Data protection
Privacy Policy
We take your personal data seriously. Below you will find detailed information about what data we collect, why, and what your rights are.
Updated: March 30, 2026
Personal data controller
The controller of your personal data is Konstancja Umińska, conducting a sole proprietorship under the business name Konstancja Umińska Jutro I Dziś, registered in the Polish CEIDG business register.
Registered address
ul. Ogrodowa 7/46, 00-893 Warsaw, Poland
Tax ID / REGON
5273087876 / 52710504700000
For all data protection matters, please contact us at: [email protected] or by phone at +48 722 324 516.
Scope of data collected
Data you provide yourself
Account registration
First name, last name, email address and phone number provided when creating a patient account.
Appointment booking
Selected therapist, date, time, session format (in person or online) and any notes you add.
Payments
Data needed to process payments. Handled by Stripe, Inc. We do not store full card numbers.
Contact form
The content of messages sent via the website form or by email.
Data collected automatically
- IP address, browser type and version, operating system, screen resolution, browser language.
- Information about how you use the service (pages visited, time on site, traffic source) collected via Google Analytics 4.
- Therapist calendar data — when Google Calendar is connected (busy times, appointment events).
- Cookies described in detail in section 8 below.
Purposes and legal bases for processing
We process personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR). Below we list the purposes of processing together with the relevant legal bases.
| Purpose | Legal basis |
|---|---|
| Performance of a contract for psychotherapy services (bookings, conducting sessions) | Art. 6(1)(b) GDPR |
| Processing payments for sessions | Art. 6(1)(b) GDPR |
| Tax and accounting records | Art. 6(1)(c) GDPR |
| Booking confirmations and appointment reminders (email, SMS) | Art. 6(1)(b) GDPR |
| Syncing appointments with the therapist’s Google Calendar | Art. 6(1)(a) GDPR |
| Handling enquiries from the contact form | Art. 6(1)(f) GDPR |
| Website traffic analysis and service improvement | Art. 6(1)(a) GDPR |
| Establishing, exercising or defending legal claims | Art. 6(1)(f) GDPR |
Google Calendar API integration
The service uses the Google Calendar API so therapists can sync appointments with their Google Calendar. The integration is optional and requires the therapist’s explicit consent (OAuth 2.0).
FreeBusy API
We read busy times from the therapist’s calendar to prevent double bookings. We do not read event content.
Creating events
We automatically create an event in the therapist’s calendar after a client books an appointment.
Google Meet
We generate Google Meet links for online sessions and add them to the calendar event.
Updates / deletion
When an appointment is rescheduled or cancelled, we update or delete the event accordingly.
Revoking access: a therapist may revoke calendar access at any time in the therapist panel or at myaccount.google.com/permissions. We do not access clients’ (patients’) calendars.
Who we share data with
We share your data only with entities without whom we could not provide our services. Each processes data only to the extent strictly necessary.
Processes payment data to complete transactions. For card data, Stripe acts as an independent controller. Stripe Privacy Policy.
Google Calendar API (appointment sync, conflict checks via FreeBusy), Google Meet (online sessions) and Google Analytics 4. Acts as a processor under standard contractual clauses.
Sends booking confirmations, appointment reminders and change notifications. Acts as a processor.
Sends SMS reminders about upcoming appointments. Processes the patient’s phone number solely for this purpose.
Translates administrative content (service descriptions, therapist profiles) into English and Ukrainian. Patient personal data is not sent to DeepL.
Application server and database hosted in a data centre in Germany (EU). Hetzner has no access to application data.
Processes data to the extent required by tax and accounting law.
Transfers outside the EEA
We use providers based in the United States (Google, Stripe, AWS, Twilio). Transfers are based on the European Commission’s adequacy decision under the EU-U.S. Data Privacy Framework and, where necessary, on standard contractual clauses supplemented by additional safeguards (encryption, pseudonymisation). DeepL and Hetzner process data only within the EU.
How long we keep data
Account data
From the last activity after account deletion. Longer if required by law.
Transaction data
From the end of the tax year in which the transaction took place (tax obligation).
Analytics cookies
Maximum data retention period in Google Analytics 4.
Email / SMS logs
Delivery logs for confirmations and reminders kept for diagnostic purposes.
Correspondence
From the last contact, as needed to handle the matter.
Google Calendar tokens
Stored until the therapist revokes authorisation.
Your rights
Under the GDPR you have a number of rights regarding your personal data. You may exercise them at any time by writing to [email protected]. We will respond within 30 days at the latest.
You may check whether we process your data and request a copy.
If your data is inaccurate or incomplete, you may request that it be corrected.
You may ask us to delete data when it is no longer needed for the purposes for which it was collected.
In certain situations you may request that we restrict processing.
You have the right to receive your data in a structured format and transfer it to another controller.
You may object to processing based on our legitimate interest.
Withdrawing consent (Art. 7(3) GDPR): if processing is based on consent, you may withdraw it at any time. This does not affect the lawfulness of processing carried out before withdrawal.
If you believe that processing of your data violates the GDPR, you have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO) (ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl).
Data security
- All communication with the service uses an encrypted HTTPS (TLS) connection.
- User passwords are stored hashed with the scrypt algorithm.
- Only authorised persons have access to personal data, and only to the extent necessary to perform their duties.
- We regularly update and monitor our infrastructure for security.
- The server is hosted by Hetzner Online GmbH in Germany (EU), with regular database backups.
Note on sensitive data
The jutroidzis.pl service does not collect or process health data (Art. 9 GDPR) via the website. Health-related information is shared only in direct contact with the therapist during sessions and is covered by psychotherapist professional secrecy.
Policy changes and contact
We reserve the right to update this Privacy Policy. We will notify you of material changes via a notice on the service or by email. The current version is always available at jutroidzis.pl/polityka-prywatnosci.
Contact for personal data matters