Privacy Policy
How I protect your personal information and respect your privacy
I am committed to protecting and respecting your privacy. This policy explains how I collect, use, store, and protect your personal information when you use my counselling services or visit my website.
1. Who I Am
Data Controller: David Lewis
Business Name: David Lewis Counselling
Address: 26 Burnand Street, Anfield, Liverpool, L4 0SH
Email: david.lewis@davidlewiscounselling.com
Phone: 07470 528 499
ICO Registration Number: ZB660829
I am registered with the Information Commissioner's Office (ICO) and adhere to the UK General Data Protection Regulation (UK GDPR), Data Protection Act 2018, and the BACP Ethical Framework for the Counselling Professions.
2. What Information I Collect
2.1 Website Visitors
When you visit my website or contact me, I may collect:
- Name, email address, and phone number
- IP address and browser information (for security)
- Cookies (see Section 8)
2.2 Clients
If you become a client, I collect:
- Personal details: name, date of birth, address, contact information
- Emergency contact details
- GP information (with your consent)
- Session notes and brief clinical records
- Signed contract and assessment forms
- Payment and invoicing information
2.3 Sensitive Personal Data
During counselling, you may share sensitive information about your mental health, racial or ethnic origin, religious beliefs, or sexual orientation. This "special category data" receives additional protection under UK GDPR.
3. How I Use Your Information
| Purpose | Legal Basis |
|---|---|
| Providing counselling services | Contractual necessity |
| Maintaining clinical records | Legal obligation & professional standards |
| Arranging appointments | Contractual necessity |
| Emergency contact | Vital interests |
| Professional supervision | Legal obligation (BACP requirements) |
| Website security | Legitimate interests |
I will never: Sell your data to third parties, use your data for marketing without explicit consent, or share your information unnecessarily.
4. Confidentiality & Supervision
4.1 Confidentiality
What you share in counselling sessions is confidential. I am a BACP registered counsellor and adhere to strict confidentiality guidelines. Your trust is fundamental to our work together.
4.2 Clinical Supervision
As required by BACP, I attend regular clinical supervision to ensure I work safely and ethically. I may discuss our work with my supervisor, but you will not be identified by name, and my supervisor is also bound by confidentiality.
4.3 When Confidentiality May Be Broken
I may need to break confidentiality if:
- You disclose serious risk of harm to yourself or others
- There is a child protection concern (a child or vulnerable adult at risk)
- Terrorism or money laundering is disclosed (legal requirement)
- A court orders disclosure of information
- You provide explicit consent for me to share information
Where possible, I will always discuss this with you first.
5. How I Store & Protect Your Data
5.1 Security Measures
- Electronic records: Stored on encrypted Google Workspace with two-factor authentication
- Session notes: Anonymised and kept separately from contact details
- Passwords: Strong, unique passwords changed regularly
- Devices: Password-protected with automatic screen lock
5.2 Third-Party Services
I use the following GDPR-compliant services:
- Carepatron — Appointment booking, client records, and secure video sessions
- Google Workspace — Email, document storage, and calendar
- Netlify — Website hosting
- IONOS — Domain registration
All third parties have data processing agreements in place and are based in the UK or EU with adequate data protection safeguards.
6. How Long I Keep Your Data
| Type of Data | Retention Period | Reason |
|---|---|---|
| Contact details (enquiries only) | 1 year | In case you re-contact me |
| Client records (adults) | 3 years after therapy ends | BACP complaint timeframe |
| Client records (under 18s) | Until you turn 25 | Extended protection for young people |
| Financial records | 6 years | HMRC requirement |
| Website analytics | 26 months | Google Analytics default |
Why 3 years? This retention period is agreed in your counselling contract and aligns with the BACP complaints procedure timeframe. After this period, all data is securely deleted — electronic records are permanently erased, and any paper documents are shredded.
7. Your Rights Under UK GDPR
You have the right to:
- Access — Request a copy of your personal data
- Rectification — Ask me to correct inaccurate information
- Erasure — Request deletion of your data (with limitations)
- Restriction — Ask me to limit how I use your data
- Data portability — Receive your data in a usable format
- Objection — Object to how I process your data
- Withdraw consent — At any time (where consent is the basis)
To exercise these rights, email me at david.lewis@davidlewiscounselling.com. I will respond within one month. There is no fee for this service.
8. Cookies & Website Analytics
My website uses cookies to improve your experience. Cookies are small text files stored on your device. You can control cookies through your browser settings.
I use Google Analytics to understand how visitors use my site. This data is anonymised and helps me improve my services. You can opt out using the Google Analytics Opt-out Browser Add-on.
9. Complaints
If you are unhappy with how I handle your data, please contact me first so I can try to resolve the issue. If you remain dissatisfied, you have the right to complain to:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Phone: 0303 123 1113
Website: www.ico.org.uk
10. Changes to This Policy
I may update this policy from time to time to reflect changes in my practice or legal requirements. Any changes will be posted on this page with an updated date. Please check back periodically.
11. Contact Me
For any questions about this privacy policy or your personal data:
David Lewis
26 Burnand Street, Anfield, Liverpool, L4 0SH
Email: david.lewis@davidlewiscounselling.com
Phone: 07470 528 499