LEGAL
Privacy Policy
At The Resilient Mind, we recognize that the information you share with us may be personal and sensitive. Protecting your privacy and maintaining your trust are fundamental to how we operate.
Information We Collect
We may collect personal information that is necessary to provide our programs, services, assessments, digital tools, and participant support. This may include information such as your name, contact information, account information, program participation information, assessment responses, and other information you voluntarily provide.
We seek to collect only the information reasonably required to provide and improve our services.
How We Use Information
Personal information may be used to:
- Provide access to The Resilient Mind programs, services, and digital platforms.
- Administer participant accounts and program activities.
- Deliver assessments, educational content, reminders, and communications.
- Provide customer and technical support.
- Evaluate and improve the effectiveness of our programs and services.
- Maintain the security, reliability, and integrity of our systems.
- Meet applicable legal, contractual, privacy, and regulatory requirements.
We do not sell personal information.
Confidentiality and Access
Access to personal information is restricted to authorized individuals who require the information to perform legitimate business, technical, administrative, or program-related responsibilities.
Employees, contractors, and service providers who may have access to sensitive information are expected to follow appropriate confidentiality, privacy, and security requirements.
Sharing of Information
We may use trusted third-party service providers to support the operation of our technology, communications, data storage, or other business functions.
Where third-party providers handle personal information on our behalf, we seek to use providers that maintain appropriate privacy and security safeguards.
Personal information may also be disclosed where required by law or where necessary to protect the rights, safety, security, or legal interests of The Resilient Mind, our users, or others.
Data Retention
We retain personal information only for as long as reasonably necessary to provide our services, meet contractual or operational requirements, and satisfy applicable legal or regulatory obligations.
Account and application information may be retained while an account remains active and for a defined period following account closure. Certain records may need to be retained longer where required by law, regulatory requirements, security obligations, or contractual commitments.
Your Choices and Rights
Depending on your location and applicable privacy laws, you may have the right to request access to, correction of, or deletion of certain personal information associated with your account.
Participants may request deletion of their ResilientMind account and associated personal data. Certain information may need to be retained where required for legal, regulatory, security, or legitimate operational purposes.
Privacy Questions
If you have questions about how your information is collected, used, stored, or protected, please contact The Resilient Mind.
We are committed to addressing privacy questions and concerns in a responsible and timely manner.
Security Policy
The Resilient Mind is committed to maintaining the confidentiality, integrity, and availability of the information entrusted to us.
Our information security program is designed to protect personal and sensitive information from unauthorized access, use, disclosure, alteration, loss, or destruction.
Security Governance
Our security and privacy practices are built around recognized principles for protecting sensitive information.
The Resilient Mind’s information security and privacy governance is aligned with applicable HIPAA and HITECH requirements, with recognized security frameworks and standards, including NIST SP 800-53 and ISO/IEC 27001, informing our approach to information protection.
Our policies establish responsibilities for the appropriate creation, access, storage, processing, transmission, retention, and disposal of information.
Access Controls
Access to systems and information is limited according to legitimate business and program requirements.
Administrative and technical controls are used to help ensure that only authorized individuals can access sensitive information and systems.
Users are responsible for maintaining the confidentiality of their login credentials and for taking reasonable steps to prevent unauthorized access to their accounts.
Protection of Sensitive Information
The Resilient Mind may hold sensitive personal information and, where applicable, protected health information.
We use administrative, technical, and organizational safeguards intended to protect this information throughout its lifecycle.
These safeguards may include secure authentication, access restrictions, system monitoring, secure infrastructure, encryption and data protection technologies, employee and contractor responsibilities, and documented security procedures.
Technology and Infrastructure
Our technology environment is designed with security and privacy considerations incorporated into the operation of our systems.
We periodically review our technology, infrastructure, policies, and security controls to identify risks and opportunities for improvement.
Where third-party technology or infrastructure providers are used, we seek providers that maintain appropriate security safeguards and established data-protection practices.
Security Awareness and Responsibility
Information security is a shared responsibility.
Employees and contractors with access to The Resilient Mind systems or information are required to understand and follow applicable security and privacy policies and procedures.
Security awareness, appropriate access practices, and responsible handling of information are important elements of our security program.
Monitoring and Review
Security threats and technology continually evolve. For this reason, The Resilient Mind periodically reviews its security practices, policies, systems, and procedures.
Our security and privacy policies may also support internal reviews, risk assessments, compliance reviews, and external assessments where appropriate.
Incident Management
The Resilient Mind maintains procedures for responding to suspected or confirmed security incidents.
Where an incident involves personal or sensitive information, we assess the nature and potential impact of the event and take appropriate steps to contain, investigate, remediate, and document the incident.
Where notification is required by applicable law or contractual obligation, appropriate affected parties or authorities will be notified.
Our Commitment
Protecting information is an ongoing responsibility.
The Resilient Mind is committed to continually improving its privacy and security practices as technology, threats, regulatory requirements, and industry standards evolve.
Our goal is to provide participants, organizations, and partners with confidence that the information entrusted to The Resilient Mind is treated with care and protected through appropriate safeguards.