Den Kognitive Diamant
Cookies and privacy policy
In brief
I am bound by professional confidentiality and a duty to keep records. Your records are kept for 5 years after the most recent entry and are then deleted.
Under the EU General Data Protection Regulation (GDPR), all businesses that collect and handle personal data are required to have a privacy policy. I take your data protection seriously and comply with EU data protection law.
In short, I use secure and encrypted systems for email, online booking and record-keeping. Data processing agreements are in place with all partners. If partners should request disclosure of information, I first obtain your consent. The risk of a data breach is assessed as low.
This website uses neither Google Analytics, Google Ads tracking nor marketing cookies, and it does not load content from YouTube, Google Maps or Trustpilot. Read about your privacy when you visit this website.
Read on below about the processing of personal data in connection with your treatment.
Statistics without cookies
Running again since 1 October 2026. The statistics first ran from 22 September 2026, were paused from 30 September 2026 and were started again on 1 October 2026 No event records were stored during the pause. From 1 October 2026 video starts, the Trustpilot button, a source category and the voluntary question are counted as well, as described below.
What is counted
This website is delivered by Cloudflare. To know how the website is used, the server counts: deliveries of selected pages, presses on the buttons for booking, the free phone call, the map and Trustpilot (which go through this website's own addresses), starts of the videos and answers to the voluntary question “Where did you first hear about the clinic?” on the confirmation page after booking. Pages and buttons are counted on the server during the ordinary delivery. A video start is counted on the server when the video file is requested from the beginning, and an answer is counted when you press it (an ordinary link). No cookies and no third-party statistics scripts are used, and nothing is stored on your device.
What is stored
Each count is stored as a small event record in a separate statistics dataset at Cloudflare with a fixed page, button or video name or the chosen answer, the page language and the time. For a page delivery a source category is also stored: Google, Google ad, AI service, Bing, Facebook/Instagram, other external source, internal (from another page of this website) or unknown. The category is derived from the domain in the browser's referrer or from Google's ad marker in the address; the address itself, the referrer and the marker's value are not stored. For a button or a video the fixed name of the page where it was used is stored, and for the confirmation page a category for whether you returned from the booking system. This dataset holds no IP address, browser information, full web address or referring web address, and there is no visitor ID; the answer to the question is not linked to your booking. Cloudflare deletes the event records after about three months; the clinic then keeps only monthly totals.
Cloudflare as hosting provider
To deliver and protect the website, Cloudflare as hosting provider receives connection information, including your IP address. That is a separate processing from these statistics and is not part of the statistics dataset.
Legal basis and your rights
The legal basis for the statistics is my legitimate interest in knowing whether the website and its buttons are used (Article 6(1)(f) of the General Data Protection Regulation). This limited server statistics uses no statistics cookies. Your rights, including the right to object, are described under “Your rights” below, and you can contact me at therese@denkognitivediamant.dk.
Privacy policy
Data controller
I process personal data and have therefore adopted this privacy policy, which tells you how I process your data.
Den Kognitive Diamant ApS, represented by psychologist Therese Ejerskov, is the data controller for the information processed about you as a client and for the information processed when you use this website.
To protect your personal data as well as possible, I continuously assess how high the risk is that my data processing affects your fundamental rights negatively. I have taken a number of preventive measures regarding data security, which means the risk of a data breach is assessed as low.
I ensure fair and transparent data processing
When I ask you to make your personal data available to us, I inform you of which data I process about you and for what purpose. You receive this information at the time your personal data is collected.
In some cases it may be necessary to obtain information from an authority or partner, in which case I obtain your consent beforehand. If partners (e.g. an insurance company) or authorities request disclosure of information, you will be asked for consent.
Processing of personal data
I store this type of data about you:
- Ordinary personal data
- Civil registration (CPR) number (if necessary)
- Sensitive data
I collect and store your personal data for specific purposes
I collect and store your data to the extent necessary for your treatment:
- In connection with record-keeping and storage of your information.
- Administration of your relationship with us, e.g. invoicing.
- Compliance with legal requirements, including the duty to keep records.
The basis for my processing of your information
When you are in treatment with me, I process your information in order to provide you with psychological treatment and to comply with my duty to keep records as an authorised psychologist. The legal basis is Article 6(1)(b) of the General Data Protection Regulation, concerning the agreement on your treatment, and Article 6(1)(c), concerning my legal obligation to keep records. For information about your health, the basis is Article 9(2)(h), because the processing takes place as part of health care under professional confidentiality.
I process information for invoicing and accounting under Article 6(1)(c), because the Danish Bookkeeping Act requires it. I only disclose your information if you consent to it or if the law requires it.
I only process relevant and necessary personal data
I only process data about you that is relevant and sufficient for the purposes defined above. I only collect, process and store the personal data necessary to carry out my work. In addition, legislation may determine which type of data is necessary to collect and store for my business operations. The type and extent of the personal data I process may also be necessary to fulfil a contract or another legal obligation.
I check and update your personal data
I check that the personal data I process about you is not incorrect or misleading. I also make sure to update your personal data on an ongoing basis. As my service depends on your data being correct and up to date, I ask you to inform us of relevant changes to your data.
I delete your personal data when it is no longer necessary
I delete your personal data when it is no longer necessary for the purpose that was the reason for my collection, processing and storage of your data. Your records are kept for 5 years after the most recent entry and are then deleted.
I obtain your consent before I process your personal data
I obtain your consent before I process your personal data for the purposes described above, unless I have a legal basis for obtaining it. I inform you of any such basis. Your consent is voluntary, and you can withdraw it at any time by contacting us.
If I wish to use your personal data for a purpose other than the original one, I inform you of the new purpose and ask for your consent before I begin the data processing. If I have another legal basis for the new processing, I inform you of this.
I do not disclose your personal data without your consent
I do not disclose personal data to other parties. I am, however, obliged to break confidentiality if it is assessed that you are a danger to yourself or others. I am also subject to an enhanced duty of notification, whereby I am obliged to notify the relevant authorities if I receive information indicating that a child or young person is at risk. In these cases, where I am legally obliged to break confidentiality, I will always inform you and try to obtain your consent.
Security
I protect your personal data and have internal rules on information security.
I have adopted internal rules on information security, which contain instructions and measures that protect your personal data against being destroyed, lost or altered, against unauthorised publication, and against unauthorised persons gaining access to or knowledge of it.
In accordance with EU data protection law, data processing agreements have been entered into with relevant partners. I also protect the confidentiality and authenticity of your data by means of encryption.
In the event of a security breach that results in a high risk to you of discrimination, identity theft, financial loss, loss of reputation or other significant disadvantage, I will notify you of the security breach as quickly as possible.
Phone calls from my ads
From 1 October 2026 I do not use Google’s call reporting. If you call via a phone number in one of my Google ads, you call the clinic directly, and Google does not record the call itself for me. Google may record that the call button in the ad was pressed; that happens in Google’s own systems under Google’s terms. Until 30 September 2026, calls from the ads went through a forwarding number from Google Ireland Limited, and Google recorded the call’s start time, duration, whether it was answered and the area code, and for calls over 15 seconds also the phone number. You can always call the clinic directly on the number at the bottom of the page.
Your rights
You have the right to access your personal data.
You have the right at any time to be informed which data I process about you, where it comes from, and what I use it for. You can also be informed how long I store your personal data, and who receives data about you, to the extent I disclose data. You can exercise your rights by contacting us. You have the right to have inaccurate personal data corrected or deleted. You have the right to object to my processing of your personal data.
You have the right to receive the personal data you have made available to us, and the data I have obtained about you from other parties on the basis of your consent. If I process data about you as part of a contract to which you are a party, you can also have your data sent to you. You also have the right to transfer this personal data to another therapist.
If you are dissatisfied with the way your information is processed, you can complain to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark, datatilsynet.dk.
Contact details regarding the privacy policy
Sessions with Therese:
- Data controller
- Den Kognitive Diamant ApS, represented by psychologist Therese Ejerskov
- Address
- Danstrupvej 27G, 1st floor, 3480 Fredensborg, Denmark
- CVR
- 39625253
- Phone
- +45 31 66 83 88
