Client Consultation Register (special-category data with explicit consent)
Last updated: 5 November 2025
Controller: Kylähtee osuuskunta (runs “Hormone Focus”)
Business ID: [add Business ID]
Postal address: [add postal address], Finland
Privacy contact: Szonja Pomazi — hormonefocus@gmail.com
— [+358451132335]
DPO: Not appointed.
Eligibility: Services for adults (18+) only.
Summary (plain language)
If you book a consultation, we collect only what we need to prepare and deliver the session. Some of this can be health data (cycle info, symptoms). We will ask for your explicit consent and you can withdraw it at any time. We protect these notes carefully and keep them only as long as needed.
What we collect
Identity & contact: name, email, country, age, preferred language/time zone
Consultation intake & notes (optional, only what you choose to share): menstrual cycle history (e.g., general cycle length range, last period start), relevant symptoms, goals, lifestyle and diet context you wish to share, and our session notes or action plan
Administrative: signed consultation agreement (name, date/time, IP and consent record)
We avoid collecting information that is not needed for your goals.
Why we process it and legal bases
Prepare and deliver consultation, provide follow-up materials — consent
Process health-related details — explicit consent (you can withdraw consent at any time)
Service security and scheduling administration — legitimate interest (minimal)
How we collect it
Directly from you via an intake form or document you complete, and during sessions
We do not obtain these details from third parties or public sources
Recipients (processors)
Secure storage within our workspace; strictly limited access to the consultant
Email (for scheduling and sending materials)
If we use digital signature or intake tools, they act as processors under contract
We do not publish or sell consultation data.
International transfers
If any tool used for intake, email, or storage processes data outside the EEA (commonly U.S.), we rely on the EU-U.S. Data Privacy Framework or SCCs with additional safeguards as needed.
Reuters
Retention
Consultation records and notes: kept for 3 years after your last session to answer follow-up questions and handle potential claims; then deleted
If you withdraw consent earlier and we have no other legal basis to keep the notes, we delete them sooner
Backups: rolling backups auto-expire within 30–90 days
Anonymisation: if we keep aggregate insights (e.g., “topics most clients ask about”), we remove all identifiers.
Your rights
You may withdraw consent at any time; request access, correction, deletion, or restriction; and object to marketing (we do not use consultation data for marketing). To complain, contact the Office of the Data Protection Ombudsman.
Tietosuojavaltuutetun toimisto
Security
Access strictly limited to the consultant; no raw health notes sent as email attachments
Encrypted storage and transport; strong authentication; audit logs for access
Staff confidentiality obligations and privacy training
Contact
Szonja Pomazi — hormonefocus@gmail.com
— +358451132335