Privacy policy
​
Effective Date: 06.01.2026
Vaida Job (“we,” “us,” or “the Company”) is committed to protecting your personal data and complying with the General Data Protection Regulation (GDPR) (EU) 2016/679, Spanish data protection law, and professional confidentiality obligations.
This privacy policy explains how we collect, process, store, and protect your personal data, particularly special category data concerning your health.
1.
Data Controller
The data controller is:
Vaida Job
Address: Irun Street 15, 28008, Madrid, Spain
Email: vaidajobv@gmail.com
2.
Data Protection Officer (DPO)
Due to the processing of sensitive health data, I have appointed myself as the Data Protection Officer (DPO) in accordance with Article 37 of the GDPR.
DPO Contact: vaidajobv@gmail.com
You may contact me regarding all matters relating to your personal data and the exercise of your rights under GDPR.
3.
Personal Data We Collect
We may collect the following personal data:
-
Identity and contact data: name, email, phone number.
-
Health and therapy data: notes from consultations, medical history, psychological assessments.
-
Technical data: IP address, cookies, browsing behavior on this website.
-
Payment data: for course purchases (processed securely via our payment provider).
Note: Therapy session recordings are not collected.
4.
Purpose and Legal Basis for Processing
We process your personal data for:
-
Providing psychological and therapeutic services (Article 6(1)(b) GDPR, Article 9(2)(a) & (h) GDPR for health data).
-
Managing your accounts and communications (Article 6(1)(b) GDPR).
-
Providing online courses and processing payments (Article 6(1)(b) GDPR).
-
Legal obligations and professional responsibilities (Article 6(1)(c) GDPR).
Explicit consent is obtained for processing health data before therapy sessions.
5.
Health Data Processing
We process sensitive health data to deliver therapy services. All health data:
-
Is collected with your explicit consent.
-
Therapy notes are stored digitally using Apple iCloud, a GDPR-compliant data processor. Technical measures such as device encryption and two-factor authentication are implemented to ensure the security and confidentiality of your health data.
-
Is processed under professional confidentiality obligations.
6.
Use of Videoconferencing Services
Online therapy sessions are conducted via Google Meet.
-
Google acts as a data processor under a GDPR-compliant Data Processing Agreement (DPA).
-
Sessions are not recorded unless explicitly authorized by the patient.
-
Technical safeguards are applied to protect your data.
7.
Google Workspace Email
All email communications are sent via Google Workspace, secured under a GDPR-compliant DPA.
8.
Data Sharing and Recipients
Your data may be shared with:
-
Service providers acting as data processors (Google, payment provider, hosting provider).
-
Legal authorities only when required by law.
We do not sell or rent your personal data.
9.
Data Retention
We retain your personal and health data only as long as necessary for the purposes of therapy, course delivery, or legal obligations.
-
Therapy notes: 10 years (per Spanish professional law).
-
Email communications and course records: 5 years.
10.
Your Rights
Under GDPR, you have the right to:
-
Access your personal data.
-
Request correction or deletion.
-
Object to or restrict processing.
-
Withdraw consent at any time.
-
Data portability (where applicable).
-
File a complaint with the Spanish Data Protection Authority (AEPD).
To exercise these rights, contact: vaidajobv@gmail.com.
11.
Cookies and Website Tracking
We use essential cookies to improve website functionality. Non-essential cookies are not used without consent.
You can control cookies via your browser settings.
12.
Personal Data Breach Notification
In the event of a personal data breach:
-
We will notify the AEPD without undue delay, and within 72 hours where feasible.
-
If there is high risk to individuals, affected data subjects will also be notified.
-
Notifications will include the nature of the breach and mitigation measures.
13.
Security Measures
We implement technical and organizational measures to protect your data:
-
Encrypted devices and storage (Apple Notepad notes).
-
Strong passwords and two-factor authentication.
-
Access restricted to authorized personnel.
-
Processor agreements with all third-party services.
14.
Changes to This Privacy Policy
We may update this policy from time to time. The effective date will be updated.
Please review this page periodically.
15.
Contact
Questions or complaints regarding this privacy policy or your personal data:
Email: vaidajobv@gmail.com
Address: Irun Street 15, 28008, Madrid, Spain