PillarX
Back

PillarX Practice - Counseling Privacy Annex

Last updated: 2026-09-05

For people receiving counseling

This notice is for people receiving counseling from a practitioner who uses PillarX Practice. It explains what is held about you, who is responsible for it, and how it is protected. Some points are still being settled with a data protection adviser, and those are marked rather than filled in with text nobody has agreed to.

1. Who This Notice Is For

This notice is for people receiving counseling from a practitioner using PillarX Practice. If you are the practitioner, the practitioner terms and the practitioner data processing agreement are the documents written for you.

PillarX Practice is software your practitioner uses to keep their records: who they are seeing, what each session covered, and what is scheduled next. This notice describes what that means for you.

It covers only those clinical records. It does not cover a PillarX wellness account you may separately hold, with its mood entries, challenges and community activity. Those are covered by the PillarX Privacy Policy, and section 9 below explains how the two relate.

Read the PillarX Privacy Policy

PillarX Practice is not generally available. It is used by a small group of practitioners by invitation, and this notice is published as the product is introduced.

If anything here is unclear, ask your practitioner. They hold your records and they are the person to start with.

2. Who Is Responsible for Your Records

Your practitioner decides which clients to record, what goes into each record, and why. Those decisions are theirs, and so is the responsibility that comes with them.

PillarX supplies and protects the software. It stores your records on your practitioner's instructions, does not read them for its own purposes, and does not decide what goes into them.

If you were referred through a workplace programme run with your employer, the organisation running that programme is also involved in deciding why the processing happens. Your employer's HR team is not. Section 7 explains exactly what they do and do not receive.

Still being settled

  • Who holds which formal role under data protection law has not yet been confirmed. The description above is the intended position and is under review with a data protection adviser. It is not a determination.
  • The written agreement recording that arrangement is not yet in place. It is being finalised and will be published with the practitioner documents.

3. What Is Held About You

Your practitioner can record the following. What is actually held depends on what they enter.

  • Your name and email address
  • Your date of birth or year of birth, and your gender
  • Session records: the date, the time and length of the session, the issue areas discussed with a severity rating for each, the causes recorded against them, and your practitioner's written note
  • Appointments: when they are, how long they run, whether they happened, and any note your practitioner attached
  • A fee amount, if your practitioner records one
  • If you came through a workplace programme: the organisation, a department label, and whether you are a member of that organisation
  • A record that your practitioner confirmed they have your consent to record your sessions, and when they confirmed it

Session records are information about your health. Under the GDPR that is special category data, and it is treated with the additional care that requires.

4. How Your Records Are Protected

These are properties of the software, not statements of intent:

  • Your records have their own encryption key. Your name, email address, date of birth, session notes and appointment notes are encrypted with it before they are stored.
  • That key is protected by a root key used only for clinical data, separate from the one protecting the rest of the PillarX platform.
  • Your practitioner reaches their own caseload and nothing else. No practitioner can browse another practitioner's clients.
  • Opening a record of yours writes an entry recording which record was opened and by whom, never what it said.
  • The clinical part of the software is separated from the rest of the platform by a boundary the build enforces.
  • The reminder emails your practitioner receives carry nothing about you: no name, no time, not even a count.
  • Nothing in your records is analysed, summarised or scored. PillarX Practice contains no artificial intelligence, and nothing recorded about you is sent to a language model.

If your records are erased, the key is destroyed and what remains cannot be read back, including from a backup. That step cannot be undone.

Still being settled

  • Where your records are stored and processed, and whether any of it happens outside the European Economic Area, is being documented and is not stated here. A claim we have not verified would be worse than none.
  • How long backups are kept is being confirmed and is not stated here.

5. Why Your Records May Be Held at All

Health data may only be processed where the law allows it, and a notice like this one is supposed to tell you which permission applies to you.

Still being settled

  • The lawful basis for clinical records, and the Article 9 condition that permits health data to be processed at all, are not yet settled. They are under review with a data protection adviser and will be published here.
  • The consent your practitioner takes from you is theirs to obtain and to word. PillarX records that your practitioner confirmed they hold it, not what you agreed to. A model form is being prepared with a data protection adviser.

In the meantime, your practitioner can tell you what they asked you to agree to and why.

6. How Long Your Records Are Kept

Nothing in the software deletes a clinical record on a timer. A record stays until your practitioner erases it.

Still being settled

  • How long a clinical record should be kept is not yet settled. No retention period is fixed, the question is under review with a data protection adviser, and the answer will be published here. The retention schedule in the PillarX Privacy Policy covers the wellness product and does not extend to clinical records.

Your practitioner may also be under professional rules about how long they must keep records. Those rules are theirs, and they can tell you what applies.

7. Who Else Sees Your Records

Your practitioner sees your records. No other practitioner does.

If you were referred through a workplace programme, your employer's HR team never sees a record, a session note, or your name. What they receive is aggregate reporting: counts and distributions across everyone in the programme.

Those aggregates are withheld below a minimum group size, and for smaller organisations most breakdowns are not produced at all, so a figure cannot be narrowed back to one person.

Clients a practitioner sees in their own practice never appear in any workplace reporting.

Still being settled

  • The complete list of service providers involved in handling clinical records is not yet final. It is being prepared and will be published with the practitioner documents. The list in the PillarX Privacy Policy covers the wellness product and was drawn up for different processing.

8. Your Rights

Under the GDPR you have the right to ask for access to your data, to have it corrected, to have it erased, to restrict or object to its processing, and to receive it in a portable form.

Start with your practitioner. They hold your records, they decide the answer, and in most cases they can act on it directly in the software.

A practitioner can correct the clinical content of a session for 24 hours after saving it. After that the note is fixed, which is what makes it a reliable record. The software offers no way to rewrite it later, so a correction after that point is something to raise with your practitioner, who can tell you how they record it.

Erasure destroys the encryption key held for you. It takes effect immediately and cannot be reversed.

Still being settled

  • The procedure for a request that PillarX itself has to act on, and how long a response takes, are not yet settled and are with a data protection adviser.

You can also complain to a data protection supervisory authority. Which authority is competent depends on where you and your practitioner are. The PillarX Privacy Policy names the authority for PillarX's own processing.

Read the PillarX Privacy Policy

9. If You Also Have a PillarX Account

PillarX also makes a wellness app with mood tracking, challenges and a community. If you use it, that account and your clinical records are kept apart. Nothing you write in the app appears in your practitioner's records, and nothing in those records appears in the app.

You can download a copy of your data from a PillarX wellness account. That export deliberately excludes clinical records, because it returns the data PillarX is itself responsible for. The exclusion is enforced in code rather than left to care: a check in our build pipeline fails if the export ever reaches a clinical table.

To get a copy of a clinical record, ask your practitioner, or the programme that referred you.

10. Contact

For anything about your records, ask your practitioner first.

For questions about the software itself, email PillarX at pillarx@mypillarx.com.

PillarX is the company behind PillarX Practice. Our legal form, registered address, company registration number and VAT number are published on the imprint page rather than repeated here.

Company details

If this notice changes, the revised version is published on this page with a new date. Because several points above are still being settled, expect it to change more than a finished notice would.