Skip to content
DancingMind

Trust & compliance

The due-diligence page, written for the reviewer

Every procurement runs the same checks: regulatory status, data protection, clinical safety, evidence. Here is our posture in one place, and the document pack we share when your governance team is ready to look closer.

Regulatory status

What we are, on the record

Medical device

The platform is registered as a medical device with Singapore's Health Sciences Authority (HSA) and is CE-marked (self-certified). Registration details are shared in the compliance pack.

Our programmes support screening, therapy and rehabilitation inside professional care settings; they are not a substitute for professional medical diagnosis or advice.

Prescription-led

Every application is designed with practising clinicians, and programmes are prescribed and overseen by care teams. There is no self-serve pathway around clinical oversight.

Claims governance

Public claims are matched to published evidence and labelled by evidence level; in-progress research is labelled as such, and evidence content passes clinical and governance review before publication.

How we word our claims →

Data protection

PDPA and UK GDPR, by design

Two kinds of data, two regimes, one principle: health data belongs to the care relationship, not to us.

Therapy and session data is processed only under a data-processing agreement with the deploying care organisation, with safeguards appropriate to health-related data. We do not sell personal data, and website enquiries go to our team, not a third-party widget.

Cross-border transfers between Singapore and the United Kingdom happen under safeguards consistent with the PDPA and UK GDPR. Our website analytics is cookie-free and does not identify individuals.

Who to contact

Data protection enquiries
dpo@dancingmind.com. UK residents may also contact the ICO; Singapore residents, the PDPC.
Claims concerns
If you believe any claim on this site overstates our evidence, tell us at hello@dancingmind.com.

United Kingdom

Clinical safety for NHS engagements

The NHS gateway is the Digital Technology Assessment Criteria (DTAC), and the updated DTAC form has been mandatory since April 2026. We prepare the documentation with each NHS partner as part of the engagement.

DCB0129

Clinical safety case and hazard log maintained under DCB0129, with a named Clinical Safety Officer assigned to the engagement.

DTAC v2

Completed per engagement, covering clinical safety, data protection, cyber security, interoperability and usability.

Evidence, matched

Trial results matched to the claims made, with protocols and endpoints available to clinical teams. Browse the evidence library.

Navigating funding alongside assessment? See funding & grants →

The compliance pack

One request, the whole file

Due-diligence teams collect the same documents on every deal. Ask once and we send the pack, under NDA where the content requires it.

Regulatory

  • HSA medical-device registration details
  • CE declaration of conformity (self-certified)

Clinical safety (UK)

  • DTAC v2 form for the engagement
  • DCB0129 clinical safety case and hazard log

Data protection

  • Data-processing agreement template
  • Data flows, hosting and security overview

Clinical evidence

  • Study protocols, populations and endpoints
  • Full results behind every published claim

Last reviewed July 2026. This page summarises our posture for evaluation purposes; the documents in the compliance pack are the authoritative record, and regulatory status is always subject to the registers of the relevant authorities.