Privacy Policy
The purpose of this policy is to inform users of this website of the personal information I Yasmin Lawes (of Kinder Minds Inclusive Therapy), the Data Controller, collect, use and store, your personal information and the rights you have regarding your personal information.
This policy has been compiled according to the UK General Data Protection Regulations (UK GDPR, 2018) and the Data Protection Act (2018). I am happy to discuss my GDPR policy with you at any point. Throughout this policy, the terms “I”, “my” and “me” refer to I, Yasmin Lawes of Kinder Minds Inclusive Therapy.
Collection of Your Personal Information
Initially collected via my website, counselling directories or direct email
Name, email address and initial message.
Collected at initial consultation and during ongoing sessions
- Name
- Email address
- Phone number
- Date of birth
- Home address
- GP name and address
- Emergency name and contact details
- Administrative information
- Country of birth
- Occupation/education
- Nature of difficulties experienced
- Relationships
- Previous experience of therapy
Your GP and emergency contact will only be contacted should there be a concern for your safety or welfare. Administrative information includes session date, time, duration and format (online or in-person), invoices and payment records.
Sensitive information
- Medical conditions
- Mental health diagnoses
- Prescribed medication
- Gender identity / pronouns / sexuality / religion / race / ethnicity / culture
This information is collected for therapeutic purposes - to understand how these aspects impact you, provide an appropriate level of care, and assess any reasonable accessibility adjustments. It is held securely and only shared carefully and anonymously in in clinical supervision.
Rarely, this information may need to be shared or processed where there is a legal or safeguarding basis to protect your welfare or someone else's, and it is not possible to obtain your consent first, or the information has already been made public. In these circumstances, your information may no longer remain anonymous. However, I will only share the essential information that is necessary.
How I Use Your Data
I use your information for the following legitimate purposes:
- Communication regarding appointments, cancellations and rescheduling
- Providing an appropriate level of service as set out in the therapy contract
- Meeting ethical body (BACP) and insurance requirements
- Brief session notes to provide continuity of care and track progress
- Sharing where required by law, or if notes are subpoenaed by a court
- Informing clients of changes to my services
- Personalising services to clients
- Collecting feedback to improve my services
- Processing payments and raising invoices
- Clinical and ethical discussion of client work with a qualified supervisor, kept anonymous unless there is a legal or safeguarding concern
- Clinical and ethical discussion of client work in peer supervision, kept anonymous, with no notes retained
- Contacting you via a Clinical Trustee in the event of my death or incapacity, and the secure transfer and storage of your records
How I Store Your Data Securely
Data Controller: Kinder Minds Inclusive Therapy is the data controller for personal information collected through the website or via online or in-person sessions.
Data Processors: I use the following third parties to process personal information collected through the website, through the initial consultation, sessions, and through BACS payments. These Data Processors only act on my instructions and do not own, control or use the data for its own purposes.
Website hosting - Netlify, Inc.
Netlify, Inc. acts hosts my website and processes data submitted through the contact form. Netlify, Inc is based in the United States- data may be processed or stored outside the UK/EEA under Standard Contractual Clauses approved by the European Commission, to ensure your data continues to receive an equivalent level of protection.
Netlify, Inc. processes contact form submissions (name, email, message) and visitors' IP addresses on my instructions only. IP addresses are processed under legitimate interest for security, fraud prevention and technical operation, and therefore, do not require separate consent. IP addresses are automatically deleted or rotated out within 30 days. Netlify does not use your data for its own purposes. Once I receive your email, I delete any personal data stored on Netlify, Inc's database.
Proton AG:
Proton AG provides zero-access encrypted email, cloud storage, scheduling and video conferencing, used to communicate with clients, store documents, plan sessions and conduct online sessions. Emails between Proton Mail accounts, along with calendar events, video calls, and files stored in Proton Drive, are also end-to-end encrypted. Proton AG is based in Switzerland (outside the UK/EEA) and is subject to strict Swiss privacy laws and high security standards.
Emails- Proton Mail
Personal information from initial enquiries, whether submitted via my website or through directories, or received by direct email, is processed and stored in Proton Mail for necessary administration and communication, so I can provide you with my therapeutic services.
Messages exchanged between Proton Mail accounts are end-to-end encrypted. Messages from Proton Mail to other email providers are protected by TLS encryption in transit, but dependant on your email provider's own security standards, may not be end-to-end encrypted once received in your inbox. However, messages that I receive from other email providers are received via TLS encryption and stored with zero-access encryption.
Client Records- Proton Drive
Personal information is processed from the initial free consultation, new client registration process and ongoing client sessions and digitally stored on Proton Drive. The following records and clinical information are processed and stored on Proton Drive:
- New Client Form - stored separately from client notes
- New Client Questionnaire- stored separately from client notes
- Client Therapy Agreement - stored separately from client notes
- Walk & Talk Agreement - stored separately from client notes
- Walk & Talk Health & Suitability Form- stored separately from client notes
- Client notes- stored separately from all other client records and stored under a unique anonymised non-identifiable client code
- Rewind Technique New Client Form & Agreement - stored separately from client notes
- Rewind Technique IES scores and notes stored using a unique anonymised non-identifiable client code
- Supervision notes- stored in the same folder with client notes under a unique anonymised non-identifiable client code
- Internal payment tracker- stored separately from client notes and uses the anonymised client code
Online Sessions- Proton Meet
In order for online sessions to take place, Proton Meet processes your video and audio data during the session, along with any chat messages, screen share or files shared in-call. The service is designed so Proton AG cannot access meeting content and their servers process only the minimal technical data needed to connect the call. Meeting content or participant details after the session ends are not stored and sessions are not recorded.
Session Management- Proton Calendar
In order for effective practice management and booking purposes, Proton Calendar is used to schedule and manage client sessions. Personal information includes client codes, appointment dates, times and any associated notes needed. This information is stored only for the management and scheduling of sessions.
Online Sessions- Doxy.me
Doxy.me is a US-based telemedicine video calling platform for healthcare professionals. Doxy.me runs directly in the browser with no downloads required for clients. Sessions are not recorded or stored by Doxy.me, and no session content is retained by Doxy.me after the call ends. Limited technical data (e.g. connection/session metadata) may be processed to enable the call. UK/EU data is handled under Doxy.me's GDPR-aligned privacy policy, which sets out how data is processed on my behalf. Processing is necessary in order to carry out therapeutic services.
Clinical Supervision
As part of my professional and ethical obligations, I take part in regular clinical supervision. This means discussing client work with a qualified supervisor to ensure the quality, safety and effectiveness of the therapy provided, and to support my own professional development. Supervision also forms a core part of my ongoing reflective practice. Client work is anonymised in supervision, with names and identifying details removed, unless there is a serious safeguarding concern or legal reason for disclosure. My supervisor is bound by the same ethical and confidentiality standards as I am.
I also take part in peer supervision with other counsellors/therapists, as a further layer of support for safe, ethical and reflective practice. Any client material discussed is fully anonymised. My peer supervisees are bound by the same ethical and confidentiality standards as I am and do not retain any notes or records from these sessions
Website analytics - Umami.is
A privacy-first, GDPR-compliant-by-design platform to measure website analytics, based in the US. Umami do not collect any personally identifiable information. No cookies are required, IP addresses are not stored and are anonymised, and there is no cross-site tracking.
Clinical Will - ClinicalWill.app
ClinicalWill.app is a UK-based platform who processes data on my instructions. They are used to securely store necessary and minimal client contact information, in the event of my death or sudden incapacity, and my Clinical Will needs to be activated and executed. The platform has session timeouts requiring re-login, and rate-limit login attempts to reduce credential-stuffing/hijacking risks.
Each user type on ClinicalWill.app (Practitioner, Clinical Trustee, Next of Kin) gets their own login tied to my (Practitioner) account, restricted to only the information relevant to their role. The Next of Kin only logs in to inform the Clinical Trustee of my death/incapacity and sees no client information. My appointed Clinical Trustee (a trusted, qualified therapist colleague) then gains access to the platform, where they will see your basic contact information so they can make contact with you and support you in finding ongoing therapeutic support, and discuss the confidential transfer of your records. Only where relevant and appropriate, brief and specific information may also be available in order to inform you sensitively of my death or incapacity- never session content. The Clinical Trustee then securely transfers and stores your records in confidence until the retention period ends, after which records are securely deleted or destroyed. My Clinical Trustee is bound by the same legal and ethical confidentiality standards as I am.
Phone Communications - Business Phone (Eco Talk - network provider)
Personal information (phone number and client code) is processed and stored on my separate business device and my mobile network provider (Eco Talk), act as a data processor. Messages and call logs are not used for any purpose beyond providing your therapy service, and are deleted when no longer needed. Messages are restricted for session administration purposes only, and SMS/iMessage exchanges are based on consent. Phone calls may occur during the initial consultation or if there are technical issues with Proton Meet or Doxy.me, and we decide to have a phone meeting as a suitable alternative. Phone calls are never recorded and are always carried out in a confidential space.
Other
- Client Code- Client Name Index Key: I store a single paper document to link your unique non-identifiable client code to your name. This data is stored in a lockable filing case, which only I have access to. This index key is required for legal, legal, ethical and insurance purposes
- All client records, files and notes are backed up on an encrypted and password-protected memory stick, which is locked in a filing case with controlled access
- Paper diary: (stored securely with controlled access) used for effective practice management of session appointments. Personal information includes client codes, appointment dates, times and associated noted needed or booking purposes
The following 3rd Party Data Controllers are also involved in using your data:
Clinical Supervisor:
I discuss client material in supervision to support the quality and safety of my practice. This material is anonymised, except in cases of serious safeguarding or legal concern, where identifying details may need to be shared. My supervisor acts as an independent data controller, deciding for themselves what information they record and retain based on what is discussed in our sessions.
Counselling/Therapy Directories:
If you contact me through a directory that I am listed on (such as Counselling Directory, BACP, or similar), the directory forwards your enquiry to me by email. Once I receive your enquiry, I become the data controller for how your information is used and stored going forward, in line with this privacy notice. The directory remains a separate, independent data controller for its own platform and processing- it is not a data processor acting on my behalf. Please refer to the relevant directory's own privacy notice for details of how they handle your information before and after it reaches us.
Finance
Monzo Bank Limited: Payment for sessions are processed via Monzo Bank Limited on the lawful basis of contract (to provide therapy services) and legal obligation (for tax and accounting records). I do not store your card or full bank details- this is securely held by Monzo Bank Limited, who act as the Data Controller as they decide what personal data is required to complete a financial transaction and how long they store transaction records. Under banking regulations, Monzo must display real names to comply with anti-money laundering laws and the UK Confirmation of Payee (CoP) framework.
HMRC: Where legally required, I may need to disclose client names on financial records (never clinical information) to HMRC for tax and accounting purposes (redaction of names or anonymisation codes will be used wherever possible). HMRC acts as an independent data controller for any information it receives, determining its own purposes for processing it (such as tax administration and enforcement) rather than acting on my instructions. This disclosure is made under the lawful basis of legal obligation, as required by UK tax law.
Finance Services: A finance professional may be used to manage financial records, including bank statements, which may show client names used for payments (redaction of names or anonymisation codes will be used wherever possible). They act as an independent data controller in their own right- determining how they carry out their professional accounting duties, rather than as a data processor on my behalf. They are bound by professional confidentiality obligations under their professional bodies and own regulatory duties (including UK anti-money laundering law) in how they handle personal information.
The following may also act as Data Controllers in certain situations:
- Holistic Insurance if I ever need to make a claim or report an incident involving client details
- GP, emergency services or court if I ever need to share information based on safeguarding or duty-of-care situation where information may be shared without prior consent or for legal obligations
- ICO if I ever need to report a data breach
Your Rights Under Data Protection Law
Under UK GDPR, you have several rights concerning your personal data:
- The right to be informed
- You have a right to be informed about the data I collect and how it is used.
- The right of access
- You have a right to see any details I hold through a formal request for data access.
- The right to rectification
- You have a right to request that inaccurate, incomplete or outdated records be amended.
- The right to be forgotten
- The right to be forgotten is not absolute for therapy clients in the UK, as your data is needed to continue providing an appropriate service. I am required legally, ethically and for insurance purposes to retain notes and personal information. If your request falls within the legal timeframe to retain information (7 years from the date of my last contact or therapy session), I may not be able to delete your records or information. Should you request this, I shall acknowledge your request, inform and explain the reason for the outcome clearly to you.
- The right to restrict processing
- You may prevent processing of your data, though I may still securely store it. Whilst the restriction is in place, I am prohibited from actively processing, sharing or altering your data. However, this right can be overridden if the restriction would prevent me from providing safe and necessary welfare and care.
- The right to data portability
- You have a right to obtain copies of your data for re-use with other services.
- The right to object
- You have a right to object to particular uses of your data, such as marketing.
- The right not to be subject to automated decision-making
- I do not use automated decision-making to provide services.
Data Breaches
Whilst procedures are in place to protect your information, my processes may be vulnerable to compromise and a potential breach of information. Should this occur, I have a legal obligation to report any data breach to affected clients and to the Information Commissioner's Office (ICO) within 72 hours of becoming aware.
Data Retention
Client data is retained only for as long as necessary.
Where a client chooses not to proceed with therapy, information gathered during the initial 15-minute consultation is retained for a period of 6 months, after which it is securely destroyed.
On termination of services or last contact, data stored on my business phone (phone number, client code and messages) will be deleted after seven days. Although text messages are reserved for administration purposes, any that contain clinical information will be stored under client notes and held for 7 years.
Emails will be deleted within 6 months of the termination of the therapy. Although emails are reserved for administrative purposes, any that contain clinical information will be stored under client notes and held for 7 years.
All other clinical records and notes are held for seven years from the date of your last therapy session or contact, governed by UK legal requirements, my insurance provider (Holistic Insurance Services) and the BACP, of which I am a registered member. After seven years, and once there is no longer a lawful reason to retain it, I will securely dispose of any remaining data.
Payment records are kept separately from clinical records and retained for six years, in line with HMRC requirements.
For BACP requirements and accreditation purposes, I continue to keep an indefinite, fully anonymised record of:
- Your unique, non-identifiable client code
- Date of session
- Duration of session
- Format (online, in-person or Walk & Talk)
- Client type - adult, child (under 12), or young person (12-18)
- Session type (e.g. individual therapy)
As this information cannot be associated or traced back to you after the index key is destroyed, this information will be used indefinitely without further notice to you.
How to Make a Complaint
If you have any concerns about my use of your personal information, please first make a data protection complaint to me at . I will acknowledge receipt of any complaint within 30 days and respond without undue delay.
If you remain unhappy with how we've used your data after raising a complaint, you can also make a complaint to the ICO:
Information Commissioner's OfficeWycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Conclusion
Your use and undertaking of the services of Kinder Minds Talking Therapy constitutes consent and acceptance of this data privacy policy and the collection, storage and processing of personal data, as laid out. You have the right to withdraw consent at any time. This policy is subject to regular review and will be updated as necessary. Clients will be notified of any changes as soon as possible.