Idevsa.com is a reading site, which is why this privacy policy holds few surprises: no accounts to create, no newsletter at launch, no advertising network recording which pages you open.
This privacy policy covers the small amount of information that does reach us, why, how long we hold it, and what you can ask us to do about it. It applies to the pages published at idevsaa.com.
Who we are
Idevsa.com is an independent guide to psychotherapy, not a clinic, a therapy platform or a referral service. Our about page explains more.
In this policy, “we”, “us” and “our” mean the owner and operator of Idevsa.com, who decides how the information below is handled. Reach us at hello@idevsaa.com or through our contact page.
What we collect
Server logs
The site is a static website built with Astro and served by a third-party web hosting provider and content delivery network. Like almost every web server, theirs logs each request: your IP address, your browser’s user agent string, the URL you asked for and a timestamp.
These logs exist so the site stays online and safe to use: they show whether pages are failing, whether traffic is abusive, and where a fault is coming from. We do not use them to build a profile of you or to work out who an individual reader is.
The contact form
Our contact form asks for your name, your email address and your message, plus a topic you pick from a short list so we can route it. It also has a consent checkbox and a hidden anti-spam field that people never see. Messages are passed to our inbox by a third-party form-processing service or email provider, and we use what you send only to reply.
If you email hello@idevsaa.com directly, we hold your message the same way, for the same purpose and the same length of time.
Please keep health details out of your message
Before you write to us: tell us which page you mean and what the problem is. You do not need to tell us anything about your own mental health, and we would rather you did not.
Information about a person’s health is treated as sensitive almost everywhere. The UK’s Information Commissioner’s Office lists data concerning health among the special categories needing extra protection, because misuse of it can create significant risks to a person’s rights and freedoms. California law also treats some personal information as sensitive and gives residents the right to limit its use and disclosure.
Our contact form is an ordinary email channel, not a clinical one, and it is not covered by the confidentiality rules that bind a licensed therapist. Because we cannot give anyone personal advice, details about your diagnosis, symptoms, medication or therapy history would not change our answer, and holding them would put you at more risk than leaving them out.
If you need support now rather than information, our crisis help page lists free, confidential helplines.
What we do not collect
- No accounts. There is nothing to sign up for, so there are no usernames, passwords or profiles.
- No analytics at launch. We do not run Google Analytics or any other measurement tool.
- No advertising or tracking pixels. No ad network, retargeting tag or social media pixel is embedded in these pages.
- No cookies set by this site. The site itself sets no cookies, which is why you see no cookie banner.
- No third-party fonts. Our fonts are self-hosted, so loading a page sends no request to Google Fonts.
- No sale or sharing for advertising. We do not sell personal information or share it for cross-context behavioral advertising.
If we ever add analytics, advertising or anything else that collects reader information, we will update this policy before it goes live.
Why we use your information
| What we use | Why | Legal basis under UK and EU GDPR |
|---|---|---|
| Server logs | Keeping the site available, diagnosing faults, blocking abuse | Our legitimate interest in running a secure, working website |
| Contact form entries and emails | Replying to you, and correcting errors you report | Our legitimate interest in answering people who write to us |
| Any of the above | Meeting a legal obligation or a lawful request | Compliance with a legal obligation |
We make no automated decisions about you and do not profile readers.
Who we share information with
We share as little as possible, with three kinds of recipient:
- Our hosting provider and content delivery network, which serves the pages and keeps the server logs described above.
- Our form-processing service or email provider, which delivers and stores your message.
- Authorities or legal advisers, if the law requires disclosure or we need to defend a legal claim.
Nobody else receives it. We do not pass information to data brokers, advertisers, therapists, clinics or therapy platforms.
International transfers
Our providers may store or process data on servers outside your country, including in the United States. Where information about people in the UK or the European Economic Area travels outside those areas, we rely on the transfer safeguards our providers have in place, such as approved standard contractual clauses. Ask us if you want to know which providers we use.
How long we keep things
Server logs are kept by our hosting provider for a limited period under their standard retention settings, then deleted. We do not archive them.
Messages are kept for as long as we need them to reply, and for up to 24 months afterwards so we can pick up a thread if you write again. After that they are deleted, unless the law requires us to keep them longer. If you want yours deleted sooner, say so.
How we protect information
Pages are served over HTTPS, so what you read travels encrypted between your browser and our host. Because the site is static, there is no database of readers to breach, and access to the inbox where messages arrive is restricted to those who reply to them.
No system is completely secure, so we hold as little as we can for as short a time as we can.
Your privacy rights
If you are in the UK or the EU/EEA
The ICO groups your rights under the UK GDPR as eight individual rights: to be informed, of access, to rectification, to erasure, to restrict processing, to data portability, to object, and rights related to automated decision-making and profiling. The EU GDPR gives the same set.
The European Commission states that an organization must respond without undue delay and at the latest within one month. You can also complain to your data protection authority: the ICO in the UK, or your national supervisory authority in the EU.
If you are in the United States
California’s privacy law gives residents the rights to know, delete, correct, opt out, limit and be treated equally: to know what is collected and why, to have it deleted or corrected, to opt out of its sale or sharing for cross-context behavioral advertising, to limit the use of sensitive personal information, and not to be treated worse for asking. Several other states have comparable laws.
The right to opt out needs no action here, since we neither sell nor share personal information, and we use anything sensitive you send only to reply. The other rights we honor on request.
How to ask
Email hello@idevsaa.com or use our contact page and tell us what you want done. We may ask a question or two to confirm the request comes from you, usually by replying to the address we already hold. There is no charge.
Children
Idevsa.com is written for adults aged 18 and over. It is not directed at children under 13, or under 16 in the EU and UK, and we do not knowingly collect information from them.
In the United States, the Children’s Online Privacy Protection Act applies to sites directed to children under 13, and to general-audience sites that know they are collecting personal information from children under 13. It requires notice to parents and, with limited exceptions, verifiable parental consent before that information is collected. If you believe a child has sent us personal information, email hello@idevsaa.com and we will delete it.
Links to other websites
Our guides link to organizations such as the American Psychological Association, the National Institute of Mental Health and the NHS. Once you follow a link you are on their site, under their privacy policy, and we have no control over what they collect. Our disclaimer says more about linking.
Changes to this policy
When this policy changes we will publish the new version here and change the “Last updated” date at the top. Where a change is significant, such as adding analytics or a mailing list, we will describe it plainly.
Contact us
Questions about this privacy policy, or a request about your information, go to hello@idevsaa.com or our contact page. Our terms of use cover the rules for using the site.