Andreasyan.io

Privacy

Privacy Policy

This policy explains how Andreasyan.io collects, uses, stores, and protects personal, health-related, therapy, contract, and payment data.

Data controller

The data controller is Armen Andreasyan Sole Proprietor, TIN 20242567, legal address: Yerevan, Davtashen, 2nd district, building 16, apartment 36, email: info@andreasyan.io, phone: +374 95 37 87 27. Privacy questions, requests, or complaints may be sent to the listed email address.

Data that may be processed

  • Identification and contact data such as name, email, telephone number, account identifier, and message content.
  • Service coordination data such as booking date and time, service type, current country or city, and preferred communication method.
  • Health-related and therapy data such as questionnaire answers, psychological-state information, previous support or medication information, risk assessments, and professional notes.
  • Contract data such as agreement version, signed content snapshot, signing time, electronic signature, and integrity hashes.
  • Payment and accounting data such as payment status, amount, currency, transaction and confirmation numbers, and receipt information.
  • Security and audit data such as basic login, device, or browser information, user agent, and, where necessary, the IP address at signing for identification, fraud prevention, and dispute protection.

Purposes and consent

Data is processed to create an account, organize bookings and payments, provide the service, assess safety, maintain professional records, preserve the signed agreement, respond to requests, and meet applicable accounting or legal duties.

Health-related and therapy information is particularly sensitive data. Informed consent for the described processing is provided when the client signs the complete agreement in the portal. Consent may be withdrawn by written request, while recognizing that withdrawal may prevent continuation of the service and does not undo prior lawful processing or mandatory retention duties.

Card and payment data

Card payments are processed on the secure Inecobank payment page. Andreasyan.io does not store and does not have access to the full card number, CVV/CVC code, or other sensitive payment-method data. Andreasyan.io may receive only the payment status, transaction number, paid amount, currency, and receipt-related information.

Access and technical providers

Therapy data is accessible only to authorized persons to the extent necessary for service delivery, safety, or lawful duties. Necessary technical providers may process limited data for hosting, database, video communication, payment, or transactional-email services under appropriate confidentiality and security conditions.

For professional supervision or consultation, de-identified case information may be used unless separate consent or a legal requirement applies. Personal data is not sold to advertisers.

Confidentiality and legal exceptions

Therapy information is confidential and is not shared with third parties without client consent except where disclosure is permitted or required by applicable law. This may include an immediate and serious danger to the client or another person, legal duties concerning abuse of a child or vulnerable person, and a binding request from a court or other competent authority. Any disclosure is limited to the minimum information reasonably necessary.

Storage, retention, and security

Data is protected through access controls, authentication, and other reasonable technical and organizational measures. Signed agreements and their integrity hashes are preserved as immutable records, while PDF documents are held in non-public storage.

Data is retained for as long as objectively necessary for service, professional, safety, accounting, legal, or dispute-protection purposes and is then deleted or de-identified unless the law requires otherwise. The exact period may depend on the data category and applicable duties.

Client rights

Clients may write to info@andreasyan.io to request a copy or correction of their data, an explanation of processing, or withdrawal of consent. Deletion or transfer requests are assessed in light of the data type, service safety, and applicable retention duties. Reasonable identity verification may be required before fulfilling a request.

Policy changes

This policy may be updated to reflect changes in services, technology, or legal requirements. Material updates are published on the website, while the content of an already signed agreement remains preserved under the version signed by the client.