top of page

Privacy Policy

Last updated: 30th September 2026 Practitioner Name: Fiona Palmer

BACP Membership Number: 422146

Introduction

​Your privacy and confidentiality are central to ethical therapeutic practice. As a registered member of the British Association for Counselling and Psychotherapy (BACP), I am committed to protecting your personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and professional ethical standards.

This policy explains how I collect, use, store, and protect your personal information from your first point of contact through to after your therapy ends, as well as your rights regarding your data.

Who I am

I am Fiona Palmer operating as an independent private practice counsellor using the business name ‘Soinetachd Counselling’. For the purposes of data protection law, I am the data controller. If you have any questions about this policy or how I handle your data, you can contact me at:

What Information I Collect

To provide a safe and professional counselling service, I may collect the following information:

  • Personal details: Full name, date of birth, address, email address, and phone number.

  • Emergency contact: Name and phone number of your GP or an emergency contact person.

  • Sensitive/Special Category data: Health and medical information, mental health history, or details regarding your background (such as race, sexuality, or religion) when relevant to the therapy.

  • Session records: Brief factual notes of our sessions and administrative records (such as dates/times of appointments).

  • Financial data: Records of payments made (Note: I do not store full bank or card details; payments are handled via bank transfer).

Lawful Basis for Processing Your Data

Under the UK GDPR, I must have a lawful basis for processing your data:

  • Consent: When you explicitly fill out my intake form or agree to start therapy.

  • Contract: To deliver the counselling services you have requested and agreed to.

  • Legal Obligation / Vital Interests: To comply with legal requirements or in rare circumstances where there is a serious risk of harm to you or others.

  • Special Category (Health Data): Processed under Article 9(2)(h) of the UK GDPR for the provision of health or social care treatment under the management of a health professional.

How Your Information Is Stored and Secured

I take reasonable and appropriate technical and physical steps to keep your data secure:

  • Digital Data: Emails, electronic client lists, and digital notes are stored on a password-protected device [encrypted laptop] using secure cloud storage secured with multi-factor authentication. Text messages and emails that are no longer needed for ongoing work are deleted after 3 months.

  • Paper Records: Handwritten session notes and paper contact forms are stored separately in a secure, lockable filing cabinet.

  • Pseudonymisation: Session notes use a code or initials rather than your full name to maintain additional privacy.

Confidentiality and Sharing Your Data

Your privacy inside the therapy room is strictly protected. However, there are rare limits to confidentiality:

  • Clinical Supervision: As required by the BACP Ethical Framework, I attend regular clinical supervision. I discuss my clinical work with my supervisor, but your identity is anonymised to protect your privacy.

  • Supervision Will/Incapacitation: My clinical supervisor has access to basic client contact details strictly to notify you and offer support in the sudden event of my death or severe incapacitation.

  • Risk of Harm: If I believe there is an immediate, severe risk of harm to you or another person, or a legal obligation (such as terrorism, drug trafficking, or safeguarding disclosures), I may need to contact emergency services or your GP. I will make every reasonable effort to discuss this with you first.

How Long I Keep Your Data

​I retain your personal data and session notes for 5 years following the end of our therapy, in line with professional insurance and legal guidelines. After this period, all records are securely shredded or permanently deleted.

Your Data Protection Rights

Under UK data protection law, you have the right to:

  • Access the personal data I hold about you (Subject Access Request).

  • Request correction of any inaccurate data.

  • Request erasure of your data in specific circumstances.

  • Restrict or object to processing in certain cases.

To exercise any of these rights, please contact me directly using the details above.

Complaints

If you have any concerns about how I handle your data, please contact me directly so we can resolve it. If you remain unhappy, you have the right to complain to the UK regulatory authority, the Information Commissioner’s Office (ICO), via ICO Make a Complaint or by calling 0303 123 1113. If your concern is about my professional practice rather than data protection, you can contact the BACP.

bottom of page