Privacy Policy
This privacy notice informs you about how I manage your personal information. This includes the information I learn from you as a client, what you share with me, and the choices you make regarding our communication. This notice outlines how I protect your data, including the information collected when you use my website and services. This policy will be updated periodically in line with the General Data Protection Regulations (GDPR) or current legislation.
Lawful Basis for Processing Information
As a sole trader, I must collect and use certain types of information about individuals who seek my services. I consider my lawful basis for processing information to be one of legitimate interest, as collecting and maintaining your information is necessary to provide the services you require. I am committed to the lawful and correct treatment of personal information per GDPR standards and have taken reasonable precautions regarding the storage and processing of your data to ensure protection.
The Data Controller is:
Myself, Douglas McCabe
From time to time, I may contract with external agencies to provide services on my behalf. In all instances, I will seek written assurance that these agencies comply with GDPR principles. These generally would tend to include other healthcare professionals, usually within the NHS or contracted to NHS services such as your GP, occupational health or insurance companies.
The GDPR Principles
I ensure that personal data is:
· Processed fairly, lawfully, and transparently regarding the data subject.
· Collected for specified, explicit, and legitimate purposes and not further processed for incompatible purposes.
· Adequate, relevant, and limited to what is necessary concerning the purposes for which it is processed.
· Accurate and, where necessary, kept up to date.
· Kept in a form that permits identification of data subjects for no longer than necessary for the purposes for which it is processed.
· Processed in a way that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and accidental loss, destruction, or damage, using appropriate technical or organizational measures.
Use of Your Personal Data
I will use the personal information provided by you for registration purposes or gathered by me for the following:
· Determining your eligibility for hypnotherapy sessions.
· Administering, updating, and maintaining my client records.
· Processing and responding to requests, inquiries, and complaints from you.
· Communicating with you about my services, events, and news.
· Analysing trends and profiles and compiling statistics.
· Surveying clients.
· Preventing or detecting fraud.
· With your consent, liaising with other healthcare professionals as necessary for your care.
I do not store bank or card details except to process refunds requested by you, and such data will be deleted immediately after processing.
In compliance with legal requirements, I will hold your personal information on my systems for the duration of our professional relationship and seven years after for adults and 25 years for children (unless there has been a complaint). After this period, records will be securely deleted. Complaints data will be retained for three years and then anonymised.
What is visible to the Public?
Some of the information you provide may be visible on my website, for example if you give me feedback and permission to share. However, I will ensure that sensitive details remain private unless you explicitly provide them for public use. Comments can be posted with a name or anonymously and can be removed at request.
Collecting Personal Information
Links to Other Websites
My website may contain links to other sites. Once you use these links, you leave my website, and I have no control over other websites. I am not responsible for the protection and privacy of any information provided while visiting other sites not governed by my privacy policy. I suggest checking the relevant site's privacy statement.
Social Media
I have social media accounts; participation with these accounts and posts will be publicly visible.
Cookies
I collect your data automatically via cookies on my website per browser settings. For more information on cookies, including usage and choices, please click here. I also collect data from you via contact forms on my website.
Contact with You
Clients will be contacted by telephone, text message, and email. Consent will be sought if you prefer not to be contacted by email. Preferences can be updated by informing me directly. Unsubscribe options are available at any time.
Security and Storage of Your Personal Data
Appropriate technical and organisational measures will be taken to limit unauthorised or unlawful processing of personal data and guard against accidental loss, destruction, or damage.
Sharing of Personal Data
Information will be shared only when necessary to resolve inquiries or disputes. I share information:
· As required by law
· In the public interest
· With your consent
Personal data may be shared with healthcare professionals and other regulatory bodies as necessary for your care and in compliance with regulatory requirements. Your consent will be requested priort the sharing of any personal data with third parties. Sharing against your permission will only rarely be undertaken in line with Safeguarding Laws protecting vulnerable groups as agreed at our first appointment.
Your Right to Access
You have the right to request a copy of your personal information and have inaccuracies corrected. I will
Amendment of Personal Data Held
If incorrect personal information is held in my records, you may access and amend it yourself.
Breach of Obligations
For concerns regarding potential breaches of my data protection policy please contact me or the ICO. If there is a breach of data protection I will log the incident with the ICO and inform those affected within 72 hours, working days, where possible.
Right of Erasure
Under Article 17 of the GDPR, individuals have the right to have personal data erased in certain circumstances.
I am registered with the Information Commissioner’s Office, Reference Number: ZB861059
Date: 9/2/25
Review: 9/2/28