Date of statement: 16/07/2022
Date statement updated: 01/05/2023
Key Facts
- Wellbeing Psychology keeps records about you in oder to provide you with a service and process payments
- We cannot work with you unless you allow us to keep these records
- Wellbeing Psychology follows legislation for record keeping covered by the Information Commissioner's Office, and professional codes of practice set out by the Health Care Professions Council and British Psychological Society
- Wellbeing Psychology uses I.T. systems and practices designed to protect the security of your personal information
- If you have any questions or concerns about this please contact us at admin@wellbeing-psychology.co.uk
- If you think we are acting unlawfully you can complain to the Information Commissioner's Office (ICO): www.ico.org.uk/concerns or phone 0303 123 1113
Who is responsible for your data
Thomas Sidebottom is the data controller for Wellbeing Psychology. This means he is responsible for all personal information held by Wellbeing Psychology and ensuring this data is collected, stored and processed in a secure way that complies with current legislation.
What personal information we collect, store and process
- Personal information including your name, address, telephone number, email address and GP contact details.
- Sensitive information about your circumstances including current mental health difficulties, personal history, obstacles to recovery and recovery goals.
- Sensitive information about your mental health history to develop a broader contextual understanding of current problems.
- Sensitive information about you from completed psychological assessment measures.
- Sensitive information about your psychological therapy including records of therapy sessions.
- Personal information for accounts and billing, such as your name, address and email so we can send invoices and record payments received.
- If you are referred to us by a health insurance provider, solicitor, or other private mental health company, we will also store and process personal information (as outlined above) provided to us by that organisation.
The lawful bases for processing your personal information
Wellbeing Psychology collects, stores and processes your personal information on the basis that we have an agreement with you to do so, because you have asked us to provide you with a service for psychological therapy. Without collecting, storing and processing the information described above, unfortunately we would not be able to provide you with that service.
In rare and exceptional circumstances we may also rely on another legal basis to share personal information about you for the purposes of protecting life. This could involve sharing personal information about you with your registered GP or the police, if they had a legitimate role in protecting your life or the life of another person connected to you. Under such circumstances we would always try to find reasonable ways of involving other professionals so that you are informed and we have tried to obtain your consent for this. However, if there was no reasonable way of doing so without increasing risk, we may still share your personal information without your awareness or consent using this legal basis.
Who we may share your personal information with
We hold personal and sensitive information about each of the people we work with in confidence. This means we will not normally share your personal information with anyone else.
However, there are exceptions to this when we may need to liaise with other parties:
- If you are referred to us by your health insurance provider, a private healthcare company acting on behalf of your insurer, or your solicitor, we will share appointment schedules with that organisation for the purposes of billing.
- We may also share personal and sensitive information about you with these referring organisations. This may consist of summary assessment reports, update reports about therapy, and end of treatment reports, to show the work we’ve undertaken with you has been in accordance with initial agreements and to the expected clinical standards. We will always explain this to you and seek your verbal consent to share such records with referring organisations at our first appointment. You do not have to consent to this, and if you do not give your consent we will not share that information, but it may affect our ability to offer you a service straight away or in the normal way. Under such circumstances we will consider and discuss alternative arrangements with you.
- Even if you consent to us sharing personal and sensitive information with other referring organisations, you have a right to later withdraw your consent to this. If you do so, we will stop sharing such information immediately. However, this is likely to affect our ability to continue offering you a service in the normal way and may result in a pause or break in therapy sessions. Under such circumstances we will consider and discuss alternative arrangements with you.
In exceptional circumstances, we might need to share your personal information with relevant authorities:
- When there is a legitimate need for another health professional to be updated about your mental health such as your GP. We would discuss such a proposed disclosure with you and seek your consent for this.
- When there is a risk of harm to yourself, or harm to another adult or child. We will discuss such a proposed disclosure with you and seek your consent unless there was no reasonable way of doing so without increasing risk of harm.
- When there is a legal obligation for us to do so such as a Court Order.
How long we store your personal information
We only store your personal information for as long as it is required for a specific purpose, such as offering you a service or following professional practice guidelines.
Basic contact information such as your name, address, email and contact telephone number is deleted from our contacts system six months after your final therapy session. We also aim to delete all email correspondence we’ve sent and received from you, and any emails we’ve sent or received about you from other parties, six months after your final therapy session.
All other sensitive information we hold about you as described above, is stored by us for a period of seven years after the end of therapy. This may seem like a long time but we do so in accordance with professional practice guidelines published by the British Psychological Society. This is because individuals may return to us for further therapy, or they may request information from us about therapy services previously received so they can approach another provider. We also keep sensitive records of services provided for legal purposes such as audits and investigations.
Where we store your personal information
Wellbeing Psychology has an entirely electronic record keeping and administration system, and we do not keep paper records of any kind. All the data we collect and process is stored electronically using a secure could-based storage system that complies with National and European data security standards. We do not store personal or sensitive data of any kind on local devices. Our cloud storage system uses end-to-end encryption technology with two factor authentication, meaning only the data controller at Wellbeing Psychology can decrypt and access your personal information when it is stored this way, and only on trusted devices owned by Wellbeing Psychology and operated securely. No-one else, not even the technology company operating the servers, can decrypt and access your data.
How we keep you data secure and confidential
- Personal information is kept to a minimum during initial telephone enquiries and never written down or typed out by us.
- If we send you an email containing any sensitive information we will do so as an attached document or .Zip file that is secured using a pin code. We will assign you a pin after the first appointment, or as soon as possible, and text this to you separately from any emails.
- If we send any emails containing personal or sensitive information about you to other organisations, we will only do so using a secure encrypted email service such as Egress Secure, or otherwise as an attached document or .Zip file that is pin or password protected.
- Our I.T. devices that access personal and sensitive data are password protected, pin protected, and/or use biometric approval to be unlocked. All these devices are set to lock after the shortest period of inactivity their settings allow.
- Wellbeing Psychology has a planned schedule for replacing all hardware devices to mitigate against hardware failure and obsolescence. This means all the devices we use run the latest software operating systems, with the latest security updates automatically installed.
- Wellbeing Psychology regularly audits the security of our electronic data systems and the routine processing of data within the business. We do this by reviewing the integrity of our records of personal and sensitive information, as well as gathering other evidence about routine data handling practices, so we can evaluate this evidence against the standards set out in this policy and other key documents regarding compliance with national legislation. Security risks and vulnerabilities are identified and addressed in an ongoing way to ensure we operate accountably and to the highest professional standards. The results of audits are available on request. The latest audit was completed on 29/04/23.
Your data protection rights
Under data protection law, you have rights including:
- You have the right to ask us for copies of the information we hold about you. We aim to share this with you within 30 days of receiving a request and we may seek further proof of identity from you before doing so.
- You have a right to ask us to correct personal information you think is inaccurate.
- You have a right to ask us to erase some of the personal information we hold if it’s no longer being stored for a legitimate reason or in accordance with the timescales outlined above.
- You have the right to ask us to share copies of the personal and sensitive information we hold about you with another organisation.
If you wish to make a request, please contact us at:
E-mail: admin@wellbeing-psychology.co.uk
Telephone: 07954601962
Making a complaint
If you have any questions, concerns or would like to complain about our use of your personal information please contact us at:
E-mail: admin@wellbeing-psychology.co.uk
Telephone: 07954601962
If you think we are acting unlawfully you can complain to the Information Commissioner's Office (ICO):
www.ico.org.uk/concerns
Tel: 0303 123 1113
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF