Privacy Policy

The following explains how Colin Johnson, as a private counselling practitioner, collects, uses, stores, and protects your personal information and sensitive data. It ensures compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who I Am

I operate a private counselling practice and act as the Data Controller for your personal data. 

Contact Email:info@colinjohnson.online 

ICO Registration reference: ZA766381

2. The Data I Collect & Process

To provide safe and professional therapeutic services, I collect the following categories of data:

Contact Information:Your name, address, date of birth, telephone number, and email address.

Emergency Details:** Name and contact information for your Next of Kin and your General Practitioner (GP).

Special Category Data:** Sensitive health data including relevant medical history, psychological history, and brief, anonymised session notes outlining themes discussed during therapy.

3. Lawful Basis for Processing

Under the UK GDPR, I process your data using the following legal frameworks:

Contractual Necessity:To provide the counselling services you have requested and agreed to.

Health and Social Care (Special Category Data): Processing is necessary for the provision of health or social care treatment under a contract with a health professional bound by professional confidentiality.

4. How I Store and Protect Your Data

Your privacy is of the utmost importance. I employ robust security measures to safeguard your information:

Digital Records:** Any electronic data, contact details, or email correspondence are stored on password-protected, encrypted devices or secure, GDPR-compliant cloud servers.

Paper Records: Any physical documents or handwritten notes are stored securely in a locked filing cabinet.

Anonymisation: Session notes are kept separate from your identifiable contact details and use a unique reference code rather than your name.

5. Confidentiality and Data Sharing

Everything discussed within our sessions remains strictly confidential. Your data will never be sold or used for marketing purposes. However, there are specific, limited exceptions where information may be shared:

Clinical Supervision: In line with professional bodies like the British Association for Counselling and Psychotherapy ([BACP](https://bacp.co.uk "BACP official website")), my work is regularly supervised. Case presentations are completely anonymised to protect your identity.

Legal Duty & Safeguarding: If I believe there is a severe risk of harm to yourself or others, or if I am legally compelled by a court of law, I may need to share information with relevant authorities (such as your GP or emergency services). I will always endeavour to discuss this with you first.

6. Data Retention Schedule

I do not keep your information longer than necessary. In accordance with professional standards and insurance requirements, clinical records are retained securely for 7 years following the conclusion of therapy, after which they are securely destroyed.

7. Your Statutory Rights

Under UK data protection laws, you hold the following rights regarding your data:

Right of Access: You can request a copy of the personal data and session notes I hold about you.

Right to Rectification: You can ask me to correct any inaccurate or incomplete information.

Right to Erasure ('Right to be Forgotten'): You can request the deletion of your data, though this may be limited by my legal and insurance obligations to retain clinical records.

Right to Restrict Processing: You can object to or limit how your data is used under certain conditions.

8. Questions or Complaints

If you have any questions or wish to exercise your rights, please contact me directly using the details provided in Section 1. 

If you remain unsatisfied with how your data is handled, you have the right to lodge a formal complaint with the Information Commissioner’s Office via the [ICO website](https://ico.org.uk "ICO contact page").