Privacy Policy
Home » Privacy Policy
Privacy Policy – Inner Peace Therapy
Practice Owner: Fiona Pendlebury‑Garnett Registered Member: BACP, NCPS, GHR Effective Date: 2026
1. Introduction
This Privacy Policy explains how Inner Peace Therapy collects, uses, stores, and protects your personal information when you engage in psychotherapy or hypnotherapy with me. Your privacy is central to my practice, and all information is handled in accordance with UK GDPR, the Data Protection Act 2018, and the ethical requirements of the BACP, NCPS, and GHR.
2. Data Controller
Inner Peace Therapy Fiona Pendlebury‑Garnett Room F8, Penrhos Manor, oak drive, Colwyn Bay.hello@fionatherapy.uk 01492447200
I am the Data Controller responsible for your personal information.
3. Information I Collect
I collect only the information necessary to provide safe and effective therapy:
Contact details — name, address, phone number, email
Background information — personal history relevant to therapy, GP details, emergency contact
Therapy records — session notes, assessments, treatment plans
Hypnotherapy‑related information — relevant psychological or behavioural information
Administrative information — invoices, payment records
Website data — cookies, analytics, contact form submissions (if applicable)
4. How Your Information Is Used
Your information is used to:
Provide psychotherapy and hypnotherapy
Communicate with you about appointments
Maintain accurate clinical records
Ensure your safety and wellbeing
Process payments
Meet legal, ethical, and professional obligations
I do not use your information for marketing.
5. Legal Basis for Processing
I process your data under:
Contract — to deliver therapy services
Consent — for optional activities or communication
Legal obligation — safeguarding, court orders, accounting
Vital interests — if there is risk of serious harm
Legitimate interests — maintaining professional records
6. Confidentiality & When Information May Be Shared
Everything you share in therapy is confidential except when:
You disclose intent to seriously harm yourself or someone else
There is a safeguarding concern involving a child or vulnerable adult
I am required by law (e.g., court order, terrorism, money laundering)
Emergency services or your GP need information to protect your life
You give explicit consent to share information
Whenever possible, I will discuss this with you first.
7. How Your Information Is Stored
Paper notes are kept in locked, secure storage.
Digital records are encrypted and password‑protected.
Devices use multi‑factor authentication.
Only I have access to your clinical records.
8. How Long Your Information Is Kept
Clinical records are retained for 7 years after your final session, or until age 25 for clients under 18. After this period, records are securely destroyed.
9. Your Rights Under UK GDPR
You have the right to:
Access your data
Correct inaccurate information
Request deletion (in certain circumstances)
Restrict processing
Object to certain uses
Receive a portable copy
To exercise these rights, contact me at [Insert Email].
10. Website, Cookies & Third‑Party Services
If you use my website:
Cookies may be used for basic functionality or analytics
Third‑party services (e.g., scheduling tools, payment processors) may process limited data
All external services comply with UK GDPR
11. Professional Bodies & Ethical Compliance
As a registered member of the BACP, NCPS, and GHR, I follow strict professional codes relating to:
Confidentiality
Record keeping
Data protection
Ethical decision‑making
Safeguarding
Professional conduct
These bodies require high standards of privacy, security, and transparency.
12. Complaints
If you have concerns about how your data is handled, you can contact:
Information Commissioner’s Office (ICO) Website: ico.org.uk Phone: 0303 123 1113
You may also raise concerns with my professional bodies if relevant to ethical practice.
13. Updates to This Policy
This policy may be updated occasionally. The latest version will always be available on my website or provided upon request.