Legal and policy

Privacy Notice

Therapy records are among the most sensitive information anyone holds about you. This notice sets out exactly what we keep, why we keep it, who ever sees it, how long it stays, and what you can ask us to do with it.

Last updated
Next review
Version
0.9 (draft for review)
A plain oak writing desk in a consulting room, with a closed notebook and a small locked drawer.

Plain English

The short version

The full notice runs to twenty short clauses because the law requires that level of detail. This is the honest précis. Nothing important appears only in the long version.

  • We hold very little, on purpose

    Your name and contact details, the dates you attended, brief clinical notes, and a record of what you paid. Nothing is collected because it might be useful one day.

  • Health information gets extra protection

    Anything about your mental or physical health is special category data under Article 9 of the UK GDPR. It is held under the health-care condition, by a professional bound by a duty of confidentiality.

  • Notes are kept apart from your name

    Session notes are stored separately from the contact details that identify you, so neither on its own tells a full story if it is ever lost.

  • We do not sell or trade anything

    No advertising networks, no data brokers, no analytics profiles, no automated decisions about you. This website sets no tracking cookies at all.

  • Sharing is rare and explained first

    Your therapist discusses anonymised work in clinical supervision. Anything beyond that — a letter to your GP, for instance — happens only with your explicit consent, or where the law requires it.

  • You can ask to see everything

    You have the right to a copy of what we hold, usually within one month and free of charge, and to have mistakes corrected. You can complain to the ICO at any point.

This summary is here to help you read the notice, not to replace it. Where the two appear to differ, the full notice below is the one that governs what we do.

At a glance

What we hold, why, and for how long

The same information as the notice below, arranged so you can find one row rather than read twenty clauses. Bracketed items are still being confirmed by the practice.

Categories of personal information held by Family Restore Ltd, the reason each is held, the lawful basis and the retention period
What we holdWhy we hold itOur lawful basisHow long we keep it
Enquiry detailsYour name, the way you asked us to reply, and whatever you chose to tell us, so we can answer and work out whether we are the right service for you.Article 6(1)(f) legitimate interests, and Article 6(1)(b) where you are taking steps towards a contract.[confirm — commonly six to twelve months] if no sessions follow.
Appointment recordsDates, times, attendance and the practical arrangements for your sessions.Article 6(1)(b) — necessary to perform our contract with you.Kept with the clinical record for the same period.
Clinical notesShort factual notes of what was discussed, the plan, and any changes to it, so the work is safe and continuous.Article 6(1)(b) contract, together with Article 9(2)(h) — the provision of health care by a professional under a duty of confidentiality.[confirm retention period with insurer] after your last session.
Risk and safeguarding informationAnything recorded because there was a concern about your safety or someone else's.Article 6(1)(d) vital interests or 6(1)(f), with Article 9(2)(c) or 9(2)(g) and the safeguarding condition in the Data Protection Act 2018.Held with the clinical record.
Payment recordsWhat was invoiced, what was paid, and when. We do not see or store your full card details.Article 6(1)(b) contract and Article 6(1)(c) — our legal obligation to keep accounting records.At least six years from the end of the accounting period, as HMRC requires.
Letters to other professionalsCorrespondence with a GP, consultant, solicitor or insurer about your care.Article 6(1)(a) and Article 9(2)(a) — your explicit, written consent, which you can withdraw.Held with the clinical record.
Website server logsThe technical record your browser leaves when it asks our host for a page: IP address, time, page requested.Article 6(1)(f) legitimate interests — keeping the site available and secure.[confirm log retention with hosting provider].

Article references are to the UK GDPR. The corresponding conditions in UK law are in Schedules 1 to 3 of the Data Protection Act 2018.

This is the full privacy notice for Family Restore Ltd. It was last reviewed on the date shown at the top of this page. If anything in it is unclear, or you would like it in another format, please ask.

About this notice

This notice explains what personal information Family Restore Ltd holds about you, why we hold it, who else ever sees it, how long we keep it and what you can ask us to do with it. It is written to meet the transparency requirements in Articles 13 and 14 of the UK GDPR and the Data Protection Act 2018.

It applies to you if you are:

  • someone who has contacted the practice — by telephone, email, the enquiry form on this website, or in person;
  • a current or former client, whether you were seen individually, as a couple, as a family, or for coaching;
  • a parent, carer or partner whose details appear in someone else’s record;
  • a visitor to this website.

We have written it in plain English and put the short version at the top of the page. Nothing important appears only in the long version. If any part of it is unclear, please ask — an explanation you can actually follow is part of what the law requires of us.

Who is responsible for your information

Family Restore Ltd is the data controller. That means we decide what information is collected and what happens to it, and we are the organisation accountable to you and to the regulator for it.

  • Registered name: Family Restore Ltd, a company registered in England and Wales.
  • Company number: [add Companies House number to lib/site.ts]
  • Address: 3 Regina Road, Chelmsford, Essex [confirm full postcode]
  • ICO registration: [add ICO registration reference — registration is a legal requirement for processing health data]
  • Data protection contact: [name the person responsible for data protection enquiries], reachable at info@familyrestore.co.uk.

A practice of this size is not required to appoint a statutory Data Protection Officer, and we have not appointed one. One named person is nevertheless responsible for answering questions about your information, and every request reaches them.

The information we hold

We keep the smallest amount of information that lets us work with you safely. In practice it falls into six groups.

Enquiry information

Your name, the telephone number or email address you asked us to reply to, and whatever you chose to tell us about why you were getting in touch. Please do not send detailed clinical information in a first message — a sentence or two is enough for us to judge whether we can help.

Contact and administrative information

Your address where you have given one, an emergency contact where you have chosen to provide one, your GP practice where relevant, your preferences about how and when we may contact you, and the dates and times of your sessions.

Your clinical record

An initial assessment, brief notes made after each session, any agreed goals or plan, correspondence about your care, and a record of any concerns about risk. Notes are short, factual and written on the assumption that you may one day read them. They are a working record, not a transcript.

Payment and financial records

Invoices, the amounts charged and paid, dates, and the method of payment. We do not hold your full card number: card payments are handled by a payment provider, and we see only a confirmation and the last four digits.

Information you send us in writing

Emails, text messages, voicemails, letters and enquiry-form submissions, together with our replies.

Website technical information

When your browser asks our hosting provider for a page, the request is logged with your IP address, the time and the page requested. That is normal server administration and security practice. This site sets no analytics or advertising cookies — see our cookie policy.

Health information and special category data

Almost everything in a therapy record says something about your mental or physical health. Under Article 9 of the UK GDPR that is special category data: a class of information the law singles out because the harm caused by mishandling it is greater than for an address or a phone number.

Special category data cannot lawfully be processed at all unless one of the conditions in Article 9(2) applies, in addition to an ordinary lawful basis under Article 6. In other words, we need two reasons rather than one, and we have to be able to state both. The conditions we rely on are set out in the next clause.

Sometimes a record will also contain information about criminal offences or allegations — for example where you describe something that happened to you, or where a safeguarding concern is raised. Article 10 of the UK GDPR treats that separately again, and we handle it under the safeguarding condition in Schedule 1 of the Data Protection Act 2018.

Practically, this is why the record-keeping described below is stricter than you might expect for a small practice: separate storage of names and notes, encrypted devices, access limited to the practitioner working with you, and a written retention period rather than keeping things indefinitely.

Why we use your information, and our lawful basis

The UK GDPR requires us to name a lawful basis for every purpose. Ours are as follows.

Answering your enquiry

Article 6(1)(f) — legitimate interests. Our interest is in replying to someone who has asked us a question, and in deciding whether we are the right service for them. This is what you would expect when you send an enquiry, and it does not override your rights. Where the enquiry leads towards booking, we also rely on Article 6(1)(b) — steps taken at your request before entering a contract. If your enquiry contains health information, we rely on Article 9(2)(h) from the moment it arrives.

Arranging and providing your sessions

Article 6(1)(b) — performance of a contract. Once you book, we need your details to arrange, confirm, change and deliver the sessions you have agreed to.

Keeping a clinical record

Article 6(1)(b), supported by Article 6(1)(f), together with Article 9(2)(h) — processing necessary for the provision of health care or treatment, by or under the responsibility of a professional subject to an obligation of confidentiality. The corresponding condition in UK law is the health or social care purposes condition in Schedule 1, Part 1 of the Data Protection Act 2018. Keeping a record is a professional requirement, not an optional extra: it is what makes the work reviewable, safe and continuous.

Protecting someone’s safety

Article 6(1)(d) vital interests, or Article 6(1)(f), with Article 9(2)(c) where you are not capable of giving consent, or Article 9(2)(g) substantial public interest, relying on the safeguarding condition in Schedule 1, Part 2 of the Data Protection Act 2018. This is the basis on which we would act if we believed a child or an adult at risk was in danger.

Taking payment and keeping accounts

Article 6(1)(b) for the payment itself and Article 6(1)(c) — a legal obligation — for the accounting and tax records a limited company must keep.

Where we ask for your explicit consent

Article 6(1)(a) and Article 9(2)(a) — explicit consent. We use consent only where the choice is genuinely yours to make and the answer could be no without any consequence for your care. The main examples are writing to your GP or another professional, releasing a report to an employer or insurer, and speaking to a family member. Consent is asked for in writing, recorded, and can be withdrawn at any time by telling us. Withdrawing it does not undo anything already done in reliance on it.

Defending a claim or complaint

Article 6(1)(f) with Article 9(2)(f) — the establishment, exercise or defence of legal claims. If a complaint or claim were made, the record may need to be shown to our insurer and legal advisers.

What we never do

We do not use your information for marketing, we do not add you to a mailing list because you enquired, we do not build profiles, and we do not sell or exchange information with anyone.

Where your information comes from

Nearly all of it comes from you, in your own words, during an enquiry, an assessment or a session.

Occasionally information reaches us from someone else. A partner or family member may make the first enquiry on your behalf. A GP, an employee assistance programme, an employer, a solicitor or another therapist may refer you. Where that happens we will tell you what we have been sent, at the latest during the first session, and we will not add anything to your record that you have not had the chance to correct.

If someone contacts us about you without your knowledge, we will not confirm whether you are a client. Confirming or denying that someone attends therapy is itself a disclosure of health information.

Couples, family work and information about other people

In couples and family work each adult in the room is a separate person in data protection terms, with their own rights over their own information. This creates a practical problem worth stating plainly: notes of a joint session unavoidably describe more than one person.

How we handle it:

  • notes of joint sessions are kept as a single shared record of the work, not as separate secret files;
  • if one of you asks for a copy of the record, we have to consider the other people described in it. We will normally provide the parts that concern you and redact material that would disclose someone else’s personal information, unless they agree or it is reasonable to disclose it without their agreement;
  • we will tell you at the outset how we handle information passed to us individually — for example in a separate telephone call — and what will and will not be brought into the joint work.

Where a child or young person is seen, please also read the clause on children and young people below.

Confidentiality, and the limits of it

Confidentiality is a professional duty that sits on top of data protection law, and it is stricter. What you say in a session stays in the room. There are a small number of exceptions, and you will be told about all of them in writing before your first session rather than discovering them afterwards.

We may need to pass information on where:

  • there is a serious and immediate risk to your life or to someone else’s;
  • a child, or an adult who is unable to protect themselves, appears to be at risk of significant harm;
  • we are required to do so by a court order, or by a statutory duty — the narrow legal duties around terrorism, and money laundering, are the usual examples;
  • you ask us in writing to share something, for instance with your GP.

Wherever it is safe and practicable to do so, we will tell you first, discuss what will be said, and share only the minimum necessary. The only situation in which we would not is where doing so would increase the danger to someone.

Separately, all clinical work is reviewed in regular independent clinical supervision. That is a professional safeguard for you, not a loophole: your therapist discusses the work, not your identity, and the supervisor is bound by the same duty of confidentiality.

How your information is kept safe

Article 32 of the UK GDPR requires security measures appropriate to the risk. Because the risk here is high, the measures are deliberately simple and strict.

  • Separation. Session notes are kept apart from the list that connects a name to a client reference, so neither on its own identifies you.
  • Paper. Any paper records are held in a locked cabinet at [confirm where paper records are held] and are never taken out of the practice.
  • Devices. Every device used for practice work is encrypted at rest, protected by a strong unique passphrase and multi-factor authentication where the service supports it, and set to lock automatically.
  • Access. Only the practitioner working with you has access to your record. Nobody browses records they have no reason to open.
  • Backups. Records are backed up [confirm backup method, location and encryption] so that a lost device does not mean a lost record.
  • Disposal. Paper is cross-cut shredded. Digital records are securely erased at the end of the retention period.

If something goes wrong. We keep a record of any personal data breach. Where a breach is likely to result in a risk to your rights and freedoms, we report it to the Information Commissioner's Office within 72 hours of becoming aware of it. Where it is likely to result in a high risk to you, we will tell you directly, without undue delay, in plain language, and explain what you can do about it.

No system is perfect and we will not pretend otherwise. What we can promise is that the number of places your information exists is kept deliberately small, and that we would tell you quickly if it were compromised.

Email, text messages and voicemail

Ordinary email is convenient and it is not secure. A message can be read on an unlocked phone, forwarded by accident, or sent to the wrong address by a single mistyped character. We would rather say that clearly than let you assume otherwise.

So, our working rules:

  • we use email for practical arrangements — times, directions, invoices — and keep clinical detail out of it;
  • we will match the channel you choose, but we may suggest a different one if the content is sensitive;
  • text messages are used only for appointment reminders, and only if you ask for them;
  • voicemail messages are deleted once acted on. Tell us if you would rather we did not leave one;
  • if you share a device, an inbox or a phone with someone else, please tell us, and we will agree a safer way to reach you.

One limitation, stated openly because you deserve to see it: the email address currently in use is a consumer webmail account. We are moving to a business mailbox on the practice domain, held under a written data-processing agreement.

Who we share your information with

We share as little as possible, with as few people as possible. The complete list is below. Anyone acting for us under contract is a processor: they may only use your information on our written instructions, must keep it secure, and must return or delete it when we ask.

  • Clinical supervisor. Work is discussed without your name or identifying details. Supervision is a professional requirement and a safeguard for you.
  • Payment provider. [name the payment processor actually used] processes card payments. They see the amount and the card details you enter; we do not.
  • Email and scheduling providers. [name the email provider and any booking or diary software]. Both are covered by a written data-processing agreement.
  • Website hosting. [name the hosting provider] operates the servers behind this website and holds the server logs described above.
  • Accountant. [name the accountant, if one is used] sees invoices and payment records, not clinical notes.
  • Insurer and legal advisers. Only if a complaint or claim is made, and only what is relevant to it.
  • A nominated colleague, under a professional will [confirm the clinical will / professional executor arrangement]. If the practitioner died or became seriously unwell, this person would contact clients and manage records under the same duty of confidentiality.
  • Emergency and safeguarding services. Where the circumstances in the confidentiality clause above apply.
  • Courts and regulators. Where we are legally required to disclose, and only to the extent required.

We do not share information with advertisers, data brokers, social media platforms or analytics companies, and we never sell it.

Where your information is held

We aim to keep everything within the United Kingdom or the European Economic Area. Some ordinary business software is operated by companies based elsewhere, most often the United States.

Where information does leave the UK, we only use a provider where one of the transfer mechanisms recognised in UK law is in place:

  • UK adequacy regulations, which cover the EEA and a number of other countries; or
  • the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment; or
  • the UK Extension to the EU–US Data Privacy Framework, where the provider is certified under it.

[list each processor, the country its data is held in, and the transfer mechanism relied on]

You can ask us for a copy of the safeguards that apply to any particular transfer.

How long we keep your information

We do not keep records indefinitely, and we do not delete them the moment therapy ends. A clinical record has to outlast the work for a period, because a former client may need a copy, and because a complaint or claim can be raised long after the last session.

  • Enquiries that do not lead to sessions: [confirm — commonly six to twelve months], then deleted.
  • Adult clinical records: retained for a defined period after your final session — [confirm the exact period with the professional indemnity insurer and professional body; UK private practice commonly operates between six and seven years] — and then securely destroyed.
  • Records of children and young people: kept for longer, because the period in which a claim can be brought does not begin until adulthood — [confirm the exact period; commonly until the person’s twenty-fifth or twenty-sixth birthday].
  • Financial and accounting records: at least six years from the end of the accounting period they relate to, which is what HMRC requires of a limited company.
  • Complaint records: [confirm complaint record retention], so that we can show what was done and learn from it.
  • Website server logs: [confirm with hosting provider].

At the end of the period, paper is cross-cut shredded and digital files are securely erased, including from backups at the next backup cycle.

Your rights over your information

These rights are yours by law. Using them costs nothing and will never affect the care you receive.

  • The right to be informed. To know what we hold and why — which is what this notice is for.
  • The right of access. To a copy of your personal information, normally within one month. There is a limited exemption for health data in Schedule 3 of the Data Protection Act 2018: we may withhold part of a record where disclosing it would be likely to cause serious harm to your physical or mental health, or to someone else’s. That test is applied narrowly, and we will tell you if we have relied on it.
  • The right to rectification. To have inaccurate information corrected. Where you disagree with a clinical opinion rather than a fact, we will not delete the opinion, but we will record your account alongside it.
  • The right to erasure. Often called the right to be forgotten. It is not absolute: where we hold a clinical record under Article 9(2)(h), or must keep accounting records by law, we will usually need to keep it for the retention period. We will explain our reasoning if we cannot erase something.
  • The right to restrict processing. To ask us to pause using your information — for instance while a dispute about accuracy is resolved.
  • The right to object. To object to processing based on legitimate interests. We must stop unless we can show compelling grounds that override your interests.
  • The right to data portability. To receive information you gave us in a structured, commonly used, machine readable form, where we process it by automated means on the basis of consent or contract.
  • The right to withdraw consent. Where we rely on your consent, you can withdraw it at any time, and it must be as easy to withdraw as it was to give.
  • The right to complain. To the Information Commissioner's Office, at any point, without going through us first.

Making a request, and what to expect

Write to us using any of the routes at the foot of this page. You do not need to use a form, quote a legal article, or explain why you want your information. Saying what you want is enough.

It helps if you tell us:

  • which right you want to use, in your own words;
  • whether you want everything, or only a particular period or document;
  • how you would like to receive it — securely by post, or in person.

We will ask you to confirm your identity before releasing anything. That is not obstruction; it is what stops someone else obtaining your record.

We respond within one month. If a request is complex or you have made several, we may extend that by up to two further months, and we will tell you within the first month if we need to and why. Requests are free. We may charge a reasonable administrative fee, or decline, only where a request is manifestly unfounded or excessive — for example a repeat of one already answered — and we would explain that in writing and tell you how to challenge it.

Children and young people

[confirm whether the practice accepts clients under 18, and from what age]

Where a young person is seen, the same rights described above belong to them, not automatically to their parent or carer. Data protection law follows capacity rather than age alone: if a young person understands what is being asked and what the consequences are, they can exercise their own rights, and a parent cannot require us to hand over the record.

In practice we agree at the outset what will be shared with parents and what will not, and we say so in front of everyone, so that nobody discovers the arrangement later. Safety is always the exception: if a young person is at serious risk, the people who can keep them safe will be told.

Where a parent or carer holds parental responsibility for a younger child, they will normally exercise the child’s rights on their behalf, and we will still consider the child’s own wishes.

Cookies and this website

This site loads no third-party scripts, no advertising tags, no analytics, no embedded social media and no externally hosted fonts. Everything it needs is served from our own domain, and at the time of the last review it set no cookies at all on a visitor’s device.

That means there is nothing on this website that builds a picture of you, follows you to other sites, or is shared with an advertising network. Our cookie policy explains what would have to change before that were ever untrue, and what your browser lets you control in the meantime.

If you send us an enquiry through this website, the content of that message is handled exactly as described in this notice.

Automated decision-making and profiling

We do not make decisions about you by automated means, and we do not profile you. There is no algorithm scoring your suitability, no automated triage, and no artificial intelligence system that reads your notes or writes them.

Decisions about whether we can help, how often you are seen, and when the work should end are made by a person, with you, in conversation.

If that ever changed, we would tell you before it applied to you, explain the logic involved, and give you the right to a human review that Article 22 of the UK GDPR requires.

If you are unhappy with how we handle your information

Please tell us first if you feel able to. Most problems are a misunderstanding, and we can usually put them right quickly. Our complaints procedure explains how, and what happens next.

You do not have to come to us first. You have the right to complain directly to the Information Commissioner's Office, the UK’s independent regulator for data protection:

  • Website: ico.org.uk
  • Helpline: 0303 123 1113
  • Post: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom

Complaining to the ICO is free, and it will not affect your care with us in any way.

Changes to this notice

We review this notice at least once a year, and whenever the way we work changes — a new payment provider, a new booking system, a change to how records are stored.

The version and the date it was last updated are shown at the top of this page. Where a change materially affects you — a new purpose, a new recipient, a shorter or longer retention period — we will tell current clients directly rather than relying on you to notice the page has changed.

Earlier versions are kept, and you can ask us for one.

A lockable cabinet in the corner of a consulting room, drawer closed, with a lamp and a trailing plant on top.

Article 32

How your records are actually kept

Security measures that a small practice can genuinely operate every day are worth more than a policy nobody follows.

  • Names and notes are stored separately. A client reference links the two. Neither half, on its own, tells anyone very much.
  • Devices are encrypted and locked. Full-disk encryption, a unique passphrase, multi-factor authentication where the service offers it, and automatic locking.
  • Access is limited to the person working with you. There is no shared login, and nobody opens a record they have no reason to open.
  • Paper stays in the building. Locked storage on site. Notes are not carried around, and they are not written on a train.
  • Everything has an end date. Records are destroyed at the end of the retention period rather than kept in case they are useful.
  • A breach would be reported, and you would be told. Reportable breaches go to the ICO within 72 hours. High-risk breaches are explained directly to the people affected.

Your rights in practice

Asking for a copy of your record

A subject access request sounds formal. In practice it is a sentence in an email, and this is what happens after you send it.

  1. Write to us

    Email, telephone or post — whichever suits. Say what you want in your own words. You do not need to quote the law or give a reason.

    Any time

  2. We confirm who you are

    A short identity check, proportionate to what has been asked for. This is what stops somebody else obtaining your record.

    Usually the same week

  3. We gather the record

    Everything we hold about you is collected, and anything that would disclose another person's information is considered and, where necessary, redacted.

    Within one month

  4. You receive it, with an explanation

    Securely, in the format you asked for, with a short covering note explaining anything withheld and why. We will offer to talk it through.

    Within one month

Reading your own notes

People are sometimes anxious about what their notes will say. Ours are short, factual and written on the assumption that you may read them. If you would like to look through them together rather than receive them cold in the post, say so and we will make the time.

If we get it wrong, go to the regulator

You can complain to the Information Commissioner's Office at any point, free of charge, without coming to us first. Call 0303 123 1113 or visit ico.org.uk. Doing so will not affect your care here in any way.

Two comfortable chairs turned slightly towards one another beside a low table with a glass of water.

Get in touch

Questions about your information

Ask us anything about this notice — what we hold, why we hold it, or how to get a copy. There is no wrong way to ask and no form to fill in.

Telephone
07395 854051
By post
Family Restore Ltd
3 Regina Road, Chelmsford, Essex [confirm full postcode]

We aim to reply within one working day. Messages are read during consulting hours only.

If you are writing about your own record, please mark the envelope or the subject line “Private and confidential”, and address it for the attention of [name the data protection contact].

This is not a crisis service and no inbox here is monitored overnight. If you need help now, call 999 in an emergency, call 111 and choose the mental health option, or ring Samaritans on 116 123. More routes are listed on our urgent help page.