Privacy Policy for Viamente LLC
Effective Date: March 7, 2026
Last Updated: August 16, 2026
Introduction
Welcome to Viamente. We are committed to protecting your privacy and ensuring the security of your personal information, especially the sensitive mental health data you entrust to us. This Privacy Policy explains how we collect, use, store, share, and protect your information when you use our mobile application and services.
Viamente is designed to support your emotional wellness journey. We understand that the information you share with us is deeply personal, and we take our responsibility to protect it seriously. This policy is written to be clear and transparent about our data practices.
Viamente is operated by Viamente LLC ("Viamente," "we," "us," or "our"), a limited liability company licensed and registered with the Sharjah Media City Free Zone Authority (Shams) under commercial licence number 2644754.01, with its registered office at Shams Business Centre, Al Messaned, Al Bataeh, Sharjah, United Arab Emirates. Viamente LLC is the controller of your personal data when you use the Viamente app, our website and related services. If you are located outside the country where Viamente LLC is established, Viamente LLC remains responsible for your data and can be contacted using the details in the "Privacy Team" and "Contact Information" sections.
By using Viamente, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use our application.
What Viamente is, and what this means for your data
Viamente is an educational and emotional wellness platform. We are not a healthcare provider, and we do not provide therapy, diagnosis, treatment or any other clinical service. We do not hold medical records, and nothing you record in Viamente forms part of a clinical file.
We treat the wellbeing information you record with us as sensitive personal data and protect it accordingly, whether or not it meets the legal definition of health data in your country.
Which law applies to you
Viamente is established in the United Arab Emirates, and our processing is governed principally by Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the UAE PDPL). Where you are located in another country whose data protection law applies to our processing, the sections of this policy dealing with that country apply to you in addition.
The Services are not directed to, and are not offered to, users located in the United States or elsewhere in North America.
We are launching first in the United Arab Emirates and the wider GCC, followed by the Levant, the rest of the MENA region, South Asia and Europe. As we open each market we will update this policy to reflect the law that applies there.
Information We Collect
Personal Information You Provide
When you create an account and use Viamente, you may provide us with:
- Account Information: Name, email address, username, password, date of birth, and profile information
- Wellbeing Data: Mood logs, journal entries, how you describe you are feeling, self-guided wellbeing check-ins, personal reflections, goals and the coping strategies you record for yourself
Please do not record sensitive information
Viamente is an educational and self-reflection tool. It is not a medical record, and it is not the right place to keep detailed personal information about your health or your private life. We ask you not to enter information of the following kinds anywhere in the Services, including in journal entries and free-text fields:
- Diagnoses, symptoms, clinical assessments or anything from a medical or therapy record
- Medication, prescriptions, dosages or treatment plans
- Details of any medical or psychological treatment you are receiving, or the name of any clinician treating you
- Information about your sex life or sexual orientation
- Your racial or ethnic origin, religious or philosophical beliefs, political opinions or trade union membership
- Emirates ID, passport, national insurance or other government identification numbers
- Financial account details or payment card numbers
- Information about other people, including family members, that they would not want recorded
Writing about how you feel is the purpose of the app and you should feel free to do that. What we are asking you to leave out is the clinical and identifying detail: the diagnosis, the prescription, the name of your doctor, the identity of the other person in the story. Keeping that out of Viamente means it cannot be exposed if anything ever goes wrong at our end, and it costs you nothing, because we do not need it in order to give you the Services.
We do not review what you write, so we cannot check whether you have followed this guidance, and we cannot remove information you choose to record. You remain free to delete any entry yourself at any time, and to delete your account with everything in it.
- Payment Information: Billing details processed by our payment provider, Geidea, including where you pay using Apple Pay or Google Pay. We do not receive or store your full payment card number
- Optional Information: Profile photo, preferred name, timezone, and other preferences you choose to share
Unless we clearly indicate otherwise, information you enter in Viamente (including mood logs, reflections, and journal entries) is private by default and is not publicly visible to other users. If we ever introduce social or community features, we will provide a separate explanation and controls so you can decide what to share and with whom.
Information Collected Automatically
When you use Viamente, we automatically collect certain information:
- Usage Data: Features accessed, time spent in the app, interaction patterns, session frequency, and content engagement
- Device Information: Device type, operating system, unique device identifiers, mobile network information, and IP address
- Technical Data: App version, crash reports, performance metrics, and error logs
- Location Data: Approximate location based on IP address (we do not collect precise GPS location unless you explicitly grant permission)
What we do not collect
We have designed the Services to ask for as little as possible. We do not collect, and we do not ask you for:
- Medical records, clinical notes, diagnoses or treatment history
- Medication or prescription information
- Genetic data or biometric data
- Precise or GPS location
- Government identification numbers
- Your payment card number, which is held by our payment provider and never reaches us
- Information about your racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, sex life or sexual orientation
We also do not buy personal data about you from data brokers, and we do not combine what you tell us with information bought from anyone else.
- Advertising IDs and Device Identifiers: Where applicable, we may collect identifiers such as Apple's Identifier for Advertisers (IDFA), Google Advertising ID (AAID), and other device IDs to support analytics, prevent fraud, and understand how users engage with Viamente. These identifiers can usually be reset or limited via your device settings. We do not use these identifiers for cross-app behavioral advertising and do not sell this data. We do not currently use advertising identifiers, and we do not participate in any advertising network. We will update this policy before that changes.
How We Treat Your Wellbeing Data
We do not collect clinical information, and we ask you not to record it. Even so, what you tell us about how you are feeling can say something about your state of mind. We therefore treat the wellbeing information you record - mood logs, journal entries, personal reflections and related data - as sensitive personal data requiring a high level of protection, and we apply that standard whether or not it meets the legal definition of health data in your country.
How We Use Your Information
We use your information solely for specified, legitimate purposes related to providing and improving our mental health services:
Primary Service Delivery
- Provide personalised educational content on mental health and emotional wellbeing, and self-guided wellness tools
- Track your progress and emotional patterns over time
- Deliver notifications, reminders, and motivational as well as educational content
- Provide customer support and respond to your inquiries
We may use your in-app activity and preferences to personalize content and recommendations within Viamente (for example, suggesting exercises, reflections, or educational materials). These recommendations are advisory only and do not constitute medical diagnosis or treatment decisions.
Service Improvement and Development
We use data (often in aggregated or anonymized form) to:
- Analyze aggregated, anonymized usage patterns to improve app features
- Develop new features and functionality based on user needs
- Conduct internal research and analytics to improve the quality and usefulness of our educational content and tools
- Optimize app performance and user experience
Communications
Service and administrative communications
We use your contact information to send transactional or service messages, such as security alerts, changes to our terms or privacy policy, and important updates about core features.
Optional wellness and marketing communications
With your consent where required, we may send emails or in-app messages about new features, educational content, or wellbeing-related updates that may interest you. You can opt out of these communications at any time through the app settings or by using the unsubscribe link in our emails, without affecting your use of the core service.
Legal and Security Purposes
We may use your information to:
- Comply with legal obligations and regulatory requirements
- Protect against fraud, security threats, and illegal activities
- Enforce our Terms of Service and protect user safety
- Respond to legal requests from authorities when required by law
- Detect, prevent, and address fraud, abuse, spam, or other harmful or unauthorized activity, and to verify that accounts are being used by real individuals rather than automated systems
Data Minimization Principle
We collect only the minimum data necessary for the purposes set out above, in accordance with Article 5 of the GDPR and Article 5 of the UAE PDPL. We do not collect information "just in case" or for unrelated purposes, and we have deliberately designed the Services so that you are never asked for clinical or identifying detail about your health.
Legal Basis for Processing (GDPR)
Where the GDPR applies to you, we process your personal data on the following legal grounds. Because your Wellbeing Data is special category data under Article 9, we rely on your explicit consent for it, and only on your explicit consent. We do not rely on legitimate interests to process Wellbeing Data.
- Explicit Consent (Article 9.2.a): You provide explicit, informed consent for processing your sensitive health data when you create an account and use mental health features, by completing an affirmative action
- Contractual Necessity (Article 6.1.b): Processing is necessary to provide the services you've requested
- Legitimate Interest (Article 6.1.f): We have legitimate interests in securing our systems and preventing fraud, balanced against your rights. We do not rely on this ground for your Wellbeing Data
- Legal Obligation (Article 6.1.c): Processing required to comply with applicable laws
Legal basis under the UAE PDPL
Where the UAE PDPL applies, we rely on your consent under Article 4, on the necessity of processing to perform our contract with you, and on our legitimate interests where those do not override your rights. We rely on your separate express consent for the processing of your Wellbeing Data as sensitive personal data.
Your Consent and Control
Granular Consent Management
You have complete control over your data through our dynamic consent interface:
- Data Storage Consent: Permission to store your Wellbeing Data
- Service Improvement Analytics: Consent for anonymized or pseudonymized data analysis to improve app features
- Communication Preferences: Control over notifications, reminders, and promotional communications
- Third-Party Sharing: We do not share your Wellbeing Data with the specialists listed in our directory or with any commercial partner. If that ever changes, we will ask for your explicit consent first
You can modify your consent preferences at any time through the app settings. Withdrawing consent will not affect the lawfulness of processing based on consent before its withdrawal, but it may affect your ability to use certain features.
Informed Consent Requirements
Before collecting sensitive mental health data, we provide clear information about:
- What specific data we collect
- Why we need this data
- How long we retain it
- Who may access it
- Your rights regarding this data
Data Sharing and Disclosure
We do not sell your personal information. We share your data only in the following limited circumstances:
Service Providers
We work with trusted third-party service providers who assist us in operating our app, such as:
The providers we currently use are:
- Google Cloud Platform - hosting, database, application infrastructure, crash reporting and technical logs. Processed in Doha, Qatar.
- Twilio SendGrid - transactional and service emails.
- Cloudinary - storage and delivery of image, audio and video content.
- Geidea - payment processing, including Apple Pay and Google Pay transactions.
- Twist Lab - our application developer, which has technical access to the environment for development and support.
We put a written data processing agreement in place with each provider. Our arrangement with Google Cloud Platform is governed by the Google Cloud Data Processing Addendum.
Mental Health Professionals
Viamente publishes a directory of the mental health professionals who present our educational content. For each of them we may publish a biography and an email address.
We do not share any of your personal data with the professionals listed in our directory. If you choose to contact one of them, you do so independently, using your own email account and outside the Services. We do not see, receive, store or have any involvement in that correspondence, and any relationship you form with them is a matter between you and them.
Legal Requirements
We may disclose your information when required by law:
- In response to valid legal process (subpoenas, court orders)
- To comply with regulatory requirements
- To protect user safety in emergency situations
- To defend our legal rights and prevent illegal activity
Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction. You will be notified of any such change and given options regarding your data where required by law.
Third-Party Websites and Services
Viamente may contain links to third-party websites, content, or services that are not operated by us (for example, external articles, therapy resources, or payment providers). If you follow a link to any third-party site or service, their own privacy policy and terms will apply. We are not responsible for the privacy practices of these third parties and encourage you to review their policies before providing personal information.
Data Security and Protection
Security Measures
We implement comprehensive security measures to protect your sensitive mental health data:
- Encryption: Data is encrypted in transit using TLS 1.2 or TLS 1.3, and encrypted at rest using AES-256
- Access Controls: Account access is protected by password authentication, and access to our production environment is restricted to authorised personnel
Where we describe cryptographic protections, we do so only to the extent that our technical implementation ensures that unauthorized parties (including our own staff, where applicable) cannot access your unencrypted data. We do not claim "zero-knowledge" or similar properties beyond what our architecture and key-management practices truly provide.
Pseudonymization and Anonymization
When using data for analytics or research:
- We are working towards separating personal identifiers from wellbeing data for analytics purposes. At present all data is held in a single database
- Data used for app improvement is anonymized when possible
- We implement technical and organizational measures to reduce the risk of re-identification
Data Breach Notification
In the event of a data breach affecting your personal information, we will notify the competent authorities and, where the breach is likely to result in a risk to your rights, notify you, in each case in accordance with applicable law. Where the GDPR applies we will notify the supervisory authority under Article 33 without undue delay and, where feasible, within 72 hours, and will notify you under Article 34 without undue delay. Where the UAE PDPL applies we will notify the UAE Data Office in accordance with Article 9. We will comply with all applicable breach notification obligations under UAE PDPL, KSA PDPL, and other applicable laws and regulations.
Data Retention
Retention Periods
We retain your personal data only as long as necessary for the purposes outlined in this policy:
- Active Account Data: Retained while your account is active and for a reasonable period thereafter for legitimate service and security purposes
- Wellbeing Data: Retained while your account is active and deleted or irreversibly anonymised within 30 days of account closure. We do not hold clinical records and no clinical retention period applies to us
- Technical Logs: Retained for a limited period (for example, 90 days) for security and troubleshooting purposes, unless a longer period is required by law or for investigations
- Anonymized Research Data: May be retained indefinitely as it cannot be linked back to you
Account Deletion
When you delete your account:
- Personal identifiers are removed or de-identified within a reasonable period
- Mental health data associated with your account is permanently deleted or irreversibly anonymized within a defined period (for example, within 30 days), subject to legal retention requirements
- Backup copies are overwritten or purged within standard backup rotation cycles (for example, within 90 days)
- Anonymized data used in aggregated statistics may be retained
- Legal or regulatory requirements may necessitate longer retention in specific circumstances
Your Privacy Rights
GDPR Rights (EEA, UK, and Other Applicable Regions)
Under GDPR and similar laws, you have the following rights:
- Right of Access (Article 15): Request a copy of your personal data we hold
- Right to Rectification (Article 16): Correct inaccurate or incomplete information
- Right to Erasure / "Right to Be Forgotten" (Article 17): Request deletion of your data under certain circumstances
- Right to Restrict Processing (Article 18): Limit how we use your data in certain situations
- Right to Data Portability (Article 20): Receive your data in a structured, commonly used, machine-readable format and transmit it to another controller
- Right to Object (Article 21): Object to processing based on legitimate interests or direct marketing
- Right to Withdraw Consent: Withdraw previously given consent at any time
- Right to Lodge a Complaint: File a complaint with your local data protection authority
Exercising Your Rights
To exercise any of these rights:
- 1. Access your account settings in the app for immediate changes where available
- 2. Email our privacy team at privacy@viamenteapp.com
- 3. Submit a request through our support channel as described in the app
We will respond to your request within the timeframes required by applicable law (for example, within 30 days under GDPR). For complex requests, we may extend this period in accordance with legal requirements and will inform you if we do so.
Additional Regional Rights
Additional Rights for Users in the United Arab Emirates (UAE)
If you are located in the United Arab Emirates, you may have specific rights under the UAE Federal Decree-Law No. (45) of 2021 on the Protection of Personal Data (UAE PDPL) and related regulations, in addition to the rights described in the GDPR Rights section.
- Right to be informed
- Right of access
- Right to rectification
- Right to erasure ("right to be forgotten")
- Right to restriction of processing
- Right to object to processing
- Right to data portability
- Rights related to automated decision-making
- Right to withdraw consent
- Right to complain
How UAE users can exercise these rights
To exercise any of these rights, please contact us using the details in the "Privacy Contact" or "Contact Information" section of this Privacy Policy and specify that your request relates to your rights under UAE PDPL. We may need to verify your identity before responding and may refuse or limit a request where permitted by law, for example to protect the rights and freedoms of others or comply with legal obligations.
Additional Rights for Users in the Kingdom of Saudi Arabia (KSA)
If you are located in the Kingdom of Saudi Arabia, you may have specific rights under the Saudi Personal Data Protection Law (KSA PDPL) and its implementing regulations, in addition to the rights described elsewhere in this Privacy Policy.
- Right to know / be informed
- Right of access
- Right to correction
- Right to deletion / destruction
- Right to restriction or objection to processing
- Right to data portability
- Rights related to automated decision-making
- Right to withdraw consent
- Right to complain
How KSA users can exercise these rights
To exercise any of these rights, please contact us using the details in the "Privacy Contact" or "Contact Information" section of this Privacy Policy and specify that your request relates to your rights under KSA PDPL. We may need to verify your identity before responding and may refuse or limit your request where permitted by law, including where responding would adversely affect the rights of others or conflict with legal obligations. Controllers in KSA must generally respond within 30 days, with a possible extension where justified.
Children's Privacy
Viamente is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. We ask for your date of birth at registration and rely on the accuracy of what you tell us. If you believe a child has provided us with personal information, please contact us immediately at privacy@viamenteapp.com, and we will take steps to delete such information in accordance with applicable law.
International Data Transfers
Viamente operates globally, and your data may be transferred to and processed in countries other than your country of residence, including countries that may not have the same data protection laws.
Where your data is hosted
Our systems and your data are hosted by Google Cloud Platform in Doha, Qatar. Personal data of users located outside Qatar is therefore transferred there, subject to the safeguards described below.
Transfer Safeguards
When transferring data internationally, we ensure adequate protection through mechanisms such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission or other relevant authorities
- Data Processing Agreements with service providers
- Adequacy decisions recognizing equivalent protection
- Additional technical and organizational security measures for sensitive health data
For EEA residents, data transfers outside the EEA comply with GDPR Chapter V requirements.
Where the UAE PDPL applies, transfers outside the UAE are made in accordance with Articles 22 and 23, either to a jurisdiction the UAE recognises as providing an adequate level of protection, or on the basis of appropriate contractual safeguards and your consent.
Aggregated analytics data may be downloaded by our authorised administrators from our administration portal. Where an administrator is located outside the hosting country, that download is itself an international transfer and is subject to the same safeguards.
Backups, once the production environment is live, will be held in [region to be confirmed]. We will keep this policy current as that is settled.
Cookies and Tracking Technologies
Limited Use of Cookies
Viamente uses minimal tracking technologies, which may include:
- Essential Cookies: Required for app functionality (authentication, session management)
- Analytics Cookies or SDKs: Anonymized or pseudonymized usage statistics (with your consent where required)
- Preference Cookies: Store your settings and preferences
Mobile App Permissions
Our app may request the following device permissions:
- Notifications: To send reminders and motivational messages (optional)
- Storage: To cache content for offline access (optional)
- Camera/Photo Library: To upload profile photos or journal images (optional, with explicit permission)
You can manage these permissions through your device settings at any time.
No Cross-App Tracking
We do not track your activity across other apps or websites. We do not participate in advertising networks or use your data for third-party targeted advertising.
Artificial Intelligence and Automated Decision-Making
AI-Assisted Features
Viamente does not use artificial intelligence. In particular:
- We do not use AI to analyse your mood logs, journal entries or any other content you record
- We do not use your content to train any artificial intelligence or machine learning model, whether our own or a third party's, and we do not send your content to any external AI provider
- We do not make any decision about you by automated means
- The content suggestions you see are based on the categories and preferences you choose, not on any automated analysis of what you write
- If we introduce any AI feature in future, we will update this policy, tell you before it takes effect, and ask for your consent where the law requires it
Transparency in AI Processing
Should we introduce any AI feature in future, we will specify the types of model used, their purpose, and how they process your data, in line with applicable laws on automated decision-making and profiling.
Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, legal requirements, or service features. We will notify you of any material changes through:
- In-app notification
- Email to your registered address (where appropriate)
- A prominent notice on our website or within the app
The "Last Updated" date at the top of this policy indicates when changes were made. Continued use of Viamente after changes constitutes acceptance of the updated policy. If you do not agree with changes, you may delete your account.
Privacy Contact
For questions about this Privacy Policy, our data practices, or to exercise your privacy rights, please contact our privacy team:
Email: privacy@viamenteapp.com
Subject Line: Privacy Inquiry – [Your Request Type] Mailing Address:
Viamente LLC - Privacy Team
Shams Business Center, Sharjah Media City Free Zone, Al Messaned,
Sharjah, United Arab Emirates
We aim to acknowledge privacy enquiries within 5 business days and to fulfil requests within the timeframes required by applicable law.
Supervisory Authority
If you are located in the EEA, UK, or other GDPR-compliant regions, you have the right to lodge a complaint with your local data protection supervisory authority if you believe we have not handled your personal data in accordance with the law.
If you are located in the United Arab Emirates, you may complain to the UAE Data Office. If you are located in the Kingdom of Saudi Arabia, you may complain to the Saudi Data and Artificial Intelligence Authority (SDAIA). We would ask you to contact us first so that we have the chance to put things right.
Contact Information
For general questions, technical support, or feedback about Viamente:
General Inquiries: support@viamenteapp.com
Website: www.viamenteapp.com
App Support: Available through the in-app help center
Your Mental Health, Our Priority
Privacy matters to us. We are committed to maintaining the trust you place in us by protecting your information with strong security measures and transparent practices. What you record in Viamente is personal, and we treat it with the care it deserves.
Thank you for trusting Viamente.