top of page

Privacy Policy

Last updated: August 13, 2026

1. About this policy

This policy explains how we collect, use, share, and protect information through our website, our online booking and payment tools, and our email communications. This is not our Notice of Privacy Practices. If you are a client of our counseling practice, the health information we maintain about you in the course of treatment is governed by a separate Notice of Privacy Practices, which you receive at intake. Where the two documents conflict as to your treatment records, the Notice of Privacy Practices controls.

Nothing on this website creates a therapist–client relationship. Please do not send clinical details, crisis information, or sensitive personal history through the website contact form, chat, or email.

If you are experiencing a mental health emergency, call 911 or 988 (Suicide & Crisis Lifeline). Do not use this website to seek emergency help.

 

2. Information we collect

Information you provide directly:

​We collect information you give us when you contact us, book an appointment, or pay for services:

  • Name, email address, and phone number — collected through our contact form, booking page, and newsletter signup. We use this to respond to you and schedule services.

  • Appointment preferences and availability — collected through Wix Bookings, to schedule and confirm appointments.

  • Billing name and address — collected at checkout, to process payment for services.

  • Anything you choose to write in a free-text field — collected through our contact form, chat, or email, and used to respond to your inquiry.

  • Insurance information, if applicable — collected through your intake, and used for verification of benefits and claims.

Payment card numbers. We do not see, receive, or store full payment card numbers. Card data is collected and processed directly by our payment processor, Wix Payments. We receive only a confirmation, the last four digits, and the card brand.

​Information collected automatically:

When you visit maria-jose.com, our website platform automatically collects:

  • IP address and approximate geographic location (typically city-level)

  • Browser type, device type, and operating system

  • Pages viewed, time on page, and the site or link that referred you

  • Date and time of your visit

  • Cookie and similar identifiers (see Section 6)

Information from other sources: 

If you contact us through a third-party directory or platform — for example, Psychology Today, a health plan directory, or a social media message — we receive whatever information that platform passes to us.

 

3. How we use your information

We use the information above to:

  • Respond to inquiries and schedule, confirm, and remind you of appointments

  • Provide counseling services and maintain the records required of a licensed practitioner

  • Process payments and, where applicable, submit insurance claims

  • Send administrative messages about your appointments or account

  • Send newsletters or practice updates, only if you have opted in (you can unsubscribe at any time)

  • Operate, secure, maintain, and improve the website

  • Comply with legal, licensing, and professional obligations

We do not sell your personal information, and we do not share it with third parties for their own advertising or marketing purposes.

 

4. How we share your information

We share personal information only in the following circumstances.

Service providers:

We use vendors to run the practice. They may access personal information only to perform services for us, and are contractually restricted from using it for their own purposes.

  • Wix.com Ltd. — website hosting, forms, scheduling (Wix Bookings), email, and analytics

  • Wix Payments — payment processing

  • Manual records— clinical records, telehealth, and billing

  • Wix — newsletters

Health information and treatment records:

Protected health information is shared only as permitted or required by the Health Insurance Portability and Accountability Act (HIPAA) and Massachusetts law, including M.G.L. c. 112, § 129A / 135A, and as described in our Notice of Privacy Practices. This includes limited circumstances where disclosure is legally required or permitted without your authorization, such as:

  • A serious and imminent threat to your safety or the safety of an identifiable other person

  • Suspected abuse or neglect of a child, elder, or person with a disability, consistent with Massachusetts mandated reporter obligations

  • A valid court order or subpoena, subject to applicable privilege

  • Certain public health and health oversight activities

Business transfer:

If the practice is sold, merged, or transferred, client records may transfer to the successor practice, subject to Massachusetts law governing the transfer and custodianship of health records and to advance notice where required.

 

5. Legal and regulatory framework

We handle personal information in accordance with:

  • HIPAA (45 C.F.R. Parts 160 and 164), as applicable to our practice

  • M.G.L. c. 93H — Massachusetts data breach notification

  • 201 CMR 17.00 — Massachusetts Standards for the Protection of Personal Information of Residents of the Commonwealth

  • M.G.L. c. 93A — Massachusetts consumer protection

  • M.G.L. c. 112, § 129A / 135A] and [262 CMR / 258 CMR  — professional confidentiality and recordkeeping standards

 

6. Cookies and website tracking

Our website uses cookies and similar technologies. Essential cookies are required for the site to function — they keep your session active, secure forms, and remember your cookie choices. These cannot be turned off. Functional cookies remember your preferences, such as language. You can manage non-essential cookies through the banner on your first visit, through the "Cookie Settings" link in our footer, or through your browser settings. Blocking essential cookies may prevent parts of the site from working. Do Not Track. Our website does not currently respond to browser "Do Not Track" signals. We do honor Global Privacy Control (GPC) signals where required by law.

 

7. How we protect your information

We maintain a Written Information Security Program (WISP) as required by 201 CMR 17.00, which includes administrative, technical, and physical safeguards appropriate to the size and scope of our practice. These include:

  • Encryption of personal information in transit (TLS/SSL) and at rest

  • Multi-factor authentication on all accounts that can access personal information

  • Access limited to those who need the information to perform their role

  • A signed Business Associate Agreement with each vendor that handles protected health information on our behalf

  • Ongoing monitoring, and a documented response plan for security incidents

No method of transmission or storage is completely secure. Email and web forms are not secure channels. Please call me directly for anything clinical or sensitive.

 

8. Data breach notification

If we discover a breach of security involving your personal information, we will notify you and the Massachusetts Attorney General and Office of Consumer Affairs and Business Regulation as required by M.G.L. c. 93H, without unreasonable delay. If the breach involves protected health information, we will also notify you, the U.S. Department of Health and Human Services, and where applicable the media, as required by the HIPAA Breach Notification Rule.

9. How long we keep information

We keep different categories of information for different periods:

  • Clinical and treatment records — 7 years from the date of last service, consistent with [YOUR BOARD'S REGULATION]. For clients who were minors at the time of service, 7 years from the date the client reaches age 18, whichever period is longer.

  • Billing and financial records — 7 years, for tax and audit purposes.

  • Website inquiries that do not become clients — 12 months.

  • Newsletter subscriber records — until you unsubscribe, plus a suppression record so we don't add you back by mistake.

  • Website analytics data — 14 months, in aggregate or de-identified form.

 

10. Your choices and rights

Regardless of where you live, you may:

  • Access your treatment records. Request a copy of the health information we maintain about you, as provided under HIPAA and Massachusetts law. Requests should go to mariajosesessions@gmail.com

  • Request a correction to information you believe is inaccurate.

  • Unsubscribe from marketing email using the link in any newsletter, or by emailing us. This does not stop appointment reminders or administrative messages.

  • Manage cookies as described in Section 6.

  • Ask us questions about this policy at any time.

Massachusetts residents. Massachusetts does not currently have a comprehensive consumer data privacy law, though legislation is pending. We honor the access, correction, and deletion requests described above as a matter of practice, and will update this policy if and when a Massachusetts law takes effect. Note that we cannot delete clinical or billing records that we are legally required to retain.

Residents of other states.] If you live in a state with a comprehensive privacy law — such as California, Colorado, Connecticut, or Virginia — you may have additional rights, including the right to access, delete, correct, or obtain a portable copy of your personal information, and the right to opt out of sale or targeted advertising. We do not sell personal information or use it for targeted advertising. To exercise any right, contact us at mariajosesessions@gmail.com. We will not discriminate against you for exercising these rights. You may appeal a denial by writing to the same address.

Visitors outside the United States. Our services are intended for people located in the United States, and information is stored and processed in the United States. 

 

11. Children's privacy

This website is not directed to children under 13, and we do not knowingly collect personal information from children under 13 through the website. If you believe a child has provided us with information through the site, contact us and we will delete it.

When we provide counseling to minors, information is handled in accordance with Massachusetts law governing consent to treatment and parental access to records, which, in some circumstances, limits what may be disclosed to a parent or guardian. This is discussed with families at intake.

 

12. Links to other websites

Our site may link to third-party sites, such as directories, resources, or a scheduling tool. We are not responsible for their privacy practices. Please review their policies before providing information.

 

13. Changes to this policy

We may update this policy. The "Last updated" date at the top will change, and material changes will be posted prominently on this page. Where required, we will notify you directly.

14. Contact us

María-José García Anguiano
West Newbury, MA
mariajosesessions@gmail.com

You may also contact the Massachusetts Office of Consumer Affairs and Business Regulation, or, for health information concerns, the U.S. Department of Health and Human Services Office for Civil Rights at hhs.gov/ocr/complaints.

bottom of page