We are Hedepy s.r.o., the limited liability company with ID: 09206281, VAT ID: CZ09206281, having its registered office: V tišině 474/3, Bubeneč, 160 00 Prague, the Czech Republic, e-mail: podpora@hedepy.cz, registered in the Czech Commercial Register maintained by the Municipal Court in Prague under file no. C 332559 (“Hedepy” or “we”). We operate a platform available at www.hedepy.cz (the “Website”). Via the Website clients may book a session with a therapist. Therapist may use the Website in order to connect with the clients. Visitors may visit the website and browse information about mental health. We have prepared this Privacy Policy in order to inform all of them how we process their data.
To sum up, for purpose of this Privacy Policy:
We process their personal data in accordance with the applicable laws, in particular, the Regulation (EU) No 2016/679 of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data and the free movement of such data and the repeal of Directive 95/46/EC (General Data Protection Regulation_)_ (the “Regulation “).
We are the data controller of your personal data, that means we decide what are the purposes and methods of processing personal data.
We will process your personal data for the purposes set out below and for the below stated processing period.
We would like to assure you, that while processing your personal data we do not use any automatic individual decision-making on the part of Hedepy within the meaning of Article 22 of the Regulation. This means the situations where the processing of personal data takes place exclusively automatically (without human intervention) and has legal consequences for you, e.g., through automatic information systems, web programs and other software.
We process the following data:
For the avoidance of doubt, we would like to point out that:
(a) Hedepy does not have an access to videoconferencing with your therapist, nor do we receive any information about you from the therapist, only confirmation that the session has taken place/has not taken place (therefore only your therapist is the controller of the personal data provided during the session); and
(b) Hedepy does not have an access to your credit card information if you pay any amount via the Website (the administrator is ComGate Payments a.s. or Stripe, Inc.) – we only get information about whether the payment has been made/not been made).
Depending on whether you order the services for yourself or draw as an employee benefit, Hedepy may be the provider or agent of the services offered (consultations) – you can find more information in the client’s terms and conditions available on the Website. However, in the context of processing of personal data, Hedepy and the individual therapist are always the independent controllers of your personal data related to the provision of services, only whether we register your employer (for the purpose of verifying your e-mail address) and whether we register documents for your payments in the accounting records.
As we mentioned above, Hedepy, as a personal data controller, does not process any of the client’s sensitive data, e.g., information about your health or recommended sessions, sexual orientation or treatment. The relationship between you as the client and the therapist is a confidential relationship and all sensitive information is processed/may only be processed by the therapist, who is bound by the Code of the European Association of Psychotherapists as well as by strict contractual confidentiality. In the event that you and the therapist decide to record the session, our company does not and will not have access to the recording.
We process your data as described in this table:
Legal basis of the processing | Purpose of processing | Period of data processing | Data processed |
CONTRACT Performance of a contract or pre-contractual negotiations GDPR Article 6 (1) b) | Providing of our services, arranging of the agreement with the therapist | Unless otherwise specified below, we will only process data about you in the reservation system for as long as you have an active client account. We will automatically delete your personal data 3 years after your last log into the account. In this case, your account will be erased. Of course, at your request, we will delete the account at any time immediately | For this purpose, we process the following data specified above: your contact details; billing and payment details; information from the booking system; information about your employer if you use our services as an employee benefit |
LEGAL REGULATIONS It is our legal obligation GDPR Article 6 (1) c) | Compliance with all our legal obligations (e.g. obligations under accounting or tax legislation) | For the duration of the relevant legal obligation, for example, some personal data relating to tax matters must be retained for 10 years. | For this purpose, we process the following data specified above: your contact details; billing and payment details; other information. |
LEGITIMATE INTEREST It is our legitimate interest GDPR Article 6 (1) f) | Enforcing contractual claims and legal obligations | We may process your personal data that we may need to defend our legal claims for a time that corresponds to the longest possible limitation period provided for by law | For this purpose, we process the following data specified above: your contact details; billing and payment details; other information; information about our communication and feedback; information about evaluation of therapists if you provide it; information from the booking system; information about your employer if you use our services as an employee benefit; information about your visit to the Website |
Improving the quality of our services, including surveying your satisfaction with our services and therapists | We process your data as long as you have an active client account. We will automatically delete your personal data 3 years after your last log in into the account. In this case, your account will be erased. | For this purpose, we process the following data specified above: your contact details; other information; information about our communication and feedback; information about evaluation of therapists if you provide it; information from the booking system; information about your employer if you use our services as an employee benefit; information about your visit to the Website | |
Direct marketing | We may send you our newsletters for 3 years since your last session, or until you object to this processing, e.g. by unsubscribing from our commercial communications | For this purpose, we process the following data specified above: contact details |
We process the following data:
Legal basis of the processing | Purpose of processing | Period of data processing | Data processed |
CONTRACT Performance of a contract or pre-contractual negotiations GDPR Article 6 (1) b) | Providing of our services, arranging of the agreement with the client | Unless otherwise specified below, if you are a therapist active on the Website, we will only process data about you for duration of our cooperation agreement. | For this purpose, we process the following data specified above: your contact details; billing and banking details; other information; information from the booking system |
LEGAL REGULATIONS It is our legal obligation GDPR Article 6 (1) c) | Compliance with all our legal obligations (e.g. obligations under accounting or tax legislation) | For the duration of the relevant legal obligation, for example, some personal data relating to tax matters must be retained for 10 years | For this purpose, we process the following data specified above: your contact details; billing and banking details; other information |
LEGITIMATE INTEREST It is our legitimate interest GDPR Article 6 (1) f) | Enforcing contractual claims and legal obligations | We may process your personal data that we may need to defend our legal claims for a time that corresponds to the longest possible limitation period provided for by law | For this purpose, we process the following data specified above: your contact details; billing and banking details; information about your visit to the Website |
Direct marketing | We may send you our newsletters for 3 years since your last consultation with the client, or until you object to this processing, e.g. by unsubscribing from our commercial communications | For this purpose, we process the following data specified above: contact details |
We process the following data:
Legal basis of the processing | Purpose of processing | Period of data processing | Data processed |
CONSENT Your grant us a consent for processing your data GDPR Article 6 (1) a) | Sending marketing information (e.g. newsletter) if you grant us consent to the processing of data for this purpose | We may send you our newsletters for 3 years or until you express your opposition to such processing, e.g. by unsubscribing from our commercial communications | For this purpose, we process the following data specified above: contact details. |
MISCELLANEOUS You may find more information in our cookie policy | The use of cookies for the purposes of analysis, statistics, advertising or even evaluation of the services provided | You may find more information in our cookie policy | You may find more information in our cookie policy |
We use the services of Twilio Inc. to ensure a secure connection between the client and the therapist. Our company has chosen an American company for its high system security and its high standard when it comes to data protection, fully in accordance with the Regulatio<n. Twilio Inc. has joined the DPF Program enforced by the U.S. Federal Trade Commission and the U.S. Department of Transportation. By joining this program Twilio Inc. accepted the strict conditions for the processing of personal data under the Regulation and undertook to comply with them. You may check that Twilio Inc. joined the program here.
Furthermore, the payment for individual sessions is organized by ComGate Payments a.s. and Stripe, Inc., which are the controllers of your personal data and only forwards to our company information whether the payment was made/did not go well. They do not pass on any of your payment data to us.
As part of Hedepy’s activities, other entities also help us with the processing of personal data, especially in the field of IT support, cloud storage management or web hosting management, specifically, we cooperate with the following entities:
We recommend that you familiarize yourself with the privacy policy before you first connect to a session.
If your employer enables you to use Hedepy, we would like to assure you that we do not pass on any of your personal data to your employer, only aggregated data about the total number of sessions and the total nominal value of the sessions claimed.
Naturally, also your therapist has an access to your personal data and is a sole controller of your data.
Our company emphasizes the confidentiality of consultations and the security of your data. We have adopted a high standard of security requirements for systems and cooperating persons. The main measures include:
Right to complaint: If you believe that despite our best efforts, we are in breach of data protection legislation, you have the possibility to contact the Czech Office for Personal Data Protection, www.uoou.cz, tel. +420 234 665 111, Pplk. Sochora 27, Praha 7, zip code 170 00, the Czech Republic.
Furthermore, you have also the following rights:
We are happy to be in contact with you and try to resolve your complaints, requests or complaints as quickly as possible.
You can contact us by podpora@hedepy.cz, at our address listed in the header. We are also available on +420 772 123 001 and online chat https://hedepy.cz/.
This privacy policy takes an effect on the 1st January 2024.