Privacy Policy
1. Purpose of This Notice
This privacy notice explains how your personal information is collected, used, stored, and protected in accordance with the Data Protection Act 2018 and the General Data Protection Regulation (GDPR, 2018). It outlines your rights and how your data is handled throughout the course of therapy.
2. Data Controller
The therapist is the data controller responsible for the personal information you provide. You may request information about how your data is used or stored at any time.
3. Information Collected
The following information may be collected and stored:
-
Name and contact details
-
Emergency contact information
-
Relevant personal or health information shared during assessment
-
Brief session notes
-
Email or text correspondence related to therapy
-
Payment records (not including full bank details)
Only information necessary for safe, ethical, and effective therapy is collected.
4. Why Your Data Is Collected
Your data is collected for the following purposes:
-
To provide counselling or psychotherapy services
-
To maintain accurate clinical records
-
To ensure your safety and wellbeing
-
To meet legal, ethical, and professional obligations
-
To contact you regarding appointments or changes
-
To process payments
5. Session Notes
Brief notes may be taken after each session. These notes are stored securely and used solely for therapeutic reflection, continuity of care, and professional supervision. Notes do not include detailed transcripts of sessions or identifiable information.
6. Confidentiality and Exceptions
All information shared in therapy is confidential. However, confidentiality may need to be broken if:
-
You infer involvement in or knowledge of terrorism, money laundering, or drug trafficking
-
You disclose information suggesting harm or neglect to children or vulnerable adults
-
You give explicit consent for information to be shared
-
The therapist is legally required to disclose information (e.g., subpoenaed by a court)
-
There is serious concern for your own safety or the safety of others
Where possible, this will be discussed with you beforehand.
7. Clinical Supervision
The therapist attends regular clinical supervision as part of ethical practice. Client material may be discussed, but all clients are kept fully anonymous, and no identifying details are shared.
8. How Your Data Is Stored
Your data is stored securely in accordance with GDPR requirements:
-
Digital records are password‑protected
-
Paper records (if used) are kept in locked storage
-
Only the therapist has access to your data
-
Data is not shared with third parties unless legally required or with your explicit consent
-
9. Data Retention
All client data, including session notes, is typically kept for up to 7 years after therapy ends, in line with professional guidelines. After this period, it will be securely destroyed.
10. Your Rights Under GDPR
You have the right to:
-
Access your personal data
-
Request corrections to inaccurate information
-
Request deletion of your data (in certain circumstances)
-
Restrict how your data is processed
-
Request data portability
-
Object to how your data is used
-
Withdraw consent at any time (where consent is the legal basis for processing)
Requests will be responded to within 30 days.
11. Complaints
If you have concerns about how your data is handled, you may raise them directly with the therapist. You also have the right to contact the Information Commissioner’s Office (ICO) at www.ico.org.uk.
12. Professional Standards
The therapist adheres to the British Association for Counselling and Psychotherapy (BACP) Ethical Framework, which includes strict guidance on confidentiality, data protection, and record‑keeping.