Privacy policy
This Privacy Policy explains how Blue Mind Psychology, operated by Vika Novak (hereinafter "we", "us", or "our"), collects, uses, and protects your personal data when you visit our website or use our services. We are committed to protecting your privacy in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and applicable Portuguese data protection legislation.
Data controller
The data controller responsible for your personal data is:
Vika Novak — Blue Mind Psychology
N114 82A, Serra d'El-Rei, Portugal
blue.mind.psychology@gmail.com
+386 51 651 392
Data we collect
We may collect and process the following categories of personal data:
Contact and identification data — your name, email address, and telephone number, provided when you complete a contact form, book a session, or communicate with us directly.
Health and psychological data — information you share in the context of psychological counseling or surf therapy sessions, which constitutes special category data under Article 9 of the GDPR. This data is collected only with your explicit prior consent.
Technical data — basic usage data such as IP address and browser type, collected automatically when you visit our website for security and performance purposes.
Legal basis for processing
We process your personal data on the following legal bases:
Consent (Article 6(1)(a) GDPR) — for marketing communications and for the processing of health data in a therapeutic context (Article 9(2)(a) GDPR).
Performance of a contract (Article 6(1)(b) GDPR) — to provide the psychological counseling, surf therapy, or workshop services you have requested.
Legitimate interests (Article 6(1)(f) GDPR) — to maintain the security of our website and improve our services.
Legal obligation (Article 6(1)(c) GDPR) — where processing is required by applicable law.
How we use your data
We use your personal data exclusively for the following purposes: to respond to your enquiries and schedule sessions; to deliver psychological counseling, surf therapy, and workshop services; to maintain client records as required by professional standards; and to comply with legal and regulatory obligations. We do not use your data for automated decision-making or profiling.
Sharing of data
We do not sell or rent your personal data to third parties. Data may be shared only in the following limited circumstances: with service providers acting as data processors on our behalf (such as website hosting and email services) under appropriate data processing agreements; where required by law, court order, or regulatory authority; or where necessary to protect our legal rights.
Our website is hosted on infrastructure that may involve data transfers outside the European Economic Area. In such cases, we ensure adequate safeguards are in place in accordance with Chapter V of the GDPR.
Data retention
Contact enquiries and non-client communications are retained for up to 12 months. Client session records are retained for a minimum of 5 years following the end of the therapeutic relationship, in line with professional obligations, unless a longer retention period is required by law. Health data is deleted upon expiry of the applicable retention period or upon your request, unless retention is required by law.
Your rights
Under the GDPR, you have the following rights regarding your personal data:
Right of access — to obtain a copy of the personal data we hold about you.
Right to rectification — to request correction of inaccurate or incomplete data.
Right to erasure — to request deletion of your data where there is no longer a lawful basis for processing.
Right to restriction — to request that we limit the processing of your data in certain circumstances.
Right to data portability — to receive your data in a structured, commonly used, machine-readable format.
Right to object — to object to processing based on legitimate interests.
Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us at blue.mind.psychology@gmail.com. We will respond within 30 days.
Right to lodge a complaint
If you believe your data protection rights have been infringed, you have the right to lodge a complaint with the Portuguese supervisory authority, the Comissão Nacional de Proteção de Dados (CNPD), at www.cnpd.pt.
Cookies
Our website may use essential cookies necessary for the proper functioning of the site. We do not use tracking or advertising cookies. You may configure your browser to refuse cookies; however, this may affect the functionality of certain parts of the website.
Changes to this policy
We reserve the right to update this Privacy Policy at any time. Any material changes will be communicated via our website. This policy was last updated in June 2025.