights
If you are a resident of California, Colorado, Connecticut, Virginia or another US state with a comprehensive privacy law, you may have the right to know what personal information we collect, to access a copy, to correct it, to delete it, and to appeal a refused request.
We do not sell personal information and we do not share it for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA. We do not knowingly sell or share the personal information of anyone under 16. We honour Global Privacy Control signals where our site can detect them.
To make a request, email info@byouimpact.org. We will verify your identity through your account email and will not discriminate against you for exercising a right. An authorised agent may submit a request on your behalf with written proof.
15. Children
BYOU is not intended for children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
16. Third-party links and apps
Our sign-up flows and mobile experiences are hosted on BYOU-operated applications. Our website may also link to third-party sites we do not control. This policy does not apply to those third parties, and we encourage you to read their privacy notices.
17. Changes to this policy
We may update this policy to reflect changes in our service or legal obligations. We will update the date at the top of this page and, where changes are significant, notify you by email or in the app.
18. Contact
Questions about this policy or how we handle your data: info@byouimpact.org. This address also reaches our privacy contact for data protection requests, breach reports and complaints.
If you are in the European Union and you are not satisfied with our response, you may complain to your national data protection authority. In the Netherlands this is the Autoriteit Persoonsgegevens; in the United Kingdom it is the Information Commissioner's Office.
