Privacy notice
1. Who we are
This privacy policy explains how Rachel Gibson Counselling collects, uses, stores, and protects your personal data. I am Rachel Gibson, a counsellor in private practice.
Contact details
I am registered with the Information Commissioner's Office (ICO) as a data controller. I take my responsibilities under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Data (Use and Access) Act 2025 seriously
2. What personal data we collect
I collect and process the following categories of personal data:
Contact and administrative information
- Your name, address, telephone number, and email address
- Emergency contact details
- GP details (where relevant and with your consent)
Health and therapy-related information
- Presenting issues and reasons for seeking therapy
- Information about your mental and emotional wellbeing
- Relevant medical history you choose to share
- Session notes documenting our therapeutic work together
- Risk assessments where applicable
Important: Health and therapy-related information is classified as special category data under Article 9(1) of the UK GDPR. This type of data reveals information about your physical or mental health and receives enhanced legal protection. I handle this data with the utmost care and confidentiality.
3. How I collect your data
I collect personal data directly from you in the following ways:
- At first contact — when you enquire about therapy via email or telephone.
- During intake — when you complete any initial paperwork or assessment forms
- During our sessions — through our therapeutic conversations
- Between sessions — if you contact me via email or telephone
I do not collect personal data about you from any other source.
4. Why we process your data — lawful basis
Under UK GDPR, I must have a valid legal reason (known as a "lawful basis") to process your personal data. Because therapy involves sensitive health information, I need two separate legal bases:
Article 6 basis (for all personal data): Article 6(1)(b) UK GDPR — processing is necessary for the performance of the therapeutic contract between us. When you engage me as your therapist, we enter into a contract. I need to process your personal data to fulfil my obligations under that contract, including scheduling appointments, communicating with you, and providing therapy.
Article 9 basis (for special category health data): Article 9(2)(h) UK GDPR — processing is necessary for the provision of health or social care treatment by a health professional. As a qualified counsellor, I am permitted to process health-related data as part of providing your therapy.
The additional condition required under UK law is met through DPA 2018 Schedule 1, Part 1, paragraph 2 (health or social care). Processing is carried out by a qualified counsellor subject to the common-law duty of confidence and the professional standards expected of counsellors in private practice.
5. Professional obligations and CPD
I am required by BACP to attend regular clinical supervision. Supervision is an essential part of safe and ethical therapeutic practice — it helps me reflect on my work and ensures I am providing you with the best possible care.
When I discuss our therapeutic work with my supervisor:
- Your name and any identifying details are NOT shared with my supervisor
- I use anonymised or pseudonymised case material only
- My supervisor is a qualified professional bound by the same confidentiality obligations as I am
- My supervisor is bound by their own professional body's ethical framework
This means my supervisor cannot identify you from anything I share with them.
7. How long we keep your data
| Type of record | Retention period | Reason |
|---|---|---|
| Therapy records | 7 years after our last session | In line with the Limitation Act 1980 and standard professional indemnity insurance requirements |
| Financial records (invoices, payment records) | 6 years | HMRC legal requirement |
| Website enquiries (if you do not become a client) | 12 months | Legitimate interest in responding to enquiries |
How records are stored: All clinical records are kept in electronic format only. Electronic records are encrypted and password-protected on secure systems, with access restricted to me alone (and anonymised material only shared with my supervisor as described above).
How records are destroyed: After the applicable retention period, records are securely deleted.
8. Your rights under UK GDPR
You have the following rights regarding your personal data. I have explained each one in plain language:
1. Right to be informed You have the right to know how I use your data. This privacy policy fulfils that right.
2. Right of access You can ask for a copy of all the personal data I hold about you. This is sometimes called a "subject access request." Under the Data (Use and Access) Act 2025, I will conduct a reasonable and proportionate search to locate your data and respond within one month.
3. Right to rectification If any of your personal data is inaccurate or incomplete, you can ask me to correct it.
4. Right to erasure You can ask me to delete your personal data in certain circumstances. However, this right does not apply where I need to keep your data to comply with professional obligations or for the establishment, exercise, or defence of legal claims. This means I may need to retain therapy records for the full retention period even if you request deletion.
5. Right to restrict processing You can ask me to limit how I use your data in certain circumstances — for example, while a complaint is being investigated.
6. Right to data portability You can ask for your data in a format that allows you to transfer it to another service. This right applies to data you have provided to me and that I process based on your consent or our contract.
7. Right to object You can object to certain types of processing. This right is limited where I am processing data under our therapeutic contract or for legal compliance.
8. Rights related to automated decision-making You have the right not to be subject to decisions based solely on automated processing. I do not use automated decision-making in my practice.
To exercise any of these rights, please contact me at: rachel@rachelgibsoncounselling.co.uk
I will respond to your request within one month. There is no fee for most requests, but I may charge a reasonable fee if your request is clearly unfounded or excessive.
9. Data protection complaints — your right under the Data (Use and Access) Act 2025
You have the right to make a data protection complaint directly to me.
To make a complaint:
- Email me at rachel@rachelgibsoncounselling.co.uk
I take all complaints seriously and will respond within one month.
If you are not satisfied with my response: You may escalate your complaint to the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Telephone: 0303 123 1113
- Address: ICO, Wycliffe House, Water Lane, Wilmslow, SK9 5AF
The ICO is the UK's independent supervisory authority for data protection.
10. Confidentiality exceptions
Everything you share with me in therapy is treated as confidential. However, there are rare circumstances where I may need to share information without your consent:
- Risk of serious harm — if I believe you or someone else is at imminent risk of serious harm, I may need to contact appropriate services
- Safeguarding concerns — if I become aware of a child or vulnerable adult at risk of abuse or neglect
- Legal requirement — if a court orders me to disclose information
In almost all cases, I will try to discuss this with you first and explain what I need to do and why — unless doing so would itself put someone at risk.
Breaking confidentiality is always a last resort. If it ever becomes necessary, I will share only the minimum information required and with the fewest people possible.