Privacy Policy
Last updated: January 2024
At glow-fang, we take your privacy seriously. This policy explains how we collect, use, store, and protect personal information when you use our website or engage with our services. We are committed to being transparent about our data practices and ensuring your information remains secure.
Information We Collect
We collect information in several ways depending on how you interact with us:
- Contact Information: When you enquire about our services, we collect your name, email address, and any details you choose to share about your circumstances.
- Clinical Information: If you become a client, we collect information relevant to providing psychological services, including health history, presenting concerns, and session notes.
- Website Usage: We collect technical data about how you use our website, including pages visited, time spent, and device information.
- Payment Information: When you pay for services, we process payment details through secure third-party providers.
How We Use Your Information
Your information is used for the following purposes:
- Responding to your enquiries and providing information about our services
- Delivering psychological services and maintaining accurate clinical records
- Processing payments and managing your account
- Improving our website and understanding how visitors use it
- Sending service-related communications such as appointment reminders
- Meeting our legal and regulatory obligations
Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Contract: Processing necessary to provide the services you've requested
- Legitimate Interests: Processing necessary for our legitimate business interests, such as improving our services
- Consent: Where you've given explicit consent, such as for marketing communications
- Legal Obligation: Processing required to comply with applicable laws
For clinical information, which constitutes special category data under UK GDPR, we rely on explicit consent and the provision of health services.
Data Retention
We retain different types of information for different periods:
- Clinical Records: Retained for a minimum of seven years after the last contact, in line with professional guidelines. For clients who were minors, records are kept until their 25th birthday or seven years after last contact, whichever is longer.
- Contact Enquiries: Retained for two years if you do not become a client
- Financial Records: Retained for six years as required by HMRC
- Website Analytics: Retained for 26 months
Data Security
We implement appropriate technical and organisational measures to protect your information:
- Encrypted storage for all digital client records
- Secure access controls limiting data access to authorised personnel
- Regular security assessments of our systems
- Secure physical storage for any paper records
- Staff training on data protection and confidentiality
Sharing Your Information
We do not sell your personal information. We may share information in limited circumstances:
- Service Providers: We use third-party providers for payment processing, website hosting, and practice management software. These providers are contractually bound to protect your information.
- Professional Supervision: Clinical material may be discussed in supervision, but identifying details are removed or anonymised.
- Legal Requirements: We may disclose information if required by law or to protect vital interests.
- With Your Consent: We may share information with other healthcare providers or third parties if you explicitly request this.
Your Rights
Under UK data protection law, you have the following rights:
- Access your personal data and receive a copy
- Correct inaccurate or incomplete information
- Request deletion of your data in certain circumstances
- Restrict or object to certain processing activities
- Data portability for information you've provided
- Withdraw consent where processing is based on consent
To exercise these rights, please contact us at [email protected]. We will respond within one month.
International Transfers
Your information is primarily stored and processed within the United Kingdom. If we transfer data outside the UK, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the UK Information Commissioner.
Changes to This Policy
We may update this privacy policy from time to time. Significant changes will be communicated via our website or directly to clients. The date at the top of this policy indicates when it was last revised.
Contact Us
If you have questions about this policy or our data practices, or wish to exercise your rights, please contact:
glow-fang
47 Welbeck Street
Marylebone, London W1G 8DN
Email: [email protected]
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your data protection rights have been breached. Visit ico.org.uk for more information.