top of page

Privacy policy

What personal data I collect and why I collect it:

Data protection law (GDPR) states that individuals have the right to be informed as to how their personal data is held and used. This privacy notice explains the personal information I collect from you as my client, as well as how I store, process and delete it. As a private practitioner I act as both:

  • Data Controller (which means that I plan procedures regarding how data is held according to the GDPR regulations), and

  • Data Processor (which means that I collect and store data required within my therapy practice).

​

We begin by setting a working agreement in place that explains my commitment to client confidentiality and data protection, as well as when confidentiality may be breached. I need you to sign an agreement to this effect before we commence therapy

I will collect personal details from you, as shown here: name; date of birth; address; contact number; email address; contact details for an emergency contact for use if something were to happen to you on my premises; contact details for your GP, for use with your permission; details of any relevant mental or physical health issues and medication. 

​

Storage of Personal Details:

The above personal details are stored in a secure file, accessed only by myself. Session notes (brief summaries of our sessions) are also stored in a secure file, accessed only by myself. These are kept completely separately from your personal details and within these session notes you are known only by your initials so that your anonymity is preserved.  

I keep a diary to manage my appointments, and you will be referred to within this only by your initials. This diary is stored separately from your personal details and session notes. I do not store any of this information on a joint computer or use cloud-based storage. I use a mobile phone to receive client phone calls and text messages. I use only your initials, and my phone is password protected. I use a password-protected computer for receipt of emails from clients. This email account is separate from my personal email account.

 

Deletion of your Personal Details:

I will keep your personal details for six months after psychotherapy has ended in case we have any outstanding administrative issues, or you choose to return. After this time, they are destroyed. Your session notes are kept for seven years in line with HCPC recommendations. After this time, they are then destroyed. Any text messages (sent and received) and any emails (sent and received) will also be deleted 6 months (or earlier) after therapy has ended.

 

Sharing of your Personal Details:

Supervision: In line with the requirements of my professional body, the UKCP, my work is regularly supervised by a qualified supervisor.  Their role is to ensure that I work ethically and professionally. You are referred to by your first name only in supervision, and conversations between myself and my supervisor are confidential.

​

I have appointed a therapeutic executor to contact and inform my clients in the event of my sudden illness or demise.  This executor is a qualified arts psychotherapist and is committed to client confidentiality. 

 

Exceptions to Confidentiality:

If I have reason to believe that you or someone else is at risk of serious harm, I will break confidentiality. I would endeavour to discuss this breach with you first so that we could come to an agreement about who needed to be informed. However, if an agreement is not reached and I still believe that you or someone else is at risk, I will discuss the situation with my supervisor and decide how to proceed. Where a threat of terrorism or drug trafficking is disclosed, I am obliged by law to inform the authorities.

 

Your Rights:

In accordance with GDPR, you have the following rights:

  • To be informed of the information that I store about you.

  • To ask to see the information that I hold about you. I am legally required to respond to any request from a client in writing to see their personal data within 30 days.

  • To ask that I rectify any information that you deem inaccurate, unnecessary, or incomplete (if I need to keep a record to comply with legal requirements then I may decline this request).

 

​

bottom of page