CLIENT PRIVACY & GDPR/ DUAA
______________________________
Are our discussions in hypnotherapy sessions confidential?
Yes, absolutely. The only time I would share any information that we have discussed is when I need support from my supervisor (in which case information is anonymised), or I believe you are about to harm yourself or someone else.
What if I see you outside of a hypnotherapy session?
I will not approach you, to maintain confidentiality. If you choose to approach me then that is up to you! You choose how to interact – or not – with me if we see each other outside of our sessions.
Will you discuss information about me with other health and social care professionals?
Only with your written consent.
What personal data do you collect?
I may collect:
- Identity Data – your name, date of birth, information shared by you during consultations.
- Contact Data – your email address, phone number, postal address.
- Health & Lifestyle Data – relevant background information shared by you for therapy (only with your explicit consent).
- Technical Data – IP address, browser type, operating system, website usage.
- Marketing Preferences – your choices for receiving updates from us, collected directly from you via forms, calls, emails, or in person.
- Information collected automatically via cookies and similar technologies.
Why are you collecting my information?
I need to have as complete a picture as possible in order to help you, support you and be able to contact you or (with your consent) other health or social care providers. The questions I ask in our initial consultation are designed to achieve this.
I then use/ process your data to:
- respond to enquiries and/ or deliver requested hypnotherapy services (including via online meeting providers, where requested by you);
- manage bookings, services, payments, and client records.
- communicate with you about sessions, updates, and services.
- comply with legal, insurance and professional obligations.
- send marketing (only with your consent).
For the purposes of the GDPR, I use your information on the following bases:: consent, contractual necessity, legal obligation, or legitimate interest.
Any health-related information that you provide to me is only processed with your explicit written consent and is stored securely.
I may provide your personal data to suppliers and service providers (for example online meeting providers) who provide certain business services for me and act as “processors” of your personal data on my behalf. In addition, I may disclose your personal data if I am under a duty to disclose or share it in order to comply with any legal obligation, or in order to protect the rights, property, or safety of you or others.
How will you store my information?
I will hold it safely and securely, in line with the General Data Protection Regulations (GDPR) and the Data Uses and Accesses Act (DUAA). Anything on my phone or laptop – like emails, text messages etc – is password protected. Any paper records – like your signed consent form or my session notes – will be in locked, fireproof storage that only I can access.
How long will you hold my information for?
Therapy records are kept for at least 8 years after our last interaction. For children, I will store records until they turn 25, or 26 if they are 17. This is in accordance with National Council for Hypnotherapy (NCH) guidelines. Records are securely destroyed after this period.
What if I would like you to destroy my information before this date?
Due to the sensitive nature of the work I (and other therapists) do, my insurance company and associations do not allow me to delete or destroy therapy records before the minimum time it must be held for. However you can:
- request access to your data via a Subject Access Request (SAR).
- ask me to correct inaccuracies.
- request deletion (where legally possible).
- request a restriction of or object to certain processing.
- request data portability (if applicable).
Subject to checking identity, I will respond to requests within one month and handle them in a reasonable and proportionate manner.
Am I able to see or get a copy of my information held by you?
Yes, within 30 days of you asking for it. This is in line with the GDPR.
General
I may update this policy from time to time. Changes will be posted here with a new “last updated” date.
By using our website or services, you agree to the terms of this policy.
If you have concerns about how your personal information has been used please email me in the first instance at contact@flowhypnotherapy.co.uk. I will acknowledge receipt of your complaint within 30 days, investigate your concerns appropriately and without undue delay, keep you informed where further time is needed and provide you with an outcome once the investigation is complete
If you are not satisfied with the outcome of the complaints process, you may contact the ICO: www.ico.org.uk.
I am the data controller. I am registered with the ICO with number ZB899548.
Last updated: 13 July 2026