This Privacy Policy explains how personal data is processed in connection with the professional psychology services provided by the Iunia Popescu psychology practice and with the operation of this website. It is intended to provide clear information under Regulation (EU) 2016/679 (the “GDPR”), applicable Romanian law and the professional rules governing psychologists in Romania.
At this stage, the public booking form is limited to the free introductory chat. Contact and scheduling data submitted for that purpose are processed to respond to your request and organise the introductory discussion. Payment data for paid clinical sessions are not collected through the website until those services are activated.
Privacy in a psychological setting is both a legal obligation and an essential condition of the professional relationship. Data is collected proportionately, used only for defined purposes and protected according to its sensitivity. This policy does not replace the specific information, consent or professional-service documents that may be supplied before an assessment, counselling process or other regulated service.
1. Scope, roles and responsibility
The Iunia Popescu psychology practice acts as data controller for information processed in the establishment and management of the professional relationship, including enquiries, appointments, assessment or counselling records, professional notes, correspondence and legally required administrative documents. The practice determines why and how this information is processed in accordance with professional independence, applicable law and the rules of the Romanian College of Psychologists.
The website was developed and is technically maintained by Empire Global Solutions SRL / EmpireX. Depending on the specific operation, the technical provider may act as a processor under the practice’s documented instructions or as an independent controller for strictly limited data connected with its own security, legal or operational obligations. Technical questions may be sent to operations@empirex.tech. Formal legal correspondence concerning the project may be sent to contact@avocatmariavasii.ro.
This policy applies to website visitors, persons requesting information or appointments, clients and, where relevant, parents, legal representatives or other persons involved in a professional service. Third-party websites and platforms are governed by their own privacy notices.
2. Categories and sources of personal data
2.1 Categories of data
- Identity and contact data: name, age or date of birth where relevant, email address, telephone number, city or country of residence and preferred means of communication.
- Appointment and administrative data: requested service (including the free introductory chat when that is the only option available), availability, appointment history, attendance, professional agreements, invoices and payment status when applicable, and necessary correspondence.
- Professional and session data: information disclosed during intake, counselling or assessment, personal history, family and social context, symptoms, observations, test results, professional conclusions and notes. Such information may constitute health data or other special-category data under Article 9 GDPR.
- Communication and consent records: messages submitted through the site or by email, requests, complaints, consent choices, withdrawals and evidence that required notices were provided.
- Technical and security data: IP address, approximate device and browser information, timestamps, requested pages, error and security logs, and cookie or analytics identifiers where the relevant technology is enabled.
2.2 Sources
Data is usually obtained directly from you through the website, email, telephone, appointment communications, professional forms and sessions. Where appropriate and lawful, information may also be supplied by a parent or legal representative, a person authorised by you, another professional or an institution involved in the requested service. Technical data is generated automatically by the website, hosting infrastructure and security systems. You should provide third-party information only when you are entitled to do so and when it is relevant to the professional context.
3. Purposes and GDPR legal bases
Processing is carried out only where a valid legal basis applies. Depending on the context, the practice may process data:
- to answer enquiries, assess whether a requested service can be provided, arrange appointments and take steps at your request before establishing a professional relationship — Article 6(1)(b) GDPR;
- to establish and perform the professional or contractual relationship, deliver agreed services, communicate about sessions and manage related administration — Article 6(1)(b) GDPR;
- to comply with accounting, tax, professional-record, safeguarding, reporting or other statutory obligations — Article 6(1)(c) GDPR;
- to protect the website, prevent abuse, maintain evidence of communications, establish or defend legal claims and ensure proportionate business continuity — Article 6(1)(f) GDPR, based on legitimate interests balanced against your rights;
- for optional, non-essential analytics or similar technologies — Article 6(1)(a) GDPR, based on consent that may be refused or withdrawn without affecting the core service.
Where professional information includes health data or other special-category data, processing also relies on the applicable condition under Article 9 GDPR and Romanian law, including explicit consent where required, the provision or management of health-related or professional services by a person subject to confidentiality, or the establishment, exercise or defence of legal claims. The precise basis depends on the service and circumstances; consent is not presented as the legal basis where processing is in fact required by law or necessary for the professional relationship.
4. Professional secrecy, ethics and crisis situations
Information learned in the course of psychological services is protected by professional secrecy, applicable Romanian legislation and the ethical and professional standards of the Romanian College of Psychologists. Access is limited to the psychologist and, only where necessary and lawfully authorised, to persons bound by confidentiality. Professional information is not disclosed merely because it may be of interest to a family member, employer, school or other third party.
Confidentiality is not absolute. Disclosure may be required or permitted in narrowly defined circumstances, including a serious and imminent risk to your life or safety or that of another person, suspected abuse or neglect where a reporting duty applies, a binding request from a competent authority, or another clear legal or ethical obligation. Any disclosure is assessed carefully and, where possible, limited to information necessary for the protective or legal purpose.
This practice is not an emergency service. If you are in immediate danger, call 112. In Romania, for suicidal crisis support you may also consult TelVerde Antisuicide 0800 801 200 (see hours on antisuicid.ro). From the diaspora, use your local emergency number.
5. Recipients, processors and international transfers
Personal data is not sold. It may be made available, on a need-to-know basis, to providers supporting hosting, website security, professional email, appointment administration, secure video communications, accounting or legal assistance. Each provider receives only the data needed for its task and is required, as applicable, to follow documented instructions, preserve confidentiality and implement appropriate security. Analytics providers receive data only when optional analytics have been enabled with valid consent.
Information may also be disclosed to public authorities, courts, professional bodies or emergency services where required by law or necessary to protect vital interests or legal rights. A video or communications platform may process account and connection metadata under its own terms; the applicable platform will be identified where this is material to the service.
Providers are selected, where reasonably possible, within Romania or the European Economic Area (“EEA”). If data is transferred outside the EEA, the transfer will rely on a GDPR mechanism such as an adequacy decision, European Commission Standard Contractual Clauses supplemented where necessary by technical and organisational measures, or another lawful derogation for a specific situation. Information about the relevant safeguards may be requested, subject to protection of confidential and security-sensitive details.
6. Indicative retention and security
6.1 Retention
Retention periods depend on the nature of the record, the professional service and applicable limitation or statutory periods. As an indicative framework, unanswered or non-material enquiries are generally retained for up to 12 months; appointment and routine administrative correspondence for approximately 2–3 years; professional files and records for the period required by professional rules and ordinarily up to 5 years after the end of the relationship, unless a longer period is justified or legally required; and accounting and tax documents for the statutory period, commonly 5–10 years depending on document type and the law then in force. Security logs are usually retained for a shorter period, commonly between 30 days and 12 months, unless needed to investigate an incident.
These periods are indicative rather than an undertaking to retain every record for the maximum duration. Data may be deleted or irreversibly anonymised earlier when no longer necessary, or retained longer where required by law, an unresolved complaint, a safeguarding concern, or the establishment, exercise or defence of legal claims.
6.2 Security
Appropriate technical and organisational measures are used in light of the sensitivity and risk of the processing. These may include access controls, strong authentication, encrypted transmission, secure and updated systems, minimisation of collected data, confidentiality commitments, backups, logging, provider review and incident-response procedures. No internet or storage system can be guaranteed to be entirely risk-free; suspected personal-data incidents are assessed and, where the GDPR thresholds are met, notified to the supervisory authority and affected persons within the applicable time limits.
7. Your data-protection rights
Subject to the conditions and exceptions in the GDPR, you may request access to your personal data, correction of inaccurate or incomplete data, erasure, restriction of processing, data portability and objection to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time for the future. You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
Some requests may be limited by professional secrecy owed to another person, third-party rights, legal retention duties or the need to establish, exercise or defend legal claims. Identity may be verified before a request is fulfilled. Requests are normally answered within one month, subject to the extension permitted by the GDPR for complex or numerous requests. No fee is generally charged, except where a request is manifestly unfounded or excessive.
Send GDPR requests to contact@iuniapopescu.ro. You may also lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) at dataprotection.ro, or with the competent supervisory authority in your EEA place of residence or work. We encourage you to contact the practice first so the matter can be examined promptly, without affecting your right to complain.
8. Children and minors
Services involving a minor are organised in accordance with applicable law, professional ethics, the minor’s maturity and best interests, and the rights and responsibilities of parents or legal representatives. Necessary consent or authorisation is obtained from the appropriate representative, while the minor is given age-appropriate information and involved in decisions to the extent required by law and professional standards.
The confidentiality expectations and their limits are explained at the beginning of the professional relationship. Information is not automatically shared in full with a parent or representative; disclosures are assessed against the minor’s best interests, safety, applicable law and the integrity of the professional process. The website is not intended for a child to independently submit special-category data without appropriate adult involvement.
9. Automated decision-making
The practice does not use personal data to make decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you. Optional audience statistics, if activated with consent, are not used to make clinical or professional decisions.
10. Changes to this policy
This policy may be revised to reflect legal, professional, technical or service changes. The current version and update date are published on this page. Material changes affecting an ongoing professional relationship may also be communicated through an appropriate direct channel. Unless a different date is stated, the revised policy applies from publication and does not retroactively alter the legal basis of earlier processing.

