Privacy Policy

Effective Date: 14/08/2026

Data Controller: Michael Lal, North Horizon Counselling

ICO Registration Number: ZC104221

Contact Details: info@northhorizoncounselling.com

1. Introduction

Your privacy is very important to me. You can be confident that your personal information will be kept safe and secure and will only be used for the purpose for which it was given to me.

I adhere to current UK data protection legislation, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), and the Privacy and Electronic Communications Regulations 2003 (PECR).

This Privacy Policy explains what I do with your personal information from initial contact through to after therapy has ended:

  • Why I process your information and the legal basis for doing so

  • How long I retain your information

  • Who your information may be shared with

  • Details regarding data transfers and automated decision-making

  • Your data protection rights

If you have any questions about this policy, please contact me via [Insert Preferred Contact Method, e.g., email].

2. Lawful Basis for Processing Personal Data

Under the UK GDPR, I must have a lawful basis for processing your personal details. The legal bases depend on the stage of our relationship:

  • Enquiry & Active Therapy Stage: Processing is necessary for the performance of a contract or to take steps prior to entering into a contract.

  • Post-Therapy Stage: Retaining records after therapy has concluded is based on legitimate interests to ensure proper practice administration and historic client record management.

  • Special Category Data (Health & Therapy Notes): Explicit consent is requested initially to process health-related details. Notes and sensitive therapy records are retained after therapy under the legal basis of defending potential legal claims.

  • Website Visitors: Website usage and analytics data are processed under legitimate interests to maintain and improve online services.

3. How Information Is Collected and Used

Initial Contact & Enquiries

When you enquire about therapy, I collect information necessary to answer your request (e.g., name, phone number, email address, basic details of your enquiry). Details may also be provided by a GP, health professional, or trusted individual acting on your behalf.

If you decide not to proceed with therapy, all personal data collected during the enquiry will be deleted within accordance to regulatory and legal timescales, or unless requested sooner.

During Therapytime

Confidentiality is a primary principle of therapy. Information shared in sessions remains strictly confidential, with exceptions made only under specific circumstances:

  • Where required by law or a court order.

  • Where there is a severe risk of harm to yourself or others.

  • Mandatory statutory disclosures (e.g., terrorism, money laundering, safeguarding concerns).

Where possible, disclosures will be discussed with you first.

  • Session Notes: Brief clinical notes are kept securely [insert method, e.g., in password-protected, encrypted cloud storage / locked storage].

  • Communications: Text messages and emails are reviewed regularly. Standard admin emails/texts are deleted after 6 months unless they contain relevant clinical information, in which case they are stored securely alongside client records.

After Therapy Ends

Once therapy ends, client records are retained for a minimum of 5 years in accordance with legal and insurance requirements. After this period, all paper and digital records are securely destroyed.

4. Website Visitors, Cookies & Digital Infrastructure

Visitors to the Website

When you visit this website, third-party services (such as site analytics and web hosting) collect standard internet log information and details of visitor behavior patterns. This is done anonymously to track visitor numbers and site usage. No individual visitor is identified through this data.

If you fill out a contact form on the website, the data is temporarily stored on the secure web server before being transmitted to me.

Hosting & Third-Party Processors

To run my practice efficiently, I engage carefully selected third-party processors under written contracts ensuring data protection compliance:

  • Web Hosting & CMS: Hostinger and WordPress

  • Online Booking / Scheduling: Setmore

  • Analytics: Google Analytics

Cookies

This website uses cookies to function properly and efficiently. Non-essential cookies (such as analytics cookies) are only enabled if you provide explicit opt-in consent via the website cookie banner.

5. Third-Party Recipients of Data

Personal data is not sold or passed to third parties for marketing purposes. Data is only shared with third-party service providers (such as IT/cloud storage providers, accountants, or supervisory legal bodies) where necessary to deliver services, satisfy legal duties, or comply with professional standards.

6. Data Security

Every reasonable precaution is taken to keep personal data safe from unauthorized access, loss, or misuse. Measures include:

  • Using encrypted, password-protected electronic devices and software.

  • Two-factor authentication (2FA) on all professional accounts.

  • [If applicable: Keeping physical paper records in locked cabinets].

7. Your Data Protection Rights

Under UK data protection law, you have the following rights:

  • Access: The right to request a copy of the personal information held about you.

  • Rectification: The right to request correction of inaccurate or incomplete data.

  • Erasure: The right to request deletion of your personal data (subject to legal or insurance retention obligations).

  • Restriction / Objection: The right to restrict or object to the processing of your data.

To make a Subject Access Request or exercise any data rights, please submit your request in writing to info@northhorizoncounselling.com

8. Complaints

If you have concerns about how your personal data is handled, please contact me directly so the issue can be addressed.

If you remain dissatisfied, you have the right to lodge a formal complaint with the statutory supervisory body (BACP) for data protection in the UK:

Information Commissioner’s Office (ICO)

Website: ico.org.uk/make-a-complaint

Telephone: 0303 123 1113