Your Privacy

Privacy Statement
The General Data Protection Regulation (GDPR) and the Privacy and Electronic Communications Regulation exist to protect and enhance the rights of EU data subjects. These rights relate to the safeguarding of personal data, protection against unlawful use of personal data and the unrestricted movement of personal data within the EU. I adhere to these regulations and to all the ethical standards expected for my profession as stipulated by the HCPC, including client confidentiality.

Privacy notice
This privacy notice provides all the information you will need to understand how I use your personal data in the context of our work together. It is my professional duty to ensure that your personal information is safe and secure and only used for reasons detailed here. I take the responsibility of processing your data responsibly very seriously.

Lawful basis for holding and processing personal information
If you are currently undertaking therapy with me, or you are in contact with me to discuss possible work together, I will process the personal data you provide as required for this purpose. I will keep any personally sensitive information confidential. The lawful basis of processing any special category personal information is for the provision of health treatment (i.e. sleep therapy), and necessary for a contract with myself as a health professional. Once our therapy has ended, the lawful basis for retaining your personal information is legitimate interest.

How your information will be used
I will never use your personal information for any purposes other than the delivery of the service I am providing to you. I will only retain your records for the necessary time period, compliant with guidance from Information Commissioner’s Office.

Initial contact
Our first contact will involve me collecting information about you including your name, age and sleep difficulties. I will hold your contact details, phone number and/or email for further contact for the agreed purposes-arranging or cancelling appointments or to provide additional information and resources. If you decide not to proceed with working together, I will ensure that all of your personal data is deleted within one month or sooner at your request.

After therapy
I retain your records from therapy for seven years following the end of therapy. These remain in a locked filing cabinet. This timeframe is compliant with professional guidelines. After this time, your therapy notes will be confidentially destroyed.

Third party recipients of personal data
I will never pass on your contact details to any third-party organisations for the purposes of sales, marketing or research.

Data security
I take the security of the data that I hold about you very seriously. My email account is password protected and mobile phones and laptops used to respond to your emails are password protected and have anti-virus software. Any email correspondence will be deleted within one month if it is not necessary to keep it. If it is necessary to retain the information. I will print the email and store it securely in a locked filing cabinet that only I have access to.
I will use the contact details that you have provided me with for correspondence regarding your sleep therapy. I will also request to have the name of your GP who would be contacted in an emergency should this situation ever arise, or for correspondence where we agree this would be beneficial. Please note that any contact with a GP is with the client’s full knowledge and consent, for a specific purpose. This information is stored in a locked filing cabinet that can only be accessed by myself. What you share with me in therapy sessions will be kept confidential and I am fully compliant with the ethical code of HCPC. The only exceptions to this are when there is risk to self or risk to others and it is my responsibility to ensure that you and others are safe. I will always be transparent about the need to share this information unless safeguarding issues make this unfeasible. Examples of information I would need to share are: disclosure of abuse or neglect of a child or vulnerable adult, or an expression of intent to harm yourself or others, or if a court of law requires disclosure of information. I am required to have clinical supervision to discuss the therapy I undertake with my clients. Your case may be discussed with another HCPC registered Psychologist, but there would be no need for disclosure of identifying information. I keep brief written notes about therapy sessions for the purpose of formulation and treatment. These do not include personally identifying information and are stored in a locked filing cabinet that only I have access to. Therapy notes are stored separately to your personal contact information.

Website visitors
By accessing the website, you are consenting to the information collection and use practices described here. I use Protonmail for my email account which has full compliance with GDPR, including automatic encryption and advanced security features. The website uses cookies and Google Analytics. This is true of almost all websites. Small files called cookies are put on your computer by websites as you access them. These cookies can store lots of information which can have privacy implications. Google Analytics is a service provided by Google that gathers anonymous data on how people are using websites and then provides visitor statistics, details of page views etc. This service is used by many website owners as the data helps website owners to improve their websites.

Your rights
You have the right to request access to the personal information that I store and process about you. You can ask for corrections to be made to the information held or for your personal information to be deleted. You can also stipulate that you do not wish me to store certain information about you, or object to the processing of any data if you so wish, which may have implications for therapy. Please read your rights at ico.org.uk/yourdata-matters.

Queries
Louise Baker-Martins is the ‘data controller,’ the person who collects and stores your information and has responsibility for your personal data. I am registered with the Information Commissioner’s Office: ZA519725. If you have any questions about this privacy policy or the way in which I handle your personal information you can contact me by email, thesleepspot@protonmail.com.

Complaints
If you have a complaint about how I handle your personal data please contact me using the above email. If you want to make a formal complaint about the way I have processed your personal information you can contact the ICO which is the statutory body that oversees data protection law in the UK. For more information go to ico.org.uk/make-a-complaint.