Data Protection and Privacy Policy
Maintaining safe protection and privacy of personal information is a vital part of my practice. This document describes my data protection and privacy policy, in line with good practice and relevant legislation, including General Data Protection Regulations (GDPR) 2018
I collect and keep some personal information from my clients. The purpose of this is to record who I am seeing and ensure that I am practicing effectively and am able to communicate with clients as necessary for our work. I keep our contract, brief notes of our sessions, your contact details (name, address, phone number, email address, relevant emails and messages as recommended by professional bodies and insurers.
I take the following measures to ensure your information is stored securely:
- Paper documents are kept in a locked filing cabinet.
- The therapy contract signed at the beginning of our work is stored separately to session notes.
- Session notes do not contain any information that would identify you or others you discuss in session.
- Email addresses and phone numbers are kept on password protected devices only.
- When information is no longer required it is deleted or shredded.
- Paper records are kept for 7 years after the therapy has ended in accordance with professional and insurance guidelines.
There are limits to the protection of private information where disclosure is legally mandated and/or concerns of child protection and significant risk of harm to self or others.
In the unlikely event of a personal data breach I will inform you as soon as possible, record it and report it within 72 hours to the relevant supervisory authority.
How to complain
If you have any concerns about my use of your personal data, you can make a complaint directly to me via my contact page.
If you remain unhappy with how I have used your data after raising your complaint with me, you can also complain to the ICO
