GDPR & your rights
PsychHeal is built and operated in the EU. You have strong rights under the General Data Protection Regulation — and we make them easy to use.
Controller
The data controller is PsychHeal (Konstantinos, founder). Contact: dpo@psychheal.app.
Your rights
- Right to access (Art. 15)
Ask what data we hold about you. We send a human-readable bundle within 30 days.
- Right to data portability (Art. 20)
Export everything as JSON from your account settings, anytime, in one click.
- Right to rectification (Art. 16)
Fix anything inaccurate — your name, email, or profile data — from your account.
- Right to erasure (Art. 17)
Delete your account in one click. Data is permanently erased within 30 days, except where law requires retention (e.g. accounting records).
- Right to object & restrict (Art. 18 & 21)
Turn off optional processing (analytics, AI memory) in your privacy settings without losing access to the core product.
- Right to lodge a complaint (Art. 77)
You can complain to your local data-protection authority. We'd love to fix it first — write to dpo@psychheal.app.
Lawful bases we rely on
- Consent — optional analytics and AI memory features.
- Contract — your account, the tools you use, and any paid features.
- Legitimate interests — safety moderation of Echoes, abuse prevention.
- Legal obligation — accounting records, responding to lawful requests.
International transfers
Our database and storage live on EU servers. Some sub-processors (e.g. AI providers) may process data outside the EEA under Standard Contractual Clauses with appropriate safeguards.
See also: Privacy charter · Cookie policy · Your privacy settings.