This Privacy Policy explains how personal data is processed by "NET Tool," software developed by ViaNova Praktijk (vianovapraktijk.nl) and used by therapists during Narrative Exposure Therapy (NET) sessions.
NET Tool is a serverless application by design: the software runs entirely in the user's (the therapist's) own browser, and all data is kept solely in that device's local storage (localStorage). Keeping this architectural feature in mind while reading this policy is important for correctly interpreting the sections below.
This document has been prepared by ViaNova Praktijk, in its capacity as data controller, with regard to the principles of the Turkish Personal Data Protection Law (KVKK) and the EU General Data Protection Regulation (GDPR/AVG).
1. What Data Is Processed
NET Tool processes data for two distinct user groups, each with a different scope:
- Client records: Lifeline symbols entered by the therapist during a session, session notes, testimony texts, and similar clinical content are stored only in the browser storage (localStorage) on the therapist's own device. These records are linked not to the client's name or identity, but to an anonymous code (client code) chosen by the therapist. Neither ViaNova Praktijk nor any other third party can remotely access this data, because it is never transmitted outside the therapist's device.
- Site visitor/user preferences: The language preference (Turkish/English/Dutch/German/Arabic) and cookie/consent preference of the therapist using the application are likewise stored only in that person's own browser via localStorage, and contain no identifying information.
- NO server logs or analytics data are collected: although the application's static files are served through a hosting provider, no analytics tool, cookie-based tracking, IP-based logging, or similar mechanism that monitors user behavior has been deliberately set up on that service. No data within the application is transmitted to ViaNova Praktijk's servers or to any third party's servers.
2. No Data Sent to a Server, and the "Local-First" Architecture
No client data entered into NET Tool is transmitted over the network to any server, cloud, or third-party service. Data is kept only in the browser (localStorage) of the device the therapist uses, and optionally in a local backup file the therapist chooses to store in a folder on their own computer.
This "local-first" architecture is not a preference but a design choice: the application has no server, no database, and no real-time communication layer (WebRTC/realtime).
This approach was not chosen at random. The European Data Protection Supervisor (EDPS) specifically recommends, for mobile health (mHealth) applications, keeping data on the device wherever possible and avoiding transfer to central servers, as a privacy-by-design method. The architecture of NET Tool is consistent with this recommendation.
However, an important caveat applies: the fact that data is not sent to a server does NOT mean that GDPR/AVG or KVKK do not apply. Wherever personal data is stored — on a server, in the cloud, or on a computer's local disk — this constitutes "data processing" under the relevant legislation. Accordingly, even when data remains on the therapist's own device, the collection, storage, and deletion of a client's special-category data remain subject to the relevant obligations under KVKK and GDPR/AVG.
3. The Nature of Client Data Under KVKK and the Consent Obligation
Under Article 6 of KVKK, information relating to a person's health and psychological condition is classified as "special category personal data." The Lifeline symbols, session notes, and testimony texts entered into NET Tool by the therapist fall into this category, as they contain information about the client's trauma history and psychological processes.
For special category personal data to be processed, KVKK requires either the explicit consent of the data subject or the existence of one of the limited exceptions set out in the law. The NET Tool software does not collect, store, or verify this consent on the client's behalf; the software is merely a tool used by the therapist within their own clinical practice.
For this reason: the therapist (user) using NET Tool is personally responsible for ensuring that the client has been informed that such data will be processed by a digital tool (including its recording, storage, and deletion where necessary) and that the client's explicit consent has been properly obtained. ViaNova Praktijk, as the party supplying the software, is not a party to this consent process and does not intervene in the clinical relationship between the client and the therapist.
4. User Rights and Their Practical Application in the Context of Local Storage
KVKK and GDPR/AVG grant data subjects rights such as access to their data, and the correction and deletion of that data. Because NET Tool's architecture keeps data directly on the therapist's device rather than on a central server, these rights are exercised in a way that differs from — but is more direct than — the classic process of "submitting a request to a company":
- Right of access: All data belonging to a client is already viewable directly on the therapist's own screen; in addition, the application's export feature can turn a client's records into a readable file that can be shared with them.
- Right of rectification: The therapist can edit Lifeline symbols, session notes, or other records directly from within the application interface, without needing the approval of any third party or any processing period.
- Right of erasure: When a client's records are deleted from within the application, that data is removed from that browser's localStorage. To fully carry out a deletion request, the therapist must additionally check: (a) clearing browser history/site data (via the browser's "clear site data" settings), (b) deleting or updating any older backup files in the local auto-backup folder, if one has been enabled, and (c) removing any exported backup files from the device or from external storage media.
- Portability: Thanks to the export feature, a client's data can be delivered as a structured file to the client or another authorized party upon request.
- Withdrawal of consent: A client may, through a request to their therapist, withdraw their consent to the digital processing of their data at any time; the therapist should then carry out the deletion steps described above.
- Right to complain: If you believe your personal data has been processed in a way that violates this policy or applicable law, you have the right to lodge a complaint with a supervisory authority — in Turkey, the Personal Data Protection Authority (kvkk.gov.tr), or, if you are based in an EU member state, your national data protection authority (for the Netherlands: the Dutch Data Protection Authority, Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl).
The actual exercise of these rights depends on the therapist operating the application carrying out these steps correctly; therapists are therefore advised to fulfil client requests within a reasonable time and to manage their local backups accordingly.
5. Data Controller and Contact
The data controller under this Privacy Policy is ViaNova Praktijk, based in the Netherlands.
For questions about how NET Tool operates, the content of this policy, or the processing of personal data, you can contact ViaNova Praktijk via vianovapraktijk.nl.
Requests concerning the direct deletion, correction, or access of client data should be directed to the relevant therapist, since the data is in fact held on that therapist's own device; ViaNova Praktijk has no technical means of accessing this data.
6. Policy Updates
This Privacy Policy may be revised from time to time in line with changes in legal regulations or updates to the functionality of NET Tool.
This policy was last updated on: July 7, 2026.