Last updated: 9 August 2026

Privacy policy

1. Data controller

The controller of personal data submitted through this website is the independent professional practice identified as “Katerina Sermpezi” (“we” or “the practice”), to the extent processing relates to operating the website and handling contact requests.

2. Scope

This policy covers the website and related online features (contact form, embedded appointment scheduling, and public content such as articles). It does not replace professional duties of confidentiality or medical-record rules that apply inside a therapeutic relationship, except where those services are explicitly connected to website features (for example, a contact request). Clinical documentation and therapy confidentiality follow applicable professional and legal standards.

3. Data we collect

Depending on how you use the site, we may collect or receive limited information:

  • Contact details: name, email address, optional phone number, and message content you submit through the contact form.
  • Booking data: when you use third-party scheduling (for example Cal.com), you may provide name, email, appointment time, and other fields required by that provider. Their privacy notice also applies.
  • Technical data and logs: hosting providers may log information such as IP address, browser type, and request timestamps for security, reliability, and troubleshooting. Content may be delivered via content networks and headless CMS infrastructure; those providers may process technical data under their own terms.
  • Fonts: brand fonts are self-hosted with the site’s static assets (not loaded from Google Fonts).

4. Legal bases and purposes

We process personal data only where we have a lawful basis under the GDPR and Greek law.

For contact-form requests: our lawful bases are typically (a) responding to your request and/or taking steps at your request before a contract (Article 6(1)(b)), and/or (b) our legitimate interests in operating the practice inbox and replying to enquiries (Article 6(1)(f)), and sometimes (c) consent where clearly required.

For security, availability, and proportionate improvement of the website: legitimate interests (Article 6(1)(f)), together with appropriate technical and organisational measures.

For bookings via a third-party platform: processing is based on contract/pre-contract steps and/or consent as presented in that provider’s flow.

5. Processors and third parties

We use service providers who process data on our behalf or determine their own purposes where they act as independent controllers. Examples include:

  • Website and application hosting (for example Vercel or comparable services).
  • Transactional email delivery for contact notifications (for example Resend).
  • Content management for articles (for example Sanity).
  • Scheduling embeds (for example Cal.com).
  • Self-hosted font files delivered with the website’s static assets.

6. International transfers

Some providers may process data outside the European Economic Area. Where required, we rely on appropriate safeguards such as EU Standard Contractual Clauses or other mechanisms recognised under applicable law.

7. Retention

We keep contact messages for as long as needed to respond, meet legal or contractual obligations, and protect legitimate interests—typically up to twenty-four (24) months unless law or the nature of a matter requires longer. Technical logs are usually kept for shorter periods according to hosting configuration.

8. Security

We apply appropriate technical and organisational measures in light of the risk, including encrypted transport where supported (HTTPS), access controls, and reputable providers. No system is perfectly secure; if a notifiable incident affects your data, we will follow applicable legal duties.

9. Your rights

Under the GDPR you may, where the law allows, request access, rectification, erasure, restriction of processing, data portability, and object to certain processing. Where processing is based on consent, you may withdraw consent without affecting the lawfulness of earlier processing.

You may lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr).

10. Children

This site is not directed at collecting marketing data from children under 16. If we learn we have collected a minor’s data without an appropriate basis, we will take steps to delete it.

11. Cookies and similar technologies

We use strictly necessary features so the site works (including storing your cookie choice in the browser). The embedded appointment scheduler (Cal.com) does not load until you explicitly accept that option via the bar at the bottom of the screen; that provider may set its own cookies or use similar technologies. If we add analytics, advertising, or other non-essential technologies later, we will update this policy and ask for consent again where required.

12. Changes

We may update this policy. The “last updated” date reflects material changes. Please review this page periodically.

For questions about this policy or to exercise your privacy rights, you can email sermpezek@gmail.com , or use the details on the website’s Contact page.