Privacy Policy

Last updated: May 2026

1. Who I am

I am Beth Robinson, a sole practitioner trading as Beth Robinson Therapy & Coaching. I am a registered member of the British Association for Counselling and Psychotherapy (BACP) and adhere to the BACP Ethical Framework for the Counselling Professions.

For the purposes of data protection law, I am the data controller of your personal information.

2. How I collect your information

When you complete the enquiry form on this website, I collect the following details:

  • Full name.
  • Email address.
  • Telephone number.
  • Service requested.
  • Organisation.
  • Requested sessions.
  • Message content.
  • Preferred contact method.

This information is used to respond to your enquiry and discuss possible next steps, including arranging an initial appointment.

If you confirm a booking, you will be asked to complete a comprehensive client contract form online. This may include:

  • Full contact details.
  • Date of birth.
  • Address.
  • GP details.
  • Emergency contact information.
  • Medical history.
  • Mental health history.
  • Current medications.
  • Risk and safeguarding information.
  • Other relevant personal history to support safe and effective therapy.

This may include special category data, including health information.

During our work together, I may also create and store brief session notes, risk assessments where appropriate, correspondence relating to your care, and administrative records such as appointments and related information.

3. How I use your information

Under UK GDPR, I rely on the following lawful bases for processing personal data:

  • Legitimate interests — responding to initial enquiries.
  • Contract — providing therapy services you request.
  • Legal obligation — maintaining appropriate financial records.

For special category data, including health information, I process data because it is necessary for the provision of health care and for the management of health or social care systems or services, with appropriate safeguards in place. Where required, I will also ask for explicit consent.

4. Confidentiality

Confidentiality is a core principle of my practice and a requirement under the BACP Ethical Framework. Your information is treated as confidential.

I may share information only in limited circumstances, including:

  • If there is a serious risk of harm to you or someone else.
  • If safeguarding concerns arise involving a child or vulnerable adult.
  • If required by law, for example by a court order.
  • In clinical supervision, discussed anonymously wherever possible.

Supervision is a professional requirement. I take care to minimise identifying details.

5. How your information is stored

I store your information securely and only for as long as necessary. Client records and forms are stored using the Kiku practice management platform. Electronic records are password protected and access is restricted to me. Paper records, if any, are stored securely in locked storage.

6. Payments

Payments may be made by bank transfer or secure payment link issued via my practice management system, Kiku, which may be paid using debit card, credit card or Apple Pay.

When payments are made via secure link, card details are processed by regulated third-party payment providers. I do not have access to or store your full card details.

Payment information is processed solely for the purpose of administering therapy services and maintaining financial records in line with legal and tax requirements.

7. Online therapy

If you attend online sessions, I use secure video platforms. While reasonable steps are taken to protect confidentiality, no online communication can be guaranteed to be completely secure. You are responsible for ensuring you are in a private space at your end.

8. Data retention

In line with professional standards and insurance requirements, I retain:

  • Adult client records for 7 years after therapy ends.
  • Child client records until age 25, or 7 years after therapy ends, whichever is longer.
  • Financial records in line with HMRC requirements.

Records are securely deleted or destroyed when the retention period ends.

9. Your rights

Under UK GDPR you have rights including:

  • Access to your data.
  • Correction of inaccurate data.
  • Erasure in certain circumstances.
  • Restriction of processing.
  • Objection to processing, where applicable.
  • Making a complaint to the ICO.

If you have any questions about this policy or wish to exercise your rights, please contact me.

You can also complain to the Information Commissioner’s Office at ico.org.uk.

10. Cookies

This website uses essential cookies to ensure the secure operation of the contact form, including session cookies and Google reCAPTCHA security verification.

These cookies support the secure operation of the contact form and do not track visitors for marketing or advertising purposes.

11. Contact details

If you have questions about this Privacy Policy or your data, please contact me.