‍Privacy Policy for Room To Be You

‍Counselling & Expressive Arts Therapy (from visiting my website, to initial contact through to end of therapy / single session).

1. Overview

‍Room To Be You with BACP Registered therapist Davina Hanlon, is committed to protecting your privacy and maintaining the security of any personal information received from you. I strictly adhere to the requirements of the data protection legislation in the UK. This includes the UK General Data Protection Regulation, (the UK GDPR 2016), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003.

‍This privacy notice tells you what I will do with your personal information from visiting my website to initial point of contact through to after your therapy or your single session has ended, including:

Why I am able to process your information and what purpose I am processing it for

Whether you have to provide it to me

How long I store it for

Whether there are other recipients of your personal information

Whether I intend to transfer it to another country

Your data protection rights.

‍I am happy to chat through any questions you might have about my Privacy Policy, and you can contact me at Davina@roomtobeyou.co.uk

‍“Data controller” is the term used to describe the person/ organisation that collects and stores and has responsibility for people’s personal data. In this instance, the data controller is me registered as Davina Hanlon trading as Room To Be You. I am registered with the Information Commissioner’s Office [Registration Number: ZC076421].

‍If I make changes to this policy, I will notify you by updating it on this website.

2. The Data I Collect

‍Initial contact. When you contact me with an enquiry about my therapy services, I will collect information to help me satisfy your enquiry. This will include your name and reasons for seeking support including relevant physical and mental health details. If you decide not to proceed, I will ensure all your personal data is deleted within one working day. If you would like me to delete this information sooner, just let me know.

‍For the provision of counselling and expressive arts therapy - I collect and process information that allows me to provide safe, professional, and ethical therapeutic services, including:

‍Personal Details: Name and date of birth.

‍Contact Information: Phone number, email address, home address, and your preferences for how I may contact you.

‍Emergency Contact: Name and contact details of a trusted person to contact if you need additional support.

‍Special Category (Sensitive) Data: Relevant physical and mental health details, GP contact information, reasons for seeking support, my clinical session notes, and CORE-10 session rating scale data at our 1st and last session where available and collected.

Expressive Arts Data: Digital photographs of creative work generated by you in sessions (where appropriate and agreed upon) or the physical work itself if left in my care.

3. Why I Need Your Data (Lawful Basis)

‍The UK GDPR states that I must have a lawful basis for processing your personal data. There are different lawful bases depending on the stage at which I am processing your data. I have explained these below:

‍If you have had therapy with me and it has now ended, I will use legitimate interest as my lawful basis for holding and using your personal information.

‍If you are currently having therapy or if you are in contact with me to consider therapy, I will process your personal data where it is necessary for the performance of our contract. The UK GDPR also makes sure that I look after any sensitive personal information that you may disclose to me appropriately. This type of information is called ‘special category personal information’. The lawful basis for me processing any special categories of personal information is that it is for provision of health treatment (in this case for psychological therapy) and necessary for a contract / agreement with a health professional (in this case, a contract (Working Agreement / Outdoor Working Agreement) between me and you). This specifically relates to UK GDPR, Article 6(1)(b) condition (e.g., Performance of Contract) and an Article 9(2)(h) (Provision of health or social care treatment). ‍

4. How I Store Your Data

‍I take data security very seriously and use the following measures to keep your information safe:

‍Storage, Technology & Digital Security - To manage administrative tasks, store client files, and conduct online video sessions securely, I use Google Workspace (including Google Drive and Google Meet). Google Workspace provides enterprise-grade data security, encryption, and privacy compliance in alignment with the UKGDPR and the Data Protection Act 2018.

‍Email & Digital Records: All client communications, administrative records, and clinical files held in Google Drive are encrypted both in transit (when sent or received) and at rest (when stored on servers). Access is restricted exclusively to me via strict, password-protected, two-factor authenticated devices.

‍Online Video Sessions: Online initial chat and therapy sessions are conducted using Google Meet. Google Meet sessions employ secure encryption protocols to protect video, audio, and chat data in transit. Online video sessions are live and are never recorded or transcribed, preserving the privacy and confidentiality of our therapeutic work.

‍Data Processing Safeguards: Google acts as a Data Processor under standard contractual clauses and data processing addendums that meet UK data protection compliance standards, ensuring client information is treated with strict confidentiality and is not used or shared for advertising or external profiling.

‍Clinical notes are stored separately from your personal details and will not have any identifying details; however, they will be linked to your personal information by a client code (e.g., RTBY4)

‍Email Minimisation: Introductory emails are permanently deleted from my active inbox once the information is transferred to your secure digital file.

‍Text / WhatsApp: For security reasons I do not retain text or WhatsApp messages for more than one year. If there is relevant information contained in a message I will insert it into my notes.

‍Physical Records & Creative Work: Any paper records, or physical creative artwork left in my care, are kept securely in a locked filing cabinet. ‍

5. Sharing Your Data (Confidentiality & Exceptions)

‍Our work together is confidential. I will not share your information with third parties unless:

‍I have your explicit written consent to do so.

I am legally compelled by a court order.

‍I believe there is a serious, imminent risk of harm to yourself or others.

‍A statutory law is being broken (e.g., safeguarding children or vulnerable adults, money laundering).

‍There is a legal obligation under terrorism or drug trafficking legislation.

‍I am discussing my clinical work with my professional Supervisor. In these instances, your identity is completely anonymised to protect your privacy.

‍Before we begin our sessions, I will explain these boundaries of confidentiality more fully. Wherever possible and legally permitted, I will discuss any potential challenge to confidentiality with you beforehand. I will provide a copy of my Privacy Policy for you to review, sign and return. At our first session I will highlight the key points of the Privacy Policy, in particular reiterating confidentiality and exceptions. I also refer to this within our Working Agreement (the contract between us) which again I will have provided for you to review, ask questions and sign ready for our work to begin.

6. How Long I Keep Your Data

‍In line with my professional indemnity insurance requirements and professional body guidelines and standards (as a registered member of the British Association for Counselling and Psychotherapy, (BACP)), I retain your clinical records (including session notes, your clinical file, and related digital / physical data) for 7 years after our final session. After this period, digital records are permanently deleted, and physical documents are securely shredded.

‍7. Your Rights

‍Under the UK General Data Protection Regulation (2018), individuals have the following rights:

‍Right to be informed. You have a right to know how and why your personal data is being processed. This privacy notice details how I use your information.

‍Right of access. You have a right to ask me for a copy of all the information I hold about you.

‍Right to rectification. You have a right to correct your information if it is factually incorrect. You can contact me directly to make a change.

‍Right to erasure. You have a right to ask me to delete or remove your personal data.

‍Right to restriction of processing. You have a right to stop businesses from processing your personal data.

‍Right to data portability. You have a right to obtain and re-use your personal data for your own benefit.

‍Right to object. You have a right to object to the processing of your personal data. If you think that I am using your data inappropriately, please get in touch.

‍To make a request for any personal information I may hold about you, please put the request in writing addressing it to Davina@roomtobeyou.co.uk. If you have any complaint about how I handle your personal data, please do not hesitate to get in touch with me by writing or emailing to the contact details given above. I would welcome any suggestions for improving my data protection procedures.

‍8. Contact and Complaints

‍If you want to make a formal complaint about the way I have processed your personal information you can contact the ICO which is the statutory body that oversees data protection law in the UK. For more information go to ico.org.uk/make-a-complaint.

‍9. Visitors to my Website and Cookies

‍When someone visits my website, I use a third-party service, Squarespace, to collect standard internet log information and details of visitor behaviour patterns (such as the number of visitors to various parts of the site). This information is processed in a way that does not identify anyone. I do not make, and do not allow Squarespace to make, any attempt to find out the identities of those visiting my website.

‍Cookies and Similar Technologies - Small files called cookies are placed on your device to help the site run effectively and to provide statistical data about visitor traffic.

‍Types of Cookies Used:

‍Essential / Functional Cookies: These are strictly necessary for Squarespace to deliver the website securely and allow core navigation to function. Consent is not legally required for these essential cookies, and they are always active.

Analytics & Performance Cookies: With your consent, I use Squarespace Analytics to collect aggregate information about how visitors interact with the site (such as page views and traffic activity). This helps me continuously improve my practice's website.

‍Managing Your Cookie Choices: You can choose to accept or decline non-essential analytics cookies when you first visit my site using the cookie banner. You can also change your preferences or withdraw your consent at any time by updating your choices via the "Cookie Preferences" link in the footer of this website.

‍For more details on the exact cookies placed by Squarespace, view the Squarespace Cookie Documentation.

‍To read about how Squarespace handles site data, view Squarespace’s Privacy Policy.

‍ ‍

‍ ‍