Privacy Statement

You may be aware of laws relating to General Data Protection Regulation (GDPR) that are in effect. The purpose of GDPR is to provide a set of standardised data protection laws across all EU member countries. This document sets out how my service comply with these laws.

Data Control

I am the data controller for my practice.

What personal data I process

I process the following personal data from therapy clients:

  • Personal data: basic contact information: name, address, email, contact number, video conference ID (if online therapy), and GP contact details.
  • Sensitive personal data: therapy records (therapist notes, letters, reports and/or outcome measures).
  • If you complete a web-based enquiry form, I will also collect any information you provide to me as well as your internet protocol (IP) address. This is automatically supplied by the website software used to offer the form.

If you are referred by your health insurance provider, then I will also collect and process personal data provided by that organisation. This includes basic contact information, referral information, and health insurance policy number and authorisation for psychological treatment.

The lawful basis for processing personal data

I have a legitimate interest in using the personal data and sensitive personal data I collect to provide health treatment. It is necessary for me to provide psychological therapy to clients.

No information you provide is passed on without your consent. I will never sell your information to others.

What I do with your personal information

I take your privacy seriously. I will only use your personal information to provide the services you have requested from me.

How long I store personal information

I will only store your personal information for as long as it is required. Any basic contact information held on my mobile phone is deleted within 6 months of the end of therapy.

The sensitive personal data defined above is stored for a period of 7 years after the end of therapy. After this time, this data is deleted at the end of each calendar year.

How your personal information is used

  • Provide my services to you.
  • Process payment for such services.

Who I might share personal information with

I hold information about you and the therapy you receive in confidence. This means that I will not normally share your personal information with anyone else. However, there are exceptions to this when there may be need for liaison with other parties:

  • If you are referred by your health insurance provider, or otherwise claiming through a health insurance policy to fund therapy, then I will share appointment schedules with that organisation for the purposes of billing. I may also share information with that organisation to provide treatment updates.
  • When there is need-to-know information for another health provider, such as your GP.
  • In cases where treatment has been instructed by a solicitor, relevant clinical information from therapy records will be shared with legal services as required and with your written consent.

In exceptional circumstances, I might need to share personal information with relevant authorities:

  • When disclosure is in the public interest, to prevent a miscarriage of justice or where there is a legal duty, for example a Court Order.
  • When the information concerns risk of harm to the client, or risk of harm to another adult or a child. I will discuss such a proposed disclosure with you unless I believe that to do so could increase the level of risk to you or to someone else.

What I will NOT do with your personal information

I will not share your personal information with third-parties for marketing purposes.

How I ensure the security of personal information

Personal information is minimised in phone and email communication. Sensitive personal data will be sent to you in an email attachment that is password protected. I use only Gmail for email communication which is GDPR compliant. I will never use open or unsecure Wi-Fi networks to send any personal data.

Personal information is also stored on an office computer owned by myself and secure GDPR compliant cloud-based storage. These are password protected. Malware and antivirus protection is installed on my computing device. My mobile device is protected with a passcode/thumbprint scanner, mobile security and antivirus software. Any written paper files do not contain your name and are stored in a locked filing cabinet in a private, secure location.

Your right to access the personal information I hold about you

  • You have a right to access the information I hold about you.
  • I will usually share this with you within 30 days of receiving a request.
  • I may request further evidence from you to check your identity.
  • A copy of your personal information will usually be sent to you in a permanent form (that is, a printed copy).
  • You have a right to get your personal information corrected if it is inaccurate.
  • You can complain to a regulator. If you think that I have not complied with data protection laws, you have a right to lodge a complaint with the Information Commissioner’s Office.

I reserve the right to refuse a request to delete a client’s personal information where this is therapy records. Therapy records are retained for a period of 7 years in accordance with the guidelines and requirements for record keeping by The British Psychological Society (BPS; 2000)[1] and The Health and Care Professions Council (HCPC; 2017)[2].

If you have any queries or concerns about the above, then please speak to me about this at the first opportunity. You will be asked in the Registration Document to acknowledge via your signature that you have read and accept this Privacy statement.

Alison Ryan
Chartered and Clinical Psychologist & Owner
May 2021


[1] The British Psychological Society (2000). Clinical Psychology and Case Notes: Guidance on Good Practice. Leicester: Division of Clinical Psychology, BPS.
[2] Health and Care Professions Council (2017). Confidentiality – guidance for registrants

 

Clinical Psychology and Neuropsychology Services​
St Albans & Online

Email: info@alisonryantherapy.co.uk

Privacy | Cookies

Websites for Psychologists by: YouCan Consulting

aviva
axa main logo
freedom
geoblue Alison Ryan

 

The Exeter Feb 2016
phc logo 250x90
saga
vitality health logo web