Privacy Policy
Introduction
Helensburgh Hypnotherapy is committed to protecting and respecting your privacy.
This Privacy Policy explains how personal information is collected, used, stored, and protected in accordance with:
- the UK General Data Protection Regulation (UK GDPR), and
- the Data Protection Act 2018.
Personal data is handled lawfully, fairly, transparently, and securely at all times.
Data Controller
The Data Controller responsible for your personal information is:
Alison Sheen
Helensburgh Hypnotherapy
ICO Registration Number: ZB615401
The Data Controller determines how and why your personal data is processed.
Personal Information Collected
To provide safe and effective hypnotherapy services, Helensburgh Hypnotherapy may collect and process the following information:
Personal Details
- Name, address, email address, and telephone number
- Emergency contact details or details of a significant other
- GP contact details (where relevant)
Therapeutic Information
- Information relating to your goals for hypnotherapy
- Relevant medical or wellbeing information
- Brief clinical session notes recording progress and agreed actions
Administrative Information
- Appointment history
- Correspondence via email, telephone, text, or messaging services
Only information that is necessary and proportionate for therapeutic care is collected.
Lawful Basis for Processing
Personal data is processed under the following lawful bases:
- Contractual necessity — to deliver hypnotherapy services requested by you
- Legitimate interests — maintaining appropriate professional clinical records
- Legal obligation — compliance with legal, safeguarding, and regulatory duties
- Explicit consent — for processing special category health data
Where consent is relied upon, you may withdraw consent at any time.
Purpose of Data Processing
Your personal information is collected and used to:
- Provide safe and effective hypnotherapy treatment
- Maintain professional clinical records
- Manage appointments and communication
- Ensure continuity and quality of care
- Meet professional, insurance, safeguarding, and legal obligations
Your personal data will never be sold, rented, or used for unrelated marketing purposes.
Data Retention
As a student member of the National Council for Hypnotherapy, records are retained in accordance with professional guidance:
- Adult clients: retained for 8 years after the final session
- Children under 16: retained until age 25
- Young people aged 17–18: retained until age 26
Records are retained only as long as necessary to satisfy professional, legal, and insurance requirements and are securely destroyed thereafter.
Your Rights Under UK GDPR
You have the right to:
- Access your personal data
- Request correction of inaccurate information
- Request erasure (“right to be forgotten”)
- Request restriction of processing
- Object to processing where applicable
- Request data portability
- Withdraw consent at any time (where consent applies)
Right of Access (Subject Access Request)
You may request access to personal data held about you.
Requests must be made in writing.
Information will normally be provided within one calendar month.
Proof of identity may be required before disclosure.
Right to Deletion or Anonymisation
You may request:
- Deletion of personal data
- Restriction of processing
- Anonymisation of identifiable information
Please note that certain clinical records may need to be retained to comply with professional, insurance, safeguarding, or legal obligations.
Where possible, identifying details will be removed and records anonymised.
Data Security and Storage
Helensburgh Hypnotherapy implements appropriate technical and organisational security measures, including:
- Session notes are hand written and securely stored.
- Electronic communication is deleted once securely printed and filed
- Paper records stored in locked filing systems
- Devices protected by strong passwords, PIN protection, and biometric security
- Secure email authentication
- Access restricted solely to the Data Controller
All reasonable steps are taken to prevent unauthorised access, loss, misuse, or disclosure of personal data.
Confidentiality of Therapy Sessions
Information shared during hypnotherapy sessions is treated as confidential and used solely for therapeutic purposes.
Confidentiality may be breached only where legally or ethically required, including:
- Risk of serious harm to yourself or others
- Safeguarding concerns involving a child or vulnerable adult
- Compliance with legal obligations or court orders
- Disclosure required under criminal law
- Professional supervision (all identifying information removed and supervisors comply with UK GDPR)
Contact Outside Therapy Sessions
Your confidentiality will always be respected.
If contact occurs outside the therapy setting, acknowledgement will remain discreet, and therapy discussions will only occur if initiated by you.
Sharing Information with Other Professionals
Your information will only be shared with healthcare or social care professionals where:
- you have provided explicit written consent, or
- disclosure is required under legal or safeguarding obligations.
Complaints
If you have concerns about how your data is handled, please contact Helensburgh Hypnotherapy in the first instance.
You also have the right to lodge a complaint with the UK supervisory authority:
Information Commissioner's Office (ICO)
Website: https://ico.org.uk
Contact Details
For questions regarding this Privacy Policy or your personal data:
Alison Sheen
Helensburgh Hypnotherapy
Email: alison@helensburgh-hypnotherapy.co.uk
Policy Review
This Privacy Policy is reviewed periodically to ensure ongoing compliance with UK data protection legislation and professional standards.
This policy has most recently been reviewed on 14th May 2026
Solution Focused Hypnotherapy requires the client’s full commitment and motivation to get the best outcomes and results can not be guaranteed..
