The Center for Professional Counseling (“we,” “our,” or “us”) is committed to protecting the privacy and personal data of all individuals who engage with our services, in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
This policy outlines how we collect, use, store, and protect personal data, and your rights in relation to that data.
1. Purpose of this Policy
This policy explains:
What personal data we collect
Why we collect it
How we use and protect it
Your rights under the GDPR
2. Lawful Basis for Processing
We process personal data under the following lawful bases:
Consent – When you have given clear permission for us to process your data for a specific purpose.
Contractual necessity – When data processing is necessary to fulfill a contract or agreement with you.
Legal obligation – When processing is required to comply with applicable laws.
Legitimate interests – When processing is necessary for our legitimate interests and does not override your rights.
3. Personal Data We Collect
Depending on your interaction with us, we may collect the following data:
Name, date of birth, and contact details
Health and mental health-related information (if applicable to counseling services)
Payment or billing information
Records of your communication or engagement with our services
Website usage data (cookies, analytics, etc.)
4. How We Use Your Data
Your personal data may be used to:
Deliver counseling and professional services
Process inquiries and manage bookings
Maintain accurate records for professional or regulatory reasons
Improve our services through feedback and analytics
Communicate important updates or information
5. Data Sharing and Transfers
We do not sell your personal data.
We may share data:
With trusted service providers or software platforms under data processing agreements
When required by law or regulatory obligations
With your explicit consent (e.g., referrals or coordinated care)
If data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place (such as Standard Contractual Clauses).
6. Data Retention
We retain personal data only as long as necessary:
For the purposes for which it was collected
To comply with legal or regulatory obligations
In accordance with professional guidelines or ethical standards
After the retention period, data is securely deleted or anonymized.
7. Your GDPR Rights
Under GDPR, you have the right to:
Access your personal data
Request correction or deletion
Restrict or object to processing
Data portability (receive a copy in a structured, machine-readable format)
Withdraw consent at any time (where processing is based on consent)
Lodge a complaint with a data protection authority
To exercise any of these rights, please contact us through the appropriate channel on our website.
8. Data Security
We implement technical and organizational measures to protect your data against unauthorized access, alteration, loss, or disclosure. These include encryption, access controls, secure storage systems, and staff training on data privacy.
9. Policy Updates
We may update this GDPR Policy from time to time. The latest version will always be available on our website, and we will notify you of significant changes where appropriate.
