Privacy Policy
Preamble and Acceptance
This Privacy Policy explains how Mental Health Board Org, available at https://mentalhealthboard.org, processes personal information associated with access to, navigation of, communication with, and use of the website.
Mental Health Board Org is a digital institutional, educational, policy-oriented, and editorial project focused on responsible mental health information, ethics, good practices, professional education, psychoanalysis, psychology, wellbeing, neuroscience, health technology, and related subjects.
The website may publish articles, essays, reference materials, analyses, ethical principles, editorial standards, institutional recommendations, evidence reviews, best-practice documents, educational resources, and other materials related to mental health.
The term “Board” is part of the project's institutional and editorial identity. It does not, by itself, mean that Mental Health Board Org is a state medical board, psychology licensing board, governmental regulator, statutory professional council, recognised accrediting agency, disciplinary authority, certification authority, hospital, clinic, or other public body.
Standards, principles, policies, recommendations, or best-practice materials developed by the website are project-level editorial or institutional materials unless a specific external authority, law, regulation, or professional standard is expressly identified and accurately cited.
Mental Health Board Org is not a clinic, medical practice, psychological practice, psychotherapy provider, psychoanalytic treatment service, telehealth provider, hospital, or emergency mental health service.
The website does not provide medical or psychological diagnosis, clinical assessment, psychotherapy, psychoanalytic treatment, prescriptions, patient management, individualised treatment recommendations, or emergency care.
By accessing or using the website, visitors acknowledge this Privacy Policy. Where consent is legally required for a specific activity, an appropriate consent mechanism will be used.
Applicable United States federal and state privacy and consumer-protection requirements will be observed where their statutory scope is satisfied, including, where applicable, the California Consumer Privacy Act as amended by the California Privacy Rights Act, the Children's Online Privacy Protection Act, Federal Trade Commission requirements, and applicable state privacy and security laws.
Where Regulation (EU) 2016/679, the General Data Protection Regulation, applies territorially and materially to a particular processing operation, the corresponding GDPR requirements will also be observed.
Data Controller and Data Protection Officer (DPO)
For transparency purposes, Mental Health Board Org is the public institutional and editorial designation used for the website available at https://mentalhealthboard.org.
The use of this designation does not, by itself, establish the existence of a corporation, government board, licensing body, physical clinic, hospital, professional council, accredited university, or healthcare establishment.
The person or organisation that actually determines the purposes and essential means of a particular personal information processing activity will be treated as the relevant controller, business, or equivalent responsible party under the law applicable to that activity.
Dr. Thomas Rivera is identified as an editorial and institutional contact associated with the production, curation, review, or communication of website content. That identification does not, by itself, constitute appointment as Data Protection Officer or independent proof of a medical licence, psychology licence, professional board membership, government position, academic appointment, or other regulated credential.
The privacy contact channel is dr.thomasrivera@mentalhealthboard.org.
United States privacy law does not generally require every informational website to appoint a Data Protection Officer. If Article 37 of the GDPR, the UK GDPR, or another applicable legal regime requires a formal DPO appointment for a particular operation, the required designation and contact details will be made available.
Legal Definitions
For purposes of this Policy, the following terms are used according to applicable law:
- Personal information or personal data: information relating to an identified or identifiable individual, as defined by applicable law.
- Sensitive personal information: information receiving heightened protection because of its nature, including categories recognised by applicable law such as health information, racial or ethnic origin, religious or philosophical beliefs, sexual orientation, precise geolocation, biometric information, and certain identifiers.
- Processing: collection, use, organisation, storage, analysis, disclosure, transmission, modification, restriction, or deletion of personal information.
- Consumer or data subject: an individual whose personal information is processed and who may receive rights under applicable law.
- Controller: a person or organisation determining the purposes and essential means of processing.
- Service provider or processor: an entity processing personal information on behalf of another responsible party under applicable legal requirements.
- Consent: an affirmative authorisation satisfying the requirements applicable to the specific processing activity.
- Clinical data: information collected or generated for diagnosis, medical treatment, psychological assessment, psychotherapy, psychoanalytic treatment, patient monitoring, or other individualised healthcare purposes.
- Health inference: a conclusion or prediction concerning a person's physical or mental health derived from other information or behaviour.
- Profiling: systematic or automated processing used to evaluate, classify, predict, or infer characteristics concerning an individual where recognised under applicable law.
- Institutional standard: an ethical, educational, editorial, methodological, or good-practice criterion adopted or published by the project, unless expressly identified as originating from an external legal or regulatory authority.
- Cookies: files, identifiers, pixels, scripts, or similar technologies used for technical functionality, security, preferences, analytics, advertising, or other disclosed purposes.
Information We Collect
Information Voluntarily Provided
When visitors contact the website, submit a question, suggest a correction, propose editorial material, comment on an institutional guideline, or use another available form, the website may process information such as name, email address, voluntarily provided affiliation, subject, and message content.
The website does not provide functionality intended to collect clinical data, medical records, psychotherapy notes, psychoanalytic session transcripts, diagnoses, prescriptions, psychological assessment results, treatment histories, or patient records.
Visitors should not submit such information through ordinary contact or editorial channels.
Technical and Navigation Information
Technical information may be processed during access, including Internet Protocol address, date and time, browser, operating system, device type, requested pages, approximate referral source, technical identifiers, and security events.
Audience and Performance Information
Where analytics technologies are actually implemented, information concerning page views, approximate session duration, referral sources, interactions, clicks, and technical performance may be processed.
Institutional and Editorial Communications
Communications concerning mental health ethics, professional education, policies, evidence, guidelines, publications, collaborations, corrections, or institutional questions may contain professional contact information and information voluntarily supplied by the sender.
Such information should be used only for purposes reasonably compatible with the relevant communication.
Feedback on Standards and Policies
If the website requests feedback concerning a proposed institutional policy, ethical principle, or best-practice document, information may be processed to evaluate the submission, communicate with contributors, document review history, and improve the relevant material.
Providing feedback does not automatically create board membership, professional certification, employment, faculty status, regulatory standing, or a voting or governance right.
Mental Health Board Org does not collect clinical data as part of its intended website functionality and does not maintain patient charts or clinical records.
If a user nevertheless includes health information in an unsolicited communication, such information is received incidentally and does not convert the website into a healthcare provider or patient-record system.
Legal Bases for Processing
In the United States, privacy obligations depend on the nature of the information, the responsible party, the visitor's jurisdiction, the purpose of processing, and the statutory scope of the applicable federal or state law.
Where the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to the responsible business, processing will be conducted consistently with California Civil Code section 1798.100 and following provisions and applicable California regulations.
Where COPPA applies, online collection from children under 13 will be handled in accordance with 15 U.S.C. sections 6501 through 6506 and 16 CFR Part 312.
Where the Federal Trade Commission Act applies to representations concerning privacy, security, health, services, products, endorsements, standards, or commercial practices, such representations must not be unfair or deceptive.
Where processing falls within the GDPR, an appropriate lawful basis under Article 6 will be identified.
Where GDPR-covered processing involves health information or another special category of data, an applicable condition under Article 9 must also be identified.
Depending on the particular GDPR-covered activity, relevant bases may include consent, contractual necessity, compliance with legal obligations, protection of vital interests, or legitimate interests where legally permissible and appropriately balanced.
Where UK GDPR applies, corresponding lawful bases and safeguards will be observed.
Where Brazil's Law No. 13,709/2018 applies to a particular operation, an appropriate legal basis under Articles 7 or 11 will be identified.
Where Peru's Law No. 29733 applies, corresponding transparency, proportionality, consent, security, and data-subject requirements will be observed.
Worldwide accessibility of the website does not automatically cause every privacy law in every country to apply to every processing activity.
Purposes of Processing
Personal information may be processed, where appropriate, to:
- operate and secure the website;
- provide requested institutional and educational content;
- respond to correspondence and enquiries;
- review corrections and scholarly feedback;
- administer editorial submissions where enabled;
- review feedback concerning ethical or institutional standards;
- manage comments where enabled;
- record privacy and cookie preferences;
- prevent fraud, spam, attacks, malicious automation, and unauthorised access;
- identify technical failures;
- produce website-performance and audience statistics where legally appropriate;
- understand aggregate interest in mental health and ethics topics;
- improve accessibility and editorial organisation;
- maintain authorship, citation, source, and revision records;
- maintain version histories of institutional standards;
- comply with applicable legal obligations;
- respond to valid governmental, regulatory, or judicial requests;
- establish, exercise, or defend legal rights;
- investigate security incidents.
Reading content concerning depression, anxiety, suicide, trauma, psychosis, addiction, sexuality, psychiatric medication, or another mental health subject will not, by itself, cause the website to determine that the visitor has that condition.
Sensitive Data and Mental Health
MENTAL HEALTH BOARD ORG DOES NOT COLLECT CLINICAL DATA THROUGH ITS ORDINARY WEBSITE FUNCTIONALITY FOR DIAGNOSIS, PSYCHOTHERAPY, PSYCHOANALYTIC TREATMENT, CLINICAL SCREENING, PRESCRIPTION, TRIAGE, OR PATIENT CARE.
The website may publish educational and institutional materials concerning depression, anxiety, trauma, suicide, self-harm, psychosis, addiction, sexuality, psychiatric treatment, psychological disorders, neurodiversity, and other sensitive topics.
READING AN ARTICLE, STANDARD, OR GUIDELINE ABOUT A MENTAL HEALTH CONDITION DOES NOT CAUSE THE WEBSITE TO DIAGNOSE THE READER WITH THAT CONDITION.
The website will not use reading history alone to classify a visitor as depressed, anxious, psychotic, suicidal, traumatised, addicted, neurodivergent, or as having another mental-health condition.
A PERSON'S INTEREST IN MENTAL HEALTH INFORMATION IS NOT, BY ITSELF, CLINICAL EVIDENCE ABOUT THAT PERSON.
Where California privacy law applies, information concerning a consumer's health may fall within legally protected sensitive personal information.
Where the GDPR applies, information concerning health may constitute special category personal data under Article 9.
The website is not intended to create personal health records, electronic patient records, psychotherapy records, or clinical profiles.
Visitors should not transmit identifiable patient information, medical records, psychological test results, psychotherapy notes, session transcripts, diagnoses, prescriptions, or confidential third-party health information through ordinary website channels.
If a user voluntarily sends such information despite this instruction, receipt is incidental and does not establish a clinical relationship or patient record.
Incidental sensitive information should be minimised, restricted, or deleted where reasonably appropriate and legally permissible.
The website will not intentionally reuse health information incidentally received through an ordinary editorial contact for behavioural advertising, clinical profiling, or unrelated model training without a separate lawful and documented assessment.
Cookies and Tracking Technologies
The website may use cookies and comparable technologies for technical functionality, cybersecurity, privacy preferences, analytics, and other disclosed purposes.
- Strictly necessary technologies: technologies needed to operate, secure, or provide essential functionality.
- Functional technologies: technologies used to remember requested settings or functionality.
- Analytics technologies: technologies used to understand aggregate audience behaviour and website performance.
- Advertising or cross-context behavioural technologies: technologies used for advertising or related tracking only where actually implemented and subject to applicable requirements.
Optional technologies should not be represented as strictly necessary when they are not essential to the requested service.
Where consent is legally required, the relevant optional technologies will be subject to an appropriate consent mechanism.
Where the CCPA applies and a practice constitutes a sale or sharing of personal information, legally required opt-out mechanisms will be provided.
Where legally required, valid opt-out preference signals, including applicable Global Privacy Control signals, will be honoured.
The website should not create advertising audiences or sensitive profiles solely because a visitor accessed content about depression, suicide, trauma, addiction, psychiatric disorders, medication, or another mental-health topic.
Sharing with Third Parties
Mental Health Board Org does not have, as its stated institutional purpose, the commercial sale of readers' personal information.
Personal information may be disclosed on a limited basis to providers necessary for website operation, including hosting, cybersecurity, email, forms, content delivery, backups, analytics, and technical infrastructure.
Each provider may act as a service provider, processor, contractor, independent business, or controller according to the applicable law and actual contractual arrangement.
Only information reasonably necessary for the relevant purpose should be disclosed.
Related Editorial Projects
The website may reference or link to other mental health, psychoanalytic, educational, or institutional projects.
A shared subject, brand family, link, editorial relationship, or related domain does not automatically establish that multiple websites are the same legal entity or that personal information may be freely exchanged among them.
Cross-domain data sharing should occur only where an appropriate purpose, transparency mechanism, security arrangement, and legal basis exist.
Authorities and Legal Requirements
Information may be disclosed where required by applicable law, valid judicial process, regulatory demand, law-enforcement request supported by appropriate authority, or the establishment, exercise, or defence of legal rights.
International Data Transfers
Because the website is internationally accessible, service providers may process personal information in the United States or other countries.
Where GDPR applies to a transfer outside the European Economic Area, an appropriate mechanism under Articles 44 through 49 will be considered, including an adequacy decision, Standard Contractual Clauses, or another legally available mechanism.
Where UK GDPR applies, the corresponding international-transfer safeguards will be considered independently.
Where Brazilian LGPD applies to a specific operation, Articles 33 through 36 and applicable regulations will be observed.
Where Peru's Law No. 29733 applies, relevant international-transfer and data-security requirements will be considered.
International processing does not eliminate obligations concerning security, transparency, purpose limitation, and data minimisation.
Retention and Deletion
Personal information will be retained only for as long as reasonably necessary for the purpose for which it was processed, subject to applicable legal, security, editorial, evidentiary, and rights-protection requirements.
General correspondence may be retained for a reasonable period necessary to respond, document editorial interactions, prevent abuse, or protect legal rights.
Records concerning institutional standards, editorial reviews, source verification, authorship, corrections, copyright permissions, or policy-version history may be retained where reasonably necessary.
Sensitive health information unnecessarily included in ordinary correspondence should be minimised or deleted where technically and legally appropriate.
Where COPPA applies, children's personal information will not be retained longer than reasonably necessary for the purpose for which it was collected, subject to applicable requirements.
Where the CCPA applies, deletion requests will be handled subject to applicable statutory exceptions.
Where GDPR applies, the storage-limitation principle under Article 5 will be observed.
Rights of Individuals
California Privacy Rights
Where the CCPA applies, eligible California consumers may have rights including:
- the right to know the categories and specific pieces of personal information collected, subject to applicable requirements;
- the right to request deletion, subject to statutory exceptions;
- the right to request correction of inaccurate personal information;
- the right to opt out of sale or sharing of personal information where applicable;
- the right to limit certain uses and disclosures of sensitive personal information where the statutory conditions apply;
- the right to receive required information concerning purposes, categories of sources, and categories of recipients;
- the right not to receive unlawful discriminatory treatment for exercising applicable privacy rights.
Automated Processing
Where current California regulations concerning automated decisionmaking technology apply to a covered business and activity, applicable notice, access, opt-out, risk-assessment, or other requirements will be assessed.
Mental Health Board Org is not intended to make automated clinical diagnoses, treatment decisions, professional licensing determinations, disciplinary findings, or eligibility decisions about website visitors.
European Rights
Where the GDPR applies, individuals may have rights under Articles 12 through 22, including access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and safeguards concerning certain automated decisions.
Where UK GDPR applies, corresponding rights will be respected.
Other Applicable Rights
Where Brazilian LGPD applies, rights under Article 18 will be observed.
Where Peru's Law No. 29733 applies, corresponding rights will be respected according to the statutory conditions.
How to Exercise Your Rights
Privacy requests may be submitted to dr.thomasrivera@mentalhealthboard.org.
Reasonable verification may be required to prevent unauthorised access, alteration, disclosure, or deletion of personal information.
The website should not request excessive verification information where a less intrusive method is reasonably sufficient.
Requests will be evaluated according to the law applicable to the relevant person and processing activity.
Where applicable law permits an authorised agent to submit a request, reasonable evidence of authority may be requested.
If a request cannot be granted in whole or in part, the reason may be provided where required or appropriate under applicable law.
Information Security
The website seeks to maintain reasonable technical and organisational safeguards appropriate to the nature and risk of the personal information processed.
Measures may include HTTPS, software updates, authentication controls, administrative-access restrictions, least-privilege practices, backups, malware and abuse protection, technical logging, and service-provider review.
Identifiable patient records, psychotherapy notes, psychiatric records, psychological assessments, or clinical case files must not be used as ordinary editorial, website-development, demonstration, analytics, or artificial-intelligence test data.
No Internet-connected system can be guaranteed completely secure.
Security is therefore treated as an ongoing process involving prevention, detection, response, recovery, and improvement.
Where California cybersecurity-audit or risk-assessment regulations apply to a covered business and processing activity, corresponding compliance requirements should be implemented according to their applicable scope and schedule.
Where a security breach triggers federal or state notification requirements, affected individuals and competent authorities will be notified according to applicable law.
Health Information Breach Rules
The website is not designed as a vendor of personal health records or as a health application collecting consumer health records.
If future functionality causes the operator to fall within the scope of the Federal Trade Commission Health Breach Notification Rule, including by offering or maintaining covered personal health records or related functionality, the resulting obligations must be assessed before that functionality is launched.
Children and Minors
The website is intended primarily for adult professionals, academics, educators, policy readers, and members of the general public interested in mental health and ethics. It is not designed primarily as a service directed to children under 13.
Under the Children's Online Privacy Protection Act and 16 CFR Part 312, specific requirements apply to covered websites and online services directed to children under 13 and to certain operators with actual knowledge that they are collecting personal information online from a child under 13.
The website does not intentionally solicit personal information from children under 13 through ordinary institutional or editorial functionality.
Where verifiable parental consent is legally required, a child's unsupported representation will not replace the required parental-consent procedure.
If the website learns that information was collected from a child under 13 in circumstances requiring action under COPPA, appropriate steps will be taken according to applicable law.
Where covered disclosures for targeted advertising or other third-party purposes require separate verifiable parental consent under the applicable COPPA Rule, that requirement must be respected.
Children and adolescents should not be encouraged to publicly disclose diagnoses, self-harm, suicidal thoughts, abuse, sexual information, psychiatric treatment, medication, family conflict, or other sensitive information through ordinary website forms or comments.
Where GDPR or UK GDPR rules concerning children's personal data apply to a particular service, the applicable age, transparency, consent, and child-protection requirements will also be considered.
Changes to this Policy
This Policy may be revised in response to changes in law, regulations, technology, website functionality, institutional activities, or privacy practices.
The Policy should be reassessed before implementing accounts, professional directories, credentialing, certification, disciplinary complaints, clinical tools, questionnaires, assessments, newsletters, paid services, behavioural advertising, artificial intelligence assistants, patient portals, health applications, or formal research involving identifiable participants.
If the website begins collecting clinical information, issuing professional credentials, processing complaints against practitioners, operating a personal health record, conducting patient assessment, or offering treatment functionality, a separate legal, regulatory, privacy, and professional-licensing review must occur before launch.
The current version will be made available on the website.
Supervisory and Enforcement Authorities
In the United States, privacy, health-data, advertising, and consumer-protection matters may fall within the jurisdiction of the Federal Trade Commission, state Attorneys General, the California Privacy Protection Agency where applicable, and other competent federal or state authorities according to statutory scope and subject matter.
Where the CCPA applies, California authorities may have jurisdiction over applicable privacy matters.
Where the GDPR applies, individuals may have the right to lodge a complaint with a competent European supervisory authority.
Where UK GDPR applies, the competent United Kingdom data-protection authority may have jurisdiction.
Where Brazilian LGPD applies, the Brazilian National Data Protection Authority may have jurisdiction.
Where Peruvian data-protection law applies, the competent Peruvian personal-data protection authority may have jurisdiction.
Contact
Questions concerning this Privacy Policy or privacy rights may be submitted to:
Mental Health Board Org
Website: https://mentalhealthboard.org
Editorial and institutional contact: Dr. Thomas Rivera.
Email: dr.thomasrivera@mentalhealthboard.org
Nature of the website: digital institutional, educational, ethics, standards, and mental health information project.
Primary jurisdiction: USA.
Last Updated
Original effective date: May 17, 2020.
Legal consolidation of this version: September 2, 2026.