Privacy policy
1. Introduction
Seed Counselling is committed to protecting your personal information and respecting your privacy. This Privacy Notice explains how and why we collect, use, store and protect your personal data when you contact us or engage in therapy.
This notice complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Data Controller
Seed Counselling is the data controller for the personal data we process.
Contact details:
Email: briony@seedcounselling.co.uk
Website: www.seedcounselling.co.uk
(You may wish to add a postal/business address here if you have one.)
Seed Counselling is registered with the Information Commissioner’s Office (ICO) (if applicable – ensure this is accurate).
3. What Personal Data We Collect
We may collect and process the following personal data:
Personal data
Name, email address, phone number, postal address
Information provided in enquiries or contact forms
Appointment, attendance and payment information
Communications (emails, messages, notes of calls)
Website usage data (e.g. IP address, browser type, cookies)
Special category data (health information)
As part of providing therapy, we may collect:
Therapy notes
Assessment information
Information about your wellbeing, mental health, and support needs
We only collect this information where it is necessary to provide therapy or meet legal obligations.
4. How We Collect Data
We collect personal data:
Directly from you (emails, contact forms, sessions)
Automatically through website tools (e.g. cookies, analytics)
From third-party tools you use to contact or book with us (e.g. booking or payment services)
Occasionally from third parties (e.g. referrals), where appropriate
5. How We Use Your Information
We use your personal data to:
Respond to enquiries
Provide counselling and manage appointments
Maintain clinical records
Process payments
Ensure safety and safeguarding
Operate and secure our website
Improve our services
Meet legal, regulatory and professional obligations
We do not carry out automated decision-making or profiling that produces legal or significant effects.
6. Lawful Bases for Processing
Under UK GDPR, we rely on the following lawful bases:
Contract – to provide therapy or take steps before entering into therapy
Legitimate interests – to respond to enquiries and manage our practice
Legal obligation – for tax, safeguarding, and regulatory requirements
Vital interests – where necessary to prevent serious harm
Consent – for mailing lists and certain cookies
For special category (health) data, we rely on:
Provision of health or social care
Explicit consent (where required)
Safeguarding and vital interests
Legal claims
7. Confidentiality
All information you share in therapy is treated confidentially.
However, there are important limits to confidentiality. We may need to share information where:
There is a risk of serious harm to you or others
There are safeguarding concerns
We are legally required to do so (e.g. court order)
Where possible, we will discuss this with you first.
8. Who We Share Your Data With
We only share data where necessary and appropriate. This may include:
Email providers and communication tools
Website hosting and security providers
Booking or payment systems
Analytics providers (if used)
Professional supervisors (information anonymised where possible)
Authorities or regulators where legally required
We do not sell or trade your personal data.
9. International Transfers
Some service providers may process data outside the UK or EU.
Where this occurs, we ensure appropriate safeguards are in place, such as:
Adequacy decisions
Standard contractual clauses
Equivalent UK GDPR protections
10. Data Retention
We keep personal data only for as long as necessary:
Enquiries: up to 12 months
Therapy records: typically 7 years after the last session
Financial records: 6 years
Mailing list data: until you unsubscribe
Website analytics: up to 26 months
Security logs: 30 days to 12 months
Retention periods are based on legal, professional, and insurance requirements.
11. Data Security
We take appropriate steps to protect your data, including:
Encryption
Secure systems and hosting
Restricted access
Regular system updates
Professional confidentiality standards
While no system is completely secure, we take reasonable measures to safeguard your information.
12. Your Rights
Under data protection law, you have the right to:
Be informed about how your data is used
Access your personal data (Subject Access Request)
Correct inaccurate information
Request erasure (where applicable)
Restrict or object to processing
Data portability (where applicable)
Withdraw consent at any time
We aim to respond to requests within one month.
13. Data Protection Complaints
If you have a concern about how your data is handled, you can make a complaint by contacting:
We will:
Acknowledge your complaint within 30 days
Investigate and respond without undue delay
Keep you informed of progress
If you remain dissatisfied, you can contact the Information Commissioner’s Office (ICO):
https://ico.org.uk
14. Cookies
We use cookies to:
Operate and secure the website
Improve performance
Analyse usage
Enable embedded content
Where required, we will request your consent for non-essential cookies.
15. Changes to This Privacy Notice
We may update this Privacy Notice from time to time. The latest version will always be available on our website.

