Be Kind To Yourself Therapy
Privacy Notice (UK GDPR & Data Protection Act 2018)
Version: 2.0
Effective Date: 18th July 2026
Review Date: 18th July 2027
Document Owner: Be Kind To Yourself Therapy
Document Control
Version: 1.0
Date: 10 October 2025
Author: Be Kind To Yourself Therapy
Changes: Original Version
Version: 2.0
Date: 18th July 2026
Author: Be Kind To Yourself Therapy
Changes: Comprehensive review to include online therapy, couples therapy, workshops, GDPR enhancements and ICO compliance
Contents
1. Introduction
2. Who We Are
3. Our Commitment to Privacy
4. The Information We Collect
5. Special Category Data
6. How We Collect Your Personal Information
7. Why We Process Your Information
8. Our Lawful Basis for Processing
9. Individual Therapy
10. Couples Therapy
11. Online Therapy
12. Face-to-Face Therapy
13. Workshops, Masterclasses and Group Programmes
14. Children and Young People
15. Clinical Records
16. Confidentiality
17. Clinical Supervision
18. Who We May Share Your Information With
19. Third Party Service Providers
20. International Transfers
21. Email Communications
22. Marketing Communications
23. Website and Cookies
24. Social Media
25. Photography and Recording
26. Artificial Intelligence (AI)
27. Data Security
28. How Long We Keep Your Information
29. Your Rights
30. Subject Access Requests
31. Correcting Your Information
32. Withdrawing Consent
33. Data Breaches
34. Complaints
35. Changes to This Privacy Policy
36. Contact Us
1. Introduction
At Be Kind To Yourself Therapy, protecting your privacy is fundamental to the therapeutic relationship.
Psychotherapy is built upon trust, professionalism and confidentiality. We understand that you are entrusting us with highly personal and sensitive information and we take that responsibility extremely seriously.
This Privacy Notice explains how we collect, use, store, protect and share your personal information when you:
enquire about our services;
- attend individual psychotherapy;
- attend couples therapy;
- participate in online therapy;
- attend face-to-face sessions;
- book workshops or masterclasses;
- participate in group programmes;
- visit our website;
- subscribe to our newsletter; or
- otherwise communicate with us.
We process personal data in accordance with:
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018
- Privacy and Electronic Communications Regulations (PECR)
- Human Rights Act 1998
- Information Commissioner's Office (ICO) guidance
- National Counselling & Psychotherapy Society (NCPS) Code of Ethical Practice
Our aim is to be transparent about what information we collect, why we collect it, and how we protect it.
2. Who We Are
Practice Name: Be Kind To Yourself Therapy
Data Controller: Be Kind To Yourself Therapy
Address: Westow Street, Crystal Palace, London SE19
Telephone: 07958127963
Email [email protected]
Website www.bekindtoyourselftherapy.com
ICO Registration Number: ZA301829
As the Data Controller, we determine how and why your personal information is processed.
3. Our Commitment to Privacy
We are committed to ensuring that your information is:
- processed lawfully, fairly and transparently;
- collected only for legitimate therapeutic and business purposes;
- accurate and kept up to date;
- limited to information that is necessary;
- protected by appropriate technical and organisational security measures;
- retained only for as long as necessary; and
- disposed of securely when no longer required.
Confidentiality is one of the cornerstones of psychotherapy. Whilst confidentiality is not absolute, any disclosure of information will only occur where legally required, ethically justified, or necessary to protect life or prevent serious harm.
4. The Information We Collect
Depending upon the services you receive, we may collect different categories of personal information.
- Identity Information
This may include:
- Full name
- Preferred name
- Previous names (where relevant)
- Date of birth
- Gender or preferred pronouns (if you choose to provide them)
Contact Information
Including:
- Home address
- Email address
- Telephone number
- Preferred method of communication
- Emergency Contact Information
Including:
- Name
- Relationship
- Telephone number
- Emergency contacts will only be used where it is considered clinically appropriate or necessary to protect your safety.
- Medical Information
Where relevant to therapy we may collect information including:
- GP details
- Medication
- Mental health diagnoses
- Previous counselling or psychotherapy
- Relevant physical health conditions
- Hospital admissions
- Current healthcare professionals
- Risk assessments
- Therapy Information
During therapy we may collect information concerning:
- Presenting difficulties
- Therapy goals
- Clinical observations
- Progress notes
- Risk management
- Session summaries
- Correspondence relating to therapy
- Clinical notes are intentionally concise and contain only information considered necessary for the safe and effective delivery of therapy.
- Financial Information
Where applicable we collect:
- Fees paid
- Outstanding balances
- Invoice history
- Payment references
We do not store debit or credit card details.
- Workshop and Event Information
If you attend workshops, courses or masterclasses we may collect:
- Booking details
- Attendance records
- Accessibility requirements
- Dietary requirements (for in-person events)
- Feedback questionnaires
- CPD records
- Certificates issued
- Website Information
When you visit our website we may collect:
- IP address
- Browser type
- Device information
- Website usage statistics
- Cookies
- Enquiry form submissions
5. Special Category Data
As a psychotherapy practice, we routinely process Special Category Data under Article 9 UK GDPR.
This may include information relating to:
- mental health;
- emotional wellbeing;
- trauma;
- abuse;
- relationships;
- bereavement;
- addiction;
- physical health;
- neurodiversity;
- disabilities;
- religious or spiritual beliefs where relevant to therapy;
- sexual wellbeing where clinically appropriate.
This information receives the highest level of protection and is only processed where necessary for the provision of psychotherapy or where another lawful basis applies under UK GDPR.
6. How We Collect Your Personal Information
We collect personal information in several ways depending on the services you receive.
Information You Provide
You may provide information directly when you:
- complete an enquiry form;
- telephone or email us;
- book an appointment;
- complete an assessment questionnaire;
- attend an initial consultation;
- participate in therapy;
- attend a workshop or masterclass;
- subscribe to our newsletter;
- complete feedback forms;
- correspond with us.
Information Collected During Therapy
Throughout the therapeutic relationship we may record information arising from:
- assessment sessions;
- therapy sessions;
- clinical observations;
- treatment planning;
- risk assessments;
- safeguarding concerns;
- reviews;
- correspondence between appointments.
Clinical records are intentionally concise and only include information necessary to provide safe and effective psychotherapy.
Information Received From Others
With your knowledge and consent, or where otherwise permitted by law, we may receive information from:
your GP; psychiatrists; psychologists; social workers; other healthcare professionals; previous therapists; insurers (where applicable); legal representatives (where appropriate).
Except where required by law, we will not obtain information from third parties without your consent.
7. Why We Process Your Information
We process personal information for a number of legitimate purposes.
These include:
- assessing whether therapy is appropriate;
- providing psychotherapy services;
- maintaining accurate clinical records;
- arranging appointments;
- communicating with you;
- safeguarding you or others where necessary;
- maintaining professional supervision;
- complying with legal and regulatory obligations;
- processing payments;
- issuing invoices;
- managing workshops and masterclasses;
- responding to enquiries;
- improving our services;
- managing complaints;
- maintaining insurance requirements.
8. Our Lawful Basis for Processing
Under Article 6 UK GDPR we rely upon one or more of the following lawful bases.
Contract
Most personal information is processed because it is necessary to fulfil our contract with you by providing psychotherapy or related services.
Examples include:
- booking appointments;
- maintaining records;
- communicating about sessions;
- processing payments.
Legal Obligation
Some information must be processed to comply with legal obligations.
Examples include:
- safeguarding duties;
- court orders;
- taxation requirements;
- anti-money laundering obligations (where applicable);
- insurance requirements.
Legitimate Interests
We also process information where necessary for our legitimate professional interests.
This includes:
- clinical supervision;
- quality assurance;
- maintaining secure records;
- improving our services;
- protecting our legal rights.
Consent
Some processing activities rely upon your consent.
Examples include:
- newsletter subscriptions;
- marketing communications;
- testimonials;
- photographs taken during workshops;
- sharing information with another healthcare professional where not otherwise required.
You may withdraw your consent at any time.
Withdrawal of consent will not affect processing that has already lawfully taken place.
9. Individual Therapy
Information collected during individual therapy is used solely for the purpose of providing professional psychotherapy.
We maintain concise clinical records to support continuity of care, clinical reflection and professional accountability.
Clinical notes are not verbatim transcripts of sessions.
They are brief professional records designed to support safe therapeutic practice.
10. Couples Therapy
Couples therapy involves two individuals participating in one therapeutic relationship.
Information disclosed by either person during joint sessions forms part of the therapeutic record.
Separate confidential disclosures made outside the joint therapeutic process may affect the continuation of couples therapy.
Where appropriate, separate individual records may also be maintained.
Should one partner subsequently continue therapy individually, a separate therapeutic contract may be required.
Our approach to confidentiality within couples therapy will be discussed fully before therapy begins.
11. Online Therapy
Online therapy provides flexibility while maintaining professional standards.
Sessions may be delivered using secure platforms such as:
- Zoom
- Microsoft Teams
- Google Meet
- other encrypted platforms considered suitable.
Clients are responsible for ensuring they:
- attend from a private environment;
- use a secure internet connection;
- minimise interruptions;
- use headphones where appropriate;
- protect the confidentiality of their surroundings.
- Neither the therapist nor the client may record sessions without prior written agreement.
- Where technical difficulties prevent a session continuing, every reasonable effort will be made to reconnect.
If reconnection is not possible, alternative arrangements will be agreed.
12. Face-to-Face Therapy
Face-to-face sessions take place within a confidential therapeutic environment.
Reasonable measures are taken to ensure privacy and confidentiality during all appointments.
Clients are asked to arrive promptly and respect the privacy of other clients attending the practice.
13. Workshops, Masterclasses and Group Programmes
When attending workshops, masterclasses or group programmes we may process information including:
- registration details;
- attendance records;
- payment information;
- accessibility requirements;
- dietary requirements;
- emergency contact details;
- certificates of attendance;
- CPD records.
Participation in group events does not create a therapeutic relationship unless specifically agreed in writing.
Personal disclosures made during workshops remain confidential between participants; however, complete confidentiality within a group environment cannot be guaranteed.
Participants are expected to respect the privacy of others.
14. Children and Young People
Where services are provided to children or young people, personal information will be processed in accordance with UK GDPR and all applicable safeguarding legislation.
Parental responsibility, consent and confidentiality will be discussed before therapy commences.
The level of confidentiality offered will be appropriate to the child's age, understanding and best interests.
15. Clinical Records
Professional clinical records may include:
- assessment information;
- therapy goals;
- risk assessments;
- safeguarding decisions;
- attendance records;
- session summaries;
- referrals;
- correspondence;
- treatment reviews.
Records are maintained in accordance with professional standards, legal obligations and insurance requirements.
Clinical records remain the property of Be Kind To Yourself Therapy.
16. Confidentiality
Confidentiality forms one of the foundations of psychotherapy.
Everything discussed during therapy is treated as confidential except where disclosure is required or justified by law or professional ethics.
Confidentiality may be breached where:
- there is a serious risk of harm to yourself;
- there is a serious risk of harm to another person;
- safeguarding concerns arise involving a child or vulnerable adult;
- disclosure is required by a Court Order;
- terrorism legislation requires disclosure;
- disclosure is otherwise required by law.
Wherever practicable, we will discuss any proposed disclosure with you beforehand.
17. Clinical Supervision
As required by the National Counselling & Psychotherapy Society, all therapists undertake regular professional clinical supervision.
The purpose of supervision is to ensure safe, ethical and effective practice.
Information shared during supervision is anonymised wherever reasonably possible.
Supervisors are themselves bound by strict confidentiality and professional ethical obligations.
Supervision forms an essential part of safe clinical practice and is considered a legitimate professional activity.
18. Who We May Share Your Information With
Your personal information is treated as confidential and will never be sold, rented or shared for marketing purposes.
We will only share information where it is lawful, necessary and proportionate to do so.
This may include:
- your GP (with your consent or where clinically necessary);
- other healthcare professionals involved in your care;
- our clinical supervisor;
- accountants or auditors (financial information only);
- legal advisers;
- professional indemnity insurers;
- the Information Commissioner's Office (where legally required);
- law enforcement agencies where disclosure is required by law;
- safeguarding authorities where there is a legal or ethical duty.
Where information is shared, only the minimum necessary information will be disclosed.
19. Third Party Service Providers
To operate our practice safely and efficiently, we use carefully selected third-party service providers.
These may include providers of:
- secure email services;
- website hosting;
- appointment booking systems;
- payment processing;
- cloud storage;
- encrypted video conferencing;
- accounting software;
- practice management software.
Examples may include:
- Microsoft 365
- Google Workspace
- Zoom
- Stripe
- SumUp
- Square
- Calendly
- Google Calendar
All providers are expected to process data in accordance with UK GDPR or equivalent data protection legislation.
20. International Transfers
Some technology providers store data outside the United Kingdom.
Where personal data is transferred internationally, appropriate safeguards are in place, including:
- UK International Data Transfer Agreements;
- UK Addendum to Standard Contractual Clauses;
- UK adequacy regulations;
- equivalent contractual safeguards.
We only use providers who demonstrate appropriate security and data protection standards.
21. Email Communications
We may communicate with you using:
- email;
- telephone;
- SMS;
- secure messaging platforms.
Please be aware that although we take reasonable precautions, email cannot be guaranteed to be completely secure.
Clients should avoid including unnecessary sensitive information in emails wherever possible.
Where highly confidential information needs to be exchanged, we may recommend a more secure method of communication.
22. Marketing Communications
If you subscribe to our newsletter or mailing list, we may send you information about:
- workshops;
- masterclasses;
- new services;
- wellbeing resources;
- newsletters;
- practice updates.
Marketing emails are sent only where:
- you have given consent; or
- another lawful basis exists.
You may unsubscribe at any time by:
- clicking the unsubscribe link; or
- contacting us directly.
Your decision to unsubscribe will not affect your therapy.
23. Website and Cookies
Our website uses cookies to:
- improve website functionality;
- remember your preferences;
- analyse visitor behaviour;
- Improve user experience;
- monitor website performance.
Where legally required, you will be asked to consent to non-essential cookies before they are placed on your device.
Our website may also use:
- Google Analytics;
- Google Maps;
- embedded booking calendars;
- security tools;
- spam prevention software.
Further information can be found within our separate Cookie Policy.
24. Social Media
You are welcome to follow Be Kind To Yourself Therapy on social media.
However, to protect your confidentiality:
- we do not accept personal friend requests from clients on private accounts;
- we will not acknowledge you publicly as a client;
- therapy matters should never be discussed via social media messaging.
If you require support regarding your therapy, please contact us through our normal communication channels.
25. Photography and Recording
Photography or filming may occasionally take place during workshops, events or masterclasses.
Photographs that identify individuals will only be taken or used where explicit consent has been obtained.
Therapy sessions are not recorded unless:
- there is a clear clinical reason;
- both parties provide written consent.
Clients may not record sessions without the therapist's prior written permission.
26. Artificial Intelligence (AI)
Be Kind To Yourself Therapy is committed to protecting client confidentiality when using technology.
Identifiable client information will not be entered into publicly available artificial intelligence systems without your explicit informed consent and appropriate safeguards.
Where AI-assisted administrative tools are used, they will not replace professional clinical judgement.
27. Data Security
We take appropriate technical and organisational measures to protect personal information.
These include:
- encrypted devices;
- password protection;
- multi-factor authentication where available;
- secure cloud storage;
- anti-virus software;
- secure backups;
- restricted access;
- locked storage for paper records;
- regular software updates.
Despite these measures, no electronic system can ever be guaranteed completely secure.
Should a significant data breach occur, we will respond in accordance with UK GDPR requirements.
28. How Long We Keep Your Information
Records are retained only for as long as necessary.
Our standard retention periods are:
Record
Retention Period
Therapy records - 7 years after therapy ends*
Couples therapy records - 7 years
Children's records - Until age 25 (or 26 if aged 17 at the end of therapy), or as required by law
Appointment records - 7 years
Financial records - 6 years
Invoices - 6 years
Workshop bookings - 6 years
Masterclass attendance - 6 years
Website enquiries - 12 months
General enquiries - 12 months
Newsletter subscribers - Until consent is withdrawn
Complaints records - 7 years
CCTV (if applicable) - As displayed on site
*Retention periods may be extended where required by legal proceedings, insurance requirements or regulatory obligations.
At the end of the retention period, records will be securely destroyed or permanently deleted.
29. Your Rights
Under UK GDPR you have the right to:
- be informed about how your information is used;
- request access to your information;
- request correction of inaccurate information;
- request deletion where legally appropriate;
- request restriction of processing;
- object to processing in certain circumstances;
- request data portability where applicable;
- withdraw consent where consent is relied upon.
Some rights may be restricted where information must be retained to comply with legal, professional or insurance obligations.
30. Subject Access Requests
You may request a copy of the personal information we hold about you.
Requests should be made in writing by email or post.
Before releasing information, we may ask for proof of identity.
We will normally respond within one calendar month unless legislation permits an extension.
There is normally no charge for a Subject Access Request unless it is manifestly unfounded or excessive.
31. Correcting Your Information
If any information we hold is inaccurate or incomplete, please let us know.
We will correct inaccuracies without undue delay.
32. Withdrawing Consent
Where processing relies upon your consent, you may withdraw that consent at any time.
Withdrawal of consent will not affect processing already carried out lawfully before consent was withdrawn.
33. Data Breaches
If we become aware of a personal data breach that is likely to result in a risk to your rights or freedoms, we will:
- investigate immediately;
- contain the breach;
- assess the risks;
- notify the Information Commissioner's Office where required;
- notify affected individuals where legally necessary;
- review our procedures to reduce future risk.
34. Complaints
If you have concerns about how your personal information has been handled, we encourage you to contact us in the first instance.
We aim to resolve complaints fairly, promptly and respectfully.
If you remain dissatisfied, you have the right to complain to the Information Commissioner's Office.
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
Website: https://ico.org.uk
35. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect:
- changes in legislation;
- changes in professional guidance;
- new services;
- technological developments;
- improvements to our practice.
The most current version will always be available on our website.
36. Contact Us
If you have any questions regarding this Privacy Policy or how we process your personal information, please contact:
Be Kind To Yourself Therapy
Address: Westow Street, Crystal Palace, London SE19 3RY
Telephone: 07958127963
Email: [email protected]
Website: www.bekindtoyourselftherapy.com
ICO Registration Number: ZA301829
Declaration
Be Kind To Yourself Therapy is committed to maintaining the highest standards of confidentiality, professionalism and data protection. We continually review our policies and procedures to ensure compliance with UK legislation, ethical standards and best practice guidance.
Last updated: 10.10.2025
At Be Kind To Yourself Therapy (“we”, “us”, or “our”), your privacy matters to us. This Cookies Policy explains how we use cookies and similar technologies on our website www.bekindtoyourselftherapy.com (“the Site”) to provide a smooth, secure, and personalised experience.
1. What Are Cookies?
Cookies are small text files placed on your device when you visit a website. They help the site function properly, remember your preferences, and improve your browsing experience. Some cookies are essential for the website to work, while others help us understand how visitors use our site so we can improve it.
2. Types of Cookies We Use
Essential (Strictly Necessary) Cookies
These cookies are needed for the website to work securely and properly - for example, to enable you to book sessions through Google Calendar or remember your cookie preferences.
They don’t collect personal information and cannot be switched off.
Performance and Analytics Cookies
We use Google Analytics to understand how visitors use our website, such as which pages are most popular or how long people spend on each page.
This helps us improve our content and user experience. Data is collected in an anonymous and aggregated way.
You can learn more about how Google uses data here: https://policies.google.com/technologies/partner-sites
Functionality Cookies
These cookies help the site remember your choices (like language preferences or accessibility settings) to make your experience smoother and more personal.
3. Cookies Used by Google Calendar
When you use the Google Calendar booking feature on our site, Google may set additional cookies to make that service function properly.
These cookies are controlled by Google and are subject to their own privacy and cookie policies.
You can read Google’s Cookie Policy here: https://policies.google.com/technologies/cookies
4. How You Can Control Cookies
When you first visit our site, you’ll see a banner asking for your consent to use non-essential cookies. You can:
- Accept all cookies
- Reject non-essential cookies
- Or manage your preferences
You can also delete or block cookies at any time by adjusting your browser settings. To do this, check your browser’s “Help” or “Settings” section for guidance.
Please note that blocking some cookies may affect how the site functions.
5. Third-Party Cookies
Some cookies on our site come from trusted third parties, such as Google Calendar and Google Analytics. These are used to deliver certain features or gather analytics data. We don’t control these cookies and recommend checking their respective privacy policies for more information.
6. Updates to This Policy
We may occasionally update this Cookies Policy to reflect changes in how we use cookies or to meet legal requirements. The updated version will always be available on this page with the latest “last updated” date.
7. Contact Us
If you have any questions about how we use cookies or about your data privacy, please get in touch:
www.bekindtoyourselftherapy.com
Copyright 2005 © | Be Kind To Yourself Therapy | Privacy Policy