Back to Home

Privacy Policy

Last Updated: May 26, 2025

1. Introduction

We are SPEAK YOUR MIND KFT, a limited liability company incorporated under the laws of Hungary, with tax identification number 32522877-1-42, registered with the Hungarian Company Register maintained by the Hungarian Court of Registration. Our registered office is located at 1082 Budapest, Leonardo da Vinci utca 7. Fsz. 2. ajtΓ³, Hungary. You can contact us at info@speakyourmind.help

We operate the online platform available at www.speakyourmind.help (the "Website"), which allows clients to book therapy sessions, enables therapists to connect with clients, and provides visitors with information related to mental health.

This Privacy Policy describes how we collect, use, disclose, and protect personal data in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679 – "GDPR").

2. Definitions

For the purpose of this Privacy Policy:

  • Client is a person who uses the Website to book and attend sessions with therapists.
  • Therapist is an entrepreneur using the Website to connect with their clients.
  • Visitor is a user who browses the Website.

3. Legal Framework

We process their personal data in accordance with applicable laws, in particular:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data and the free movement of such data, and the repeal of Directive 95/46/EC (General Data Protection Regulation, "GDPR");
  • Hungarian Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information ("Infotv.").

4. Personal Data We Process

Why do we process your data as a data controller?

We are the data controller of your personal data, which means that we determine the purposes and means of processing your personal data. We process your personal data for the purposes set forth below and for the durations specified herein.

We hereby confirm that, in the course of processing your personal data, we do not engage in any automated individual decision-making as defined in Article 22 of the GDPR. This refers to situations where personal data processing is carried out solely by automated means, without any human intervention, and produces legal effects concerning you or similarly significantly affects you.

We DO NOT sell your personal data.

4.1 Clients

If you book and attend a session via the Platform as a client, we process the following data:

  • Your contact details: first and last name (if provided), phone number, and e-mail address.
  • Billing and banking details (if you pay for the session by yourself): personal data appearing on invoices, information about payments and their status, information on the method of payment.
  • Other information about you: other personal data related to the contract we enter into together, and the communication the client maintains with the platform, or communication between the client and the therapist.
  • Information about the feedback you provide to the therapists.
  • Information about the evaluation of therapists, if you provide it.
  • Information from the booking system: session dates, cancellations, communication between clients and therapists (except therapy sessions or chat consultations themselves), results from self-assessment tests available via the Website, etc.
  • Information about your employer - if you use our services as an employee benefit.

SPEAK YOUR MIND KFT does not have access to video conferencing with your therapist, nor do we receive information about you from the therapist, only confirmation that the session has taken place/has not taken place (therefore, only your therapist is the controller of the personal data provided during the session). Additionally, SPEAK YOUR MIND KFT does not have access to your credit card information if you pay via the Website (the administrator is Stripe Payments Europe, Ltd.) -- we only receive information about whether the payment has been made/not made.

Depending on whether you order the services for yourself or draw as an employee benefit, SPEAK YOUR MIND KFT may be the provider or agent of the services offered (consultations). However, in the context of personal data processing, SPEAK YOUR MIND KFT and the individual therapist are always independent controllers of your personal data related to the provision of services. We may register your employer (for email verification) and document payments in accounting records.

As noted, SPEAK YOUR MIND KFT does not process sensitive client data, such as health information, recommended sessions, sexual orientation, or treatment details. The relationship between you and your therapist is confidential, and all sensitive information is processed solely by the therapist, who is bound by professional ethical standards and strict confidentiality agreements.

Should the client and therapist mutually agree to record sessions, such recordings are made solely on their own responsibility. SPEAK YOUR MIND KFT has no access to, does not store or process these recordings, and assumes no liability for their handling, storage, or use. The parties involved bear full responsibility for maintaining the confidentiality and security of such recordings.

4.2 Confidentiality Responsibility

SPEAK YOUR MIND KFT acts as a platform providing technical support and processing personal data necessary for the operation of the service. However, all confidential information related to the content of therapeutic sessions (including recordings, notes, and other data) is solely the responsibility of the therapists delivering the services. The platform is not liable for the processing, storage, or any consequences arising from the disclosure or use of such information.

4.3 Data Processing Table for Clients

We process your data as described in this table:

Legal basis of the processingPurpose of processingPeriod of data processingData processed
CONTRACT (GDPR Article 6(1)b) and Infotv. Β§ 6)Performance of a contract or pre-contractual negotiationsFor as long as you have an active client account. We will delete your personal data 3 years after your last log-in to the account, or immediately at your request.Contact details, billing and payment details, booking system information, employer details, etc.
LEGAL REGULATIONS (GDPR Article 6(1)c) and Infotv. Β§ 6)Compliance with legal obligationsFor the duration of the legal obligation (e.g., tax retention for 10 years).Contact details, billing and payment details, other information.
LEGITIMATE INTEREST (GDPR Article 6(1)f) and Infotv. Β§ 6)Enforcing contractual claims and legal obligationsAs long as the legal claims can be enforced, but no longer than 5 years from the end of the contractual relationship, unless otherwise provided by law.Contact details, billing/payment details, communication, feedback, booking system information, employer details.
LEGITIMATE INTEREST (GDPR Article 6(1)f) and Infotv. Β§ 6)Improving service qualityUntil you have an active client account (data will be erased after 3 years of no activity).Contact details, feedback, booking system info, etc.
CONSENT (GDPR Article 6(1)a) and Infotv. Β§ 5)Direct marketingFor 3 years or until you object (e.g., unsubscribe from commercial communications).Contact details

4.4 Therapists

If you use the Website as a therapist, we process the following data:

  • Your contact details: first and last name, phone number, and e-mail address.
  • Billing and banking details: personal data from invoices, payment information, and payment method.
  • Your education and experience: degree and practice duration.
  • Other information related to the contract and communications.
  • Information from the booking system: session dates, cancellations, communication between clients and therapists.

Legal basis and processing details are similar to those for clients, with data retention aligned to the therapist's cooperation duration with SPEAK YOUR MIND KFT.

4.5 Visitors

If you visit the Website without registration:

  • We process your contact details: email.
  • We process your visit to the Website as per our Cookie Policy.

5. Use of Cookies

Our Platform uses cookies and similar technologies to ensure proper functionality, analyze usage, and provide personalized content and marketing. Cookies are small text files stored on your device that help us recognize your preferences during future visits.

For detailed information about the types of cookies we use, their purposes, and how you can manage or disable them, please refer to our separate Cookie Policy.

By continuing to use the Platform, you consent to the use of cookies as described in our Cookie Policy.

Legal basis of the processingPurpose of processingPeriod of data processingData processed
CONSENT (GDPR Article 6(1)a)Sending marketing information (e.g., newsletter) if you grant us consent to the processing of data for this purposeWe may send you our newsletters for 3 years or until you express your opposition to such processing, e.g., by unsubscribing from our commercial communications.Contact details.
MISCELLANEOUSThe use of cookies for the purposes of analysis, statistics, advertising, or even evaluation of the services providedYou may find more information in our cookie policy.You may find more information in our cookie policy.

6. Data Sharing with Third Parties: Our Partners and Service Providers

To ensure the protection and lawful processing of your personal data, SPEAK YOUR MIND KFT has entered into data processing agreements with all our external service providers (processors) involved in handling your data. These agreements clearly define obligations regarding data confidentiality, security measures, and compliance with applicable data protection laws, including the GDPR and Hungarian Infotv. These agreements guarantee that all processors act under our instructions and maintain adequate technical and organizational safeguards to protect your personal data throughout the processing lifecycle.

We use the services of Google LLC (Google Meet) to provide secure and encrypted video communication between clients and therapists. Google's infrastructure is widely trusted for its reliability, data protection standards, and compliance with the General Data Protection Regulation (GDPR). Google acts as a data processor under a valid Data Processing Agreement (DPA), and data is handled exclusively within the European Economic Area (EEA) or under appropriate safeguards.

Additionally, payments for individual sessions are processed by Stripe Payments Europe, Ltd., who are the controllers of your personal data. They only forward to our company information about whether the payment was successful or not. They do not share any payment details with us.

As part of SPEAK YOUR MIND KFT's operations, we collaborate with other entities for personal data processing, especially in areas such as IT support, cloud storage, and web hosting management. Specifically, we work with the following companies:

6.1. Communication and Session Support

  • Google LLC (USA) β€” provides secure video communication between clients and therapists through Google Meet. All communication is encrypted, and data is processed under Google's GDPR-compliant Data Processing Agreement (DPA). Google ensures adequate safeguards for international data transfers.
  • Airtable Inc. (USA) β€” provides internal database tools used for organizing therapist profiles and administrative workflows. Airtable is certified under the EU-U.S. Data Privacy Framework (DPF) and processes data in compliance with GDPR.

6.2 Data Storage and Hosting

  • DigitalOcean Holdings, Inc. (USA) β€” cloud infrastructure provider. Data transfers are safeguarded by Standard Contractual Clauses (SCCs).
  • Google Ireland Ltd. β€” provides Google Cloud and analytics services.
  • Aleksandr Rogachev PR Beograd β€” provides enterprise software and internal system hosting.

6.3 Marketing and User Engagement

  • Brevo (formerly Sendinblue SAS, France) β€” used for email communications such as onboarding messages, reminders, and updates. Brevo is based in the EU and fully GDPR-compliant. All data is processed on EU servers, and users may unsubscribe or manage preferences at any time.
  • Meta Platforms Inc. β€” may be used for brand visibility and optional advertising campaigns. If used, all data processing is governed by Meta's EU Data Transfer Addendum and requires user consent when applicable.

6.4 Productivity and Workflow Tools

  • Formagrid Inc. (Airtable, USA) β€” used for internal coordination of therapist profiles, onboarding, and scheduling. Data transfers are governed by Standard Contractual Clauses (SCCs).
  • Typeform SL (Spain) β€” used for collecting therapist applications and user feedback via embedded forms. Typeform processes data within the EU under GDPR.

6.5 Infrastructure and Frontend Services

  • Next.js β€” framework used as the foundation of our frontend interface. It helps deliver a fast and smooth user experience.
  • Google Meet API (part of Google Ireland Ltd.) β€” used to facilitate secure video calls between clients and therapists. Data processing under Google's data protection policies.
  • Google Workspace (Gmail, Docs, Forms) β€” used for internal communication and managing forms, operated by Google Ireland Ltd.

6.6 Payment Solutions

  • Stripe Payments Europe, Ltd. β€” responsible for processing client payments and planned automatic session scheduling. Stripe acts as a data controller for payment information and forwards only payment status to us.

6.7 Infrastructure and Analytics

  • Vercel Analytics β€” optionally used for website analytics if enabled.
  • Functional Cookies β€” cookies necessary for user login and session management, following standard practices used by Vercel and Supabase.
  • Supabase β€” used for backend services such as database management and authentication (if applicable). Data handled under Supabase's privacy terms.

6.8 Additional Security Measures

All processors listed above have signed data processing agreements obligating them to maintain confidentiality and implement technical and organizational security measures that comply with GDPR and Hungarian data protection laws.

We recommend that you familiarize yourself with the privacy policies of these companies before starting a session.

If your employer provides access to SPEAK YOUR MIND KFT, rest assured that we do not share any of your personal data with them. Only aggregated data about the total number of sessions and their total value are disclosed.

Your therapist also has access to your personal data and acts as the sole controller of this information.

7. How Do We Protect Your Personal Data?

We are committed to safeguarding your personal data and maintaining the confidentiality of your consultations. Pursuant to Article 32 of the GDPR, we implement appropriate technical and organizational measures to ensure a level of security commensurate with the risk. These include:

  • High standards for therapists: Including confidentiality and security requirements specified in contracts.
  • Organizational and technical safeguards: Ensuring the security of the reservation system and video conferencing platforms through measures such as user verification, data anonymization, access restrictions, server security, monitoring, and service level agreements (SLAs).
  • Data minimization: Limiting the data processed and restricting access to it.
  • Confidentiality: Ensuring all parties with access to the reservation system are bound by confidentiality obligations.

8. Data Breach Notification

In the event of a personal data breach, SPEAK YOUR MIND KFT will notify the competent supervisory authority – the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) – without undue delay and, where feasible, within 72 hours of becoming aware of it, in accordance with Article 33 of the GDPR. If the breach is likely to result in a high risk to your rights and freedoms, you will also be informed without undue delay.

The supervisory authority can be contacted at:

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address: 1055 Budapest, Falk Miksa utca 9-11., Hungary
Website: https://www.naih.hu

9. Your Rights

  • Right to complain: Lodge a complaint with the supervisory authority if you believe your data protection rights have been violated (contact details above).
  • Right to information: You can ask us about the personal data we process and any other related information that isn't addressed above.
  • Right to rectification: If your email, phone number, or name changes, please contact us to update your details.
  • Right to object to processing: If you believe we are processing your personal data improperly, you may request an explanation and you have the right to object to processing based on our legitimate interest.
  • Right to data portability: You may request a copy of your personal data in electronic form.
  • Right to erasure: You can request the deletion of your personal data at any time, provided there are no legal grounds for further processing, unless we are required to retain the data by law.
  • Right to object: You have the right to object to the processing of your personal data for direct marketing purposes. You can refuse such processing, for example, through your device settings.
  • Right to restriction of processing: You have the right to request the restriction of processing of your personal data under certain circumstances (Article 18 of the GDPR).

Response time to data subject requests:

SPEAK YOUR MIND KFT commits to respond to any data subject requests (such as access, correction, or deletion requests) within one month of receipt, in accordance with Article 12 of the GDPR.

How can you exercise these rights?

We are happy to assist with any complaints or requests you may have. You can contact us by email at info@speakyourmind.help

This privacy policy is effective as of 05.26.2025.