The Psych PerspectiveThe Psych Perspective

Privacy Policy

Last updated: 19 July 2026

1. Who We Are

The Psych Perspective (“we,” “us,” “the practice”) is a solo counseling psychology practice operated by Simran Rani, Counseling Psychologist (NCAHP Reg. No. 99-4742-0504-5668 (2025)), based in Hyderabad, Telangana, India, and accessible at thepsychperspective.in (the “Site”).

For the purposes of the Digital Personal Data Protection Act, 2023 (“DPDPA”), The Psych Perspective is the Data Fiduciary for personal data collected through this Site - we decide why and how your personal data is processed.

This Policy explains what personal data we collect through the Site (booking, the Resonance Board, and related features), why we collect it, how it is stored and protected, who else can see it, and what rights you have over it. It applies to visitors, clients, prospective clients, and - where relevant - the parents, guardians, or third parties who interact with the Site on a client’s behalf.

This Policy does not cover information you share with us verbally or in writing during an actual therapy session; that is governed separately by clinical confidentiality obligations described in our Terms of Service.

2. A Note on What This Site Does Not Do

Before detailing what we collect, it’s worth being explicit about what we don’t do, since it shapes everything below:

  • We use Google Analytics for aggregate site-usage statistics only- which pages are viewed, approximate location (derived from IP address, not GPS), device/browser type, and how visitors found the Site. This never includes anything you submit through the booking form or the Resonance Board, which is stored separately and is never sent to Google. Analytics only runs if you actively accept it via the cookie banner shown on your first visit - see “Cookies and Consent” below.
  • We do not use Meta/Facebook Pixel, advertising pixels, or any cross-site behavioral tracking. Google Analytics is never used for ad personalization or remarketing on this Site - only aggregate usage statistics.
  • We do not run targeted or behavioral advertising.
  • We do not sell personal data, to advertisers or anyone else.
  • Besides analytics cookies (only after consent), the only other thing stored in your browser is a short-lived session token used solely to keep our clinician logged into the password-protected admin panel - this is not used to track visitors and is not present at all unless you are the clinician logging in.

Cookies and Consent

On your first visit, a banner asks whether you accept analytics cookies. If you decline (or simply close the banner without choosing), Google Analytics does not run and no analytics cookies are set - we use Google’s Consent Mode, which keeps analytics off by default until you actively opt in. You can change your choice at any time via “Manage Cookie Preferences” in the Site footer.

3. Personal Data We Collect

3.1 Appointment Booking

When you submit a booking request, we collect, depending on the flow you use:

  • Who the booking is for - yourself, a family member, or a friend.
  • If you are booking on someone else’s behalf:your own name, email address, and mobile number, and - if you are a family member - your relationship to the client. If the client is an adult, you’ll be asked to confirm you understand this is a scheduling request only, not the client’s own informed consent (see our Terms of Service).
  • Client details: full name, preferred pronouns (optional), age, and location preference (online, or one of our listed Hyderabad service areas).
  • Contact details:the client’s own email and mobile number - or, if the client is a minor (under 18), the parent’s or legal guardian’s name, email, and mobile number instead (see Section 3.2 below).
  • Clinical intake information: the presenting concerns you select from a checklist (e.g., anxiety, stress, grief, relationship difficulties) and anything you write in the free-text field describing why you are seeking therapy. This is sensitive personal data relating to your mental health, and we treat it accordingly - see Section 6.
  • Logistics: employment status, preferred session date, best time to reach you, and how you heard about the practice.
  • Consent record: your acknowledgement of our informed-consent terms, a checkbox confirmation, and a hand-drawn electronic signature (Section 3.3).

A booking submission is a request, not a confirmed appointment. It is reviewed and either confirmed or declined by the clinician.

3.2 Minors and Guardian Data

If the client is under 18, our booking flow requires a parent or legal guardian to provide their own name, email, and mobile number, and to be the one who reviews and signs the consent record. A friend cannot book or consent on behalf of a minor under any circumstance, and a family member may only do so if they are the minor’s parent or legal guardian (not a sibling, spouse, or other relative).

At present, we rely on the guardian’s own representation of their identity and relationship to the client, provided at the time of booking, rather than a separate government-backed identity verification step.

As noted in Section 2, this Site never runs behavioral advertising or cross-site tracking - for any visitor, including minors. The only tracking of any kind is aggregate-usage Google Analytics, which only runs after an explicit accept via the cookie banner, and never includes anything submitted through the booking form.

3.3 Digital Signature and Consent Record

The signature you draw during booking is captured as an image and embedded into a PDF copy of the informed-consent terms you agreed to. That PDF is stored in a private, access-restricted storage location that is not reachable from outside our systems, and is emailed to you (or your guardian) only after the clinician confirms your appointment. A one-way cryptographic hash of your name, email, and the consent text is kept as tamper-evidence - this lets us later confirm the consent record hasn’t been altered, without needing to store the underlying data twice.

3.4 The Resonance Board

If you submit a question through the Resonance Board, we collect the question text (up to 1,500 characters), an email address (used only to send you a private reply - it is never published), your age, and your profession category. We ask you not to include your name or other identifying details in the question itself.

By submitting a question, you grant us permission to edit, redact, and publish an anonymized version of your question and our reply on the Site and our associated channels, for as long as we choose to keep it published. We decide, at our discretion, whether a given submission is published at all, and we redact it to remove names, contact details, and other identifying information before doing so. Your email address and the original, unredacted question are never published.

If you would like a previously published Q&A removed, email us at contact@thepsychperspective.in and we will take it down.

Replies are written personally by the clinician - not generated by AI or automated in any way. Submissions are limited to three per email address in any 24-hour period.

3.5 Third-Party Data (People Who Aren’t You)

If you book on behalf of someone else, or list a guardian’s contact details, you are providing us with that other person’s personal data. By submitting it, you confirm you have their permission to do so (or, in the case of a minor, that you are their parent/legal guardian). Please don’t submit another adult’s contact details without their knowledge.

4. Why We Process Your Data (Purpose Limitation)

We use the personal data described above only to:

  • Evaluate and respond to appointment requests, and schedule and deliver therapy sessions (online or in person);
  • Communicate with you (or a guardian/proxy) about your booking - confirmations, rejections, and logistics;
  • Maintain the clinical and consent records expected of a mental health practice;
  • Respond to Resonance Board submissions and, where you don’t object, share a redacted, anonymized version publicly for the educational benefit of other visitors;
  • Meet our own legal and record-keeping obligations.

We do not use your data for marketing profiling, do not sell it, and do not use it to train third-party AI models.

5. Our Legal Basis for Processing

Our primary basis for processing your personal data is your consent, given at the point of booking (or, for a minor client, your parent’s/legal guardian’s consent) and, separately, when you submit a Resonance Board question. Where the data concerns a minor, DPDPA Section 9 requires that consent be given by a parent or legal guardian rather than the child - our booking rules exist specifically to enforce this (Section 3.2 above). The exact consent record you review and sign depends on how your booking is made - as yourself, as a guardian, or as someone booking on another adult’s behalf - see our Terms of Service for what each covers.

6. Sensitive Personal Data - Mental Health Information

The presenting concerns and free-text intake information you provide is sensitive information about your mental health. We limit access to it as follows:

  • It is stored in our database behind row-level access controls that restrict visibility to the single authenticated clinician account.
  • In the admin dashboard, your email address and phone number are masked by default (e.g., s***n@example.com) and only revealed with a manual, per-record action by the clinician - not shown in full automatically.
  • It is never used for marketing, advertising, or shared with any third party for their own purposes.

7. Who We Share Data With

We do not sell your personal data. We share it only with:

  • Our clinician, Simran Rani, who is the sole person with access to the admin panel and appointment records.
  • Service providers who process data on our behalf(“Data Processors”), each governed by a data processing agreement:
    • Supabase - our database, file storage, and authentication provider, which hosts appointment records, consent PDFs, and Resonance Board submissions. Our Supabase project is hosted in the AWS Mumbai (ap-south-1) region, India - your data stays within India for this processor, so no cross-border transfer arises from its use.
    • Resend - our transactional email provider, used to send booking confirmations, rejections, and Resonance Board replies. Resend is a US-based provider and may process personal data (such as your name and email address) outside India in the course of delivering these emails. This transfer is permitted under the DPDPA, which currently allows cross-border transfer of personal data except to countries specifically restricted by the Central Government (none have been notified to date).
    • Google Analytics - used only if you accept analytics cookies via the banner described in Section 2. When active, Google (a US-based provider) processes aggregate usage data such as pages viewed, approximate location, and device type - never anything you submit through the booking form or the Resonance Board. As with Resend above, this cross-border transfer is permitted under the DPDPA.
  • A parent, legal guardian, or booking proxy, where applicable, as part of delivering the service they booked.
  • Legal authorities or third parties, without your consent, only where:
    • There is an imminent risk of serious harm to you or to another person;
    • Disclosure is required to report suspected abuse of a child, elder, or other vulnerable person;
    • We are required to do so by a court order or other binding legal mandate.

We do not use any payment processor, CRM, or third-party calendar/scheduling tool - none are integrated into the Site, so no personal data flows to such services.

8. Your Rights

As a Data Principal under the DPDPA, you (or, for a minor, your parent/legal guardian) may:

RightWhat it means here
AccessAsk for a summary of the personal data we hold about you and the processors involved in handling it.
CorrectionAsk us to correct inaccurate contact, demographic, or billing information. Clinical notes that accurately reflect a session at the time it occurred are not altered retroactively, consistent with standard clinical record-keeping practice.
ErasureAsk us to delete your personal data once your consent is withdrawn or the therapeutic relationship has ended. This is subject to our clinical record-retention practice (see Section 9) - we’ll tell you what, if anything, we’re required to keep and for how long.
GrievanceRaise any concern about how your data is handled with our Grievance Officer (Section 11) before escalating to the Data Protection Board of India.

To exercise any of these rights, email us at contact@thepsychperspective.in. We will acknowledge your request within 2 business days and aim to resolve it within 30 days.

9. How Long We Keep Your Data

Clinical and consent records are retained for a minimum of 3 years after your last session. After that period, or upon a valid erasure request (whichever is later), we securely delete the record.

Resonance Board submissions that are not published are retained only as long as needed to respond to and moderate them.

10. Security Measures

We take the following measures to protect your personal data:

  • Appointment and consent data is protected by row-level security restricting access to a single authenticated clinician account.
  • Consent PDFs are stored in a private file-storage location that is not publicly reachable and is only accessible via server-side, restricted credentials.
  • Login sessions for the admin panel use short-lived, browser-session-only storage - not persistent local storage - reducing the risk that a login token lingers on a shared device.
  • Personal identifiers (email, phone) are masked by default in the admin interface and only revealed deliberately, per record.
  • All connections to our database and email provider are encrypted in transit (TLS), and data at rest in our database is encrypted using our hosting provider’s standard encryption-at-rest capability.

No system is perfectly secure, and we can’t guarantee absolute security. If we become aware of a personal data breach affecting your information, we will notify you and the Data Protection Board of India as required by law.

11. Grievance Officer

If you have a concern about how your personal data is handled, please contact:

Grievance Officer: Simran Rani, Counseling Psychologist
Email: contact@thepsychperspective.in
Location: Hyderabad, Telangana, India

We will acknowledge your grievance within 2 business days and work to resolve it within 30 days. If you remain unsatisfied after raising it with us, you may escalate the matter to the Data Protection Board of India.

12. Children’s Privacy

This Site is designed to be usable by teenagers with the involvement of a parent or legal guardian, as described in Section 3.2. We do not knowingly collect personal data directly from a child without a parent or legal guardian being the party who submits and consents to that data on the child’s behalf.

13. Third-Party Links

Our Site may link to third-party services we don’t control, such as video-conferencing tools for online sessions, professional directory listings, and social media profiles. This Policy does not apply to those third-party services - please review their own privacy policies.

14. Changes to This Policy

We may update this Policy from time to time, for example as our data practices or applicable law change. We’ll update the “Last updated” date above when we do. Material changes affecting how we use your data will be communicated to clients directly where practical.

15. Governing Law

This Policy is governed by the laws of India. See our Terms of Service for the applicable jurisdiction and dispute resolution process.

16. Contact Us

The Psych Perspective
Simran Rani, Counseling Psychologist (NCAHP Reg. No. 99-4742-0504-5668 (2025))
Hyderabad, Telangana, India
Email: contact@thepsychperspective.in
Phone: +91 83092 71713