Privacy & Data Protection Policy
1. Information I Collect & Purpose
To provide safe, ethical therapy and fulfil my professional responsibilities, I collect and hold specific personal data. This includes details gathered during your initial enquiry, consultation, and intake, as well as records sent by healthcare professionals (such as your GP) or trusted representatives acting on your behalf.
Contact Details
Your name, address, email address, phone number, and date of birth. These are used to manage appointments and verify your identity if I need to contact your GP or process a formal data request.
Emergency & GP Details
The contact information for your registered doctor's surgery and your designated emergency contact, used only if serious safety concerns arise.
Session & Process Records
Summary notes regarding your mental health history, session themes, and clinical reflections relevant to our work. In line with UK GDPR and the Data Protection Act 2018, this information is classified as Special Category Data and is handled with the highest level of confidentiality.
Financial Data
Invoices and basic transaction records (name, fee, date) required for tax, accounting, and legal compliance. I do not store credit card or full bank account numbers.
Written Communication
Emails, text messages, and administrative correspondence relating to your sessions.
2. Confidentiality, Safety & Professional Wills
Everything shared within our sessions is kept strictly private in accordance with the BACP Ethical Framework. Confidentiality will only be broken in rare and exceptional circumstances:
Safeguarding & Emergencies
If there is a serious risk of harm to you or someone else, or in an acute medical emergency. Where safe and possible, I will always aim to discuss this with you before contacting your GP, emergency services, or relevant authorities.
Legal Obligations
If disclosure is mandated by a court order or legal requirement (e.g., severe crime, terrorism, or fraud).
Clinical Supervision
I discuss casework anonymously with a qualified supervisor who is bound by identical confidentiality rules.
Therapeutic Will (Incapacity or Death)
Your contact details are securely accessible by a designated Clinical Executor (a qualified therapist bound by equal confidentiality standards). Should I become unexpectedly incapacitated or pass away, they will contact you to explain the situation, support a safe ending or referral, and manage records securely. They will not act as your ongoing therapist without your consent.
3. How Your Data Is Stored & Managed
To ensure complete privacy, your personal identity and clinical records are kept strictly separate:
Separation of Data
Your name and contact details are stored independently from consultation records and process journals, linked only by an anonymous identifying code.
Digital & Physical Security
Digital files are held on password-protected devices with active antivirus protection, utilising encrypted European communication providers. Physical documents, if any, are kept in a locked filing cabinet.
Communication Channels
My professional mobile device is password-protected. Email communications are managed via standard secure email platforms. Text messages are deleted at least once per year.
Retention Period
Contact details, written correspondence, invoices, and clinical/process records are retained for 7 years following the end of our work together, in line with standard UK professional indemnity insurance and accounting regulations (unless a longer period is mutually agreed upon or legally required). After 7 years, all digital and physical records are permanently and securely deleted.
4. Your Rights & Data Breach Protocols
Under UK data protection law, you have specific rights regarding the information held about you:
Right of Access
You may request a copy of the personal data and records I hold about you at any time. Requests can be made verbally or in writing, and I will endeavor to fulfill them within four weeks.
Right to Rectification
You have the right to request that any inaccurate or incomplete information be corrected.
Data Breach Notification
In the unlikely event that your personal data is accidentally or maliciously accessed by an unauthorized third party, I will notify you within 72 hours (3 days) of becoming aware of the breach.
If you have questions or concerns about how your data is handled, please discuss them with me directly on therapy@sagiyaari.co.uk. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO). My ICO registration reference is ZC254383.