Privacy notice
Privacy and Cookie Notice
This notice describes the current Innerblade website implementation. The public contact form is for a brief first contact, not for medical records, crisis communication, or clinical case documentation.
- Data controller
- KERTÉSZ FERENC-ÁLPÁR – Cabinet individual de psihologie
- Privacy contact
- kertesz.f.alpar@innerblade.com
Analytics controls
You can change your analytics choice at any time. Turning analytics off stops future visitor beacons and removes the optional analytics identity cookies.
Last updated: 21 July 2026
1. Data we process
The contact form asks for your name, email address, preferred language, a short message, the site language, and confirmation that you accepted this notice. The application sends these fields server-side through the configured SMTP service to the controller's mailbox. Innerblade does not write contact messages to its application database.
The application does not intentionally put message content in analytics, browser logs, URLs, or query strings. Hosting and mail providers may process ordinary network and operational metadata needed to deliver the page and email.
- Spam protection uses a hidden honeypot and short-lived rate limits. Raw IP and email values are converted server-side to keyed hashes for process-local rate-limit buckets; those buckets expire after 10 minutes.
- Cookieless analytics may record a query-free public path, site language, date, host-only referrer, broad browser, operating-system and device categories, country, region and city supplied by Vercel, consent mode, and a daily server-side hash derived from IP address and user agent. Raw IP addresses are not stored in the analytics table.
- If you opt in to analytics cookies, server-hashed returning-visitor and session identifiers are also stored. Journal text, private vault content, contact messages, diagnoses, and medical documents are not analytics fields.
2. Purposes and legal bases
Contact data is used only to read and answer your request and, where appropriate, arrange an introductory conversation. The legal basis is your consent under GDPR Article 6(1)(a). You are asked not to send health data. If you nevertheless choose to include special-category information, the required explicit-consent statement covers only receiving and handling it for this limited contact purpose under Article 9(2)(a).
Short-lived anti-spam controls and cookieless aggregate traffic measurement support site security, reliability, and understanding of public-page use. The controller relies on legitimate interests under Article 6(1)(f), balanced against the minimized and pseudonymized data. Optional returning-visitor and session cookies are used only with consent under Article 6(1)(a).
The website does not use contact data for advertising, sell it, or make automated decisions about you.
3. Processors and international transfers
Vercel hosts and delivers the Next.js application and therefore processes requests and operational metadata. Hostinger provides the configured SMTP and mailbox service and receives contact-form email content. If persistent analytics storage is configured, a PostgreSQL hosting provider selected in the deployment account processes the minimized visitor-event rows; the repository does not expose that provider's identity, so it is disclosed here as a recipient category rather than guessed.
These providers may use subprocessors or process data outside the European Economic Area. Where a transfer requires safeguards, it is governed by the provider's data-processing terms and mechanisms such as the European Commission's Standard Contractual Clauses. Current provider terms are linked below. You may ask the controller for the current processor list and relevant safeguard information.
4. Retention
Process-local anti-spam buckets expire after 10 minutes. Stored visitor-event rows are pruned after 180 days. The privacy-choice cookie is kept for up to 180 days; an opt-in visitor cookie for up to 395 days; and an opt-in session cookie for up to 30 minutes after its latest refresh.
The application keeps no database copy of contact messages. Messages remain in the configured Hostinger mailbox until the controller deletes them when they are no longer needed for the contact exchange or related legal obligations. The codebase does not impose an automated mailbox deletion period. Provider security and operational logs follow the retention rules of the applicable hosting or mail plan.
5. Your rights
Depending on the circumstances, you may request access, correction, deletion, restriction, or portability of your personal data, and may object to processing based on legitimate interests. You may withdraw consent at any time by email; withdrawal does not affect processing that was lawful before withdrawal. Analytics consent can also be changed with the settings control on this page.
Send requests to the privacy contact shown above. You also have the right to lodge a complaint with Romania's National Supervisory Authority for Personal Data Processing (ANSPDCP).
6. Cookies and analytics choices
ib_privacy_v1 stores one of three choices: analytics cookies accepted, cookieless measurement only, or analytics off. It is a first-party preference cookie. ib_aid and ib_sid are first-party, HttpOnly identifiers created only after analytics-cookie consent; their values are hashed server-side before analytics storage.
Cookieless only does not create analytics identity cookies. Analytics off prevents the browser visitor beacon and deletes ib_aid and ib_sid. No third-party analytics scripts are loaded in the current implementation.
7. Security, minors, and first contact
The site uses encrypted HTTPS transport and server-side validation, but ordinary web forms and email cannot guarantee absolute confidentiality. Do not send diagnoses, medical records, third-party names, or other highly sensitive details. A minor should make contact only with a parent or legal guardian involved.
Do not use the form for emergencies or crisis messages. The first message does not create a psychologist-client relationship. If you believe someone is in immediate danger, contact the local emergency service or an appropriate crisis service instead.
This is an implementation-based privacy notice, not a legal certification. Independent legal review is recommended before expanding advertising, clinical intake, or cross-border processing.