Skip to main contentSkip to navigation

Privacy Policy

Information about the protection of your personal data

1. Data Controller

The data controller responsible for data processing on this website is:

MMag. DDr. Gregor Studlar BA (MatchYour GmbH i.G.)

Domgasse 14

4020 Linz, Austria

datenschutz@matchyourtherapy.at

2. Data Collection

Account Data

During registration, we collect: Name, email address, encrypted password. For therapists additionally: Professional qualifications, practice address, specializations.

Matching Data

For therapy matching we collect information about: therapy needs, level of distress, preferences (online/in person), location and preferred language. These details are health data within the meaning of Art. 9 GDPR (see section 4). For the search itself we do not store them: the computation runs on our servers in the EU and the result goes back to your browser, without the details being stored permanently or linked to your name. Only when you send an inquiry are they stored encrypted and thereby linked to that inquiry and to your name and email address. They are only passed on to a therapist if you explicitly enable that when sending.

Contact inquiries to therapists

When you send an inquiry to a therapist we store your name, your email address, optionally your phone number, your message and, if you consent, your matching answers. These contents are stored in our database encrypted with AES-256-GCM (see section 4). The therapist only receives an email notification with a link to their dashboard; the content of your inquiry is not transmitted by email and is therefore not accessible to our email provider Brevo. For the transmission of your inquiry to the therapist you selected and its storage until deletion, we are jointly responsible with that therapist (Art. 26 GDPR). The essence of our arrangement: we handle the technology, encrypted storage, deletion and this information; the therapist is responsible for handling the inquiry in their own domain (e.g. reply, their own documentation). You can exercise your rights under Art. 15–22 GDPR against either of us; the central contact point is datenschutz@matchyourtherapy.at.

Usage Data

IP addresses are processed only transiently from request headers for rate-limit checks and spam protection; they are not stored in our database. Browser type, operating system, access times and pages visited are recorded as standard hosting logs by our hosting provider Vercel (retention see section 9).

4. Special Category: Health Data

During the matching process, you may voluntarily provide information about your mental well-being. This data is subject to special protection pursuant to Art. 9 GDPR.

  • Processing only with your explicit consent (Art. 9 (2) (a) GDPR). We obtain it actively at two points and record the time in each case: before your questionnaire answers are transmitted to us to compute the results, and before you send an inquiry
  • Contents of contact inquiries (name, email, phone, message, matching answers) are stored in our database encrypted with AES-256-GCM. The key is held only in the runtime environment of our application server and is transmitted neither to our database nor to our email provider
  • The message you write is shown to the therapist you selected, as that is the purpose of the inquiry. Your matching answers are only shown if you additionally enable that when sending. Beyond that, nobody accesses them without your authorisation
  • Deletion at any time: immediately and without questions via the link in your confirmation email, and we additionally delete the contents automatically 30 days after receipt

5. Third Parties & Data Transfer

We use the following service providers who process data on our behalf:

Vercel Inc.

Hosting by Vercel Inc. (US provider, EU standard contractual clauses), servers located in Frankfurt (EU). Additionally Vercel Web Analytics and Speed Insights for page views and performance metrics, both only with your consent.

Stripe Inc.

Payment processing (SCC, certified)

Brevo (Sendinblue SAS)

Delivery of transactional emails (registration confirmation, contact-inquiry notification, password reset) as well as email marketing lists for registered therapists (servers in France, EU). You can unsubscribe at any time via the unsubscribe link in every marketing email or by deleting your account.

Cloudinary

Image optimization & delivery (US provider, EU standard contractual clauses). Image uploads are processed through our server. However, profile, gallery and practice images are loaded directly from Cloudinary servers when a page is displayed; your IP address is transmitted to Cloudinary in the process.

Neon

Database (PostgreSQL). Neon Inc. is a US provider (EU standard contractual clauses); the database servers are located in the EU.

Unsplash Inc.

Stock photos for blog articles (provider based in the USA, EU standard contractual clauses). The images are delivered through our own server (image proxy); your IP address is not transmitted to Unsplash when you visit a page.

OpenStreetMap Foundation

Map display on therapist profile pages (EU/UK). The map only loads after you click "Load map"; your browser then loads map tiles directly from OpenStreetMap servers and your IP address is transmitted. Address-to-coordinate lookups run through our own server, so your IP address never reaches OpenStreetMap for those.

Google Ireland Ltd. / Vimeo Inc.

Embedding of introduction videos where a therapist has added one. Videos are only loaded after your active click (two-click solution); only then is your IP address transmitted to the respective provider.

PostHog Inc.

Analysis of user behaviour to improve the matching process. Provider: PostHog Inc., data is processed on EU servers. Client-side analytics only start after your consent; independently of that we count page requests on the server without a cookie and without a person profile (see below).

Google (Gemini API, Places API)

AI summary of reviews on therapist profiles (USA/SCC): public Google reviews as well as approved, anonymous reviews from our platform. Additionally we use the Google Places API server-side to import public practice and review data; no visitor data is transmitted in the process.

Special Protection for AI Processing

Your input in search and matching is not processed by any AI system: the topic search in the questionnaire runs entirely locally in your browser (keyword and synonym matching), the matching itself is a fixed weighting procedure without artificial intelligence (see section 6), and contact inquiries are never transmitted to a language model. We use language models in exactly three places, none of which touches data of people seeking therapy:

  • Summarising public reviews: A Google language model (USA, EU standard contractual clauses) condenses publicly visible Google reviews of therapists into short overviews. Only these public review texts are processed.
  • Summarising reviews on our platform: Once a profile has at least three approved reviews, the same Google language model condenses these already published, anonymous and pre-moderated review texts into a short overview. The summary is labelled as AI-generated on the profile; display names are not transmitted.
  • Editorial and profile tools: A language model by Groq Inc. (USA, EU standard contractual clauses) supports us in drafting editorial content and, at their own request, supports therapists in phrasing their profile text. Only our own content or the therapist's own profile data is processed.

Data of patients and visitors, i.e. search queries, questionnaire answers and messages, never reaches any of these systems.

Data processing agreements pursuant to Art. 28 GDPR or corresponding data protection agreements exist with all service providers that process personal data on our behalf.

International Data Transfers (Schrems II)

Some of our service providers are based in the USA or other third countries. We have implemented the following safeguards for these transfers:

  • EU Standard Contractual Clauses (SCC) pursuant to Art. 46 (2) c GDPR
  • Supplementary technical measures (encryption, pseudonymization)
  • Transfer Impact Assessments (TIA) for each US provider
  • Preference for EU server locations where possible

Server locations in the EU/EEA: Vercel (hosting in Frankfurt), Brevo (France), Neon (EU), PostHog (EU). US providers with EU standard contractual clauses: Vercel, Neon, Stripe, Cloudinary, Groq (editorial texts), Google (AI summary of public reviews, Places API), Unsplash. When profile images (Cloudinary) and map tiles (OpenStreetMap, only after clicking "Load map") are loaded, your IP address is transmitted to the respective provider (see the list above for details); Unsplash stock photos, by contrast, are delivered through our own server. The analytics tools PostHog, Vercel Web Analytics and Speed Insights only start after your consent; independently of that we count page views server-side without cookies and without a person profile on the basis of Art. 6(1)(f) GDPR (see section 7).

6. Automated Decision-Making

Pursuant to Art. 22 GDPR, we inform you about the use of automated decision-making:

Automated matching

Our matching algorithm calculates a fit score from your answers and sorts therapists by it. It is a fixed set of rules and weightings, not artificial intelligence: the weights are defined in code and do not learn from your data. The calculation is driven mainly by the topic areas you select, i.e. information about your mental health within the meaning of Art. 9 GDPR, plus your answers on therapy style, location, cost and language. Where enough matching profiles exist, therapists without a topical match are not shown. Your answers therefore affect not only the order but also who you get to see.

Your Rights

  • Matching results are suggestions, not binding decisions, and have no legal effect on you
  • You decide freely which therapists to contact, and you can use the search at any time without the questionnaire
  • You can request a manual review of the results at any time
  • You can state your point of view and object to the assessment

For a manual review or questions about our automated systems, contact us at: datenschutz@matchyourtherapy.at

7. Cookies

Our website uses cookies. We distinguish between:

Necessary Cookies

Session cookies for login and security. These are required for website operation.

Functional Cookies

Store your preferences such as language, theme, font size and your progress in the questionnaire, as well as your consent decisions (cookie banner and the consent given in the matching questionnaire, the latter for 12 months). This storage is required for the respective feature or as proof of consent and therefore happens without separate consent. It stays entirely in your browser. The interim figures in the questionnaire, such as the number of matching therapists, are also computed by your browser itself; your answers are only transmitted to us when you ask to see the results, and we obtain your consent before that. Via “Cookie settings” in the footer you can reset all stored consents at any time.

Analytics Cookies (optional)

With your explicit consent, we use the following analytics tools to improve our service:

  • PostHog (EU servers): Analysis of user behaviour to improve the matching process. Provider: PostHog Inc., data is processed on EU servers. Client-side analytics only start after your consent; independently of that we count page requests on the server without a cookie and without a person profile (see below).

These tools are only activated after your active consent in the cookie banner. You can withdraw your consent at any time.

Independently of consent we also count on the server how often a page was requested. No cookie is set and no person profile is created: the IP address is not stored but combined with the date and browser signature into a daily-rotating pseudonym that cannot be reversed. Without this count we would simply be missing every visitor who declined tracking. The legal basis is our legitimate interest in privacy-preserving reach measurement (Art. 6(1)(f) GDPR); you can object to this processing at any time (Art. 21 GDPR, contact see section 10).

You can change your cookie settings at any time via the cookie banner or in your browser.

8. Your Rights

Pursuant to the GDPR, you have the following rights:

  • Right of access (Art. 15)
  • Right to rectification (Art. 16)
  • Right to erasure (Art. 17)
  • Right to restriction (Art. 18)
  • Right to data portability (Art. 20)
  • Right to object (Art. 21)

Right to Complain

You have the right to complain to the Austrian Data Protection Authority:

Austrian Data Protection Authority
Barichgasse 40-42, 1030 Vienna
dsb@dsb.gv.at

9. Data Retention

  • Account dataUntil account deletion
  • Contact inquiries, content (name, email, phone, message, topics, severity, postcode region)Name, email, phone, message and topic data are stored encrypted (AES-256-GCM). Severity and postcode region are stored only as coarse categories that are not identifying on their own. 30 days after receipt all of these fields are automatically purged from our database by a daily cron job. You can also delete your inquiry yourself at any time via the link in the confirmation email. The email notification that was sent to the therapist at the time of the inquiry is subject to the therapist's professional confidentiality obligation and is not covered by this deletion.
  • Contact inquiries, pseudonymized residual data (therapist ID, timestamp, match score, technical status flags)12 months after anonymization; the record is then deleted from the database entirely. Topic, severity and postcode-region data are already removed by the 30-day deletion and are not retained beyond it. The remaining fields still count as pseudonymized pursuant to Art. 4 (5) GDPR.
  • Questionnaire answers, as long as no inquiry has been sentIn your browser only, for the lifetime of the browser tab. Nothing of it remains on our servers. Separately, your browser remembers the consent you gave for 12 months.
  • Billing data7 years (legal retention requirement)
  • Server logsRetention of hosting logs at the provider: approx. 1 hour

10. Data Protection Contact

For questions about data protection or to exercise your rights, please contact us at:

datenschutz@matchyourtherapy.at

We will respond to your request within 30 days.

Last updated: July 2026