Privacy Policy
Privacy, Data Protection and Record-keeping policy.
I am committed to offering a safe, respectful and confidential therapy space. This policy outlines how your data is used and protected in line with the Data Protection Act, 2018, GDPR, Data Use and Access Act (DUAA) 2025 and in accordance of the BACP Ethical Framework. I am registered with the Information Commissioners Office (ICO) as a data controller, registration number ZB667898.
My intention is to be transparent about how your information is handled and to ensure it is treated with care, dignity and professionalism.
What information I collect
To provide safe and effective therapy, I collect only the information necessary for our work together including:
- Your name and contact details.
- Your GP and emergency contact information
- Relevant background or health information you choose to share
- Brief, factual therapy notes recorded under an anonymous identifying code.
- Email, or text correspondence relating to appointments or therapy.
I do not use your information for marketing or share with third parties for commercial purposes.
How your information is stored:
Your information is stored securely in the following ways:
Contact details:
- held separately from therapy notes in encrypted or password protected digital form.
Therapy notes:
- recorded under an anonymous code (not your name)
- Contain brief, factual information to support safe, therapeutic practice.
- Stored securely and separately from personal data.
Digital Communication:
- Emails and text messages may be held on password-protected devices with up-to-date security software.
Paper records:
- Kept in a locked cabinet.
- Only I have access to these records unless required by law or ethical obligations such as Clinical Will.
How long your information is kept for:
In accordance with professional and legal guidance:
- Therapy notes kept for 7 years after completion of therapy.
- Contact details kept for up to 3 years after therapy ends.
- Emails/texts relating to therapy may be retained for the same duration as notes.
After these periods all data is securely destroyed or deleted.
Confidentiality:
Everything shared in therapy is confidential, except in the following circumstances:
Clinical Supervision:
- I discuss my work with a qualified supervisor as part of ethical practice. Your identity is protected and no identifying details are shared.
Risk of serious harm:
- If I believe you or someone else is at immediate risk of serious harm, I may need to contact appropriate services. I will discuss this with you as appropriately as possible.
Legal requirements:
- I may be required to share information in cases involving:
- Safeguarding of children or vulnerable adults
- Terrorism or serious crime
- Court orders or legal directives.
- Wherever possible I will discuss this with you first.
Unexpected incapacity (Clinical will):
You contact details may be shared with an appointed professional solely to inform you should I become unable to continue practicing.
Your rights:
Under GDPR you have the right to:
- Access a copy of the information I hold about you.
- Request corrections to inaccurate information.
- Request deletion of your data (in certain circumstances).
- Object to how your information is used.
- Request the transfer of data to another provider.
- Raise concerns about your data handling.
Requests must be made in writing and may take up to 30 days to process.
Digital safety:
Steps I take to protect your information are:
- Password-protected devices.
- Updated firewalls and security software.
- Secure digital storage.
- Encrypted communication where appropriate.
- Secure disposal of old records.
If you choose to share personal information via email or text, I will assume you are aware of the associated risks and have made an informed choice.
Email and text/messages should not be used in an emergency.
Questions, concerns or complaints:
If you have any questions about this policy or the way your information is used, you are welcome to discuss it with me at any time via email at clare@shilohtherapy.co.uk. Complaints will be handled within 30 days.
If you have any concerns that cannot be resolved directly with me, you may contact:
The British Association for Counselling and Psychotherapy (BACP)
The Information Commissioner’s Office (ICO)