Data Protection & GDPR
Last updated: 16/07/2026
1. Commitment to GDPR Compliance
As a mental health professional, I take the privacy and security of your data with the utmost seriousness. All operational procedures of the office, both for in-person and online sessions, are designed to fully comply with the General Data Protection Regulation (EU) 2016/679 (GDPR).
2. Your Rights as a Data Subject
The GDPR grants you extensive rights regarding how we handle your data. Specifically, you have:
- The Right of Access (Article 15): You have the right to request a copy of your personal data held in our records, as well as information on how it is processed.
- The Right to Rectification (Article 16): If you believe any information is inaccurate or incomplete, you have the right to request its immediate correction.
- The Right to Erasure / Right to be Forgotten (Article 17): You have the right to request the deletion of your personal data. Note: This right is not absolute and may be limited by our legal obligation to maintain medical/clinical records for 10 years (Article 9(2)(h) GDPR).
- The Right to Restriction of Processing (Article 18): You can request to suspend the processing of your data (e.g., until its accuracy is verified).
- The Right to Data Portability (Article 20): You can request that we transfer your clinical history directly to another mental health professional, in a structured, commonly used, and machine-readable format.
- The Right to Object (Article 21): You have the right to object to processing based on legitimate interest (although we do not use data for direct marketing purposes).
3. Data Subject Access Request (DSAR) Process
You can exercise the above rights by submitting a written request to ioannisdovletoglou@gmail.com. We are committed to reviewing your request and responding within 30 days (with a possible extension of two additional months if the request is exceptionally complex).
For your protection, we may need to request information to verify your identity before fulfilling the request.
4. Online Sessions and Service Providers (Data Processors)
For providing teletherapy services, we use platforms (e.g., Zoom) that are certified and compliant with the GDPR. You should know that:
- Sessions are end-to-end encrypted.
- No video or audio recording takes place. Any such action is strictly illegal without written consent, both from us and from your side.
5. Right to Lodge a Complaint with the Supervisory Authority
If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA).
HDPA Contact Information:
Kifissias Avenue 1-3, P.C. 115 23, Athens, Greece
Phone: +30 210 6475600
Email: contact@dpa.gr
Website: www.dpa.gr
6. Contacting the Data Controller
Yiannis Dovletoglou
Address: Lokridos 42, Gyzi, P.C. 11474, Athens, Greece
Phone: +30 698 056 1988
Email: ioannisdovletoglou@gmail.com