Katie Payne Counselling: Privacy Policy & Data Protection Notice
Last Updated: June 2026
Your privacy is paramount to my practice. You can feel entirely confident that your personal information and clinical records will be kept safe, highly secure, and will only ever be used for the exact professional purposes for which you provided them to me.
I strictly adhere to current UK data protection legislation, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Data (Use and Access) Act 2025, and the Privacy and Electronic Communications Regulations 2003 (PECR).
________________________________________
1. Important Contact Details & Data Controller Info
Under UK data law, the "Data Controller" is the specific individual or organization responsible for collecting, storing, and safeguarding your personal data. In this instance, the Data Controller is me.
• Practice Name: Katie Payne Counselling
• Data Controller: Katie Payne
• Phone Number: 07974361305
• Email Address: hello@katiepaynecounselling.co.uk
• ICO Registration Number: CSN6786946
________________________________________
2. My Lawful Bases for Processing Your Data
The UK GDPR mandates that I must establish clear, lawful grounds to hold and process your information. Because I handle standard personal details (like emails) alongside highly sensitive health information (clinical notes), my practice relies on two separate legal frameworks:
A. Standard Personal Data
This covers your name, date of birth, address, phone number, email, and booking histories.
• In-Contract or Enquiry Stage: I process this data under Contractual Necessity (Article 6(1)(b) of the UK GDPR). It is entirely necessary to hold this information to satisfy your initial enquiry, execute our therapeutic agreement, schedule your appointments, and communicate about sessions.
• Post-Therapy Stage: Once our therapy has officially ended, I switch to Legitimate Interests (Article 6(1)(f) of the UK GDPR) as the legal ground to store your contact history for administrative continuity.
•
B. Special Category Data (Clinical Consultation Notes)
All session write-ups, psychological profiles, and medical contexts you share constitute highly sensitive health data.
• Lawful Ground: Legitimate Interests (Article 6(1)(f) of the UK GDPR). It is in our legitimate professional interest to keep accurate medical records to maintain safety, risk management, and clinical accountability.
• Special Category Condition: Provision of Health or Social Care (Article 9(2)(h) of the UK GDPR). This explicitly permits me to process health data for counselling and therapeutic treatments. As a qualified practitioner, I process this under a strict professional duty of confidentiality (aligned with the BACP ethical framework).
• Legal Defence Guardrail: I also hold records to ensure I can defend the practice against potential future legal or insurance claims (Article 9(2)(f)). Please note: I do not use "Consent" as a legal basis for holding therapy notes, as consent can be withdrawn at any time, which would conflict with my legal and insurance record-keeping duties.
________________________________________
3. How Your Information is Used Throughout Therapy
Initial Contact & Enquiries
When you, your GP, a health professional, or a trusted individual contacts me to make a referral or enquiry, I collect your name, address, date of birth, and contact paths.
• If you decide not to proceed with therapy: All of your personal data and messages will be permanently and securely deleted from my systems within 30 days (or sooner if you explicitly request it).
While You Are Accessing Counselling
Everything you share with me during our sessions remains strictly confidential. This confidentiality will only ever be broken if statutory legal requirements demand that I inform the authorities. These rare exceptions are typically governed by UK law (such as the Serious Crime Act 2007) and include:
• Disclosures or evidence of current, ongoing child abuse or neglect.
• Situations where there is an imminent, severe risk of a client causing serious harm to themselves or to another person.
• Statutory duties related to terrorism, money laundering, murder, manslaughter, or human trafficking.
Whenever legally and safely possible, I will always discuss my intention to break confidentiality with you before doing so.
Data Security & Storage Actions
• Administrative Details: Your general personal profiles are kept on a password-protected laptop and a password-protected phone (where your contact information is saved under your initials only).
• Clinical Notes: I write concise notes after sessions to act as an aide-memoire. These notes are completely separate from your admin profiles, are completely anonymized (using your initials only), and are stored on an encrypted, password-protected device.
• Communications: To maintain strict digital security, I routinely delete unnecessary or non-essential text messages and emails that do not directly impact your ongoing care.
• Automated Decisions: I do not perform any automated decision-making or data profiling.
________________________________________
4. Data Retention: How Long I Hold Information
In adherence to the UK GDPR Storage Limitation principle, I do not hold data forever. However, I must comply with the strict professional indemnity insurance criteria set by Holistic Insurance Services:
• Adult Records: All clinical session notes, intake records, and contact summaries are securely stored for exactly 5 years from the date of our final therapy session.
• Minor/Child Records (Under 18): If you access therapy as a minor, your records are securely held until 5 years after your 18th birthday (when you turn 23).
• Destruction: Once these timelines expire, digital records are permanently wiped via secure data deletion software, and physical logs are cross-shredded.
________________________________________
5. Third-Party Data Recipients
I never sell your data. I only share personal data with external third parties when strictly necessary to operate my business infrastructure (such as my encrypted web host or booking system).
In every scenario, I carefully select my partners, ensuring binding contracts are in place. These partners are legally prohibited from using your information for any reason other than the specific, secure administrative task they have been contracted to do.
________________________________________
6. Your Legal Data Rights
Under the UK GDPR, you have the right to request access to your data, request corrections, or object to its use.
Fulfilling Data Subject Access Requests (DSAR)
You have an absolute right to request a complete copy of the personal information and clinical notes I hold about you.
• Cost: This service is provided completely free of charge.
• Timeline: I will fulfill your request without undue delay and at the maximum within one calendar month.
• Identity Check: To protect your deep clinical confidentiality, I will require official proof of identity before releasing sensitive records.
• The Redaction Rule: If your notes contain identifiable information relating to a third party (e.g., a relative or partner), that specific data will be completely redacted to protect their privacy rights under UK law.
• Limits to Erasure: While you can request the deletion of your data, the "Right to be Forgotten" does not override my legal insurance obligation to retain clinical notes for the mandatory 5-year period.
To submit a formal request to see or correct your data, please write directly to: hello@katiepaynecounselling.co.uk.
________________________________________
7. Internal Complaints Procedure (Mandatory Addition)
If you have any queries, doubts, or complaints regarding how your personal or health data is being managed, you are encouraged under the Data (Use and Access) Act 2025 to submit your concerns to me directly so they can be reviewed and rectified internally.
• How to Complain: Please email your concern in writing to hello@katiepaynecounselling.co.uk with the subject heading "Data Protection Complaint".
• My Timeline Commitment: I will formally acknowledge your complaint in writing within 30 days of receipt. I will investigate your concern fully and supply a detailed written outcome report without undue delay.
Escalating to the Regulator
If you remain unsatisfied with my internal investigation, or if I fail to provide you with an outcome notice within the required legal timeframe, you have a statutory right to escalate the matter directly to the UK regulator:
Information Commissioner’s Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
• Helpline: 0303 123 1113
• Website: https://www.ico.org.uk
________________________________________
8. Visitors to My Website
My website is built and hosted using a third-party platform, GoDaddy. GoDaddy collects standard internet log profiles and visitor behavioral patterns (such as tracking the number of hits to specific pages).
• This web traffic data is completely anonymous and is processed in a way that does not identify individuals. Neither I nor GoDaddy make any attempt to discover the clear identities of anyone visiting the site.
• My lawful basis for this anonymous analytics collection is Legitimate Interests.
• Website Forms: If you choose to complete an enquiry form on my website, that data is briefly processed by the secure web host before being delivered directly to my email address.