Idevsa.com is a reading site, which is why this privacy policy holds few surprises: no accounts to create, no newsletter at launch, no advertising network recording which pages you open.

This privacy policy covers the small amount of information that does reach us, why, how long we hold it, and what you can ask us to do about it. It applies to the pages published at idevsaa.com.

Who we are

Idevsa.com is an independent guide to psychotherapy, not a clinic, a therapy platform or a referral service. Our about page explains more.

In this policy, “we”, “us” and “our” mean the owner and operator of Idevsa.com, who decides how the information below is handled. Reach us at hello@idevsaa.com or through our contact page.

What we collect

Server logs

The site is a static website built with Astro and served by a third-party web hosting provider and content delivery network. Like almost every web server, theirs logs each request: your IP address, your browser’s user agent string, the URL you asked for and a timestamp.

These logs exist so the site stays online and safe to use: they show whether pages are failing, whether traffic is abusive, and where a fault is coming from. We do not use them to build a profile of you or to work out who an individual reader is.

The contact form

Our contact form asks for your name, your email address and your message, plus a topic you pick from a short list so we can route it. It also has a consent checkbox and a hidden anti-spam field that people never see. Messages are passed to our inbox by a third-party form-processing service or email provider, and we use what you send only to reply.

If you email hello@idevsaa.com directly, we hold your message the same way, for the same purpose and the same length of time.

Please keep health details out of your message

Before you write to us: tell us which page you mean and what the problem is. You do not need to tell us anything about your own mental health, and we would rather you did not.

Information about a person’s health is treated as sensitive almost everywhere. The UK’s Information Commissioner’s Office lists data concerning health among the special categories needing extra protection, because misuse of it can create significant risks to a person’s rights and freedoms. California law also treats some personal information as sensitive and gives residents the right to limit its use and disclosure.

Our contact form is an ordinary email channel, not a clinical one, and it is not covered by the confidentiality rules that bind a licensed therapist. Because we cannot give anyone personal advice, details about your diagnosis, symptoms, medication or therapy history would not change our answer, and holding them would put you at more risk than leaving them out.

If you need support now rather than information, our crisis help page lists free, confidential helplines.

What we do not collect

  • No accounts. There is nothing to sign up for, so there are no usernames, passwords or profiles.
  • No analytics at launch. We do not run Google Analytics or any other measurement tool.
  • No advertising or tracking pixels. No ad network, retargeting tag or social media pixel is embedded in these pages.
  • No cookies set by this site. The site itself sets no cookies, which is why you see no cookie banner.
  • No third-party fonts. Our fonts are self-hosted, so loading a page sends no request to Google Fonts.
  • No sale or sharing for advertising. We do not sell personal information or share it for cross-context behavioral advertising.

If we ever add analytics, advertising or anything else that collects reader information, we will update this policy before it goes live.

Why we use your information

What we useWhyLegal basis under UK and EU GDPR
Server logsKeeping the site available, diagnosing faults, blocking abuseOur legitimate interest in running a secure, working website
Contact form entries and emailsReplying to you, and correcting errors you reportOur legitimate interest in answering people who write to us
Any of the aboveMeeting a legal obligation or a lawful requestCompliance with a legal obligation

We make no automated decisions about you and do not profile readers.

Who we share information with

We share as little as possible, with three kinds of recipient:

  1. Our hosting provider and content delivery network, which serves the pages and keeps the server logs described above.
  2. Our form-processing service or email provider, which delivers and stores your message.
  3. Authorities or legal advisers, if the law requires disclosure or we need to defend a legal claim.

Nobody else receives it. We do not pass information to data brokers, advertisers, therapists, clinics or therapy platforms.

International transfers

Our providers may store or process data on servers outside your country, including in the United States. Where information about people in the UK or the European Economic Area travels outside those areas, we rely on the transfer safeguards our providers have in place, such as approved standard contractual clauses. Ask us if you want to know which providers we use.

How long we keep things

Server logs are kept by our hosting provider for a limited period under their standard retention settings, then deleted. We do not archive them.

Messages are kept for as long as we need them to reply, and for up to 24 months afterwards so we can pick up a thread if you write again. After that they are deleted, unless the law requires us to keep them longer. If you want yours deleted sooner, say so.

How we protect information

Pages are served over HTTPS, so what you read travels encrypted between your browser and our host. Because the site is static, there is no database of readers to breach, and access to the inbox where messages arrive is restricted to those who reply to them.

No system is completely secure, so we hold as little as we can for as short a time as we can.

Your privacy rights

If you are in the UK or the EU/EEA

The ICO groups your rights under the UK GDPR as eight individual rights: to be informed, of access, to rectification, to erasure, to restrict processing, to data portability, to object, and rights related to automated decision-making and profiling. The EU GDPR gives the same set.

The European Commission states that an organization must respond without undue delay and at the latest within one month. You can also complain to your data protection authority: the ICO in the UK, or your national supervisory authority in the EU.

If you are in the United States

California’s privacy law gives residents the rights to know, delete, correct, opt out, limit and be treated equally: to know what is collected and why, to have it deleted or corrected, to opt out of its sale or sharing for cross-context behavioral advertising, to limit the use of sensitive personal information, and not to be treated worse for asking. Several other states have comparable laws.

The right to opt out needs no action here, since we neither sell nor share personal information, and we use anything sensitive you send only to reply. The other rights we honor on request.

How to ask

Email hello@idevsaa.com or use our contact page and tell us what you want done. We may ask a question or two to confirm the request comes from you, usually by replying to the address we already hold. There is no charge.

Children

Idevsa.com is written for adults aged 18 and over. It is not directed at children under 13, or under 16 in the EU and UK, and we do not knowingly collect information from them.

In the United States, the Children’s Online Privacy Protection Act applies to sites directed to children under 13, and to general-audience sites that know they are collecting personal information from children under 13. It requires notice to parents and, with limited exceptions, verifiable parental consent before that information is collected. If you believe a child has sent us personal information, email hello@idevsaa.com and we will delete it.

Our guides link to organizations such as the American Psychological Association, the National Institute of Mental Health and the NHS. Once you follow a link you are on their site, under their privacy policy, and we have no control over what they collect. Our disclaimer says more about linking.

Changes to this policy

When this policy changes we will publish the new version here and change the “Last updated” date at the top. Where a change is significant, such as adding analytics or a mailing list, we will describe it plainly.

Contact us

Questions about this privacy policy, or a request about your information, go to hello@idevsaa.com or our contact page. Our terms of use cover the rules for using the site.

Sources

  1. A guide to individual rightsInformation Commissioner's Office
  2. Information for individualsEuropean Commission
  3. What is special category data?Information Commissioner's Office
  4. Frequently Asked Questions (FAQs)California Privacy Protection Agency
  5. Complying with COPPA: Frequently Asked QuestionsFederal Trade Commission

Try “CBT”, “first session”, “cost” or “online therapy”.

    In crisis? Find a crisis line · In the US, call or text 988