Last updated: 10 October 2026
At Art of Mind we respect your privacy. This policy explains in plain language which personal data we process, why, how long we keep it and what rights you have under the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and Greek Law 4624/2019. Our services are provided from Greece, so Greek and EU data-protection law applies wherever you are.
1. Who is responsible for your data
The data controller is psychotherapist Matina Ladikou, founder of Art of Mind – Psychotherapy Centre, Korinthou 288, 262 22 Patras, Greece.
Email: [email protected] · Phone (questions only): +30 2611 180005
2. What data we process and why
When you send us an enquiry in English
Our English enquiry form asks for your name, email address, country, the type of session you are interested in (individual or couples) and your message. When you press “Send”, the form is emailed to us at [email protected] and you receive an automatic confirmation email. The form does not store your enquiry on the website; we keep it only in our mailbox, for as long as we need it to reply and arrange your sessions.
Legal basis: the steps you ask us to take before a possible agreement (Article 6(1)(b) GDPR) and our legitimate interest in answering questions (Article 6(1)(f) GDPR). If your message says anything about your health or wellbeing, we process that information only with the explicit consent you give with the consent box on the form (Article 9(2)(a) GDPR). You can withdraw that consent at any time by emailing us; withdrawal does not affect what was done before it. Please keep your message short and do not include detailed health information: we will talk about what brings you to therapy in the first session.
When you email or call us
Your name, contact details and whatever you write or tell us, so that we can reply. Legal basis: Article 6(1)(b) and (f) GDPR, and Article 9(2)(a) GDPR for any health information you choose to share.
When you start sessions
Once we have agreed a therapist, day and time with you by email, we record your identity and contact details, the service, the date and time of each session and your session and package history, so that we can provide the sessions. Legal basis: performance of a contract (Article 6(1)(b) GDPR).
Payments
Payments are made online and card details are processed directly by Stripe; we never see or store your card number. If you pay with Apple Pay or Google Pay, Apple or Google process the payment details under their own terms. Stripe may use its own strictly necessary cookies on the payment page for payment security and fraud prevention. Legal basis: performance of a contract (Article 6(1)(b) GDPR).
Receipts and Greek tax reporting (myDATA)
For every payment we issue an electronic receipt through a certified Greek e-invoicing provider (B Binary S.A. – mono invoicing / SimpleInvoicing, VAT no. 802062210). It is sent to the Greek tax authority (AADE, myDATA) and emailed to you. The receipt contains only what tax law requires (for example your name, the service, the amount and VAT) and nothing about your health. Legal basis: compliance with a legal obligation (Article 6(1)(c) GDPR). Receipts are kept for as long as tax law requires.
During therapy
Your therapist may keep clinical notes. These are health data, a special category of data (Article 9 GDPR). They are processed only to provide and continue your therapy, by the therapist from our centre who works with you, who is bound by professional confidentiality (Article 9(2)(h) and 9(3) GDPR). We do not share them with anyone without your explicit consent, unless the law requires it.
When you visit the website
Technical data needed to run and protect the website (for example your IP address in server logs). Visitor statistics (Google Analytics), advertising measurement (Google Ads) and page-usage analysis (Microsoft Clarity) run only with your cookie consent (Article 6(1)(a) GDPR and Article 4(5) of Greek Law 3471/2006). We do not pass your name, email, phone number or health information to these providers, and we do not build advertising audiences from the health topics you read about. You can withdraw consent at any time from the cookie settings. See our cookie policy.
3. Online sessions via Google Meet
Online sessions take place by video call on Google Meet, a Google service. To connect the call, Google processes technical call data under its own terms and privacy policy. Sessions are not recorded and are covered by the same professional confidentiality as an in-person session. For extra privacy we suggest joining from a quiet, private room, with headphones, on your own device and connection.
4. Who else has access to data
We do not sell or rent personal data. We use service providers only as far as needed to run our services:
- website hosting (Hostinger);
- email: our mailbox and email delivery provider, which carry enquiry-form emails, confirmations and our correspondence with you;
- our booking system at sessions.artofmind.gr, if you book or manage sessions there;
- payments (Stripe);
- receipts (the e-invoicing provider above) and their transmission to AADE (myDATA);
- video calls (Google Meet);
- only with your cookie consent: visitor statistics (Google Analytics) and advertising measurement (Google Ads), by Google, and page-usage analysis (Microsoft Clarity), by Microsoft;
- live chat on the website (Tawk.to), which loads only with your consent to marketing cookies and receives your messages only if you choose to write to us there;
- our website technical partner, for maintenance and to check that the website and its emails work correctly;
- our accountant, for our tax obligations, and public authorities where the law requires it.
Some providers (for example Google, Microsoft and Stripe) may process data outside the European Economic Area. Such transfers rely on the safeguards provided by the GDPR, such as standard contractual clauses or an adequacy decision, under the providers’ terms.
5. How long we keep data
- Enquiries and correspondence: as long as needed to reply and handle your request.
- Sessions and packages: for as long as we work together and for a reasonable period afterwards, for questions, requests or legal obligations.
- Tax documents: as long as Greek tax law requires.
- Clinical notes: as long as needed for the continuity of your therapy and as long as applicable obligations require.
After that, data is deleted or anonymised.
6. How we protect data
We take reasonable technical and organisational measures, such as limiting access to the people who need it and protecting accounts with passwords. No method of transmission or storage over the internet is completely secure, which is why we collect only the data we need.
7. Your rights
You have the right to access, correct and erase your data, to restrict or object to its processing and to data portability, and to withdraw your consent at any time without affecting processing carried out before withdrawal. Some data (for example tax records) may have to be kept even if you ask for erasure.
To exercise your rights, email [email protected]. We will reply within one month, as the GDPR requires. You also have the right to complain to the Greek supervisory authority, the Hellenic Data Protection Authority, Kifisias 1–3, 115 23 Athens, www.dpa.gr, or to the data-protection authority of the country where you live or work.
8. Under-18s
For anyone under 18, contact and arrangements are made by a parent or guardian, with their consent. If you are the parent of a teenager, please contact the centre first.
9. Changes to this policy
If the way we process data changes, we will update this page and its “last updated” date. See also our terms of use and cookie policy.