5. Privacy & Data Protection Policy

Privacy & Data Protection Policy

1. Information I Collect & Purpose

To provide safe, ethical therapy and fulfil my professional responsibilities, I collect and hold specific personal data. This includes details gathered during your initial enquiry, consultation, and intake, as well as records sent by healthcare professionals (such as your GP) or trusted representatives acting on your behalf.

Contact Details

Your name, address, email address, phone number, and date of birth. These are used to manage appointments and verify your identity if I need to contact your GP or process a formal data request.

Emergency & GP Details

The contact information for your registered doctor's surgery and your designated emergency contact, used only if serious safety concerns arise.

Session & Process Records

Summary notes regarding your mental health history, session themes, and clinical reflections relevant to our work. In line with UK GDPR and the Data Protection Act 2018, this information is classified as Special Category Data and is handled with the highest level of confidentiality.

Financial Data

Invoices and basic transaction records (name, fee, date) required for tax, accounting, and legal compliance. I do not store credit card or full bank account numbers.

Written Communication

Emails, text messages, and administrative correspondence relating to your sessions.

2. Confidentiality, Safety & Professional Wills

Everything shared within our sessions is kept strictly private in accordance with the BACP Ethical Framework. Confidentiality will only be broken in rare and exceptional circumstances:

Safeguarding & Emergencies

If there is a serious risk of harm to you or someone else, or in an acute medical emergency. Where safe and possible, I will always aim to discuss this with you before contacting your GP, emergency services, or relevant authorities.

Legal Obligations

If disclosure is mandated by a court order or legal requirement (e.g., severe crime, terrorism, or fraud).

Clinical Supervision

I discuss casework anonymously with a qualified supervisor who is bound by identical confidentiality rules.

Therapeutic Will (Incapacity or Death)

Your contact details are securely accessible by a designated Clinical Executor (a qualified therapist bound by equal confidentiality standards). Should I become unexpectedly incapacitated or pass away, they will contact you to explain the situation, support a safe ending or referral, and manage records securely. They will not act as your ongoing therapist without your consent.

3. How Your Data Is Stored & Managed

To ensure complete privacy, your personal identity and clinical records are kept strictly separate:

Separation of Data

Your name and contact details are stored independently from consultation records and process journals, linked only by an anonymous identifying code.

Digital & Physical Security

Digital files are held on password-protected devices with active antivirus protection, utilising encrypted European communication providers. Physical documents, if any, are kept in a locked filing cabinet.

Communication Channels

My professional mobile device is password-protected. Email communications are managed via standard secure email platforms. Text messages are deleted at least once per year.

Retention Period

Contact details, written correspondence, invoices, and clinical/process records are retained for 7 years following the end of our work together, in line with standard UK professional indemnity insurance and accounting regulations (unless a longer period is mutually agreed upon or legally required). After 7 years, all digital and physical records are permanently and securely deleted.

4. Your Rights & Data Breach Protocols

Under UK data protection law, you have specific rights regarding the information held about you:

Right of Access

You may request a copy of the personal data and records I hold about you at any time. Requests can be made verbally or in writing, and I will endeavor to fulfill them within four weeks.

Right to Rectification

You have the right to request that any inaccurate or incomplete information be corrected.

Data Breach Notification

In the unlikely event that your personal data is accidentally or maliciously accessed by an unauthorized third party, I will notify you within 72 hours (3 days) of becoming aware of the breach.

If you have questions or concerns about how your data is handled, please discuss them with me directly on therapy@sagiyaari.co.uk. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO). My ICO registration reference is ZC254383.