Privacy and cookie policy
This page explains how personal data of people who visit psicote.com or contact us is handled, in line with articles 13 and 14 of the General Data Protection Regulation (GDPR). It applies wherever you are in the world.
1. Data controller
Dr Samuele Filomena, Ambulatorio La Psicoterapia, Via C. Braico 10, 72012 Carovigno (BR), Italy · VAT no. IT02434400749 · info@psicote.com.
For any request about your data: info@psicote.com.
2. What data we process
- Browsing data. Like any website, our server automatically logs IP address, date and time, requested page and browser type. This is used to run and secure the site, not to identify you.
- Data you send us. If you write, call or use the booking form, we process your name, contact details, the reason for your request and your availability. Please do not send unnecessary clinical detail by email. If you do, it is still health data and is handled with the same safeguards and duty of confidentiality.
- No profiling. The site does not use analytics or advertising tools [confirm].
3. Purposes and legal bases
- Answering your enquiry and arranging a first session: steps taken at your request before entering into a contract (art. 6(1)(b) GDPR). For any health data you choose to share, your consent, given by sending it voluntarily (art. 9(2)(a)).
- Site security and proper functioning: legitimate interests (art. 6(1)(f)).
- Administrative, tax and professional obligations: legal obligation (art. 6(1)(c)).
- Establishing, exercising or defending legal claims: legitimate interests (art. 6(1)(f) and art. 9(2)(f)).
If you begin treatment, clinical data is covered by a separate notice and an informed consent form you receive at the first session. It is not covered by this page.
4. Recipients
Your data is not published or sold. It may be processed by service providers acting as data processors: website hosting [provider name], email [provider name], booking tool [provider name] and video-call platform Whereby (whereby.com, GDPR and HIPAA compliant). Tax and administrative advisers bound by confidentiality may receive data, as may authorities where the law requires it.
5. Transfers outside the European Economic Area
If a provider is based or hosts data outside the EEA, transfers only take place with the safeguards required by the GDPR (an adequacy decision, including the EU-US Data Privacy Framework, or standard contractual clauses).
6. How long we keep data
- Enquiries not followed by treatment: no longer than [12] months, then deleted.
- Clinical and administrative records: for the period required by the professional and legal rules that apply to the practitioner [specify per jurisdiction].
- Server logs: only as long as needed for security [state the host provider period].
7. Your rights
You can ask for access to your data, correction, erasure, restriction, portability, and object to processing based on legitimate interests. Where processing relies on consent, you can withdraw it at any time without affecting earlier processing. Write to info@psicote.com; we reply within one month.
You also have the right to lodge a complaint with the Italian Data Protection Authority, Garante per la protezione dei dati personali (garanteprivacy.it), or, if you live in the UK, the Information Commissioner's Office (ico.org.uk).
If you are outside the European Union
The controller is based in Italy, so the GDPR applies to this website. If you are in the United Kingdom, the UK GDPR gives you equivalent rights. If you are in the United States or elsewhere, you may have additional rights under local law; write to us and we will tell you how we can help. This page is a website notice. The disclosures that Vermont rules require a certified psychoanalyst to give to clients (qualifications, complaints procedure) are provided separately [confirm and link when available].
8. Children and adolescents
For children and adolescents, a request for treatment is made by the person with parental responsibility. We do not knowingly collect minors' data through the website without their involvement.
9. Security and confidentiality
We use appropriate technical and organisational measures. Everyone working with us is bound by professional secrecy and confidentiality.
10. Changes
This notice may be updated. The date above shows the latest version.
Cookie policy
Cookies are small files a website stores in your browser. Technical cookies make the site work. Profiling or non-anonymised analytics cookies require your consent.
- Profiling and marketing cookies: we do not use them.
- Analytics cookies: we do not use statistics tools [confirm].
- Technical cookies: the pages of this site do not set cookies [check after publishing with your browser developer tools].
Third-party services
- Google Fonts. Page fonts are loaded from Google's servers. Your browser sends Google your IP address and technical data to fetch the files. This is not a cookie but it is a data transfer, so we disclose it here. Google's notice: policies.google.com/privacy.
- Booking a session. The booking button leads to a page run by [provider name], which may use its own technical cookies and has its own notice.
- External links (professional bodies, associations, other sites) have their own policies.
Banner and consent
Because we do not use cookies that require consent, the site shows no cookie banner. If that changes, we will update this page and ask for consent before activating them.
Managing cookies
You can block or delete cookies in your browser settings.