Privacy policy

1. Introduction

Seed Counselling is committed to protecting your personal information and respecting your privacy. This Privacy Notice explains how and why we collect, use, store and protect your personal data when you contact us or engage in therapy.

This notice complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Data Controller

Seed Counselling is the data controller for the personal data we process.

Contact details:
Email: briony@seedcounselling.co.uk
Website: www.seedcounselling.co.uk

(You may wish to add a postal/business address here if you have one.)

Seed Counselling is registered with the Information Commissioner’s Office (ICO) (if applicable – ensure this is accurate).

3. What Personal Data We Collect

We may collect and process the following personal data:

Personal data

  • Name, email address, phone number, postal address

  • Information provided in enquiries or contact forms

  • Appointment, attendance and payment information

  • Communications (emails, messages, notes of calls)

  • Website usage data (e.g. IP address, browser type, cookies)

Special category data (health information)

As part of providing therapy, we may collect:

  • Therapy notes

  • Assessment information

  • Information about your wellbeing, mental health, and support needs

We only collect this information where it is necessary to provide therapy or meet legal obligations.

4. How We Collect Data

We collect personal data:

  • Directly from you (emails, contact forms, sessions)

  • Automatically through website tools (e.g. cookies, analytics)

  • From third-party tools you use to contact or book with us (e.g. booking or payment services)

  • Occasionally from third parties (e.g. referrals), where appropriate

5. How We Use Your Information

We use your personal data to:

  • Respond to enquiries

  • Provide counselling and manage appointments

  • Maintain clinical records

  • Process payments

  • Ensure safety and safeguarding

  • Operate and secure our website

  • Improve our services

  • Meet legal, regulatory and professional obligations

We do not carry out automated decision-making or profiling that produces legal or significant effects.

6. Lawful Bases for Processing

Under UK GDPR, we rely on the following lawful bases:

  • Contract – to provide therapy or take steps before entering into therapy

  • Legitimate interests – to respond to enquiries and manage our practice

  • Legal obligation – for tax, safeguarding, and regulatory requirements

  • Vital interests – where necessary to prevent serious harm

  • Consent – for mailing lists and certain cookies

For special category (health) data, we rely on:

  • Provision of health or social care

  • Explicit consent (where required)

  • Safeguarding and vital interests

  • Legal claims

7. Confidentiality

All information you share in therapy is treated confidentially.

However, there are important limits to confidentiality. We may need to share information where:

  • There is a risk of serious harm to you or others

  • There are safeguarding concerns

  • We are legally required to do so (e.g. court order)

Where possible, we will discuss this with you first.

8. Who We Share Your Data With

We only share data where necessary and appropriate. This may include:

  • Email providers and communication tools

  • Website hosting and security providers

  • Booking or payment systems

  • Analytics providers (if used)

  • Professional supervisors (information anonymised where possible)

  • Authorities or regulators where legally required

We do not sell or trade your personal data.

9. International Transfers

Some service providers may process data outside the UK or EU.

Where this occurs, we ensure appropriate safeguards are in place, such as:

  • Adequacy decisions

  • Standard contractual clauses

  • Equivalent UK GDPR protections

10. Data Retention

We keep personal data only for as long as necessary:

  • Enquiries: up to 12 months

  • Therapy records: typically 7 years after the last session

  • Financial records: 6 years

  • Mailing list data: until you unsubscribe

  • Website analytics: up to 26 months

  • Security logs: 30 days to 12 months

Retention periods are based on legal, professional, and insurance requirements.

11. Data Security

We take appropriate steps to protect your data, including:

  • Encryption

  • Secure systems and hosting

  • Restricted access

  • Regular system updates

  • Professional confidentiality standards

While no system is completely secure, we take reasonable measures to safeguard your information.

12. Your Rights

Under data protection law, you have the right to:

  • Be informed about how your data is used

  • Access your personal data (Subject Access Request)

  • Correct inaccurate information

  • Request erasure (where applicable)

  • Restrict or object to processing

  • Data portability (where applicable)

  • Withdraw consent at any time

We aim to respond to requests within one month.

13. Data Protection Complaints

If you have a concern about how your data is handled, you can make a complaint by contacting:

 briony@seedcounselling.co.uk

We will:

  • Acknowledge your complaint within 30 days

  • Investigate and respond without undue delay

  • Keep you informed of progress

If you remain dissatisfied, you can contact the Information Commissioner’s Office (ICO):
https://ico.org.uk

14. Cookies

We use cookies to:

  • Operate and secure the website

  • Improve performance

  • Analyse usage

  • Enable embedded content

Where required, we will request your consent for non-essential cookies.

15. Changes to This Privacy Notice

We may update this Privacy Notice from time to time. The latest version will always be available on our website.