SECURITY & PRIVACY
Your trust, protected.
Resilience work is personal. We treat the privacy and security of every participant’s data with the seriousness it deserves — so people can focus on growth, not worry.
HOW WE PROTECT YOU
Privacy by design
The Resilient Mind holds information that is sensitive and valuable — including personal and protected health information. Our security and privacy policies define how that information is created, stored, accessed, and transmitted, and every member of our team is required to know and follow them.
HIPAA-aligned governance
Our information security and privacy program is built around HIPAA and HITECH requirements, with recognised standards including NIST SP 800-53 and ISO/IEC 27001 informing how we protect sensitive information.
Your health data, protected
Personal and protected health information is guarded against unauthorised access, use, or disclosure. Every employee and contracted worker is required to follow our security and privacy policies.
Clear data retention
We keep account and app data only as long as your account is active, and for up to five years after it closes. HIPAA-related records may be held for at least six years where the law requires it.
WHAT WE SAFEGUARD
Built to protect what matters
Our policies cover every system and every form of information across the places we work — from the app to our assessments and internal tools.
Confidentiality, integrity & availability
The three pillars our policies are designed to preserve across all information assets.
Protected health information (PHI)
Health and personal data guarded from unauthorised use, disclosure, or modification.
Every device & connection
From office equipment to personally-owned devices used for work, wired or wireless.
Ongoing audits & reviews
Our policies form the basis for internal and external audits, reviews, and assessments.
YOUR CONTROL
Delete your data anytime
You can request deletion of your ResilientMind account and associated personal data at any time. Just email us with the subject line ResilientMind Account Deletion Request, including the name and email address on your account so we can verify it. Once we receive a valid request, we delete or de-identify your account and personal data within a reasonable period — except where we’re required to retain certain records for legal, HIPAA-related, or security reasons.
Questions about security?
We’re happy to walk you through our privacy and data-protection practices in detail.