Privacy Policy

Confidentiality

The content of therapy is held in confidence. However, there are some instances in which a therapist may have to breach confidentiality:

• If there is a concern of risk of harm to yourself or to others

• If you disclose a serious crime. There are some crimes that are mandatory to report- drug trafficking, terrorism, and money laundering

• If a court orders access to client notes

If I feel it may be necessary to break confidentiality, I will prioritise your agency and autonomy as far as possible. Therefore, I will discuss this with you beforehand, explaining why and in what way I feel it would be appropriate to break confidentiality and discuss the content of a session with another party. Where possible, I will support you in doing this yourself- for instance, if I feel you need to speak to your GP to help manage your mental health, I will encourage you to do this yourself and will support you in this. If this is not possible, I would ensure you are informed before I breach confidentiality (except in extreme circumstances in which it would be unsafe to do so).

Your Privacy

Your privacy is very important to me and you can be confident that your personal information will be kept safe and secure and will only be used for the purpose it was given to me. I adhere to current data protection legislation, including the General Data Protection Regulation (EU/2016/679) (the GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications (EC Directive) Regulations 2003. This privacy notice tells you what I will do with your personal information from initial point of contact through to after your therapy has ended.

Why am I processing your information? In order to properly assess your mental health and begin to develop a treatment direction, I complete an onboarding document with you in our initial assessment call. This involves asking about and documenting personal things such as any mental health history, your family and social context, your living situation etc. Some of this information, particularly your address, GP, and contact details, need to remain updated as this information is vital if your mental health or safety become at risk. Holding and understanding this information is vital in the production and performance of our treatment contract.

Do you (the client) have to provide this information? This depends. I would not work with someone whose name, address, GP, and contact details were unknown to me. To do so would be irresponsible, as in an emergency this information is vital. Some information however I would be less urgent about knowing immediately- for instance, if you have suffered a trauma that would be detrimental for your mental health to disclose upon our first meeting, I would understand if this wasn’t disclosed fully at that time. It would, however, be expected that you would make me aware of the fact that you are currently choosing to not inform me of the details of said trauma, as this is still clinically relevant information and would impact our approach to the therapy work.

How long is it stored for? I will store your assessment document, session notes, and other relevant information/documentation for 7 years after our last session. After this I will delete it. Please ask me in writing if you want me to delete this information sooner than this. If you agree for me to tape sessions for supervision purposes (you are free to decline to consent), I will delete them once the need for the tape has ended (typically after I have brought that session to supervision). The only exception to this would be if I intended to use a particular clip from a session tape for an assessment for further personal training, however if I intended to do this I would ask for your permission first. If granted, I would retain this clip until the assessment had been completed and would then delete the tape.

Will any other people receive this personal information? During clinical supervision, I will discuss the minimum necessary information required to discuss my caseload with my supervisor. Any other information would not be given to my supervisor. The only other circumstances in which a third party would receive some of your personal information would be if I had to breach confidentiality to report a crime, to manage an escalation of risk to yourself or others, or if a court subpoenaed your notes. If I had to breach confidentiality in this way, I would inform you first, and where possible involve you, unless doing so would result in a high risk of harm to yourself or someone else.

Will the information be transferred to another country? I use Google Workspace to keep your documentation, Google being an American company. In this sense, an American company will hold your data, however your data is securely kept on my Google Workspace account. The information stored there would be your clinical note for that session (see the example below), your assessment document, and any extra worksheets we may complete during our work together.

At the end of each session, I will make a clinical note, which is securely stored on my Google Drive. These notes are anonymised and do not refer to you or anyone else by name. They contain the date and time of our meeting, and a brief factual summation of the session. For instance:

“01/01/2026, 09:00. Discussed anxiety after recent bereavement. Discussed how this links with childhood experience of loss.”

During sessions, I often take factual pen-and-paper notes to ensure I note down important relevant facts that help us carry out the work- for instance, the name of a book that is important to you or an important date in your life. These notes remain offline and are kept in a locked cabinet in my house, which only I know the code for. You may view these notes at any time during the session- they are not my private thoughts or theories, only a reflection of relevant factual statements from the session. I maintain your anonymity in these notes.

Do I do automated decision-making or profiling? When making an intervention or treatment decision, I consider your current mental health status, my personal competencies and capacities at that time, your general context of support etc. Therefore, none of my decisions are made automatically. I will sometimes make clinical decisions in consultation with my clinical supervisor and will inform you if I intend to bring a specific concern to my supervisor. I don’t use any automated system such as AI to make any clinical decisions.

Data Protection

Under GDPR, you have the right to:

• be informed about what data is being kept about you

• Access your data

• Request erasure of your data

• Data portability

To learn more about your rights under GDPR, here is a link to the Information Commissioner’s Office (ICO) webpage:

https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/

I am the ‘data controller’ for Nathan Place Counselling, meaning I am responsible for managing clients’ personal data. I am registered with the ICO- registration number ZC114725. You have the right to ask for a copy of any information I hold about you and to object to the use of your personal data in some circumstances- read more at https://ico.org.uk/for-the-public/

If I do hold information about you, you have the right to ask me to:

• give you a description of it and where it came from

• tell you why I am holding it, tell you how long I will store your data and how I made this decision

• tell you who it could be disclosed to

• let you have a copy of the information in an intelligible form.

You can also ask me at any time to correct any mistakes there may be in the personal information I hold about you. To make a request for any personal information I may hold about you, please put the request in writing addressing it to nathanplace@nathanplacecounselling.co.uk

If you have any questions or complaints about how I handle your personal data please do not hesitate to get in touch with me via the email address given above. I would welcome any suggestions for improving my data protection procedures. If you want to make a formal complaint about the way I have processed your personal information you can contact the ICO which is the statutory body that oversees data protection law in the UK. For more information go to http://ico.org.uk/make-a-complaint