Privacy
Flutura Ltd makes software for CBT therapists. This policy explains what we do with personal data when you use it.
It is written for the therapists and institutions who hold a Flutura account. If you are a client of a therapist who uses Flutura, your therapist decides what happens to your data and is the right person to ask about it. Clause 3 explains why.
For data protection questions, contact us at support@flutura.appLast updated: 24 September 2026
Flutura Ltd
7 Craven Terrace, Pole Lane, Darwen, England, BB3 3FW
Company number 16205296
Registered with the Information Commissioner’s Office, reference ZB870821. You can check that on the ICO’s public register.
Contact us about anything in this policy at support@flutura.app. Our named contact for data protection is Tino Triste, reachable at the same address. We have not appointed a Data Protection Officer, because Flutura does not meet the threshold that requires one.
It covers:
It does not cover what your therapist does with your data outside Flutura, or any third-party service you reach through a link.
Flutura is provided in the United Kingdom, for practitioners working in the United Kingdom.
Under UK GDPR there is a difference between the organisation that decides how personal data is used, the controller, and the organisation that handles it on their instruction, the processor.
For your clients’ data, you are the controller and Flutura is the processor. Their records, session recordings, transcripts, notes and assessment scores belong to your practice. We hold and process them on your instruction, and for no other purpose. Where an institution holds the licence, that responsibility is the institution’s.
For your own account, Flutura is the controller. That covers your name, contact details, professional details, subscription and payment records, and how you use the product.
This matters in practice. Your clients exercise their data rights through you, not through us, and we help you answer them. Your own rights, in clause 12, you exercise directly with us.
Your account. Your name, email address, professional details, login credentials, subscription and billing records.
Your clients’ data, entered by you. Client names and contact details, session recordings and the transcripts made from them, session notes, assessment scores, homework and diary entries. This is health data, which UK GDPR treats as special category data and gives the highest level of protection.
Technical and usage data. Sign-in records, device and browser information, IP address, and a log of actions taken in your account.
This clause covers the data we control, which is your account data. Your clients’ data we process on your instruction, under clause 3, and the lawful basis for it is yours to determine as the controller.
Providing the product and your account. Performance of our contract with you.
Taking payment and keeping accounting records. Our contract with you, and our legal obligations.
Keeping the platform secure and preventing misuse. Our legitimate interests.
Understanding which features are used, so we can improve them. Our legitimate interests.
Service messages about your account. Performance of our contract with you.
Marketing emails. Your consent, which you can withdraw at any time.
Meeting regulatory and legal obligations. Legal obligation.
In the UK. All Flutura infrastructure runs in Amazon Web Services’ London region: the application you sign into, the database holding your records, your account data, session recordings, transcripts and the notes made from them.
All of it encrypted in transit and at rest.
Four companies process data on Flutura’s behalf. Each works under a contract that limits them to what we instruct.
Cloud infrastructure, UK. Runs the application, session recordings, transcripts and the processing queue in its London region. Infrastructure only, with no access to content. Kept for as long as your account is open.
Database hosting, UK. Holds client records, notes and account data, also in London. Database hosting only, with no access to content. Kept for as long as your account is open.
Transcription, United States. Receives session audio and turns it into a transcript. Keeps the audio for up to 72 hours, then deletes it automatically. SOC 2 certified and contractually barred from training on your data.
Note drafting, United States. Receives the transcript and drafts your note from it. Keeps the transcript for up to 30 days, then deletes it. Works under a data processing agreement and does not use your data for training.
Account holders and institutions can have the named list on request, at support@flutura.app.
If we change a processor or add one, we will tell you at least 30 days before it takes effect. If you object on reasonable data protection grounds, tell us and we will work it through with you. If we cannot resolve it, you can end your subscription.
Session audio is processed in the United States during transcription. The transcript is processed in the United States while your note is drafted. Both carry personal data, including health data.
Both sit under data processing agreements and the UK GDPR rules governing international transfers, using the transfer mechanisms those rules require.
Everything else stays in the UK.
Your clients’ data we keep for as long as your account is open, because it is your clinical record and you decide when it goes. You can delete individual records at any time.
Session audio held by the transcription provider is deleted automatically within 72 hours. Transcripts held by the note-drafting provider are deleted within 30 days. Your own copies stay in your account.
Your account data we keep while your account is open.
Billing records we keep for as long as tax and company law requires.
Action logs we keep for as long as your account is open.
If you close your account, you have 30 days. During that time you can still sign in to export your data, or to change your mind. After that, write to support@flutura.app and everything is permanently deleted: recordings, transcripts, notes, client records and account data.
If Flutura ever stops operating, every account holder gets 90 days’ notice by email. Export works throughout that period, and for 30 days after the service ends.
Data is encrypted in transit and at rest.
Your session recordings are accessible only to you, through your authenticated account. Flutura staff do not access session audio. There is an administrator role for running the platform, and it has no access to session audio either.
You see your own clients and nothing else. No other therapist using Flutura can see any of it. Your clients see only what belongs to them, and they cannot see your notes.
Every action taken in an account is logged.
If there is a breach affecting your data, we will tell you without undue delay after we become aware of it, and give you what you need to meet your own duties as the controller. Where a breach is reportable, it is you who reports it to the ICO, and you have 72 hours from becoming aware to do so.
No service can promise perfect security, and we do not. What we can tell you is what we do and who can reach what, which is the whole of this clause and clause 7.
On flutura.app, the site you are reading, cookies fall into four groups. Only the first is set before you choose.
Essential. Needed for the site to work and to keep it secure. These are always on, because without them the site does not function.
Analytics, off until you agree. Google Analytics, to see which pages people read, and Microsoft Clarity, which records how visitors move through a page so we can find what is confusing.
Advertising, off until you agree. Google Ads and Meta, so we can measure whether our advertising reaches the right people.
Support, off until you agree. Gleap, the widget you can use to send us feedback or report a problem. It remembers your conversation between pages so you do not have to start again.
You choose when you first arrive, and you can change your mind at any time from Cookie settings in the footer.
In the Flutura app you sign into, cookies keep you signed in, remember your preferences, and measure how features are used so we can improve them.
We do not use your client data for analytics. We measure how the product is used, not what is said in a session.
You can ask us to:
Write to support@flutura.app. We will respond within one month.
If you are not happy with how we have handled your data, you can complain to the Information Commissioner’s Office at ico.org.uk. We would rather you came to us first, but you do not have to.
Your clients have the same rights, and they exercise them through you, because you are their controller.
You can export, correct or delete any client’s records from within Flutura. Where a request needs something the product does not do on its own, write to support@flutura.app and we will help you answer it. We handle requests as your processor, including the right to erasure under Article 17 of UK GDPR.
Clients under 16. Therapists use Flutura with younger clients, and their data carries the same protection as any other client’s, with the same access limits and the same retention. As their controller, you decide the lawful basis for working with a young person, and you obtain consent from the young person or from someone with parental responsibility, as their age and understanding require. Flutura holds the record; the clinical and consent decisions are yours.
Your client data is never used to train any AI model, ours or anyone else’s. That holds for the companies who process it, by contract.
It is never sold. It is never shared for advertising. It is never used for anything other than providing the service.
We update this policy when the product or the law changes. The date at the top always tells you which version you are reading. If a change materially affects you, we will tell you by email or in the app before it takes effect.
Flutura Ltd
7 Craven Terrace, Pole Lane, Darwen, England, BB3 3FW
support@flutura.app
The terms under which Flutura processes your clients’ data, as Article 28 of UK GDPR requires, are set out in clause 5 of our Terms of Service. They apply to every account, so there is nothing to request.
Institutions can have the governance pack, and a conversation with their own IT and data protection people, before any pilot begins.