The Resilient Mind

LEGAL

Security & Privacy Policy

Our Information Security and Privacy Governance Policy sets out how The Resilient Mind protects sensitive information across all of its systems and people. This page summarises the key points; the definitive HIPAA governance policy is available in full on request.

Governing statement

The Resilient Mind Empowering Self-Care Inc. holds information that is sensitive and valuable — including personal health information, personally identifiable information, and financial data — as well as information required for everyday business. Some of this is protected by federal and state law and by contractual obligations. Unauthorised access could cause serious harm to the company and its community, so every employee and contracted worker is required to protect this information and the systems that support it, and to know and follow the associated policies.

Purpose

Our security and privacy policies exist to protect company information and system resources; to preserve the confidentiality, integrity, and availability of information assets; to establish clear governance and accountability; to build awareness so personnel make sound security decisions; to protect patient, customer, and employee information from unauthorised use or disclosure; and to support compliance with HIPAA, HITECH, and other applicable legal and regulatory requirements.

Scope

These policies apply to all company personnel — including contracted workers and consultants — and to every system, application, and piece of information in all forms and locations where company business is performed. They cover the full network of hardware, software, and communication equipment, including personally-owned devices used for company purposes, whether connected by wire or wirelessly. Where the company has a legal, contractual, or fiduciary duty to protect resources owned by others, the more restrictive measures apply.

Applicable laws & standards

The company follows all HIPAA and HITECH requirements alongside other applicable laws and regulations. Its practices are informed by widely recognised standards, including NIST SP 800-53 and SP 800-66 and ISO/IEC 27001 and 27002 for security policy and controls.

Data retention

We retain user account information and associated app data for as long as an account remains active, and for up to five (5) years after it becomes inactive or is closed — unless a longer period is required or permitted by law, contract, regulation, security or accounting obligations, dispute resolution, or legitimate business purposes. Where information is subject to HIPAA-related obligations, certain records may be retained for at least six (6) years where required. Once the applicable period expires, personal information is securely deleted, de-identified, or anonymised.

Your data deletion rights

You can request deletion of your ResilientMind account and associated personal data at any time by emailing support@theresilientmind.life with the subject line ResilientMind Account Deletion Request. Please include the name and email address associated with your account so we can verify and process the request.

Once we receive a valid request, we delete or de-identify your account and personal data within a reasonable period — unless we are required or permitted to retain certain information for legal, regulatory, HIPAA-related, contractual, security, accounting, audit, or dispute-resolution purposes. Deleting an account may permanently remove access to your app account, progress records, saved responses, and program history. Some information may remain temporarily in secured backup or disaster-recovery systems until removed under our normal retention procedures, and we may keep de-identified or aggregated data that does not identify you for research, reporting, and product improvement.

Policy exceptions

Exceptions may be granted only in unusual circumstances where compliance with a specific policy is not possible. They are coordinated with management, documented with the mitigating controls that must be followed, and approved by the Information Security Officer or the Corporate Privacy Officer for a defined, reasonable time period.

Questions about this policy? Contact us and we’ll be glad to help.

Scroll to Top