Data Processing Agreement
Allocation of roles pursuant to Art. 4(7), Art. 26 and Art. 28 GDPR; part of the terms of use for therapists
1. Principle and Roles
This agreement defines the data protection roles of MatchYourTherapy (hereinafter the "Platform") and the therapists registered on the Platform. Decisive are the actual decision-making powers over the purposes and means of processing (Art. 4(7) and (8) GDPR; EDPB Guidelines 07/2020): the roles follow from the real processes, not from designations. This agreement forms part of the usage contract between Platform and therapist, applies for the duration of the registration and replaces the previous version designated as a processor agreement.
2. Sole Responsibility of the Platform
The Platform is the sole controller (Art. 4(7) GDPR) for:
- the operation of the matching questionnaire, including collection, evaluation and algorithmic scoring of the health and preference data entered by people seeking therapy before a therapist has been selected
- the technical provision, storage, encryption and time-bound deletion of the contact-inquiry infrastructure
- the selection and contracting of all technical service providers (hosting, database, email delivery, analytics, image delivery)
- the processing of therapists' profile, account and contract data to provide the Platform (registration, presentation, billing, support)
- all other processing operations where the therapist has no actual decision-making power over the purpose or essential means
3. Sole Responsibility of the Therapist
The therapist is their own, sole controller (Art. 4(7) GDPR) for:
- the content and conduct of the communication and treatment relationship with the person seeking therapy after receiving a contact inquiry, including appointment scheduling, anamnesis and their own patient documentation in accordance with professional law (PthG 2024, duty of confidentiality)
- the decision whether and how to respond to a received contact inquiry
- the content of their public profile and microsite, insofar as they design it themselves
4. Joint Controllership for Contact Inquiries (Art. 26 GDPR)
For the processing of the content of a specific contact inquiry (from its transmission to the therapist selected by the person seeking therapy until expiry of the retention period at the Platform) Platform and therapist are joint controllers (Art. 26(1) GDPR). The following allocation applies:
- The Platform is responsible for the technical transmission, encrypted storage, access control and timely deletion of the inquiry content, and for informing the person seeking therapy about this technical processing (Art. 13 GDPR).
- The therapist is responsible for handling the inquiry content received in their own domain (e.g. transfer into their own patient documentation, reply) and for informing about this further processing of their own.
- People seeking therapy can exercise their rights under Art. 15–22 GDPR against either party (Art. 26(3) GDPR). The central contact point is the Platform (datenschutz@matchyourtherapy.at); it forwards requests concerning the therapist's domain without undue delay.
- The essence of this arrangement is made available to people seeking therapy in the Platform's privacy policy (Art. 26(2) GDPR).
- The therapist's professional duties of confidentiality remain unaffected.
5. No Processor Relationship
With regard to the processing operations listed in section 2, no processor relationship pursuant to Art. 28 GDPR exists between Platform and therapist: the therapist does not issue instructions to the Platform in this respect and assumes no data protection responsibility for them. Should the Platform in future carry out processing exclusively on the documented instructions of a therapist, a separate data processing agreement will be concluded for it.
6. Data Categories Concerned
The following categories of personal data are processed on the Platform:
- Name and contact details of therapists
- Professional qualifications and specialisations
- For contact inquiries from patients: name, email address, optional phone number, the free-text message, the selected therapy topics, the stated level of distress and the location provided
- Therapy preferences of patients: stored encrypted and linked to the respective inquiry, not anonymised
- Free text and display name from submitted reviews
- Usage data and statistics (pseudonymised)
7. Technical and Organisational Measures
For the processing under its responsibility, the Platform implements in particular the following measures (Art. 32 GDPR):
- Encryption of contact-inquiry content (AES-256-GCM) and transport encryption (TLS)
- Access control and confidentiality obligations for all persons with data access
- Automated deletion of inquiry content after 30 days plus a self-deletion link for people seeking therapy
- Regular automated security checks (dependency scanning, static code analysis)
8. Service Providers of the Platform
For the processing under its responsibility, the Platform uses the following processors (Art. 28 GDPR). A data processing agreement is in place with each of them:
- Vercel Inc. (hosting, edge functions), US provider with servers located in Frankfurt (EU), EU standard contractual clauses
- Neon Inc. (PostgreSQL database), US provider with database servers in the EU, EU standard contractual clauses
- Stripe Inc. (payment processing), USA, EU standard contractual clauses
- Cloudinary Ltd. (image optimisation and delivery), EU/USA, EU standard contractual clauses. When profile images are displayed, visitors' IP addresses are transmitted to Cloudinary
- Brevo / Sendinblue SAS (email delivery), France, EU/GDPR
- Groq Inc. (language model for editorial texts and the therapists' profile-text assistant; no patient data), USA, EU standard contractual clauses
- Google LLC (Places API plus summarisation of public Google reviews and approved, anonymous platform reviews), USA, EU standard contractual clauses
- PostHog Inc. (analytics, EU hosting)
In addition, when a profile page is opened or only after an active click, data is transmitted to the following independent third-party services. These do not process on the Platform's behalf; there is therefore no data processing agreement, but a transfer based on legitimate interest (Art. 6(1)(f) GDPR) or your consent:
- OpenStreetMap Foundation (mapping service), EU/UK. For the location search in the therapist search and for converting practice addresses into map coordinates, our server queries OpenStreetMap (with our server IP, not yours). Your own IP address is only transmitted when you actively click "Load map" on a profile page and your browser then loads the map tiles directly from OpenStreetMap
- Google Ireland Ltd. / Vimeo Inc. (embedding of introduction videos, where a therapist has added one). Videos are only loaded after an active click (two-click solution); only then is the visitor's IP address transmitted to the respective provider
A detailed description of the data processing by these services can be found in our Privacy Policy.
9. Deletion
Therapists can delete their account, and with it their profile and contract data, at any time via the account settings. Independently of this, contact-inquiry content is automatically deleted or anonymised after the 30-day period; statutory retention obligations remain unaffected.
10. Data Protection Contact
For questions about data protection and this agreement, please contact:
MMag. DDr. Gregor Studlar BA (MatchYour GmbH i.G.)
Domgasse 14, 4020 Linz, Austria
Last updated: July 2026