No rush, at your own pace.

Take the first step
It can be difficult.

When the time is right, schedule with

-20%

your initial session.

Use the coupon

DATERAPIA20

Taking the first step can be difficult. To help, schedule your first session with –20% Value. Coupon DATERAPIA20.

Privacy Policy

Last updated: October 15, 2025

DaTerapia (“Platform”, “we”), operator of the website psicologo-online.pt, respects your privacy and processes personal data in accordance with Regulation (EU) 2016/679 (GDPR) and Law No. 58/2019. This Policy explains clearly and completely how we collect, use, store and protect your data.

Responsible for treatment: MAKE IT DIGITAL, UNIPESSOAL LDA, operator of the website psicologo-online.pt.
Contacts: dpo@psicologo-online.pt | +351 911 559 506.
Address/Tax ID: Praça Conde Agrolongo, nº 74, 3º, trás, 4700-312 Braga, 517 998 270.

1. Who is responsible for the treatment and how do we work with the psychologists?

MAKE IT DIGITAL, UNIPESSOAL LDA is, as a rule, responsible for the treatment with regard to platform operations (account creation, scheduling, transactional communications, invoicing and security).
You clinical acts (Session content, clinical notes, and therapeutic decisions) are carried out by psychologists duly registered with the OPP, who act as autonomous managers for these clinical treatments. For certain joint purposes (e.g., ensuring continuity of care through the platform), DaTerapia and the psychologist may act as jointly responsible, with a documented division of responsibilities. In any scenario where DaTerapia acts as subcontractor Treatment provided by a psychologist or clinical entity is conducted under documented instructions and a written contract.

2. Categories of personal data processed

We only process the data that is necessary and proportionate to the purposes:
Identification and contactName, email, mobile phone number, address, tax identification number (for invoicing).
Account and usage: credentials (stored using hashing), access logs, preferences.
Scheduling and invoicingBooking history, payment methods (tokens or pseudonymized references), invoices/receipts.
CommunicationsMessages exchanged via forms, email, reminder notifications, and service information.
Technical dataIP address, device identifiers, timestamps, technical events, and cookies (see Cookie Policy).
Health data (Special category): Information shared during psychological assessment and consultation, reports and clinical notes, strictly accessible only to the attending psychologist and, when essential, to those providing operational support under a duty of confidentiality.

MinorsWhere applicable, processing depends on the valid consent of the holder of parental responsibilities, in accordance with the law.

3. Purposes and legal basis

We process the data to:
the) Provision of psychological services (includes assessment, intervention and follow-up; online or in person via platform) – contract execution; health data under Article 9(2)(h) GDPR (provision of healthcare by a professional subject to confidentiality) and 9(3).
b) Account management, customer service and support. (authentication, responding to requests, incident resolution) – contract execution and legitimate interest in ensuring a functional and secure service.
w) Billing and compliance with legal obligations (Issuance of tax documents, auditing) – legal obligation and contract execution.
d) Safety and abuse prevention (logs, fraud detection, integrity and availability) – legitimate interest and, where applicable, legal obligation.
and) Service improvement and statistics (aggregated/pseudonymized metrics, user experience) – legitimate interest; consent when necessary.
f) Communications:
Transactional (confirmations, reminders, appointment changes) – contract execution/legitimate interest;
Marketing (relevant news) – only with prior consent or under legally permissible terms, with the option to easily object at any time.
g) Complaints management, exercise/defense of rights – legal obligation and legitimate interest; health data only when strictly necessary and proportionate.

4. Data Source

The data is mostly obtained directly from the data subject. In limited cases, it may come from referring entities, healthcare professionals, or payment/billing providers. When received indirectly, we ensure the information is provided as stipulated in Article 14 of the GDPR, unless otherwise required by law.

5. Need for the data

Essential information for identification, contact, payment/billing, and security is required to provide the service. Its absence may prevent the booking or the consultation from taking place. Optional information is clearly indicated.

6. Storage periods

We apply the principle of minimization e conservation limitation:
Tax/accounting documentsUp to 10 years.
Account and technical recordsWhile the account is active and for proportional periods for security and compliance.
Clinical data: for the period necessary for therapeutic monitoring and for minimum periods adequate to the standard of care and the defense of rights. In the absence of a specific period, a minimum period of [amount] is adopted as a reference. 10 years counted from the last intervention, unless a higher requirement exists.
After the deadlines, the data is eliminated or anonymized in a safe manner, with a record of the procedure.

7. Recipients and subcontractors

We only share data when necessary and with appropriate safeguards:
Psychologists providing servicesAccess is strictly necessary for the execution of the clinical act and follow-up.
Subcontractors (Hosting/infrastructure, videoconferencing, transactional messaging, payments, invoicing, IT support and security): governed by processing agreements (Article 28 GDPR), with documented instructions, confidentiality and appropriate security measures.
Public authorities and entitiesWhen required by law or by legitimate order.
Audits and complianceLimited access, with pseudonymization whenever possible and confidentiality clauses.

8. International Transfers

We prioritize processing within the European Economic Area. When it is necessary to use suppliers in third countries without an adequacy decision, we apply... Standard Contractual Clauses and complementary measures (encryption, minimization, logical separation), preceded by a risk assessment, as per Article 46 of the GDPR.

9. Information security

We maintain measures technical and organizational Proportional to the risk: encryption in transit, password hashing, environment segregation, granular access control by profile (principle of least privilege), access logs, backups, hardening, testing and monitoring, retention and deletion policies, confidentiality agreements, and team training. Access to health data It is strictly limited to what is necessary and covered by duty of professional confidentiality. We periodically evaluate the effectiveness of the measures, including when we change technologies or suppliers. When the nature of the treatment justifies it, we carry out... Data Protection Impact Assessment (DPIA).

10. Cookies and similar technologies

We use cookies. strictly necessary Regarding functionality. Cookies analytical/functional/marketing These cookies are only used with prior consent and after informing the purposes and duration. You can adjust your preferences at any time through the consent manager. Use of the service is not conditional on accepting non-essential cookies.

11. Communications, sessions and recordings

We send communications. transactional (e.g., appointment confirmation, reminder, access information). The content of the queries. It is not communicated by email/SMS.. Recording sessions is not standard practice.; If clinically justified and permitted, it will be explained beforehand (purpose, legal basis, access, time frame, and disposal) and, when required, requested. explicit consent.

12. Automated decisions and profiling

We do not make decisions with legal effects based solely on automated processing. We may use simple profiles to improve the user experience (e.g., time zone-appropriate reminders). Whenever the basis is a legitimate interest, we may... to oppose.

13. Rights of data subjects

Under the GDPR, you have the rights to access, rectification, deletion, limitation, portability e opposition (including the opposition to marketing). He can withdraw consent at any time when the treatment is based on consent, without affecting the lawfulness of previous treatment.
To exercise your rights, contact the DPO: dpo@psicologo-online.pt +351 911 559 506. We generally respond within a maximum of 1 month (Extendable in complex situations). For your security, we may request identity verification elements.

14. Personal data breaches

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority. within 72 hours After becoming aware of the situation and, when required by law, we will inform the affected data subjects as quickly as possible, indicating the measures taken and mitigation recommendations.

15. Third parties and external links

The website may link to third-party content. Each third party is responsible for its own privacy practices. We recommend reading the applicable policies before providing personal data in these contexts.

16. Internal procedures and governance

We maintain Record of Treatment Activities, policy of access control, incident response plans, procedures for managing holder applications, selection and evaluation processes for subcontractors e periodic audits security and compliance. The team with data access is linked to confidentiality clauses and receives regular training in data protection and security.

17. Updates to this Policy

We may update this Policy to reflect legal, technical, or operational changes. When changes are significant, we will provide visible notice on the website and/or by email, indicating the effective date. The applicable version is the one published on psicologo-online.pt on the date of use of the service.

18. Contacts

Data Protection Officer (DPO): dpo@psicologo-online.pt
Telephone: +351 911 559 506
Postal address for correspondence: Please indicate when applicable.


 

  • Note on operational coherence (telepsychology)

    Consultations are provided by psychologists with valid registration with the OPP. In situations where psychological emergency, teleconsultation It does not replace emergency services.. In case of crisis, you should contact emergency services by dialing 112 or go to the nearest health unit. The identification of minors and parental consent, when applicable, are verified and recorded. The duration of sessions and the therapeutic format follow professional standards and best practices.

Important Notice

Online psychology consultations aim to support psychological well-being and are not a substitute for medical, psychiatric, or emergency services.
In case of a psychological crisis or emergency, contact 112 immediately or go to the nearest emergency service.