GDPR Policy

The Center for Professional Counseling (“we,” “our,” or “us”) is committed to protecting the privacy and personal data of all individuals who engage with our services, in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”).

This policy outlines how we collect, use, store, and protect personal data, and your rights in relation to that data.

1. Purpose of this Policy

This policy explains:

What personal data we collect

Why we collect it

How we use and protect it

Your rights under the GDPR

2. Lawful Basis for Processing

We process personal data under the following lawful bases:

Consent – When you have given clear permission for us to process your data for a specific purpose.

Contractual necessity – When data processing is necessary to fulfill a contract or agreement with you.

Legal obligation – When processing is required to comply with applicable laws.

Legitimate interests – When processing is necessary for our legitimate interests and does not override your rights.

3. Personal Data We Collect

Depending on your interaction with us, we may collect the following data:

Name, date of birth, and contact details

Health and mental health-related information (if applicable to counseling services)

Payment or billing information

Records of your communication or engagement with our services

Website usage data (cookies, analytics, etc.)

4. How We Use Your Data

Your personal data may be used to:

Deliver counseling and professional services

Process inquiries and manage bookings

Maintain accurate records for professional or regulatory reasons

Improve our services through feedback and analytics

Communicate important updates or information

5. Data Sharing and Transfers

We do not sell your personal data.

We may share data:

With trusted service providers or software platforms under data processing agreements

When required by law or regulatory obligations

With your explicit consent (e.g., referrals or coordinated care)

If data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place (such as Standard Contractual Clauses).

6. Data Retention

We retain personal data only as long as necessary:

For the purposes for which it was collected

To comply with legal or regulatory obligations

In accordance with professional guidelines or ethical standards

After the retention period, data is securely deleted or anonymized.

7. Your GDPR Rights

Under GDPR, you have the right to:

Access your personal data

Request correction or deletion

Restrict or object to processing

Data portability (receive a copy in a structured, machine-readable format)

Withdraw consent at any time (where processing is based on consent)

Lodge a complaint with a data protection authority

To exercise any of these rights, please contact us through the appropriate channel on our website.

8. Data Security

We implement technical and organizational measures to protect your data against unauthorized access, alteration, loss, or disclosure. These include encryption, access controls, secure storage systems, and staff training on data privacy.

9. Policy Updates

We may update this GDPR Policy from time to time. The latest version will always be available on our website, and we will notify you of significant changes where appropriate.

Scroll to Top