This document describes what personal data the site skryzhanivska.com collects, how it is used, and how it is protected. It is written with respect to the sensitivity of mental-health topics and aligns with the basic principles of GDPR (for EU visitors) and Ukrainian personal-data protection law.
01
Who controls your data
The controller of your personal data is Svitlana Kryzhanivska, psychologist and psychotherapist in training. For data-related questions: skryzhanivska.consulting@gmail.com.
02
What we collect
We collect only what you knowingly provide:
- Contact form: name, email or messenger contact, your message. Sent directly to the therapist's inbox — not stored in any site database.
- Site registration (used for tracking questionnaire history): email, name, avatar — provided by your OAuth provider (Google or GitHub).
- Self-observation questionnaires (Group 1): results tied to your account and visible only to you.
- Clinical questionnaires by code (PHQ-9, PCL-5, Group 2): stored under an anonymous numeric code only — no name, email or other identifiers. The mapping between code and client lives only in the therapist's personal notes outside this system.
03
Special category: health data
Clinical questionnaire results are sensitive data under GDPR Article 9. They get extra protections:
- Stored in a separate Firestore collection under an anonymous code with no PII;
- Accessible only to the therapist via a NextAuth-protected admin interface;
- Not shared with any third party — no ad networks, no analytics, no aggregators;
- Used in supervision only in aggregated, anonymised form, never tied to a specific person.
04
Cookies and analytics
The site uses no third-party trackers (Google Analytics, Facebook Pixel, etc). The only analytics is Vercel Analytics, which collects anonymous aggregate statistics (country, device type, popular pages) without cookies and without any data that could identify a specific visitor.
Technically necessary cookies are used only for the site to function (NextAuth session, locale).
05
Retention
- Contact form requests: in the therapist's inbox for as long as needed to respond. Deleted after communication closes.
- Site accounts: until you request deletion.
- Questionnaire results: kept for the duration of your work with the therapist, plus the period required by professional standards for client-record keeping. Deleted on your request at any time.
06
Your rights
You have the right to:
- access your data (see what we store);
- correct inaccuracies;
- delete your data ("right to be forgotten");
- restrict processing;
- receive your data in a machine-readable format;
- withdraw consent at any time.
Send requests to skryzhanivska.consulting@gmail.com — we respond within 30 days.
07
Technical infrastructure
Data is stored and processed at:
- Vercel — site hosting (US/EU data centers by request geography)
- Google Firebase — authentication and Firestore database (EU region: europe-west)
- Resend — contact-form email delivery
All data transfers are encrypted (HTTPS/TLS). Providers process data under GDPR-compatible Data Processing Agreements.
08
Changes to this document
Any changes take effect when published on this page. The last-updated date is shown at the top.
This document is a starting template. For situation-specific questions, contact the therapist directly: skryzhanivska.consulting@gmail.com.