Privacy Policy
Effective date: June 3, 2026
Last updated: June 3, 2026
Version: 1.0
This Privacy Notice explains how Pink Elephant, Unipessoal Lda, NIPC 519056582, operating PsyStandard, processes personal data in connection with the PsyStandard practitioner verification directory.
PsyStandard is a practitioner verification directory for psychedelic coaches, integration specialists, harm-reduction practitioners, retreat facilitators and clinicians across Europe. PsyStandard is operated as a functionally separate unit from Pink Elephant’s Education vertical. Separate data environments and access controls are maintained between PsyStandard verification data and the Education vertical.
This Privacy Notice applies to prospective practitioners, verification applicants, verified practitioners, professional referees, supervisors, colleagues, assessors, mock-session participants, complainants, listed practitioners who are the subject of a complaint, and other identifiable persons whose personal data is included in PsyStandard records.
1. Controller
The controller responsible for the processing described in this Privacy Notice is:
Pink Elephant, Unipessoal Lda
NIPC 519056582
Edifício Amoreiras Square, Rua Carlos Alberto da Mota Pinto, no. 17, second floor
1070-313 Lisboa, Portugal
Email: [email protected]
PsyStandard has assessed that a Data Protection Officer is not required under Article 37 GDPR for the current processing. Privacy questions and data-subject rights requests may be sent to [email protected].
2. Overview of PsyStandard processing
PsyStandard processes personal data to operate a practitioner verification and public directory system. The processing includes expression-of-interest and waitlist communications, practitioner verification applications, active verification records, public directory listings, harm-governance and complaint investigations, and the internal preparation of anonymised aggregate research or statistical outputs.
PsyStandard does not intend to collect special-category data in the ordinary verification, active badge or public directory listing processes. The main situation where health or other special-category data may arise is complaint and harm-governance processing, where a complainant or supporting evidence may include identifiable health, mental-health, treatment, therapeutic-context or adverse-event information about a complainant, a client or another identifiable person.
PsyStandard does not use L2 mock-session recordings for facial recognition, biometric identification or automated inference. Assessor scoring is manual.
Website analytics are anonymised at the point of collection. PsyStandard does not use cross-session tracking of individual website users, advertising tracking scripts or session replay.
3. Expression of interest and waitlist
If you register interest in a future practitioner directory listing or application process, PsyStandard processes your email address, timestamp of submission and consent record.
This processing is used to record your expression of interest and send related follow-up communications about the PsyStandard directory or application process.
The legal basis is Article 6(1)(a) GDPR, consent. You may withdraw consent at any time.
The data is accessible to authorised PsyStandard personnel. Brevo is used as the email platform, with EU processing recorded in the RoPA. DigitalOcean Amsterdam is used for website hosting and form-submission processing.
The data is retained for 12 months from submission unless consent is withdrawn earlier, or until you proceed to the full application and your data is migrated to the practitioner verification application record, whichever occurs first.
4. Practitioner verification application
If you apply for PsyStandard verification, PsyStandard processes application data needed to assess eligibility across L0 and L1 verification tiers.
The data may include your full name, date of birth, email address, phone number, city/country-level postal address, professional title, training certificates and programme documentation, professional licence number where applicable, years of experience, practice insurance documentation, professional specialisations and client-population areas served, professional conduct history or disciplinary disclosures where requested, professional references and reference responses, completed L0/L1 application form responses, application status, decision and rejection reason where recorded.
PsyStandard may also process personal data of professional referees, supervisors or colleagues named by the applicant where reference details or reference responses are processed.
The legal basis for applicant data is Article 6(1)(b) GDPR, because processing is necessary to take steps at the applicant’s request before entering into the PsyStandard verification and listing relationship and to assess eligibility for the requested verification tier.
The legal basis for professional referee, supervisor or colleague details and reference responses is Article 6(1)(f) GDPR, legitimate interests. PsyStandard has a legitimate interest in verifying practitioner eligibility, checking professional references, preventing unreliable verification outcomes and maintaining trust in the practitioner directory. Reference processing is limited to professional referees, supervisors or colleagues named by the applicant and is used only for verification purposes.
No Article 9 special-category data is intended to be processed in the practitioner verification application. Applicants should not include client-identifying information, client case histories, applicant health data or unnecessary special-category data in the application.
The data is accessible to authorised PsyStandard assessors and the verification team. Typeform is used for L1 form collection. DigitalOcean Amsterdam is used for database hosting. Professional referees, supervisors or colleagues may be contacted for verification purposes.
L0 rejected applications are deleted 30 days after the rejection decision. L1 incomplete applications are deleted 30 days after the application deadline. Successful applications are migrated to the active verification record.
5. Active verification record
If you become a verified practitioner, PsyStandard maintains an active verification record during the badge validity period.
This data may include your practitioner ID, badge tier, listed or verified status, badge issuance date, badge expiry date, assessment summary, competency-domain scores, supervisor assessment notes, reference-check outcomes, application history, L2 mock-session recordings and assessment evidence, including audio/video recordings where applicable.
Where assessment evidence, recordings, supervisor notes or reference-check records include personal data of assessors, supervisors, mock-session participants or referees, PsyStandard processes that data only as part of the verification record.
The legal basis is Article 6(1)(b) GDPR, because the processing is necessary to maintain the practitioner’s active verification record, badge tier, badge validity, assessment evidence and verification history as part of the verification/listing relationship requested by the practitioner.
No Article 9 special-category data is intended to be processed in this activity.
The data is accessible to authorised PsyStandard assessors and the verification team. Amazon Web Services / Amazon S3 is used for L2 mock-session recording storage in the EU region. Google Workspace may be used for Google Meet and Google Drive processing in the L0/L2 verification flow, as recorded in the DPIA. L2 recordings stored temporarily in Google Drive are deleted within 14 days of confirmed upload to Amazon S3.
L2 mock-session recordings and assessment evidence are retained for 2 years from badge issuance. The active badge record is maintained while the badge is active and for 90 days after expiry for the renewal grace period. Assessment summaries are retained for 2 years from badge issuance.
6. Public directory listing
If your practitioner profile is published in the PsyStandard directory, PsyStandard processes and publishes professional profile data to make verified practitioners discoverable to consumers, organisations and other directory users.
The data may include your full name, professional title, practice location at city/country level, training background summary, languages spoken, services offered, fees and insurance information where provided, self-authored short practitioner bio, contact method or preferences, verification badge tier and verification status.
The legal basis for the core public profile, badge tier and verification status is Article 6(1)(b) GDPR, because publication and maintenance of the verified practitioner profile is necessary to perform the practitioner directory/listing relationship requested by the practitioner.
The legal basis for optional public profile fields that are not necessary for the core listing, such as optional practitioner bio, optional fees/insurance information, optional contact preferences or optional expanded service descriptions, is Article 6(1)(a) GDPR, consent.
No Article 9 special-category data is intended to be processed in the public directory listing.
Public profile information is visible to all directory users, including consumers, organisations and researchers. PsyStandard personnel may access profile data for profile maintenance. DigitalOcean is used for hosting/database infrastructure, and Cloudflare may be used for routing, CDN and security services.
No individual practitioner profile data is shared with retreat operators or other third parties beyond public profile display. Because published profile information is publicly accessible, it may be viewed by users outside Portugal and outside the EEA through ordinary website access.
Public profiles are retained while the practitioner holds an active verification badge. Profiles are unpublished within 5 business days of badge lapse, expiry, suspension, practitioner unpublishing request or withdrawal of consent for optional public fields. Profile data is retained internally for 90 days after unpublishing for renewal or grace-period administration and is then deleted unless the practitioner renews.
7. Harm governance and complaint investigations
PsyStandard processes complaint and harm-governance data to receive, assess and manage reports of practitioner conduct concerns or adverse events involving listed practitioners.
The data may include complainant contact details and email address, the nature and description of the concern, supporting documentation provided, the name and badge ID of the practitioner subject to the complaint, dates and location of the alleged incident, communication records between PsyStandard and relevant parties, details of other identifiable persons named in the complaint or evidence where provided, investigation status, outcome and decision documentation.
The data subjects may include complainants, listed practitioners who are the subject of a concern, and other identifiable persons named in the complaint or supporting evidence.
The legal basis is Article 6(1)(f) GDPR, legitimate interests. PsyStandard has a legitimate interest in receiving, assessing and managing practitioner conduct concerns and adverse-event reports, protecting the integrity and trustworthiness of the practitioner directory, supporting user safety, investigating complaints, ensuring fairness and right of response, and maintaining harm-governance records.
Where complaint materials include identifiable health, mental-health, treatment, therapeutic-context or adverse-event information about the complainant, a client or another identifiable person, the Article 9 condition is Article 9(2)(f) GDPR, because processing may be necessary for the establishment, exercise or defence of legal claims. This includes complaint investigation, harm-governance assessment, practitioner conduct decisions, legal hold, dispute handling and defence of potential claims.
Complaint data is accessible to the designated PsyStandard harm-governance reviewer and relevant authorised personnel where necessary. The complainant and the subject practitioner may receive information only to the extent necessary for investigation, fairness, right of response and resolution. No individual case data is shared externally.
Complaint and investigation records are retained for 7 years from closure of the investigation. Cases linked to active litigation are retained under legal hold until the matter is resolved.
8. Internal preparation of anonymised aggregate research or statistical outputs
PsyStandard may use verification data internally to prepare anonymised aggregate research or statistical outputs. This may include badge tier, professional specialisation, competency-domain scores, training programme representation and verified-practitioner status.
The purpose is to support standards and training programme development through anonymised aggregate outputs. External research partners receive anonymised aggregate outputs only and do not receive personal data or access to PsyStandard systems.
The legal basis for the internal preparation of anonymised aggregate outputs from verified-practitioner records is Article 6(1)(f) GDPR, legitimate interests. PsyStandard has a legitimate interest in preparing non-identifying aggregate statistics to improve standards, verification quality and training programme development.
No Article 9 special-category data is intended to be processed for this activity. No names, contact details, practitioner IDs, recordings, notes or individual-level records are included in external outputs.
Anonymous aggregate outputs may be retained indefinitely once no practitioner can be identified, linked or singled out.
9. Anonymous website analytics
PsyStandard website analytics are anonymised at the point of collection. No cross-session tracking of individual users is used. No advertising or third-party tracking scripts are used. Session replay is disabled.
Because the analytics are anonymised at the point of collection, PsyStandard does not treat this activity as personal-data processing under the GDPR. If the analytics configuration changes so that personal or pseudonymous data is processed before anonymisation, PsyStandard will reassess the processing and update its records and notices as required.
10. Recipients and processors
PsyStandard may disclose or make available personal data to authorised internal personnel and to processors used to operate the service.
Internal recipients include authorised PsyStandard personnel, assessors, supervisors, verification team members, product or technical personnel, legal/privacy personnel and harm-governance personnel, each only where access is necessary for their role.
External processors include Brevo for expression-of-interest email communications; Typeform for application form collection; DigitalOcean Amsterdam for hosting and database infrastructure; Google Workspace for Google Meet and Google Drive processing in the verification workflow; Amazon Web Services / Amazon S3 for L2 mock-session recording storage in the EU region; and Cloudflare for routing, CDN and security services where used.
Professional referees, supervisors or colleagues may be contacted for verification purposes where named by the applicant. Public directory users receive access to public profile information. Research partners receive anonymised aggregate outputs only and do not receive personal data.
Processor arrangements are governed by data processing agreements or equivalent processor terms where required.
11. International transfers
The processing is intended to take place within the EEA.
If any personal data is transferred outside the EEA, or if non-EEA support access or subprocessor processing occurs, PsyStandard will rely on an appropriate transfer mechanism under Chapter V GDPR, such as an adequacy decision, Standard Contractual Clauses or another lawful transfer safeguard, as applicable.
Public directory profile data is published on the internet and may be viewed by users outside the EEA. This is inherent in the public directory function.
12. Data security
PsyStandard applies technical and organisational measures to protect personal data.
Access to backend systems is controlled through role-based access controls and the least-privilege principle. MFA is required for admin access to production systems. Production and staging environments are separated. Admin access events are logged and retained for audit purposes.
TLS 1.2+ is enforced for public endpoints. Data at rest is encrypted in the DigitalOcean managed database using AES-256. Object storage is encrypted at rest. L2 mock-session recordings are stored in Amazon S3 EU region with server-side encryption. L2 recordings are accessible only to authorised PsyStandard assessors and supervisors. L2 recordings are not processed for facial recognition, biometric identification or automated inference, and assessor scoring is manual.
Daily automated snapshots are used for DigitalOcean Managed DB, with a 24-hour recovery point objective and a 4-hour recovery time objective. Backup retention is a 7-day rolling window. Restore testing is quarterly, and backup data is encrypted and stored within the EEA.
PsyStandard verification data is stored separately from Pink Elephant Education data. Role-based access controls prevent the Education team from accessing practitioner verification records, application materials or assessment scores. Personnel with data access are subject to annual compliance attestation.
13. Retention
PsyStandard retains personal data only for the periods necessary for the purposes described in this Privacy Notice, unless a longer period is required for legal, dispute, complaint, audit or compliance reasons.
Expression-of-interest data is retained for 12 months from submission unless consent is withdrawn earlier or the practitioner proceeds to a full application and is migrated to the application record.
L0 rejected applications are deleted 30 days after rejection. L1 incomplete applications are deleted 30 days after the application deadline. Successful applications are migrated to the active verification record.
L2 mock-session recordings and assessment evidence are retained for 2 years from badge issuance. Active badge records are maintained while the badge is active and for 90 days after badge expiry for the renewal grace period. Assessment summaries are retained for 2 years from badge issuance.
Public profiles are retained while the practitioner holds an active verification badge. Profiles are unpublished within 5 business days of lapse, expiry, suspension, practitioner unpublishing request or withdrawal of consent for optional public fields. Profile data is retained internally for 90 days after unpublishing for renewal/grace-period administration and is then deleted unless the practitioner renews.
Complaint and investigation records are retained for 7 years from closure of the investigation. Cases linked to active litigation are retained under legal hold until the matter is resolved.
Anonymous aggregate outputs may be retained indefinitely.
14. Your rights
Where the GDPR applies, you may have the right to request access to your personal data, rectification of inaccurate personal data, erasure of personal data, restriction of processing, data portability where applicable, and objection to processing based on legitimate interests.
Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect processing carried out before withdrawal. If you withdraw consent for expression-of-interest communications or optional public profile fields, PsyStandard will stop the relevant consent-based processing as applicable.
You may object to processing based on Article 6(1)(f), including reference-check processing, harm-governance processing and internal preparation of anonymised aggregate outputs, where applicable. PsyStandard may continue processing where it demonstrates compelling legitimate grounds or where processing is required for legal claims.
You may exercise your rights by contacting [email protected]. PsyStandard may need to verify your identity before responding to a request.
If a request affects data shared with processors or recipients, PsyStandard will take reasonable steps to notify them where required and feasible.
15. Article 14 information for third-party data
PsyStandard may receive personal data about professional referees, supervisors, colleagues, assessors, mock-session participants, complainants, subject practitioners or other persons named in complaints or supporting evidence.
The source of such data may be the practitioner applicant, a professional referee, a supervisor, a colleague, a complainant, a subject practitioner, an assessor, or another person involved in the relevant verification or complaint process.
Where PsyStandard receives personal data indirectly, it will provide information to the relevant data subject where required by Article 14 GDPR, unless an exemption applies or provision of the information would be impossible or involve disproportionate effort in the circumstances.
16. Automated decision-making
PsyStandard does not use solely automated decision-making producing legal or similarly significant effects.
Verification assessments and competency scoring are carried out manually by authorised assessors. L2 recordings are not processed for facial recognition, biometric identification or automated inference.
17. Complaints
You may contact PsyStandard at [email protected] if you have questions or concerns about the processing of your personal data.
You also have the right to lodge a complaint with the Portuguese supervisory authority, the Comissão Nacional de Proteção de Dados.
18. Changes to this Privacy Notice
PsyStandard may update this Privacy Notice from time to time. If material changes are made, PsyStandard will provide notice in an appropriate manner.
PsyStandard will update this Privacy Notice before introducing materially different processing, new categories of personal data, new special-category processing, non-EEA transfers, new processors, new public disclosure models, or non-anonymised research sharing.