Privacy policy
Amy Griffin Counselling Privacy Statement
The purpose of this Privacy Policy is to inform you what personally identifiable information may be collected and how it may be used. This statement governs the manner in which Amy Griffin Counselling uses, maintains and discloses information collected from clients using this website and if engaged in counselling services with Amy Griffin Counselling. This notice applies to people who contact me about therapy, current and former clients, and visitors to my website.
Contact:
If you have any questions about this privacy policy you may contact me by email via
amy@amygriffincounselling.co.uk
This policy was last updated: June 17, 2026
The data I collect:
In accordance with the General Data Protection Regulation (GDPR) and Data Protection. I take your privacy seriously and I am registered with the Information Commissioners Office (ICO).
Information is captured automatically when you visit websites such as this website; certain information about you and the device with which you access the Website will be collected. For example, your IP address, operating system type, browser type, referring website, pages you viewed, and the dates/times when you accessed the Website will be logged. Information about the actions you take when using the Website, such as any links you clicked may also be logged.
Personal identification information that is captured via this website after being voluntarily submitted:
-
Name and contact number and/or email address
-
Any information you provide as part of the enquiry
Personal identification information that is captured as part of counselling services:
-
Name
-
Contact number and/or email address
-
Date of birth
-
Address
-
Preference of contact
-
History of previous or existing medical/psychiatric conditions
-
GP details
-
Counselling session notes
Personal identification information is captured for the following purposes:
I use your personal information to:
-
Respond to enquiries
-
Arrange initial calls and appointments
-
Provide therapy
-
Keep appropriate clinical records
-
Manage payments, invoices and appointments
-
Communicate with you about sessions
-
Meet legal, professional and ethical responsibilities
-
Manage risk, safeguarding or emergency situations where necessary
-
Maintain insurance, tax and accounting records
-
Respond to data protection requests or complaints
I keep very brief anonymous notes of our sessions, in accordance to my indemnity insurance and professional governing body of the British Association of Counsellors and Psychotherapists (BACP).
I do not sell your personal information.
Lawful basis of using your information
Under UK GDPR, I need a lawful basis for using personal information. Different parts of my work may rely on different lawful bases:
-
Responding to queries: To reply to you and discuss whether therapy may be suitable.
-
Arranging and providing therapy: To provide the service we have agreed to.
-
Keeping brief counselling notes: To practice safely, ethically and professionally.
-
Payments, invoices and accounts: T manage fees and meet tax/accounting responsibilities
-
Risk, safeguarding and legal concerns: Only where necessary, proportionate and lawful.
-
Data protection requests or complaints: To respond to rights requests and complaints.
AI tools, transcription and recording
I do not record, transcribe or use AI tools to process therapy sessions. I may use digital tools for general practice administration, writing, planning or education. Where I do, I avoid putting identifiable client material into tools that are not appropriate for confidential clinical information, and I take data protection and confidentiality into account when choosing how to use those tools.
Retention of data:
I keep your brief session notes and your unique code for up to 7 years. Personal information that is provided as part of the client agreement ahead of commencing counselling services, including your contact details, will be deleted 3 months after the counselling sessions end.
Your information may be stored in the following systems. I have named the actual providers I use so you can see where information may be processed: Wix, Google workspace, Google Meet, bank records, WhatsApp, SMS.
I use appropriate technical and organisational measures to keep information secure. This may include password protection, device security, two-factor authentication, restricted access and secure storage. Where I use external providers, they may process data on my behalf. I aim to use reputable providers with appropriate data protection and security arrangements.
Sharing your personal information and confidentiality:
Therapy is confidential, but confidentiality is not absolute. I will not share what you tell me unless there is a lawful, ethical or safeguarding reason to do so. Where information does need to be shared, I will aim to share only what is necessary. I may need to share information if:
-
I believe there is a serious risk of harm to you or someone else
-
There is a safeguarding concern involving a child, vulnerable adult or person at risk
-
I am required to do so by law, court order or legal process
-
Disclosure is necessary to prevent or detect a serious crime
-
There is a medical emergency and information is needed to protect life
-
I need to consult my clinical supervisor, while protecting your identity as far as possible
Where possible and appropriate, I would aim to discuss this with you before sharing information. I may not be able to do so if this would increase risk, prejudice safeguarding action, undermine the purpose of the disclosure, or would otherwise not be possible.
Like other ethical therapists, I use clinical supervision to support safe and effective practice. In supervision I may discuss aspects of client work, but I aim to minimise identifying detail where possible and appropriate. My supervisor is also bound by confidentiality and professional standards.
E-mail communications
Should you download any products from this website, you will automatically be subscribed to a newsletter and will be contacted via email from time to time for the purpose of providing announcements, promotional offers, alerts, confirmations, surveys, and/or other general communication.
If you would like to stop receiving marketing or promotional communications via email from Amy Griffin Counselling, you may opt out of such communications by clicking the unsubscribe button at the bottom of all emails.
Third party websites:
Clients may find content on my website that links to the sites of other third parties. I do not control these sites which have a link to mine and I am not responsible for how they collect, store or use information.
Changes to this privacy policy:
I have the right to update this privacy policy at any time. If I do, I will revise the date at the bottom of this section. I encourage all clients to check this document for any changes, to stay informed about how I am helping to protect the personal information I collect. You acknowledge and agree that it is your responsibility to review this privacy policy periodically and become aware of modifications.
Your acceptance of these terms:
By filling in online enquiry forms, completing consultation documents, leaving voice messages or attending my counselling sessions (online, by telephone or in my private practice) or completing any forms, you signify your acceptance of this policy. If you do not agree to this policy please do not use my site or my products or services. Your continued use of the site or my products and services following the posting of changes to this policy will be deemed your acceptance of those changes.
Your rights
Under UK data protection law, you have rights over your personal information. These may include the right
to:
-
be informed about how your data is used
-
access a copy of your personal information
-
ask for inaccurate information to be corrected
-
ask for information to be deleted in some circumstances
-
restrict or object to certain processing
-
complain about how your information has been handled
Some rights are not absolute and may depend on the circumstances. For example, I may need to keep some information for legal, professional, safeguarding, insurance or complaint-related reasons. There may also be limits on what can be disclosed where information includes third-party data or where a relevant exemption applies.
If you would like to exercise your rights, please contact me using the details at the top of this policy. I will usually respond
within one month. If a request is complex or if I receive a number of requests from you, I may extend this by up to a further two months. If I need more time, I will tell you within the first month and explain why.
Data protection concerns and complaints
If you have a concern about how I have handled your personal information, you can make a data protection complaint by contacting me using the details in this notice.
From 19 June 2026, and as good practice before then, I will acknowledge a data protection complaint within 30 days. I will take appropriate steps to look into it, keep you informed where necessary, and tell you the outcome without undue delay.
Please include:
-
your name
-
what your concern is about
-
what you would like me to look into
-
how you would prefer me to respond
If you are not satisfied with my response, or if you would prefer to contact the UK regulator directly, you can contact the Information Commissioner's Office:
-
Information Commissioner's Office
-
Website: www.ico.org.uk
-
Telephone: 0303 123 1113