Legal
Privacy Policy
How we collect, use, store, and protect your personal data
For EU/EEA Residents: Gyfts Inc. acts primarily as a data controller for platform operations and may act as a data processor in limited circumstances. Independent practitioners listed on the Platform act as their own data controllers.
1. Who We Are
Gyfts Inc. is a Delaware corporation operating the holistic health discovery and practitioner connection platform at gyfts.io (the "Platform").
Gyfts provides directory listings, AI-assisted discovery tools, booking tools, messaging functionality, saved preferences, and account management features that allow users to connect with independent practitioners.
Contact: privacy@gyfts.io
2. Data Protection Roles
Gyfts as Controller: We determine the purposes and means of processing personal data related to account registration, platform functionality, AI-assisted features, analytics, security, and communications.
Gyfts as Processor (Limited Circumstances): In certain booking or messaging scenarios, we may process data solely on behalf of independent practitioners.
Practitioners as Independent Controllers: When you book an appointment or communicate with a practitioner, that practitioner independently determines how to process any treatment or professional records. Gyfts does not control or assume responsibility for practitioner data practices.
3. Data We Collect
We collect only information that you provide directly or generate through use of the Platform.
Account Information:
- Name
- Email address
- Phone number (optional)
- Preferred language
Platform Activity Data:
- Practitioners and organizations you follow
- Appointment booking details
- Messages sent via the Platform
- Search queries and browsing activity within the Platform
- Feature preferences and settings
- Wellness map entries and saved interactions (if used)
- AI interaction history (e.g. Vidi conversations)
Technical Data:
- IP address (used in-request only; not persisted in raw form — see View-count beacon below)
- Device and browser type (used in-request only; not persisted in raw form)
- Country or region-level location
- Cookie and analytics data
View-count beacon (operational analytics): To prevent the same person inflating a page's view counter on refresh, our beacon at /api/page-view computes a short-lived pseudonymous SHA-256 hash from your IP address, User-Agent, the current UTC date, and a server-only secret. The raw IP and User-Agent are never stored — only the resulting hash, alongside the page identifier and date, is written to a dedup ledger. The ledger entry is deleted after 30 days. The hash cannot be reversed to identify you without the server secret, and rotates every UTC day. This data is used solely for deduplicating view counts and abuse prevention; it is not used for billing, ranking trust, verification, or any claim about a practitioner's quality.
Sensitive Information (User-Provided): Users may voluntarily provide information relating to symptoms, health conditions, wellness goals, or other personal or sensitive topics. Gyfts does not require users to submit health data. However, where users choose to include such information in AI interactions, wellness tools, or communications, this may constitute special category data under GDPR. Gyfts does not create or maintain clinical or medical records.
4. User Controls and Data Minimisation
Users can manage their data through account settings, including:
- Editing profile information
- Managing marketing preferences
- Deleting saved items and search history
- Managing AI interaction history (where available)
- Disabling optional features
- Deleting their account
Upon verified account deletion, personal data is deleted or anonymised except where retention is required by law.
5. How We Use Personal Data
We use personal data to:
- Operate and improve the Platform
- Facilitate bookings and practitioner communication
- Provide AI-assisted discovery and organisational tools
- Enable wellness map and content exploration features
- Provide account management services
- Ensure security and prevent fraud
- Comply with legal obligations
6. AI, Profiling, and Automated Features
Gyfts uses AI-powered systems, including Vidi, to generate informational responses, recommend practitioners, modalities, or content, organise user inputs into structured formats (e.g. wellness maps), and improve platform usability and relevance.
These systems analyse user-provided inputs, platform activity, and content relationships within Gyfts.
AI outputs are informational in nature, not medical advice, not legally binding, and not used to make decisions with legal or similarly significant effects. Gyfts does not use AI to make automated decisions that replace user choice.
7. Legal Basis (GDPR)
We process personal data under the following legal bases:
- Contract performance (Art. 6(1)(b)) — to provide platform services
- Legitimate interests (Art. 6(1)(f)) — to improve functionality, security, and user experience
- Consent (Art. 6(1)(a)) — for optional features, marketing, and sensitive data processing
- Legal obligation (Art. 6(1)(c)) — for compliance requirements
Where users voluntarily provide sensitive (health-related) information, processing is based on explicit consent (Art. 9(2)(a)). Users may withdraw consent at any time.
8. Data Sharing
We do not sell, rent, or share personal data for cross-context behavioural advertising.
We may share data:
- With practitioners selected by you
- With contracted service providers under data processing agreements
- When required by law
- During corporate restructuring transactions
9. International Transfers
Data may be processed in the European Union or the United States. Where transfers occur outside the EU/EEA, appropriate safeguards such as Standard Contractual Clauses or equivalent lawful mechanisms are implemented.
10. Data Retention
We keep personal data only for as long as we need it for the purpose it was collected, after which it is deleted or anonymised. General retention periods:
- Account data: during account lifetime plus up to 2 years
- Booking data: up to 3 years unless deleted earlier
- Direct messages: deleted on the schedule below
- AI interaction data: retained only as necessary for functionality and user access
- Wellness map data: until user deletion
- Analytics data: anonymised
- Legal compliance records: as required by law
Specific retention periods apply to privacy requests and to practitioner verification:
- Data-export files. When you request a copy of your data, the file we generate is available to download for 7 days and is then permanently deleted. This gives you time to retrieve it while limiting how long a complete copy of your personal data is stored. We do not keep the export file after this period.
- Account-deletion requests. When you ask us to delete your account, it is held for 30 days before your personal data is anonymised. The hold lets you reverse a request made in error and gives us time to complete the erasure and check whether any data must be retained by law. After anonymisation we keep only a record that the deletion was carried out.
- Direct messages. We delete conversations rather than keeping them indefinitely. An enquiry nobody replied to is deleted 6 months after it was sent. An ordinary conversation is deleted after 12 months with no messages. A conversation between a client and a practitioner they have booked with is deleted after 18 months with no messages. If content was reported to us, we keep the conversation for 24 months after we close the case, and while a case is open we do not delete it at all. A conversation stays only because someone is still using it — there is no setting that keeps a conversation forever, and we do not offer one. We tell you before a conversation is due to be deleted, and you can download your own copy as a text file at any time from the conversation menu. Deleting a conversation from your own inbox removes it for you; it does not remove the other person’s copy, which is deleted on the same schedule. After deletion we keep only a minimal record — a conversation reference, pseudonymous participant identifiers that cannot be traced back to you, the dates it was created and deleted, whether it was ever replied to, and whether a moderation case existed. We do not keep message text, attachments, health details, searchable extracts or notification previews. We remove or anonymise even that minimal record once it no longer serves fraud prevention, security or accountability. Where a specific legal case requires it, we place a hold on the individual conversation involved and preserve it until the case ends, rather than keeping everyone’s messages longer.
- Verification documents. Identity and credential documents you submit for practitioner verification are deleted 90 days after the verification decision. The documents are needed to make that decision and to defend it if it is later challenged; after 90 days they are removed in line with data minimisation. We keep a record of the verification itself — the outcome, the date, who reviewed it, and the type, issuing body and expiry of each document checked — but not the documents themselves.
11. Your Rights
Depending on your jurisdiction, you may have rights including access, rectification, erasure, restriction, data portability, objection, and withdrawal of consent.
Contact: privacy@gyfts.io
12. Security Measures
We implement technical and organisational safeguards including encryption, access controls, audit logging, and contractual controls with service providers.
13. Children
The Platform is not directed to individuals under 16. We do not knowingly collect personal data from children.
14. Recruitment Data (Easy Apply)
This section applies when you apply for a job through Easy Apply. It sits alongside the rest of this Policy rather than replacing it. You do not need a Gyfts account to apply.
What we collect. The contact details you enter — your name, your email address, and your telephone number if you choose to give one. Your answers to the hiring organisation’s screening questions and any cover note you write. The documents you upload: your CV or résumé, and optionally one supporting document. Your confirmation that you have the right to work, where the role requires it. We do not ask for special category data such as health information, and you should not include it. Uploads are limited to PDF or Word (.docx) files of 3 MB or less.
Our role, and the organisation’s. Gyfts receives your application and delivers it securely to the hiring organisation. Gyfts does not make, influence or advise on hiring decisions. Once your application reaches the organisation, that organisation decides how it is assessed and acts as an independent controller for its own recruitment purposes. Questions about a hiring decision should go to the organisation.
Why we process it. To deliver your application to the organisation you chose, to let you view and withdraw it, to protect the service from abuse, and to keep the security records described below. Our lawful basis is the steps taken at your request before entering into a contract, together with our legitimate interest in operating a safe platform.
Who can access it. Owners and managers of the organisation you applied to — no other organisation on Gyfts can see your application. A small number of Gyfts staff, where necessary to operate or support the service. Our processors, including the malware-scanning provider described below. Your application is never published, never listed publicly, and is never shown to other candidates.
Document storage and malware scanning. Uploaded documents are held in private storage. They are never public, never given a permanent public link, and never sent as email attachments. An authorised person at the hiring organisation can open a document only through a short-lived link generated at the moment they ask for it. Every document is scanned for malware first, by Cloudmersive acting as our processor under contract and solely to return a security verdict. Your document is transmitted to Cloudmersive’s scanning service, processed in memory for the moment of the scan, and not retained afterwards — the service is stateless and keeps no copy once the scan completes. Cloudmersive operates in multiple regions, including North America, so your document may be processed outside the European Economic Area. That transfer is made under the safeguards in our agreement with them, and the document is used for nothing except returning the security verdict. If a document cannot be confirmed clean, it stays inaccessible. Uploaded documents are not used to train any model and are not shared for threat-intelligence purposes.
No automated decisions. We do not score, rank or filter candidates automatically, and no automated system makes or assists a hiring decision. The platform provides no scoring, weighting or automatic-rejection feature.
No marketing. We do not use information from your application for marketing. Applying does not create a Gyfts account, does not subscribe you to anything, and is not used to build a candidate profile or to advertise to you.
Withdrawal, deletion and retention. Every application includes a private link that lets you view it and withdraw it at any time; withdrawing tells the organisation you are no longer a candidate. We delete applications on a schedule the hiring organisation sets for each role — 30, 60 or 90 days after you submit, and never more than 90. The exact period for the role you are applying to is shown to you on the application form before you submit. That date is fixed at the moment you apply — it does not move if the job closes later, if the organisation changes the setting afterwards, or if your application status changes. On that date your name, email address, telephone number, cover note, answers and uploaded documents are permanently deleted, and we keep only an anonymised record that an application existed and was deleted on time. You can ask us to delete your application sooner, and we will, unless a legal obligation requires us to keep something — in which case we keep only the minimum required, for no longer than required.
Your rights. You have the rights described in section 11, including access, correction, deletion and objection. For anything concerning a job application, contact privacy@gyfts.io. For decisions about the role itself, contact the hiring organisation directly.
15. Changes to This Policy
This Policy may be updated periodically. Where changes are material, we will notify users as required by applicable law. Continued use of the Platform constitutes acceptance of any updates.