Privacy Policy
Who I am and how I process your personal data
New Leaf Hypnotherapy is the business name of sole trader Ann Mason. I am Data Controller and Processor of New Leaf Hypnotherapy. I comply with my obligations under the General Data Protection Regulation (GDPR) by keeping personal data up to date; by storing (and destroying it) securely; by not collecting or retaining excessive amounts of data; by protecting personal data from loss, misuse, unauthorised access and disclosure and by ensuring that appropriate technical measures are in place to protect personal data.
What data is held?
- Name, address, email address, phone number.
- Brief medical information.
- Information that you give me as part of the work we do together
- Brief session records which enable me to provide a high quality service to you,
- Emails, texts and/or messages that are sent between us
- Information sent to or from any third party on your behalf, eg. receipts for insurance company, colleges, GP., other Health Care Professionals. Made only with your explicit consent.
How is your information held securely?
- Hard copy documents– Are all stored in a locked cabinet in a locked room.
- Text messages– mobile phones are secured with a pin code.
- Emails– email accounts require a user name and password.
Everything that we discuss during our sessions is strictly confidential between client and therapist. N.B. In the event that recorded data is utilised for my own supervisionall such data will be sufficiently anonymised to the extent that individual clients cannot be identified. Should a client indicate that their data should not be used for these purposes, I would refrain from using that data.
I use your personal data for the following purposes:
- To deliver the services that clients have requested;
- To contact those clients as necessary in accordance with the services they have requested.
- To maintain my own accounts and records.
- Individual client data will never be passed to a third party without the express consent of the respective client, always provided that such confidentiality is neither inconsistent with the therapist’s own safety or that of the client, the client’s family members or other members of the public, nor in contravention of any legal action or legal requirement.
How long is data kept?
My professional body and insurers require me to retain client data for a minimum period of 8 years. For clients under the age of 18, data will be retained until their 25th birthday.or 26th birthday if the client was 17 when the treatment ended. As per Section B8 of the CNHC Code
Our Lawful Basis for processing client personal data
The client has given clear consent for me to process their personal data for a specific purpose. Further, the processing is necessary for both my client’s and my own legitimate interests.
Your rights and your personal data
Unless subject to an exemption under the GDPR, you have the following rights with respect to your personal data:
The right to request a copy of your personal data which the I holds about you.
The right to request that I correct any personal data if it is found to be inaccurate or out of date.
The right to request your personal data is erased where it is no longer necessary for me to retain such data. This request needs to be done in writing. Although the request would need to be saved, any other data would be deleted. An exception to this is if my insurance insist that I have a legal basis to hold the data.
The right to withdraw your consent to the processing at any time.
The right, where there is a dispute in relation to the accuracy or processing of your personal data, to request a restriction is placed on further processing;
The right to lodge a complaint with the Information Commissioners Office. (See below).
Complaints Notice
The client has the right to complain to the Independent Commissioner’s Office (ICO) if theythink there is a problem with the way we are handling their data
(see https://ico.org.uk/concerns/handling/).
If a breach of data occurred, full details will be given to the Information Commissioners Office and any person affected within 72 hours of the breach and I will do all possible to minimise any potential impact.
How is data deleted ?
Paper records are shredded using a cross shredder.
Electronic data – emails or text messages are permanently deleted from the devices they are stored on.
General disclaimer
Your session with a hypnotherapist is not a substitute for a medical diagnosis or treatment.
If you have any questions related to your mental or physical health health, physical fitness or medical conditions, please seek the advice of a qualified medical practioner before coming for any treament.
Do not stop or alter ant treatment that you are currently receiving without prior consent of your doctor or mental health adviser.
Anyone under the influence of substances, including alcohol or drugs will not be seen or treated.
Everyone is unique therefore results will vary.