No advertising sale
We do not sell personal data or use client details for behavioural advertising.
Seneca Notify
How Seneca handles account, client, appointment and messaging data when professionals use our mobile apps, website and related services.
Last updated: 10 August 2026
We do not sell personal data or use client details for behavioural advertising.
Client details are used to manage appointments and send the messages selected by the professional.
Professionals can correct records and request account deletion from the app.
Seneca Notify (“Seneca”, “we”, “us” or “our”) is provided by ESC Mobile LTD, company number 07699810, registered at Unit Da2 Sutherland House, 43 Sutherland Road, London, England, E17 6BU.
This policy covers the Seneca Android and iOS apps, beseneca.com and the backend, support and messaging services used to provide Seneca.
For account administration, security, service operation, support and product analytics, ESC Mobile LTD acts as a data controller.
The therapist or other professional decides why and how their clients' data is used. The professional is normally the data controller, and ESC Mobile LTD processes that data as their data processor to provide Seneca.
| Account and profile | Name, email address, authentication-provider identifier, profile image URL where supplied, sender name, preferred language, terminology and app preferences. |
|---|---|
| Clients | Client name, telephone number, optional email address, preferred message language and optional short notes entered or selected by the professional. |
| Appointments | Date, time, time zone, duration, recurrence, optional appointment note, cancellation state and selected reminder/message settings. |
| Messages and delivery | Recipient name and number, approved template variables, scheduled and delivery times, provider and message identifiers, delivery status, failures, retry and audit events. We do not provide free-form WhatsApp chat or read clients' WhatsApp conversations. |
| Credits and administration | Credit balance and transaction records, account status, account-deletion request date, and support communications. |
| Device, session and security | Session and refresh-token records, hashed IP address, device/user-agent information, app platform and version, login times and security/audit logs. |
| Analytics and diagnostics | Limited product events such as welcome-screen and feature interactions, an internal user identifier, and sanitised crash diagnostics. We intentionally exclude user-entered client names, phone numbers, appointment notes and backend error text from analytics and crash reports. |
| Website | Standard server logs and any information submitted through our contact form. The website or its hosting provider may also use essential cookies; any optional analytics or marketing cookies are governed by the choices shown on the website. |
We receive information from the professional, their device when they use an optional feature, Google during sign-in, messaging providers through delivery reports, and our infrastructure and diagnostic services.
| Provide the contracted service | Create and secure accounts; manage clients and appointments; schedule, send and report messages; maintain credits; and provide requested support. Our basis is performance of our contract with the professional. |
|---|---|
| Operate and protect Seneca | Prevent misuse, investigate delivery failures, maintain audit records, diagnose faults and improve reliability. Our basis is our legitimate interests in operating a secure, dependable service. |
| Meet legal obligations | Keep records or disclose information where law, regulation, legal process or valid authority requires it. |
| Optional device access | Access device contacts only after the user grants permission. Permission can be withdrawn in device settings. The professional remains responsible for their lawful use of imported details. |
We do not use solely automated decision-making that produces legal or similarly significant effects. We do not use Google data, client data or appointment data to train general-purpose artificial-intelligence models.
If permission is granted, Seneca displays accessible device contacts so the professional can choose one. Contact data is read for this selection flow. Only details the professional chooses to save as a Seneca client are sent to and stored by Seneca. Seneca does not continuously synchronise the address book.
Google authentication provides identity information needed to sign in, such as the Google account identifier, email, name and profile image where available. Seneca does not receive the user's Google password.
The current mobile feature opens the device's standard calendar event screen with appointment details pre-filled. The user decides whether and where to save it. Seneca does not read the user's Google Calendar through this feature, and later edits or cancellations in Seneca do not automatically update the calendar entry.
When enabled by the professional, Seneca sends approved appointment-reminder, appointment-created or appointment-cancelled templates. The minimum information required—normally recipient phone number, professional/sender name, appointment date and time, language and technical delivery metadata—is passed to our messaging providers and WhatsApp/Meta. Appointment notes are not included in these templates. WhatsApp and the relevant provider process data under their own terms and privacy information.
We disclose only what is reasonably necessary to:
Providers are selected and instructed for defined service purposes. They may also act as independent controllers for parts of their services; their own notices then apply. We do not sell or rent personal data.
Seneca is operated by a UK company and uses international technology and messaging providers. Data may therefore be processed in the UK, Türkiye, the EEA, the United States and other locations in which a relevant provider operates.
Where data protection law requires a transfer mechanism, we use an applicable adequacy regulation or contractual safeguards such as the UK International Data Transfer Agreement/Addendum or EU Standard Contractual Clauses, together with supplementary measures where appropriate. Contact us to request further information about applicable safeguards.
We retain account, client and appointment information while the account is active and for as long as needed to provide history and message-delivery records. We retain security, delivery, credit and audit records for periods reasonably necessary to prevent abuse, resolve disputes, demonstrate transactions and comply with law.
An account-deletion request can be initiated in Settings. This records the request so we can verify and process it; it does not instantly erase the account. After verification, we delete or anonymise data that is no longer required, subject to legal obligations, dispute/security needs and technical dependencies. Deleted data may remain temporarily in access-restricted backups until those backups are overwritten under the applicable backup schedule and will not be restored for ordinary use.
Because Seneca processes client data on the professional's instructions, clients should normally ask their professional first to correct or delete their records.
We use measures appropriate to the nature of the service, including encrypted network connections, authentication, access controls, token protection, monitoring, backups and restricted administrative access. No internet service can guarantee absolute security. Professionals must protect their devices and accounts and notify us promptly of suspected unauthorised use.
Depending on the law and our role, individuals may have rights to access, correct, erase, restrict or object to processing, and to receive portable data. Consent, where it is the basis, may be withdrawn without affecting earlier lawful processing. Rights can be limited where an exemption applies.
Account users can update certain information in the app and initiate account deletion under Settings. For other requests, use the contact route below. We may need to verify identity. If the request concerns data controlled by a therapist or professional, we may refer the request to that professional and assist them as processor.
Seneca accounts are intended for adult professionals. A professional may only enter information relating to a child client where they have the authority and lawful basis to do so and have provided all notices required by law. They should use particular care to minimise such data.
We may update this policy as Seneca or applicable requirements change. We will publish the revised version here, update the date above and provide additional notice where a change is material.
Questions and privacy requests can be sent through our contact page or by post to ESC Mobile LTD at the registered address above.
If you are in the UK, you may complain to the Information Commissioner's Office (ICO). If you are elsewhere, you may also have the right to contact your local data-protection authority. We would appreciate the opportunity to address your concern first.
Need a demo? Have a question? Let us know. We never spam.
© 2026 ESC Mobile LTD.