Privacy & Confidentiality

Data Protection and Confidentiality in Counselling

Your privacy, dignity and trust are central to my work as a counsellor. This counselling privacy policy explains how your personal information is collected, stored, protected and used, and how confidentiality is maintained throughout our work together.

I am committed to handling your information safely, lawfully and transparently in line with UK data protection law, GDPR, and the professional ethical standards of the British Association for Counselling and Psychotherapy (BACP).

Legal and Professional Framework

I comply with:

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018
  • Privacy and Electronic Communications Regulations (PECR)
  • Professional ethical requirements of the British Association for Counselling and Psychotherapy (BACP)

Data Controller

The data controller is the person responsible for collecting and managing personal data.

This policy explains how your personal information is collected, stored, protected and used, and how confidentiality is maintained throughout our work together.

If you have any questions about how your information is handled, you are welcome to contact me at any time.

Confidentiality

Confidentiality is a cornerstone of counselling. What you share with me will be treated with respect and kept private.

Information discussed in sessions will not be shared with anyone without your consent, except in rare situations where there is a legal or ethical duty to disclose.

Confidentiality may be broken if:

  • You or someone else is at serious risk of harm
  • A child or vulnerable adult is at risk of abuse or neglect
  • I am required to disclose information by law or court order
  • There is disclosure of serious criminal activity such as terrorism, money laundering or drug trafficking

Where possible, I will discuss any need to share information with you first, unless doing so would increase risk or is legally prohibited.

Lawful Basis for Processing Your Information

Under GDPR, I must have a lawful basis for processing personal data.

If you are making an enquiry or currently in therapy, your data is processed because it is necessary for the performance of our contract.

After therapy has ended, your data is retained under legitimate interests for professional, legal and insurance purposes.

Health and mental health information is classed as “special category data”. This is processed lawfully for the provision of health treatment (counselling services).

How Your Information Is Used

Initial Contact

When you contact me with an enquiry, I may collect:

  • Name
  • Date of birth
  • Contact details
  • GP details
  • Relevant health or background information

This helps me respond appropriately to your enquiry.

If you choose not to proceed with counselling, your details will be deleted within two weeks (or sooner on request).

During Counselling

To provide a safe and effective service, I keep:

  • Contact and administrative details
  • Brief factual session notes
  • Appointment records

Records are:

  • Stored securely on encrypted devices or secure software
  • Password protected
  • Not shared with third parties without lawful reason

For security reasons:

  • Text messages are not kept longer than two days
  • Non-essential emails are deleted promptly
  • Important information may be transferred into your secure clinical notes

After Counselling Ends

Records are kept for seven years after our last contact. This is standard professional practice for legal, insurance and safeguarding reasons.

After this period, records are securely destroyed.

You may request earlier deletion where appropriate by contacting me.

Information Sharing

Your information is never sold or shared for marketing purposes.

In limited circumstances, data may be shared with trusted third parties where necessary, including:

  • My clinical supervisor (bound by professional confidentiality)
  • HMRC for tax and legal compliance
  • Secure service providers for email, record keeping or scheduling
  • The Information Commissioner’s Office or authorities if legally required

All third parties are required to handle data securely and only for the intended purpose.

Data Security

I take the protection of your information seriously. Safeguards include:

  • Encrypted devices and software
  • Secure storage systems
  • Password protection
  • Limited access
  • Regular professional review of procedures

Your Rights

You have the right to:

  • Access the personal data I hold about you
  • Request corrections to inaccurate information
  • Request deletion of your data in certain circumstances
  • Restrict or object to processing
  • Request a copy of your data
  • Lodge a complaint

Requests can be made in writing to: rabina@sereniquecounselling.co.uk

If you are unhappy with how your data is handled, you may contact the Information Commissioner’s Office at ico.org.uk.

Website Use

When you visit my website, anonymous information may be collected to help understand how the site is used and to improve the support offered. This does not identify you personally.

The website is hosted by GoDaddy and built using WordPress, who provide secure hosting and website management. They process data in line with their own privacy policies.

If you complete a contact form or make an enquiry, your information is stored securely and sent directly to me.

Appointments are booked through Calendly and payments are processed securely via Stripe. These services manage personal data according to their own privacy and security policies.

Email communication is managed through Outlook with Microsoft security protection in place to help keep correspondence safe and confidential.

Cookies may be used to ensure the website works properly and to understand general visitor activity.

Policy Review

This policy is reviewed regularly to ensure continued compliance with legal and professional standards.