Privacy
Privacy
How INTROSPECT processes personal and health-related data under the GDPR.
Controller
INTROSPECT (online psychiatry practice of Dr. Miftar Zenelaj) is the data controller for session requests, clinical reports, and session recordings created in this application.
Privacy contact
Purposes
- Respond to and schedule session requests.
- Provide online video sessions.
- Create and retain clinical documentation required for care.
- Secure the service (access control, audit logging, abuse prevention).
Lawful bases
- Art. 6(1)(b) — steps prior to a contract / provision of the requested session.
- Art. 6(1)(a) & Art. 9(2)(a) — explicit consent for health-related information you submit in the booking form.
- Art. 6(1)(a) & Art. 9(2)(a) — explicit consent on the session join screen before any video recording may start.
- Art. 9(2)(h) — provision of health care / clinical documentation by a regulated professional, where applicable under national law.
- Art. 6(1)(f) — limited legitimate interests for security logging and fraud prevention.
Categories of data
- Identity and contact: name, email, phone (optional).
- Booking content: preferred language, topic, message, chosen slot.
- Clinical report fields written by the psychiatrist.
- Technical: session join tokens, IP addresses in security/audit logs, browser user-agent.
- Optional session recordings only after you give explicit consent on the session join screen; the clinician cannot start recording without that agreement.
Your rights
- Access, rectification, erasure, restriction, objection, and data portability where applicable.
- Withdraw consent for booking-form health data without affecting processing based on other lawful bases (e.g. existing clinical records).
- Lodge a complaint with your supervisory authority.
- Contact the practice privacy email to exercise rights. Clinical retention duties may limit erasure of medical records.
Retention
Booking and clinical data are retained according to configured retention (default seven years for clinical material unless law requires otherwise). Security audit logs are retained for accountability. Exact periods should be confirmed with legal counsel for your jurisdiction.
Security measures
- Clinician authentication with session timeout and login rate limiting.
- HTTPS required in production; secure cookies; CSRF protection; security headers.
- Access and export/erasure actions are written to an audit log.
- Recordings are stored outside the public web root and served only to authenticated clinicians.
Transfers & processors
Self-hosted deployment by default. If you later use cloud hosting, email, or backup providers, execute Art. 28 processor agreements and document international transfers (Ch. V GDPR) before go-live.
This notice version is dated 2026-09-09. Material changes will update the consent version captured on new requests.