Privacy Policy
Information under Art. 13 and 14 GDPR · Last updated: August 2026
This page is a translation for convenience — the German version is the original.
1. In short
To suggest suitable psychotherapists to you, we need information about your situation — for example your concern, your level of distress, and your preferences. This is health data within the meaning of Art. 9 GDPR — data deserving special protection. We process it only with your explicit consent, and solely to calculate suitable suggestions for you. Only once you decide yourself to contact a specific person or book an appointment do your contact details — and, depending on how you get in touch, your questionnaire answers too — become accessible to that one person. Never to all suggested therapists at once, and never without you taking the first step yourself.
2. Controller
- office@mendsch.at
- Data protection officer
- Martin Baumgartner, office@mendsch.at
Full details about the operator are in the Imprint.
3. Questionnaire and therapy suggestions
What data: your answers in the questionnaire — such as desired therapy format and setting, postal code and radius, languages, preferences regarding the therapist's personality and way of working, information about your level of distress, your concern, prior experience with therapy, medication, safety/crisis questions, urgency, budget and reimbursement, as well as your free-text description. Information about you personally (age, gender, cultural background) is optional.
Purpose: to calculate a matching profile from this and suggest a list of suitable psychotherapists to you. Part of this calculation — mapping your free-text input to thematic focus areas — is supported by a language model (see section 9).
Legal basis: your explicit consent to the processing of health data (Art. 9(2)(a) in conjunction with Art. 6(1)(a) GDPR). We store the time of your consent for evidentiary purposes. You can withdraw your consent at any time with effect for the future — informally, to office@mendsch.at.
Completing the questionnaire is voluntary; however, without this information we cannot make suggestions to you.
4. Special category: health data
Information about your mental state, your concern, your medication, or safety/crisis questions is a special category of personal data under Art. 9 GDPR. We treat it with corresponding care:
- It is processed only with your explicit consent (Art. 9(2)(a) GDPR), which you give when submitting the questionnaire and can withdraw at any time (section 3).
- Your answers are evaluated to calculate your suggestions, but are not passed on to therapists as long as you don't contact anyone.
- If you book an appointment with a psychotherapist, the answers relevant to their professional assessment — such as your concern, level of distress, medication, and safety questions — become accessible to that one person you chose, so they can assess whether they can help you appropriately (details on this, and on the direct-inquiry path that differs from it, are in section 5). This is already part of the consent from section 3 and is not governed by a separate checkbox per request — we point it out explicitly again here so you're aware of it when getting in touch. Psychotherapists are themselves bound by the statutory duty of confidentiality under the Psychotherapiegesetz (Austrian Psychotherapy Act).
- Transmission is encrypted via HTTPS, and access to this data is limited to the people and systems that need it to do their job. We continually review additional technical safeguards for particularly sensitive fields.
- Deletion happens automatically according to the periods listed in section 10, and at any time on request to office@mendsch.at.
5. Getting in touch and booking an appointment
There are two ways you can get in touch with a psychotherapist — they differ in what data is transmitted:
Appointment request for a published open slot: You book an open slot the therapist has listed. In doing so, your first and last name, your email address, optionally your phone number, your message, and the questionnaire answers relevant to assessment described in section 4 are shown in the therapist's dashboard. The therapist only receives an email notification with your name, the appointment time, and a link to their dashboard — the content of your message and your questionnaire answers are not transmitted by email and are therefore not accessible to our email provider, Brevo (see section 9).
Direct inquiry to a psychotherapist without a bookable slot: Some psychotherapists don't (yet) offer online appointment management. In this case we send your inquiry to the therapist by email; this transmits your name, your email address, optionally your phone number, and the wording of your message — your questionnaire answers are not used for this. Because the message text is part of this email, it is in this case also accessible to our email provider, Brevo, which sends the message on a purely technical basis (see section 9).
In both cases the legal basis is the performance of pre-contractual measures at your request (Art. 6(1)(b) GDPR) as well as — insofar as your information contains health data — your consent (Art. 9(2)(a) GDPR). From the point of contact onward, the respective psychotherapist is independently responsible for further processing; for transmitting your inquiry and storing it until deletion, we are jointly responsible together with them (Art. 26 GDPR) — we handle the technology, encrypted transmission, and deletion according to the periods listed in section 10. You can exercise your rights under Art. 15–22 GDPR against either party; the central point of contact remains office@mendsch.at.
After the appointment, we ask you and the therapist for brief feedback. Participation is voluntary; the feedback is collected via an access link that contains no real names, and serves to improve our suggestions (Art. 6(1)(f) GDPR).
6. Accounts for psychotherapists
To register as a psychotherapist, we process master data (name, contact details, practice addresses), professional information (entry in the register of psychotherapists, methods, focus areas, languages, insurance and pricing details), profile content and images, open appointment slots, and login data. Login codes (email-based login) are not stored in plain text, but as a hash value. The legal basis is the usage agreement (Art. 6(1)(b) GDPR); for checking professional accreditation, additionally our legitimate interest in a trustworthy platform (Art. 6(1)(f) GDPR). Profile information is displayed publicly on mendsch; practice addresses are converted server-side into coordinates once, for location search (see section 9).
7. Newsletter
If you sign up for updates, we process your email address on the basis of your consent (Art. 6(1)(a) GDPR) via our email provider, Brevo (see section 9). You can unsubscribe again at any time via the link in every email, or by messaging us.
8. Server logs, cookies, and reach measurement
When you visit the website, technical log data is generated (IP address, time, requested resource, browser type). We ourselves do not store your IP address in our database — it is used only temporarily, in our server's working memory, to detect abuse and excessive numbers of requests (rate limiting). In addition, our hosting providers Vercel (frontend) and Railway (server and database) generate the usual technical access logs, which they delete after their own, short retention periods. The legal basis is our legitimate interest in the secure and stable operation of the platform (Art. 6(1)(f) GDPR).
Technically necessary cookies — for example for logging into the therapist and admin areas — are required for the site to operate and do not need consent. Fonts are served from our own server; there is no connection to Google Fonts.
Google Analytics and Google Ads: In addition, we use the Google tag (gtag.js) from Google Ireland Limited to measure how our site is found and used, and to evaluate the effectiveness of our ads. This sets cookies and transmits a shortened IP address as well as device and browser information to Google. This happens only with your consent (Art. 6(1)(a) GDPR in conjunction with § 165(3) TKG 2021), which you can give or decline on your first visit via our cookie notice. Until you consent, the tag is set via Google's "Consent Mode" so that it sets no cookies and stores no identifiers. You can change or withdraw your decision at any time via "Cookie settings" in the page footer; the withdrawal takes effect for the future.
This consent is independent of the consent to processing your health data (section 3): it concerns only cookies and reach measurement. Your questionnaire answers are not transmitted to Google — neither content nor results, whether you consent or decline. If you decline, you can use mendsch fully and without restriction.
Questionnaire drop-off statistics: To identify where the questionnaire is too long, too difficult, or unclear, we count how many people reach a given question and how long they spend there on average. Only a counter value per question and day is recorded — no IP address, no identifier, no cookie, and none of your answers. No history of individual sessions is created and there is no link to a person; the analysis is purely statistical and allows no inference about you. This data is therefore not personal data and is not transmitted to Google or other third parties — we collect it on our own servers. We disclose this here anyway because we think it's fair to be transparent about it.
For the radius map in the questionnaire, we load map tiles directly from CARTO (basemaps.cartocdn.com) based on OpenStreetMap data. In doing so, your IP address is transmitted to CARTO; no cookies are set for this. The legal basis here too is our legitimate interest in a working map display (Art. 6(1)(f) GDPR).
As long as the questionnaire hasn't been submitted yet, we store your answers so far in your browser's local storage ("localStorage"), so you can continue later on the same device. This data stays on your device and is not transmitted to us — only once you submit the questionnaire do we receive your information. You can delete it at any time via "Discard saved answers" on the questionnaire's start page, or via your browser settings.
9. Recipients and processors
We only pass on data to the extent necessary to operate the platform. With all service providers who process personal data on our behalf, data processing agreements under Art. 28 GDPR are in place, or will be concluded before launch.
- Psychotherapists you choose — receive your inquiry as soon as you contact them, to the extent described in section 5 (independently responsible, not a data processor).
- Vercel Inc. (USA, EU Standard Contractual Clauses) — hosting of our website, server location Frankfurt am Main (Germany, EU).
- Railway Corporation (USA, EU Standard Contractual Clauses) — hosting of our application server and our PostgreSQL database, data center in the Netherlands (EU).
- Cloudflare, Inc. (USA, EU Standard Contractual Clauses) — object storage (R2) for therapists' profile images and verification documents; our storage bucket is restricted to the EU jurisdiction, and the data does not technically leave the EU.
- Brevo (Sendinblue SAS / Brevo SAS, France) — sending of system and newsletter emails. For appointment requests (section 5), Brevo only receives a notification without message content; for direct inquiries without a bookable slot, the wording of your message is part of the email sent.
- Mistral AI SAS (France) — AI-assisted evaluation of your free-text input in the questionnaire, to better map thematic focus areas. Processing takes place in the EU, your information is not used to train models, and your name or email address are not transmitted for this.
- Google Ireland Limited (Ireland) — reach measurement (Google Analytics) and evaluation of our ads (Google Ads), only with your consent via the cookie notice (see section 8). What's transmitted is a shortened IP address plus device, browser, and visited-page information — but not your questionnaire answers, your name, or your email address.
- Map display (CARTO, based on OpenStreetMap data) — to display the radius search in the questionnaire, map tiles are loaded; in doing so, your IP address is transmitted to the map service.
- Address suggestions (Photon / Komoot GmbH, Germany) — while you enter an address in the questionnaire, we query suggestions from this service server-side.
- Geocoding (Nominatim, OpenStreetMap Foundation) — when a therapist adds a practice address, we convert it into coordinates server-side, once; in doing so, it is not your request but only our server's request that is transmitted to this service.
International transfer: Vercel, Railway, and Cloudflare are headquartered in the USA; however, processing of your data takes place within the EU for all three (see above), additionally safeguarded by EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). Brevo and Mistral AI are companies headquartered and processing data in France (EU).
For Google, on the other hand, a transfer to the USA is not excluded: while the contracting party is Google Ireland Limited (Ireland), data can be transmitted to and processed by Google LLC in the USA. This is based on the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework, under which Google LLC is certified (Art. 45 GDPR), supplemented by EU Standard Contractual Clauses. Despite this decision, it cannot be fully ruled out that US authorities may access this data, and that the same legal remedies available within the EU may not be available to you against that. This transfer only takes place if you consent via the cookie notice — if you decline, it does not.
10. Retention period
We store personal data only for as long as necessary for the respective purpose:
- Appointment requests and bookings: first and last name, email address, and phone number are deleted automatically — at the latest 48 hours after the request if the therapist doesn't respond; around 24 hours after the appointment itself in case of a confirmation; within around 24 hours in case of a cancellation or withdrawal. Deletion is carried out by an automated process that runs hourly.
- Direct inquiries without a bookable slot: name, email address, phone number, and message are deleted automatically 90 days after receipt.
- Questionnaire answers: once your contact details have been deleted as described above, these remain only without your name, email address, or phone number, and serve to improve our suggestions (Art. 6(1)(f) GDPR). If you never submitted an inquiry, no link between your answers and your identity is created in the first place.
- Therapist accounts: are stored for as long as the account exists, and removed after its deletion — less any statutory retention obligations (e.g. seven years for invoicing records under § 132 BAO, once and if we issue invoices).
- Server logs: short-term, according to our hosting providers' standard periods (see section 8).
- Reach measurement (only with consent): cookies set by Google expire after 24 months at the latest; usage data stored at Google is deleted according to the periods set there. We store your decision in the cookie notice itself in your browser's local storage, so we don't ask you again on every visit — it stays on your device.
- Questionnaire drop-off statistics: purely statistical counter values with no link to a person (see section 8); these are kept permanently, since no person can be derived from them.
11. Automated suggestions
The ranking of suggested psychotherapists is calculated automatically. It's a fixed weighting method — the weights are set in code and don't learn from your data — supplemented by a language-model-assisted layer that maps your free-text input to additional focus areas (see section 9). These suggestions are non-binding: there is no automated decision within the meaning of Art. 22 GDPR that has a legal effect on you.
You alone decide which therapists you contact, and can request a manual review of the suggestions or object to this processing at any time. To do so, contact office@mendsch.at.
12. Your rights
You have the rights at any time to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21 GDPR). You can withdraw any consent given at any time with effect for the future, without affecting the lawfulness of processing carried out before the withdrawal. Simply contact office@mendsch.at.
If you believe we are not processing your data lawfully, you can lodge a complaint with the supervisory authority: Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at, www.dsb.gv.at.
13. Data security
Your data is transmitted encrypted via HTTPS. Access to personal data within our systems is limited to the people who need it to do their job; login codes are not stored in plain text but as a hash value. Contact details are removed automatically once the respective process concludes (see section 10). There is currently no additional encryption of individual database fields; we continually review whether and where further technical safeguards make sense.
14. Changes to this policy
Since mendsch is still under development, this policy is continually expanded and will be replaced with a reviewed version before public launch. The version published on this page applies at any given time.
We're happy to answer questions about privacy — write to us at office@mendsch.at or via the contact page.