Privacy Policy
Information about the protection of your personal data
1. Data Controller
The data controller responsible for data processing on this website is:
MMag. DDr. Gregor Studlar BA (MatchYour GmbH i.G.)
Domgasse 14
4020 Linz, Austria
2. Data Collection
Account Data
During registration, we collect: Name, email address, encrypted password. For therapists additionally: Professional qualifications, practice address, specializations.
Matching Data
For therapy matching we collect information about: therapy needs, level of distress, preferences (online/in person), location and preferred language. These details are health data within the meaning of Art. 9 GDPR (see section 4). For the search itself we do not store them: the computation runs on our servers in the EU and the result goes back to your browser, without the details being stored permanently or linked to your name. Only when you send an inquiry are they stored encrypted and thereby linked to that inquiry and to your name and email address. They are only passed on to a therapist if you explicitly enable that when sending.
Contact inquiries to therapists
When you send an inquiry to a therapist we store your name, your email address, optionally your phone number, your message and, if you consent, your matching answers. These contents are stored in our database encrypted with AES-256-GCM (see section 4). The therapist only receives an email notification with a link to their dashboard; the content of your inquiry is not transmitted by email and is therefore not accessible to our email provider Brevo. For the transmission of your inquiry to the therapist you selected and its storage until deletion, we are jointly responsible with that therapist (Art. 26 GDPR). The essence of our arrangement: we handle the technology, encrypted storage, deletion and this information; the therapist is responsible for handling the inquiry in their own domain (e.g. reply, their own documentation). You can exercise your rights under Art. 15–22 GDPR against either of us; the central contact point is datenschutz@matchyourtherapy.at.
Usage Data
IP addresses are processed only transiently from request headers for rate-limit checks and spam protection; they are not stored in our database. Browser type, operating system, access times and pages visited are recorded as standard hosting logs by our hosting provider Vercel (retention see section 9).
3. Legal Basis
- Art. 6 (1) a GDPR:Consent (e.g., newsletter, sharing matching results)
- Art. 6 (1) b GDPR:Contract fulfillment (account management, matching service)
- Art. 6 (1) c GDPR:Legal obligations (invoice retention)
- Art. 6 (1) f GDPR:Legitimate interests (security, fraud prevention)
4. Special Category: Health Data
During the matching process, you may voluntarily provide information about your mental well-being. This data is subject to special protection pursuant to Art. 9 GDPR.
- Processing only with your explicit consent (Art. 9 (2) (a) GDPR). We obtain it actively at two points and record the time in each case: before your questionnaire answers are transmitted to us to compute the results, and before you send an inquiry
- Contents of contact inquiries (name, email, phone, message, matching answers) are stored in our database encrypted with AES-256-GCM. The key is held only in the runtime environment of our application server and is transmitted neither to our database nor to our email provider
- The message you write is shown to the therapist you selected, as that is the purpose of the inquiry. Your matching answers are only shown if you additionally enable that when sending. Beyond that, nobody accesses them without your authorisation
- Deletion at any time: immediately and without questions via the link in your confirmation email, and we additionally delete the contents automatically 30 days after receipt
5. Third Parties & Data Transfer
We use the following service providers who process data on our behalf:
Vercel Inc.
Hosting by Vercel Inc. (US provider, EU standard contractual clauses), servers located in Frankfurt (EU). Additionally Vercel Web Analytics and Speed Insights for page views and performance metrics, both only with your consent.
Stripe Inc.
Payment processing (SCC, certified)
Brevo (Sendinblue SAS)
Delivery of transactional emails (registration confirmation, contact-inquiry notification, password reset) as well as email marketing lists for registered therapists (servers in France, EU). You can unsubscribe at any time via the unsubscribe link in every marketing email or by deleting your account.
Cloudinary
Image optimization & delivery (US provider, EU standard contractual clauses). Image uploads are processed through our server. However, profile, gallery and practice images are loaded directly from Cloudinary servers when a page is displayed; your IP address is transmitted to Cloudinary in the process.
Neon
Database (PostgreSQL). Neon Inc. is a US provider (EU standard contractual clauses); the database servers are located in the EU.
Unsplash Inc.
Stock photos for blog articles (provider based in the USA, EU standard contractual clauses). The images are delivered through our own server (image proxy); your IP address is not transmitted to Unsplash when you visit a page.
OpenStreetMap Foundation
Map display on therapist profile pages (EU/UK). The map only loads after you click "Load map"; your browser then loads map tiles directly from OpenStreetMap servers and your IP address is transmitted. Address-to-coordinate lookups run through our own server, so your IP address never reaches OpenStreetMap for those.
Google Ireland Ltd. / Vimeo Inc.
Embedding of introduction videos where a therapist has added one. Videos are only loaded after your active click (two-click solution); only then is your IP address transmitted to the respective provider.
PostHog Inc.
Analysis of user behaviour to improve the matching process. Provider: PostHog Inc., data is processed on EU servers. Client-side analytics only start after your consent; independently of that we count page requests on the server without a cookie and without a person profile (see below).
Google (Gemini API, Places API)
AI summary of reviews on therapist profiles (USA/SCC): public Google reviews as well as approved, anonymous reviews from our platform. Additionally we use the Google Places API server-side to import public practice and review data; no visitor data is transmitted in the process.
Special Protection for AI Processing
Your input in search and matching is not processed by any AI system: the topic search in the questionnaire runs entirely locally in your browser (keyword and synonym matching), the matching itself is a fixed weighting procedure without artificial intelligence (see section 6), and contact inquiries are never transmitted to a language model. We use language models in exactly three places, none of which touches data of people seeking therapy:
- Summarising public reviews: A Google language model (USA, EU standard contractual clauses) condenses publicly visible Google reviews of therapists into short overviews. Only these public review texts are processed.
- Summarising reviews on our platform: Once a profile has at least three approved reviews, the same Google language model condenses these already published, anonymous and pre-moderated review texts into a short overview. The summary is labelled as AI-generated on the profile; display names are not transmitted.
- Editorial and profile tools: A language model by Groq Inc. (USA, EU standard contractual clauses) supports us in drafting editorial content and, at their own request, supports therapists in phrasing their profile text. Only our own content or the therapist's own profile data is processed.
Data of patients and visitors, i.e. search queries, questionnaire answers and messages, never reaches any of these systems.
Data processing agreements pursuant to Art. 28 GDPR or corresponding data protection agreements exist with all service providers that process personal data on our behalf.
International Data Transfers (Schrems II)
Some of our service providers are based in the USA or other third countries. We have implemented the following safeguards for these transfers:
- EU Standard Contractual Clauses (SCC) pursuant to Art. 46 (2) c GDPR
- Supplementary technical measures (encryption, pseudonymization)
- Transfer Impact Assessments (TIA) for each US provider
- Preference for EU server locations where possible
Server locations in the EU/EEA: Vercel (hosting in Frankfurt), Brevo (France), Neon (EU), PostHog (EU). US providers with EU standard contractual clauses: Vercel, Neon, Stripe, Cloudinary, Groq (editorial texts), Google (AI summary of public reviews, Places API), Unsplash. When profile images (Cloudinary) and map tiles (OpenStreetMap, only after clicking "Load map") are loaded, your IP address is transmitted to the respective provider (see the list above for details); Unsplash stock photos, by contrast, are delivered through our own server. The analytics tools PostHog, Vercel Web Analytics and Speed Insights only start after your consent; independently of that we count page views server-side without cookies and without a person profile on the basis of Art. 6(1)(f) GDPR (see section 7).
6. Automated Decision-Making
Pursuant to Art. 22 GDPR, we inform you about the use of automated decision-making:
Automated matching
Our matching algorithm calculates a fit score from your answers and sorts therapists by it. It is a fixed set of rules and weightings, not artificial intelligence: the weights are defined in code and do not learn from your data. The calculation is driven mainly by the topic areas you select, i.e. information about your mental health within the meaning of Art. 9 GDPR, plus your answers on therapy style, location, cost and language. Where enough matching profiles exist, therapists without a topical match are not shown. Your answers therefore affect not only the order but also who you get to see.
Your Rights
- Matching results are suggestions, not binding decisions, and have no legal effect on you
- You decide freely which therapists to contact, and you can use the search at any time without the questionnaire
- You can request a manual review of the results at any time
- You can state your point of view and object to the assessment
For a manual review or questions about our automated systems, contact us at: datenschutz@matchyourtherapy.at
8. Your Rights
Pursuant to the GDPR, you have the following rights:
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure (Art. 17)
- Right to restriction (Art. 18)
- Right to data portability (Art. 20)
- Right to object (Art. 21)
Right to Complain
You have the right to complain to the Austrian Data Protection Authority:
Austrian Data Protection Authority
Barichgasse 40-42, 1030 Vienna
dsb@dsb.gv.at
9. Data Retention
- Account dataUntil account deletion
- Contact inquiries, content (name, email, phone, message, topics, severity, postcode region)Name, email, phone, message and topic data are stored encrypted (AES-256-GCM). Severity and postcode region are stored only as coarse categories that are not identifying on their own. 30 days after receipt all of these fields are automatically purged from our database by a daily cron job. You can also delete your inquiry yourself at any time via the link in the confirmation email. The email notification that was sent to the therapist at the time of the inquiry is subject to the therapist's professional confidentiality obligation and is not covered by this deletion.
- Contact inquiries, pseudonymized residual data (therapist ID, timestamp, match score, technical status flags)12 months after anonymization; the record is then deleted from the database entirely. Topic, severity and postcode-region data are already removed by the 30-day deletion and are not retained beyond it. The remaining fields still count as pseudonymized pursuant to Art. 4 (5) GDPR.
- Questionnaire answers, as long as no inquiry has been sentIn your browser only, for the lifetime of the browser tab. Nothing of it remains on our servers. Separately, your browser remembers the consent you gave for 12 months.
- Billing data7 years (legal retention requirement)
- Server logsRetention of hosting logs at the provider: approx. 1 hour
10. Data Protection Contact
For questions about data protection or to exercise your rights, please contact us at:
datenschutz@matchyourtherapy.atWe will respond to your request within 30 days.
Last updated: July 2026