Saskia Joss Therapy Privacy Notice
Your privacy is very important to me, and you can be confident that your personal information will be kept safe and secure. It will only be used for the purpose for which it was given to me. I adhere to current data protection legislation, including:
The General Data Protection Regulation (EU/2016/679) (GDPR)
The Data Protection Act 2018
The Privacy and Electronic Communications (EC Directive) Regulations 2003
How I Use Your Personal Information
This privacy notice explains how I handle your personal information from the initial point of contact through to after your therapy has ended, including:
Why I am able to process your information and for what purpose
Whether you are required to provide it to me
How long I store it for
Whether there are other recipients of your personal information
Whether I intend to transfer it to another country
Whether I use automated decision-making or profiling
Your data protection rights
I am happy to discuss any questions you may have about my data protection policy. You can contact me via email at saskiajosstherapy@gmail.com.
Data Controller
‘Data controller’ refers to the person or organisation that collects, stores, and has responsibility for people’s personal data. In this instance, the data controller is me.
I am registered with the Information Commissioner’s Office: 00016601428
Contact Information
Postal address: 27 Hale Drive, Mill Hill, London, NW7 3EL
Phone number: 07815150434
Email address: saskiajosstherapy@gmail.com
My lawful basis for holding and using your personal information
The GDPR states that I must have a lawful basis for processing your personal data. There are different lawful bases depending on the stage at which I am processing your data. I have explained these below:
If you or your child have had therapy with me and it has now ended, I will use legitimate interest as my lawful basis for holding and using your personal information.
If you or your child are currently having therapy or if you are in contact with me to consider therapy, I will process your personal data where it is necessary for the performance of our contract.
The GDPR also makes sure that I look after any sensitive personal information that you may disclose to me appropriately.
This type of information is called ‘special category personal information’. The lawful basis for me processing any special categories of personal information is that it is for provision of health treatment (in this case counselling) and necessary for a contract with a health professional (in this case, a contract between me and you).
How I use your information
Initial contact
When you contact me with an enquiry about my child therapy services, I will collect information to help me satisfy your enquiry. This will include your child’s name, age, school and aspects of their medical history. Alternatively, your GP or other health professional may send me your details when making a referral or a parent or trusted individual may give me your details when making an enquiry on your behalf.
If you decide not to proceed, I will ensure all your personal data is deleted within six months. If you would like me to delete this information sooner, just let me know.
While you or your child are accessing therapy
Rest assured that everything you discuss with me is confidential. Confidentiality will only be broken if I believe there is a serious risk of harm to you, your child, or someone else, or if I am required by law to disclose information. Where possible, I will discuss this with you first unless safeguarding concerns prevent this.
I will keep a record of your personal details to help the therapy services run smoothly. These details are kept securely and are not shared with any third party.
For security reasons I do not retain text messages for more than six months. If there is relevant information contained in a text message, I will transfer it to my electronic notes. Likewise, any email correspondence will be deleted after six months if it is not important.
After therapy has ended.
Once counselling has ended, your records will be kept for three years from the end of our contact with each other and are then securely destroyed. If you want me to delete your information sooner than this, please tell me.
Your rights
Access to Your Personal Information
I aim to be as open as possible in providing access to personal information. You have the right to:
Request the deletion of your personal information
Limit how I use your personal information
Stop the processing of your personal information
Request a copy of any information I hold about you
Object to the use of your personal data in certain circumstances
You can read more about your rights at ico.org.uk/your-data-matters.
If I do hold information about you, I will:
Provide a description of it and its source
Explain why I am holding it, how long I will store it, and how I made this decision
Inform you of any parties to whom it could be disclosed
Provide a copy of the information in an intelligible format
You may also request corrections to any mistakes in the personal information I hold about you.
Making a Request
To request access to your personal information, please submit your request in writing to saskiajosstherapy@gmail.com.
Complaints
If you have any concerns about how I handle your personal data, please contact me via the details provided above. I welcome any suggestions for improving my data protection procedures.
If you wish to make a formal complaint about the way I have processed your personal information, you can contact the Information Commissioner's Office (ICO), the UK’s statutory body overseeing data protection laws. More information is available at ico.org.uk/make-a-complaint.
Data security
I take the security of the data I hold about you very seriously and as such I take every effort to make sure it is kept secure. I use two-step security on all my accounts and encrypted devices.
Visitors to My Website
When someone visits my website, I use a third-party service, WordPress, to collect standard internet log information and details about visitor behaviour patterns. This helps me understand things like the number of visitors to different parts of the site.
This information is processed in a way that does not identify any individual. I do not make, and I do not allow WordPress to make, any attempt to identify those visiting my website.
I rely on legitimate interests as the lawful basis for holding and using your personal information in this way when you visit my website.
I also use Google Analytics to continually improve the service I offer you. You can read Google Analytics's privacy notice on its website.
The website’s content management system is powered by WordPress. You can find out more about WordPress and data protection at https://wordpress.com/support/your-site-and-the-gdpr/.
Like most websites, I use cookies to help the site function more efficiently. You can learn more about my use of cookies at www.saskiajosstherapy.co.uk/cookie-policy.
No user-specific data is collected by me or any third party. If you fill in a form on my website, that data will be temporarily stored by the web host before being sent to me.