Data Protection
The Principles of this policy
Blossom Tree Therapy shall:
Hold an ICO registration as a lawful holder of client data.
Obtain only appropriately relevant information with regards to the purpose of personal therapy.
Keep personal data accurate and up to date.
Hold information for the time specified by the National Counselling Society and no longer. This amounts to 7 years for both societies, after which any information is removed and securely destroyed.
Take appropriate measures to ensure the security of that data.
Ensure that checks are made as to the GDPR compliance of electronic areas where client data is stored.
What is Data protection?
The data Protection Act aims to protect an individual’s rights and freedom to privacy, in respect of personal data processing.
It applies to paper and electronic records containing personal information relating to living individuals who can be identified from the data.
Individuals have the right to gain access to their own data; they are entitled to make a subject access request in order to do this. This implies access to:
A description of their personal data
The purposes for which it is being processed
Details of whom this information may be disclosed to and in what circumstances
ICO Registration
Blossom Tree Therapy holds a valid ICO registration certificate, registration reference Z.
Data Classes
Data classes refers to the type of data which is being held about clients. Blossom Tree Therapy holds the following type of details:
Personal details – name, email address, phone numbers
Some limited medical information (disclosure of serious health conditions and medication)
Doctor’s name and address
Client notes
Hypnotherapy scripts, which are anonymised
Areas in which hard copy data is stored
Client details are collected by means of a client questionnaire and contract, to be signed by both Sarah Legg and the client – with a scanned copy provided so that both parties have access to the terms of engagement.
Both the contract, questionnaire and any notes shall be kept in a securely locked filing cabinet, accessed only the sole key-holder, Sarah Legg.
Areas in which electronic data is stored
GoogleDrive
Dropbox (copies of personalised hypnotherapy recordings only)
Gmail
Occasionally clients contact Blossom Tree Therapy via business facebook page – all details are deleted immediately from this after reading.
Mobile phone (current client phone numbers may be occasionally stored. These are removed once therapy is terminated)
In addition:
Website – clients can message directly from this but no email addresses are retained.
Blog – comments can be left, leaving an email trace. None of these email addresses are retained.
All electronic areas where client information is collected/stored are GDPR compliant or are currently preparing for compliance.
Security arrangements
Hard copy data: Data is kept in a securely locked filing cabinet, accessed only by Sarah Legg, the sole key holder.
Electronic data: No data is retained on the hard drive; Client notes, resources used etc are all kept on GoogleDrive, Business laptop is password protected and stored in a locked filing cabinet whilst not in use.