Psychology Privacy Policy & Data Protection
Privacy Policy
Effective Date: 10-May-2026
Data Controller: Dr Jo-Ann Valentine, ByValentine Psychology Services Ltd.
ICO Registration Number: ZC116235
1. Introduction
At byValentine Psychology Services Ltd ("byValentine", "I", or "we"), your privacy and confidentiality are at the core of our therapeutic relationship. This Privacy Policy outlines how your personal and sensitive health data is collected, stored, and protected in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the ethical guidelines of the Health and Care Professions Council (HCPC).
2. Website Analytics & Cookies
Our website is hosted on Wix. We use Usercentrics to manage your cookie preferences.
-
Essential Cookies: Automatically used for site security and stability.
-
Analytics Cookies (Microsoft Clarity & Wix Analytics): Only used if you provide explicit consent via our cookie banner. These tools help us understand site performance through anonymized heatmaps and session recordings (e.g., where users click or scroll).
-
Future Use: We may implement Google Analytics 4 in the future; if so, this notice and your cookie settings will be updated.
3. Lawful Basis for Processing Your Data
Under UK GDPR, I must have a lawful basis for processing your data. We collect and process personal data to provide safe and effective psychological assessment and therapy.
-
Contract: For standard personal data, processing is necessary to fulfill our agreement and provide the therapy services you have requested.
-
Legitimate Interests: To manage my practice efficiently and provide high-quality care.
-
Provision of Health or Social Care (Article 9(2)(h)): For health data (Special Category Data), as a health professional providing treatment.
4. What Data We Collect
To provide safe and effective psychological therapy, I need to collect and process the following:
-
Personal Information: Name, address, date of birth, contact details, and GP information.
-
Special Category Data (Health Data): Mental health history, clinical session notes, symptoms, psychological assessments, and GP details.
-
Third-Party Data: Emergency contact details (next of kin) provided on your intake form.
-
Financial Data: Payment history and invoicing details.
-
Website Data: Basic analytics and cookies collected via our website host (Wix) to ensure the site runs securely.
5. How We Store and Protect Your Data
I take the security of your highly sensitive information very seriously.
-
Secure Storage: Your data is stored within a secure Google Workspace environment, protected by Two-Factor Authentication (2FA) and encrypted to industry standards.
-
Pseudonymization: To maximize your privacy, client folders and clinical notes are pseudonymized using a unique Client Code (e.g., C-XXXXX) rather than your real name in file titles.
-
Physical Notes: Any handwritten notes are kept securely locked in a safe and destroyed or digitized securely as soon as possible.
Communication: Emails are hosted on secure servers; however, communication should be limited to administrative matters.
6. Sharing Your Data
We do not sell your data or share it with third parties for marketing purposes. We only share information in the following circumstances:
-
Consent: You request us to share information with a third party (e.g., your GP).
-
Safeguarding & Risk: If there is a legal or ethical obligation to protect you or others from serious harm, or if a safeguarding concern arises regarding a child or vulnerable adult.
-
Legal Obligation: If compelled by a court of law or required by legislation (e.g., Prevention of Terrorism Act).
-
Professional Supervision: In line with HCPC and BABCP requirements, I discuss anonymized clinical work with a supervisor to ensure best practice.
7. Data Retention
In line with HCPC and BABCP clinical record-keeping guidelines:
-
Adult Records: Retained for 7 years after the conclusion of our final therapy session.
-
Child/Young Person Records: Retained until the client reaches their 26th birthday (or 7 years after treatment ends, whichever is later).
After this period, all identifiable data is securely destroyed.
8. Clinical Will
I maintain a clinical will appointing a professional executor. In the event of my death or permanent incapacitation, they will ensure the confidential storage and eventual destruction of your notes in accordance with this policy.
9. Your Rights
Under UK GDPR, you have the following rights:
-
Access: Request a copy of the records and data I hold about you (Subject Access Request).
-
Rectification: Ask to correct inaccurate information.
-
Erasure: Request deletion of data (subject to our legal retention obligations).
-
Restriction: Request temporary limits on how we process your data.
-
Portability: Receive your data in a structured, machine-readable format.
-
Objection: Object to processing in certain circumstances.
-
Withdraw Consent: The right to withdraw consent for non-clinical processing at any time.
10. Complaints
If you have concerns, please contact me first at office@byvalentine.co.uk. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at www.ico.org.uk.
