AI Use Policy

Effective date: 12/08/2026

Purpose

This policy sets out rules for the use of artificial intelligence (AI) tools within Sophie de Vieuxpont Psychotherapy to protect client confidentiality, support ethical practice, and ensure compliance with applicable UK law and professional standards. The policy is designed to minimise risk by restricting AI use in all clinical and client-identifiable contexts.

Scope

This policy applies to all staff, associates, contractors, trainees, and supervisors working for or on behalf of Sophie de Vieuxpont Psychotherapy, and covers any use of AI tools (including “chatbots”, “writing assistants”, “transcription”, “summarisation”, and “decision support” systems) on any device used for practice work, whether practice-owned or personal.

Statement of principle

Sophie de Vieuxpont Psychotherapy prioritises client safety, confidentiality, and autonomy. Psychotherapy is a relational and ethical practice that requires professional judgement and accountability. AI tools must not be used in ways that could identify a client, influence clinical decision-making, or undermine informed consent, data protection, or professional standards. Where AI is used for limited non-clinical tasks, it must be used conservatively, transparently within the organisation, and with robust safeguards.

Permitted uses (non-clinical only)

AI may only be used where all of the following are true: (1) the task is strictly non-clinical, (2) no client-identifiable information is entered, (3) no client-related decision-making is supported, and (4) the tool and settings are approved by Sophie de Vieuxpont Psychotherapy in writing.

  • General training and education — generating generic learning resources (e.g., summaries of publicly available guidance) that do not reference client material.

  • Administrative drafting for internal use — drafting generic policies, checklists, templates, or non-client-facing materials (e.g., this policy), provided no client-identifiable information is included.

  • Language support — improving grammar or clarity of generic text that does not relate to a client or to client communications.

  • Technical assistance — generic troubleshooting or productivity advice not involving client systems or client data.

Important: “No client-identifiable information” includes names, contact details, dates/times of sessions, addresses, unique circumstances, clinical history, voice recordings, written material, or any combination of details that could reasonably identify a client directly or indirectly.

Prohibited uses (strict)

AI must never be used for any of the following, whether directly or indirectly, even if identifying details are removed or “anonymised”:

  • Clinical notes, progress notes, psychotherapy notes, or any part of the clinical record.

  • Session summaries, session transcripts, process notes, or reflective notes about a client.

  • Client administration — including referrals, onboarding, waiting lists, or any handling of client administrative information.

  • Appointment handling — scheduling, cancellations, reminders, or diary management relating to clients.

  • Billing and payment — invoices, receipts, claims, payment chasing, or any financial administration linked to a client.

  • Correspondence that could identify a client — including emails, letters, reports, insurance communications, court/third-party communications, or any client-facing message where the client could be identified directly or indirectly.

  • Risk assessments, safeguarding assessments, or any analysis of harm risk or safety planning.

  • Clinical formulation, diagnosis, treatment planning, or any clinical decision-making or recommendations about a client.

  • Supervision content that includes client material or could identify a client (directly or indirectly).

  • Any decision-making about clients — including triage, suitability, referral pathways, frequency of sessions, ending therapy, or any judgement that affects a client’s care.

Confidentiality and client information

Sophie de Vieuxpont Psychotherapy treats all client information as confidential and processes personal data in line with UK GDPR and the Data Protection Act 2018. AI use must not compromise confidentiality, informed consent, or the client’s reasonable expectations of privacy.

  • No client-identifiable information may be entered into any public, consumer, or general-purpose AI tool, including tools embedded in web browsers, search engines, phones, or email platforms.

  • No client data may be uploaded to AI services for summarisation, transcription, sentiment analysis, categorisation, or “insights”.

  • Do not copy/paste client text (including emails or messages), assessment content, or extracts from notes into AI tools.

  • Do not use AI to “anonymise” client data. Removing names is not sufficient to protect identity.

Approved tools and settings

By default, Sophie de Vieuxpont Psychotherapy has no approved AI tools for practice work. If Sophie de Vieuxpont Psychotherapy later chooses to approve a tool for strictly non-clinical use, it must be documented here and configured in accordance with a written risk assessment and data protection review.

Tool name

Permitted purpose (non-clinical only)

Required settings / controls

Approval date & owner

Where any AI tool is approved, staff must use only the approved account and configuration. Personal accounts, free trials, and consumer versions are not permitted for practice work.

Human oversight

Any permitted AI output must be treated as a draft or reference only. A suitably qualified human professional must review and take full responsibility for any use of AI-generated content. AI outputs must not be relied upon as authoritative, and must not be used to provide clinical guidance, interpret client information, or influence any client-related action.

Record keeping

Where AI is used for a permitted non-clinical purpose, a brief internal record must be kept, proportionate to risk, to support accountability and auditability. Records should include:

  • Date and user.

  • Tool used (approved name/account).

  • Purpose (non-clinical).

  • Confirmation that no client-identifiable information was entered.

  • Summary of how the output was reviewed and used.

Safeguarding and high-risk decisions

AI must not be used in safeguarding contexts or in any high-risk decisions. If a safeguarding concern arises, practitioners must follow Sophie de Vieuxpont Psychotherapy safeguarding procedures and relevant professional guidance. Decisions affecting client safety, escalation, reporting, referrals, and emergency action must be made by an appropriately qualified human professional without AI involvement.

Safeguarding note: In situations involving immediate risk, follow emergency procedures and contact emergency services where appropriate. Do not use AI tools to assess risk, draft safety plans, or decide next steps.

Data protection and security

All staff must handle information in line with Sophie de Vieuxpont Psychotherapy’s data protection, confidentiality, and information security policies. In relation to AI, the minimum requirements are:

  • Data minimisation — do not share any information with an AI tool unless it is strictly necessary for a permitted non-clinical purpose (and never client-identifiable).

  • Access control — use strong passwords and multi-factor authentication where available; do not share accounts.

  • Device security — keep devices updated; use screen locks; do not use AI tools on shared/public devices for practice work.

  • Storage and retention — do not store AI prompts/outputs in locations that could mix with client records; follow retention rules for internal documents.

  • Third-party risk — AI tools may process data outside the UK; this increases risk and may be unlawful without appropriate safeguards. Public/consumer AI tools are treated as high risk and are not permitted for any client-related content.

Training and review

Sophie de Vieuxpont Psychotherapy will ensure all relevant personnel understand this policy, the limits on AI use, and their confidentiality and data protection obligations. Training should cover:

  • What constitutes client-identifiable information (including indirect identifiers).

  • Common AI risks (hallucinations, bias, over-reliance, data retention, unintended disclosure).

  • How to use approved tools safely (if any are approved in future).

This policy will be reviewed at least annually and whenever there is a material change in technology, practice systems, legal/regulatory guidance, or after any incident involving AI.

Breach reporting

Any suspected or actual breach of this policy, confidentiality incident, or accidental entry of client-identifiable information into an AI tool must be reported immediately in line with Sophie de Vieuxpont Psychotherapy’s incident management process. This includes near-misses.

  • Immediate actions — stop the activity, preserve evidence (do not delete logs/messages unless instructed), and notify the designated contact below.

  • Assessment — Sophie de Vieuxpont Psychotherapy will assess risk, including whether the incident constitutes a personal data breach under UK GDPR and whether notification to the ICO and/or affected individuals is required within statutory timeframes.

Contact details

Policy owner / Data protection contact: Sophie de Vieuxpont

Email: sophie@devieuxpont.co.uk

Closing statement

This policy exists to protect clients, uphold confidentiality, and ensure ethical and lawful practice. Where there is any doubt, AI must not be used and guidance should be sought from the policy owner.