top of page

PRIVACY POLICY

PRIVACY NOTICE

Effective from: June 2026

Last updated 19th June 2026

Introduction

I am committed to protecting your privacy and handling your personal information securely and in accordance with UK data protection law, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This privacy notice explains what information I collect, how I use it, how it is stored, who it may be shared with, and your rights regarding your personal information.

Data Controller

Emma Levinson is the data controller responsible for the personal information collected and processed in connection with the provision of counselling and psychotherapy services.

ICO Registration Number: ZC176835

Information I Collect

If you contact me or engage in therapy, I may collect and process the following information:

• Name and contact details

• Date of birth

• Emergency contact details

• GP details

• Information provided in enquiry forms, emails, telephone calls, or consultations

• Information contained within intake forms

• Session notes

• Risk and safeguarding information

• Appointment and attendance records

• Payment and invoicing information

How Information is Collected

 

Information may be collected through:

• My website contact form

• Email correspondence

• Telephone conversations

• Intake forms

• Therapy sessions

• Payment records

How Information is Used

Personal information is processed for the purposes of:

• Responding to enquiries

• Assessing suitability for therapy

• Providing counselling and psychotherapy services

• Maintaining clinical records

• Managing appointments

• Processing payments and invoices

• Meeting professional, ethical, legal, and insurance obligations

Storage and Security

Personal information is stored electronically using password protected devices and systems.

Information is stored using systems including Gmail, Wix, Apple iCloud, Microsoft Word, Zoom, QuickBooks, PayPal, and banking services.

Clinical notes are generally stored using a client reference code rather than a client's full name. Information that identifies a client is retained within their confidential client records.

Measures used to protect information include:

• Password protected devices

• Biometric security

• Two factor authentication where available

• Secure cloud storage services

Reasonable steps are taken to protect personal information from loss, misuse, unauthorised access, disclosure, alteration, or destruction.

Confidentiality and Sharing Information

Confidentiality is an important part of therapy. Information will not normally be shared without your knowledge or consent unless there is a legal obligation to do so, or there are concerns about serious risk of harm to yourself or others.

 

Information may be shared in the following circumstances:

• Professional clinical supervision to support safe, ethical, and effective practice. Wherever possible, identifying information is minimised.

• With professional advisers, such as an accountant, where necessary for the operation of the practice.

• Where required by law.

• Where there are safeguarding concerns or concerns about serious risk of harm.

• Where you have given consent for information to be shared.

Only information necessary for the relevant purpose will be shared.

Online Sessions

Online sessions are conducted using Zoom. Whilst reasonable steps are taken to protect confidentiality, no online platform can be guaranteed to be completely secure.

Retention of Information

If you make an enquiry but do not begin therapy, your information will normally be retained for up to six months and then deleted.

If you become a client, records will normally be retained for seven years after therapy ends and then securely deleted or destroyed.

Website Cookies

My website may use cookies and similar technologies necessary for the operation, functionality, and security of the website.

 

Your Rights

Under data protection law, you may have the right to:

• Request access to your personal information.

• Request correction of inaccurate information.

• Request erasure of information in certain circumstances.

• Restrict or object to certain processing activities.

• Request transfer of information where applicable.

• Lodge a complaint regarding the handling of your personal information.

Data Protection Concerns

If you have concerns about how your personal information is handled, please contact me in the first instance and I will aim to respond within 30 days.

If you remain dissatisfied, you have the right to complain to the Information Commissioner's Office (ICO).

Contact

If you have any questions about this privacy notice or how your personal information is handled, please contact:

 

Emma Levinson

bottom of page