Last updated 1 August 2026

Privacy Policy

What personal data we collect, why we collect it, the legal bases we rely on, and the rights you have.

Operator
Naleia & co ltd
Audience
Visitors, account holders and invited organisation users
Contact
privacy@theconsiliom.com

Who we are and the scope of this policy

This Privacy Policy explains how The Consiliom collects, uses, shares and protects personal data when you use our website and app. For your personal account we are the data controller responsible for your information. Where you use the Service as part of an organisation, that organisation may be a separate controller for its own care or workforce purposes and will provide its own privacy information.

We serve users internationally and comply with the UK GDPR and Data Protection Act 2018, the EU GDPR, and applicable US state privacy laws including the California Consumer Privacy Act as amended by the CPRA.

Information we collect

We aim to collect only the information needed to provide the Service you use.

  • Account and identity data: your name, email address and phone number, together with email-verification state and authentication records.
  • Content you create: goals, pillars, plans, tasks, workouts and any wellbeing values or notes you choose to enter.
  • Usage and analytics data: how you interact with the app, feature usage, approximate device and browser details and general performance and diagnostic information.
  • Security and operational data: timestamps, IP address, audit events and rate-limit records used to keep accounts secure.
  • Subscription and billing metadata (paid plans only): your subscription status, plan and renewal dates, and limited details such as the card brand and last four digits returned to us by Stripe. We never receive or store your full card number.
  • Organisation data (where those features are enabled): membership, role, invitation and agreement records, and any category-level sharing decisions you make.

Payment data and Stripe

All payments are processed by Stripe, our payment processor. Your full card or bank details are entered directly with Stripe and are never collected, seen or stored by us. We only receive the limited billing metadata described above — such as subscription status, plan and the last four digits of your card — that we need to manage your account and subscription.

Stripe processes your payment data as an independent controller under its own terms. Please read the Stripe Privacy Policy at https://stripe.com/privacy to understand how Stripe handles your information.

Why we use your information and our legal bases

We use your information to provide and secure the Service, to manage accounts and subscriptions, to communicate with you about the Service, to improve and troubleshoot it, and to meet our legal obligations.

  • To provide the Service and manage your account and any subscription — legal basis: performance of a contract with you.
  • To secure the Service, prevent abuse and keep audit and diagnostic records — legal basis: our legitimate interests in a safe and reliable service.
  • To send service and transactional messages (for example verification and billing notices) — legal basis: performance of a contract and our legitimate interests.
  • To measure usage through analytics and to send optional marketing — legal basis: your consent, which you can withdraw at any time.
  • To comply with legal, tax and accounting obligations — legal basis: compliance with a legal obligation.

Cookies and analytics

We use essential storage to sign you in and keep the Service secure, and — only with your consent — analytics technologies to understand usage and improve the app. You can review and change your choices at any time. See our Cookie and Tracking Notice for details.

How we share your information

We do not sell your personal data. We share it only with service providers that help us run the Service under contract and on our instructions, and where the law requires or permits it.

  • Stripe, to process payments and manage subscriptions.
  • Hosting and database providers that operate the platform infrastructure.
  • Analytics and communication providers used to measure usage and send service messages.
  • Authorised organisation users, where you use organisation features and have chosen to share with them.
  • Authorities or advisers where necessary to comply with law, enforce our terms, or protect rights and safety.

International data transfers

Because we serve a global user base, your information may be processed in countries other than your own, including the United States. Where we transfer personal data outside the UK or the European Economic Area, we protect it using an approved transfer mechanism such as an adequacy decision, the UK International Data Transfer Addendum, or the European Commission's Standard Contractual Clauses, together with appropriate safeguards.

How long we keep your information

We keep personal data only for as long as needed for the purpose it was collected, to provide the Service, and to meet legal, tax, accounting and security obligations. When you close your account we delete or de-identify your personal data within a reasonable period, except where we must retain certain records (for example billing records) for a legally required time. Backups follow a controlled expiry cycle.

Your rights under the UK and EU GDPR

If you are in the UK or EU you have rights over your personal data. Depending on the circumstances you can:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — ask us to delete your data where there is no overriding reason to keep it.
  • Restriction — ask us to limit how we use your data in certain cases.
  • Portability — receive certain data in a portable, machine-readable format.
  • Objection — object to processing based on our legitimate interests, and to any direct marketing.
  • Withdraw consent — where we rely on consent, withdraw it at any time without affecting prior processing.

Your rights under California law (CCPA/CPRA)

If you are a California resident you have the right to know what personal information we collect and how we use and disclose it; to request access to and deletion of that information; to correct inaccurate information; and to opt out of the "sale" or "sharing" of personal information. We do not sell your personal information and do not share it for cross-context behavioural advertising. We will not discriminate against you for exercising your rights. You may use an authorised agent to make a request, and we will verify requests through your account.

How to exercise your rights

You can start a request from the Privacy Centre in your account, or contact us at privacy@theconsiliom.com. We will respond within the time required by law (generally one month under the GDPR, or 45 days under the CCPA, with any permitted extension). If you are in the UK you can also complain to the Information Commissioner's Office (ico.org.uk); if you are in the EU you can complain to your local supervisory authority.

Security

We protect your information with measures including tenant-scoped authorisation, multi-factor authentication for privileged access, encryption of sensitive data, append-only audit records, least-privilege database roles and tested recovery procedures. No system is perfectly secure; if you suspect a problem, contact privacy@theconsiliom.com promptly.

Children

The Service is intended for adults aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

Changes to this policy and contact

We may update this policy from time to time and will change the effective date shown above; material changes will be brought to your attention. For any privacy question or to exercise a right, contact privacy@theconsiliom.com.