Privacy & GDPR


Last updated: September 2026

At MindMatters Therapy, I take your privacy seriously. This Privacy Policy explains what personal data I collect and use, why I use it, how I protect it, and what rights you have.

1. Who I am

This Privacy Policy applies to the services provided by:

Lara Maestrini
MindMatters Therapy
Jephtastraat 53-2
Email: support@mindmatterstherapy.nl

I am the data controller responsible for the processing of your personal data.

This Privacy Policy applies to clients and people who contact me about therapy, as well as to relevant personal data collected through this website.

2. What personal data I process

Depending on your contact with me and the services you receive, I may process:

  • Your name and date of birth
  • Contact details such as your email address, phone number and address
  • Emergency contact details where relevant
  • Appointment and administrative information
  • Payment and invoicing information
  • Information you share in the context of therapy, including health information and therapy records
  • Communication related to appointments and the organisation of therapy
  • Information you voluntarily provide when contacting me through my website

I only collect and use information that is necessary for providing services, managing the therapeutic relationship, and meeting my legal and professional obligations.

3. Why I process your data

I process your personal data for purposes including:

  • Providing psychological and counselling services
  • Communicating with you and managing appointments
  • Maintaining therapy records
  • Processing payments and invoices
  • Meeting legal, administrative and professional obligations
  • Protecting the security of my practice and systems

Health information is considered special category personal data under the GDPR and receives additional protection.

Depending on the purpose, personal data is processed on the basis of the applicable legal grounds under Article 6 of the GDPR. Health information is processed where an applicable exception under Article 9 of the GDPR permits this, including where processing is necessary for the provision of healthcare or treatment.

Consent is not generally used as the primary legal basis for processing information that is necessary to provide therapy.

4. Confidentiality and sharing of information

Information shared in therapy is treated as confidential.

I do not sell or use client information for advertising or marketing purposes. Personal data is only shared with third parties where this is necessary for the provision or administration of my services, where I am legally required to do so, or where you have requested or authorised the sharing.

For example, I may use external service providers for communication, data storage, website hosting and payment processing. These providers process personal data on my behalf where applicable and are required to provide appropriate safeguards under data protection law.

5. Service providers and data storage

I use a limited number of trusted service providers to operate my practice and website. Depending on the service, these providers may process personal data on my behalf.

Google Workspace and Google Drive
I use Google Workspace and Google Drive for secure storage and management of practice-related information. Google processes data in accordance with applicable data protection legislation and may process data within the European Economic Area and, where applicable, in other countries using appropriate safeguards for international data transfers.

Proton Mail
I use Proton Mail for professional email communication. Proton states that its Mail infrastructure is located in Switzerland, Germany and Norway, with data stored in encrypted form.

Stripe
I use Stripe to process payments. Stripe processes payment and related customer information in accordance with its privacy and data-processing terms. Where personal data is transferred outside the EEA, appropriate safeguards are used.

WhatsApp Business
I may use WhatsApp Business for communication with clients and prospective clients where appropriate. WhatsApp may process and transfer data outside the EEA using legally recognised safeguards. I do not use WhatsApp to store formal therapy records or session notes.

Website hosting and WordPress
My website is hosted by Bluehost. Information submitted through website forms may be stored in the WordPress database associated with my website. Bluehost operates infrastructure and data centres in multiple locations internationally.

Google Maps
My website uses Google Maps to display the location of my practice. When a visitor views or interacts with the map, Google may process technical information and information relating to use of the map, including IP address and location-related information. Google processes this information under its own privacy policy.

Website analytics and cookies
Where enabled, my website may use Google Analytics to understand how visitors use the website, such as which pages are visited and how visitors interact with the site. Google Analytics may process information such as browser and device information, approximate geographic location and website usage data. Where required, analytics cookies are only used after the visitor has given the relevant consent.

I only use the personal data necessary for the relevant service and take reasonable measures to ensure that my service providers process personal data in accordance with applicable data protection requirements.

6. Website and cookies

When you visit this website, limited technical information may be processed for website functionality, security and, where applicable, analytics.

The website may use cookies or similar technologies. Where consent is legally required for non-essential cookies, you will be asked for consent before they are placed.

If you contact me through the website, the information you provide is used to respond to your enquiry and, where applicable, arrange or provide services.

7. How long I keep your data

Therapy records are retained in accordance with applicable Dutch healthcare and data protection requirements. Where the Dutch statutory retention period for a medical record applies, records are generally retained for at least 20 years from the last change to the record.

Financial and accounting records are retained for the period required by applicable tax and financial legislation.

Other personal data is not kept longer than necessary for the purpose for which it was collected, unless a longer retention period is required by law.

When personal data is no longer required, it is securely deleted or otherwise disposed of.

8. How I protect your data

I take appropriate technical and organisational measures to protect personal data against loss, unauthorised access, alteration or disclosure.

These measures include secure accounts and storage, access controls and encryption where appropriate.

Access to therapy records is limited to me, except where access by a service provider is necessary to provide the relevant technical service.

9. Your rights

Under the GDPR, you may have the right to:

  • Request access to your personal data
  • Request correction of inaccurate or incomplete information
  • Request restriction of processing in certain circumstances
  • Request deletion of your personal data where legally permitted
  • Object to certain types of processing
  • Receive information about how your personal data is processed

Some of these rights may be limited where I have a legal obligation to retain information or where other legal requirements apply.

If you would like to exercise your rights or have questions about how your data is processed, please contact me at support@mindmatterstherapy.nl.

You also have the right to lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens.

10. Changes to this Privacy Policy

I may update this Privacy Policy from time to time to reflect changes in legislation, technology or the way my practice operates.

The most recent version will always be available on this website.