And as the following website(s) and social media identities:
Suite 236 Maddison House
226 High Street
Croydon, CR9 1DF
There are two sections to the following information:
About your personal data:
When you make an enquiry
The name and contact details you give and the content of your message(s) are retained for three reasons:
When you make an online purchase as a single purchase, a membership or subscription
This is a contract for services. Your contact details are dealt with as above (consent, contract, legitimate reasons) – also these, your purchase history and the payment details (sent to me from Paypal or Stripe) are retained for six years beyond the end of the contract for legal reasons – accounting law.
When you attend a workshop or training
All of the above applies. I also keep record of your attendance, your certificates earned etc., on the legal bases of both contract and legitimate interest – so that I can confirm your certificate status / reissue certification if required, also so that I can send you updates or offers which may be of specific interest to you as an attendee/graduate.
When you work with me 1:1
Client work is different. Dependent on the work, you may wish (or need) to provide personal details of a sensitive nature.
As an intake form these are retained in printed or handwritten format and include your contact details and where appropriate, signature. The sensitive nature of such documents will generally be in relation to health or medical history.
As session notes these are scant memos handwritten by me for the sole purpose of fulfilling our contract and keeping tabs on the work during the session and from one session to the next, filed separately with only initials and date as identifiers so that no other person may connect these details alone to your personal identity.
In both cases I am required by law to retain these records for six years after the completion of our contract – or in the case of a minor, from six years beyond the date of their eighteenth birthday.
Other data sources:
Incoming data is also received from Tsohost, Paypal, Stripe, Skype, Zoom, Mailchimp.
I may receive information from another practitioner or therapist as part of a referral. In such a case you may be unaware that the consented data transfer has taken place, I will therefore inform you of receipt within 28 days.
Sharing your data
Your privacy is important, and I do not sell your data nor share it except by your consent or under the law.
When working together, I may give out elements of your personal information to another practitioner or therapist as part of a referral. This will always only be with your personal consent.
In continuation of current UK law on confidentiality I also retain the right and, in some cases, the legal requirement to breach confidentiality to inform an authority such as the police or your GP of impending harm or illegality.
The GDPR sets out clearly what your rights are. It also lays out deadlines for a reply and other rules which are reproduced for your information at the bottom of this section.
Right to be informed
You have the right to be informed about the collection and use of your personal data. This is a key transparency requirement under the GDPR.
I must provide you with information including: my purposes for processing your personal data, my retention periods for that personal data, and who it will be shared with. This ‘privacy information’ is provided above.
I must provide you with privacy information at the time I collect your personal data from you, in other words it has to be available to you before you fill in a form or hand over your data such as your email address.
If I obtain your personal data from other sources, e.g. by referral or from the payment service provider your selected, I must provide you with privacy information within a reasonable period of obtaining the data and no later than one month.
There are a few circumstances when I do not need to provide people with privacy information, such as if an individual already has the information or if it would involve a disproportionate effort to provide it.
The information I provide to people must be concise, transparent, intelligible, easily accessible, and it must use clear and plain language. Therefore, if there is anything you do not understand, please get in touch.
Right of access
You have the right to access your personal data and supplementary information. This allows you to be aware of and verify the lawfulness of the processing.
You are entitled to confirmation that your data is being processed, access to your personal data, and
other supplementary information as provided in this privacy notice.
Right to rectification
You have the right to have the data your personal data corrected if it is incorrect or completed if it is incomplete.
Right to erasure
You may request, verbally or in writing, to have your data erased. This is also commonly known as ‘the right to be forgotten’. This right only takes effect when:
Right to restrict processing
You have the right to request the restriction or suppression of your personal data. In other words you want to stop the data being used but keep it on file.
In this case your personal data cannot be used and can only be stored unless:
Right to data portability
This allows you to obtain and reuse your personal data for your own purposes across different services. It allows you to move, copy or transfer personal data easily from one IT environment to another in a safe and secure way, without affecting its usability. Doing this is meant to enable you to take advantage of applications and services that can use this data to find you a better deal or help you understand your spending habits. In general this rule exists for data held by big service providers, such as your call history or insurance or gas bill history. The right also only applies to information you have provided.
If, as a private client you wish to carry a copy of your case notes or other sensitive data to another practitioner or other mental, physical or spiritual health service, these may be provided to you or to the nominated service provider, on request, as an encrypted and password protected document.
Right to object
Individuals have the right to object to:
Your objection must be made on grounds relating to your particular situation.
Once you object your data can no longer be processed, unless
You may complain directly to me using the contact details above. If you find the outcome unsatisfactory you are then able to object or complain to:
Information Commissioner’s Office
You may of course also exercise your right to legal action.
You can claim a right verbally or in writing.
A response should come without delay and at least within one month of receipt. The time limit is calculated from the day after you make the request (whether the day after is a working day or not) until the corresponding calendar date in the next month.
I aim to respond within 28 days.
When you request access to your data, a copy must be provided free of charge. However, you can be charged a ‘reasonable fee’ when a request is: