Privacy Policy
Last updated: 23 July 2026.
In order to provide you with the best service possible I need to hold your personal contact details and records of your therapy sessions. This privacy notice tells you what I will do with your personal information from initial point of contact through to after therapy has ended. Your privacy is very important to me and you can be confident that your personal information will be kept safe and secure and will only be used for the purpose it was given to me. I adhere to current data protection legislation, including the General Data Protection Regulation (EU/2016/679) (the GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications (EC Directive) Regulations 2003. I also adhere to the ethical guidelines regarding protecting client privacy and confidentiality set by the British Association for Counselling and Psychotherapy (BACP).
1.Information Collected
Transform Therapy only collects personal information that is voluntarily provided when an individual expresses an interest in obtaining information about therapy services. The personal information collected via the secure contact form may include:
- Full Name
- Email address
- Phone number
- Any personal details the user chooses to share within the message body
2. How Your Information Is Used
The information provided is used solely for the following professional purposes:
- To respond to inquiries and arrange therapy consultations.
- To provide ongoing therapeutic services and manage the client relationship.
- To comply with the legal and regulatory obligations required of a registered healthcare professional.
Personal information will never be sold, rented, or traded to any third parties for marketing purposes.
3. How Data is Secured and Stored
Modern, enterprise-grade security architecture is employed to ensure client data is never left vulnerable:
- No On-Site Storage: This website is a secure, static environment hosted on the Cloudflare Edge network. Personal data and contact form submissions are not stored in a website database.
- Secure Transmission: When a contact form is submitted, the data is encrypted and securely routed directly to a private email server using an authenticated Application Programming Interface (API).
- Encrypted Email Hosting: All client communications and personal data are stored within a secure, encrypted Microsoft 365 Business environment, protected by modern authentication and strict access controls.
4. Website Analytics and Cookies
The right to browse privately is highly respected. To measure website performance without compromising visitor data, Transform Therapy utilizes Cloudflare Web Analytics.
- Privacy-First Tracking: This analytics tool is entirely privacy-first. It does not use any client-side analytics cookies, it not track individual IP addresses, and it does not collect personally identifiable information (PII).
- Cookie Consent: This website does not use non-essential cookies or third-party tracking technologies.
5. Lawful Basis
Personal data is processed on the lawful basis of legitimate interests and, where applicable, steps taken at your request before entering into a service agreement.
6. Data Storage and Retention
Reasonable technical and organisational safeguards are used to protect your information. Personal data is retained only for as long as necessary to fulfil the purpose for which it was collected and to meet legal, professional, and insurance obligations.
7. Your Rights
You may have rights to request access to, correction of, or deletion of your personal data, and to object to or restrict certain processing. To make a request, contact: pamela@transform-therapy.co.uk.
8. Contact
If you have questions about this privacy policy, please email pamela@transform-therapy.co.uk.
Data Protection Complaints Process
Purpose
This procedure sets out how Transform Therapy receives, investigates, responds to, and records complaints relating to the handling of personal data. It is designed to support compliance with UK data protection legislation, including the UK GDPR, the Data Protection Act 2018, and requirements introduced under the Data (Use and Access) Act (DUAA).
1. Scope
This procedure applies to all complaints concerning the collection, use, storage, sharing, retention, security, or disposal of personal data handled by Transform Therapy.
2. How to Make a Complaint
Complaints may be submitted in writing, by email, or verbally. Complaints should include the complainant's name, contact details, details of the concern, and any supporting information.
3. Acknowledgement
All complaints will be acknowledged within five working days of receipt. The complainant will be informed of the name and contact details of the person managing the complaint.
4. Investigation
The complaint will be reviewed by the Data Protection Lead or another appropriately authorised individual. Relevant records, systems, policies, may be consulted. Where necessary, additional information will be requested.
5. Timescales
A substantive response will normally be provided within one calendar month. If the complaint is complex and requires additional time, the complainant will be informed of the reason for the delay and the expected response date.
6. Outcomes
Following investigation, Transform Therapy may: uphold the complaint in full; uphold it in part; or not uphold the complaint. Where appropriate, corrective actions, service improvements, policy changes, or remedial measures will be implemented.
7. Communication of Decision
The outcome will be communicated in writing and will include a summary of the investigation, findings, actions taken, and any further options available.
8. Escalation
If the complainant remains dissatisfied, they may request an internal review. Following completion of the internal review, individuals may raise their concerns with the Information Commissioner's Office (ICO).
9. Record Keeping
A complaints register will be maintained recording the date received, nature of the complaint, actions taken, outcome, and any lessons learned. Records will be retained in accordance with Transform Therapy’s retention schedule.
10. Responsibilities
The Data Protection Lead is responsible for overseeing compliance with this procedure.
11. Monitoring and Review
This procedure will be reviewed at least annually, or sooner if legislation, regulatory guidance, or organisational practices change.