General Data Protection Regulations
We conform to GDPR and this explains how we do so.
How does GDPR affect me?
After 20 years, the Data Protection Act has been replaced by the GDPR. The aim is to ensure that your personal, sometimes sensitive, confidential data is held privately and securely, being processed in the way that you have agreed to. It exists to protect your rights as a consumer involving your identifiable data, e.g. your name and address & any reason you might have for visiting me. It also covers any session records, text messages or emails between us.
​
As a member of the GHR, we are bound by their regulations regarding the length of time I must hold onto your information. This organisation stipulates that I must hold your data for 8 years after your final session. The exception to this rule applies to children, for whom I must hold their data until their 25th birthday, (unless they are 17 when treatment ends when I must keep it until their 26th birthday). All records will be deleted in the January after the above retention scales. This is in line with NHS regulations for holding data.
Can I ask for my information to be deleted before this date?
GDPR allows you to request the deletion of any of your records, by making a request in writing to me. Should you request this then all your paper records would be shredded. Any electronic data such as emails or text messages would be permanently deleted from the devices they are stored on. Please note that we would have to save the deletion request you made, but would not save any other data. Exceptions occur where there is a legitimate legal reason for maintaining your information, for example for accounting purposes.
Can I ask to see my data and if so how quickly can I look at it.
You are now able to ask to see any information that is held about you within 30 days of asking. You can even ask for a copy of any personal information held by me if you wish. It is possible however, that my insurance company’s legal team may want to verify information I send out.
Why do you need a record of this information?
In order to give you the highest quality support I can, I collect information about: what you want to achieve by coming for hypnotherapy or coaching, a small amount of medical information and some information about your important others, alongside brief session notes. This information allows me to refer to information about previous discussions and the content of earlier sessions. Your contact details / address and GP’s details will only be used with your explicit consent.
How do I know that my information will be held securely?
• Paper session notes – Are all stored in locked cabinets, behind a locked door.
• Text messages – My work phone is secured with finger print recognition or a pass code.
• Emails – My email account requires a username and password.
• Bookings Information – Where bookings are made using an online booking system, we ensure that such third parties are also GDPR compliant.
• Other – Your data may be handled also by other third party systems, for example when completing a contact form on our website. We ensure that any systems we use are GDPR compliant.
Do our discussions during the sessions remain confidential?
Everything we discuss during our sessions remains strictly confidential between you and me. On occasion I may choose to discuss elements of our sessions with my supervisor to ensure I am doing my job effectively. During these discussions I will not disclose any identifying details about you to my supervisor. My supervisor also adheres to the GDPR.
What if I see you away from a hypnotherapy or coaching session?
I am obligated by GDPR to protect your confidentiality, so for this reason, although I will acknowledge you, it would be better to avoid any further conversation. However, if you wish to discuss your therapy with other people, you are welcome to do so. Having said this, we may have a relationship that has already been established outside of our sessions. In such cases, the usual contact may continue. Any other further contact, the content of which does not relate directly to your sessions, can only arise at your request, so as to avoid any invasion of your privacy.
Will you discuss me with other Health and Social Care Professionals?
We are only able to contact other health and social care professionals with your written consent. Should I write to your GP, to notify them that you have come to see me for treatment and again at the end of the therapeutic relationship, I would require your signature in line with GDPR requirements? The only exceptions to this would be if I believed that you were about to harm yourself or another when I would be required to inform the relevant authorities as part of my “Duty of Care”. However, I would always aim to discuss this with you before taking any action. Legally, I would also have to provide the police with information as set out in a warrant or court order, should the situation arise.
​
CONTACTING US
You have the ‘right to be informed’ about how your personal information is used. This is the reason for this privacy policy. Further rights are itemised below.
In order to exercise your rights under data protection law, where there is any doubt, we will need to verify your identity for your security, in order to communicate with you about your personal information.
You can contact us by emailing Rebeccahelenhypnotherapy.co.uk
Privacy and confidentiality
Your personal information/data
Any information that I keep is subject to the Data Protection Act 2018 (DPA 18) and United Kingdom General Data Protection Regulation. See Information Commissioner’s Office: https://ico.org.uk
To begin working together, I will record your name and preferred contact details (for example, telephone number, email address). I use this information only for essential administrative tasks: contacting you and arranging appointments. I do not share it with others without your consent unless I am legally or ethically required to do so, as in the confidentiality statement above.
In the event of my death or incapacity through ill-health, a colleague will have access to your contact details so that you can be informed.
During our work, you might verbally share a range of sensitive personal information, but I do not routinely record it. I might sometimes make brief notes about our sessions but these are kept separately from your contact details and are anonymised, so they do not identify you.
Storing and deleting your information
Any personal data I have recorded or that is contained in documents given to me by you or by third parties in the course of our work will be stored securely, either in a locked filing cabinet or in a password protected digital folder, and kept for a maximum of 6 years after the counselling ends, then deleted.
Your consent and rights
When we start working together, I will ask if you consent to me using your personal data as described in this statement. It is your right to see the data I hold about you and to request that it be corrected (if you believe there are inaccuracies) or deleted. If you would like this to happen or have any other questions about privacy or confidentiality, then please contact me and I will attempt to resolve your query as soon as possible.