Back to home

Privacy Policy

Last updated: November 22, 2024

Leer en español →

1. Data Controller

Rocío Touza Sanchez
Licensed Psychologist No. 33914
Email: info@rociotouzasanchez.com
Phone: +34 633 779 016
Location: Barcelona, Spain

2. Data We Collect

We only collect data strictly necessary to provide online psychotherapy services:

  • Contact information: Name, email, phone number
  • Health data: Information provided during therapy sessions, clinical notes, therapeutic history
  • Communication data: Content of emails and WhatsApp messages related to your psychological care

🍪 This website does NOT use cookies. We do not track your activity, do not use web analytics tools, and do not share your data with third parties for advertising or marketing purposes.

3. Purpose and Legal Basis

We use your data for the following purposes:

Purpose Legal Basis (GDPR)
Coordinate appointments and therapy sessions Consent (Art. 6.1.a) and Contract performance (Art. 6.1.b)
Provision of psychotherapy services Explicit consent for health data (Art. 9.2.a) + Preventive or occupational medicine purposes (Art. 9.2.h)
Retention of clinical records Legal obligation (Art. 6.1.c) - Healthcare and professional regulations
Respond to inquiries and communications Consent (Art. 6.1.a) and Legitimate interest (Art. 6.1.f)

4. Retention Period

  • Clinical records and therapy notes: Will be retained for a minimum of 5 years from the last session, as established by the Official College of Psychologists and applicable healthcare regulations.
  • Contact information: Until you request deletion or up to 2 years from the last contact or session.
  • Communications (emails, WhatsApp): Will be retained while necessary for service provision and subsequently during the clinical record retention period.

5. Data Recipients

Your data is NOT shared with third parties, except in the following cases necessary for service provision:

  • Google Meet: Online therapy sessions are conducted via Google Meet. Google LLC may process technical connection data. More information: Google Privacy Policy
  • Legal obligations: Only if required by law or competent judicial authority.

We do not use third-party cloud storage services. Your data is under my direct control and is stored securely on encrypted local devices.

6. Your Rights

You have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your data (subject to legal obligations to retain clinical records)
  • Restriction: Request restriction of processing of your data
  • Portability: Receive your data in a structured, commonly used format
  • Objection: Object to processing of your data in certain circumstances
  • Withdrawal of consent: Withdraw your consent at any time (without affecting the lawfulness of prior processing)

How to exercise your rights?
Send an email to info@rociotouzasanchez.com indicating which right you wish to exercise. I will respond within a maximum of 30 days.

You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD): www.aepd.es

7. Security Measures

I protect your data through the following measures:

  • Encryption of devices and files containing sensitive data
  • Strong passwords and two-factor authentication
  • Encrypted connections (HTTPS, SSL/TLS) for all communications
  • Restricted access: only I have access to your clinical data
  • Compliance with professional secrecy according to the Psychologist's Code of Ethics

8. International Transfers

Your data is stored and processed exclusively in Spain (European Union). The only exception is the use of Google Meet for video call sessions, whose servers may be located in different countries. Google LLC complies with the EU-U.S. Data Privacy Framework.

9. Consent for Health Data

When starting the therapeutic process with me, I will request explicit and informed consent for the processing of your health data, in accordance with Article 9 of the GDPR. This consent:

  • Is completely voluntary
  • Can be withdrawn at any time
  • Is subject to professional secrecy and absolute confidentiality
  • Is documented in writing before sessions begin

10. Minors

If you are under 16 years old, you will need consent from your parents or legal guardians to use this service. In the case of care for minors, the guidelines of the Official College of Psychologists on informed consent and confidentiality will be followed.

11. Changes to This Policy

I reserve the right to modify this Privacy Policy at any time. Any changes will be communicated through this website, indicating the date of the last update. If changes are substantial, I will notify you by email.

12. Contact

If you have questions about this Privacy Policy or how I handle your personal data, you can contact me at:

Email: info@rociotouzasanchez.com

Phone/WhatsApp: +34 633 779 016

Location: Barcelona, Spain

This Privacy Policy has been drafted in accordance with the General Data Protection Regulation (GDPR - EU 2016/679), Spanish Organic Law 3/2018 on Personal Data Protection and guarantee of digital rights (LOPDGDD), and the Psychologist's Code of Ethics in Spain.