Privacy Policy

Effective date: 12/08/2026

Version: 2

Introductory statement

This Privacy Policy explains how Sophie de Vieuxpont Psychotherapy (“we”, “us”, “our”) collects, uses, stores, shares, and protects personal data. We are committed to handling personal information responsibly, in line with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and good professional practice, including the National Counselling & Psychotherapy Society (NCPS) Code of Practice and ethical principles (including respect for privacy, client autonomy, and confidentiality).

We aim to be transparent about what we do with your information. If you have any questions or complaints, please contact us using the details at the end of this policy.

Who we are

Controller: Sophie de Vieuxpont is the “data controller” for the personal data described in this policy (meaning we decide how and why it is processed).

Email: sophie@devieuxpont.co.uk

Website: www.devieuxpont.co.uk

ICO registration number (if applicable): ZB646256

What information we collect

We may collect and process the following categories of personal data, depending on the services you use and what you choose to share:

  • Identity and contact details — name, date of birth, address, email address, phone number, emergency contact details, GP details (if relevant and provided).

  • Service and appointment information — session dates/times, attendance, communications with us, preferences (such as accessibility needs).

  • Payment and billing information — invoices/receipts, payment status, and limited payment references. We do not normally store full card details; card payments (if offered) are handled by the payment provider.

  • Therapy information (special category data) — information relating to your physical and mental health, wellbeing, therapeutic goals, and other information you share in sessions or in correspondence; assessments, formulations, risk information, and any agreed plans.

  • Session notes and clinical records — brief therapy notes, safeguarding/risk notes, and administrative records (see “How session notes and records are handled”).

  • Technical and online information — if you use our website/online booking/remote therapy platforms, we may collect device and usage data, IP address, and cookies/analytics data (see “Cookies and website analytics”).

How we collect information

We collect personal data in the following ways:

  • Directly from you — when you enquire, complete intake forms, book appointments, attend sessions, communicate by email/text/phone, or provide information in therapy.

  • From third parties (limited) — for example, if you ask a referrer to contact us, if we receive information from another healthcare professional with your consent, or if an emergency contact/third party provides information relevant to safeguarding or immediate safety.

  • Automatically — when you visit our website or use online services (subject to your settings and cookie choices).

Why we use personal data

We use personal data to:

  • Provide psychotherapy services — arrange and deliver sessions, maintain appropriate records, and support continuity of care.

  • Communicate with you — respond to enquiries, send appointment confirmations, and share relevant service information.

  • Manage safeguarding and risk — assess and respond to serious risks of harm, and follow professional and legal obligations.

  • Handle payments and administration — issue invoices/receipts, manage cancellations, and maintain accounting records.

  • Meet legal and regulatory duties — comply with applicable laws, resolve complaints, and manage professional supervision/consultation appropriately.

  • Improve our services — maintain service quality, manage our website, and understand how our online services are used (where applicable).

Lawful bases for processing (UK GDPR & Data Protection Act 2018)

Under UK GDPR, we must have a “lawful basis” for processing your personal data. Depending on the context, we rely on one or more of the following lawful bases:

  • Contract (Article 6(1)(b)) — where processing is necessary to provide therapy services you request and to manage our therapeutic agreement (for example, scheduling sessions, communicating about appointments, invoicing).

  • Legal obligation (Article 6(1)(c)) — where we must process data to comply with law (for example, certain record-keeping or responding to lawful requests).

  • Legitimate interests (Article 6(1)(f)) — where necessary for our legitimate interests (or those of a third party) and your rights do not override those interests (for example, limited service administration, security, and maintaining professional standards). We consider and balance impacts on privacy before relying on this basis.

  • Consent (Article 6(1)(a)) — where you have given clear consent for a specific purpose (for example, if we contact a third party at your request, or if you opt in to certain communications). You can withdraw consent at any time (see “How to withdraw consent or object”).

Where we process special category data (including health information), we also identify a separate condition under Article 9 UK GDPR and the Data Protection Act 2018 (see next section).

Special category data and health information

Psychotherapy typically involves processing special category data about health, mental health, and related personal circumstances. We may process special category data on one or more of the following grounds (as applicable):

  • Explicit consent (Article 9(2)(a)) — where required or appropriate, and where you provide explicit consent for a defined purpose.

  • Healthcare/social care (Article 9(2)(h)) — where processing is necessary for the management of health or social care systems and services, including the provision of care, where applicable to the way services are delivered and recorded.

  • Substantial public interest (Article 9(2)(g)) — in limited circumstances, including where safeguarding and protection of individuals is engaged and the relevant conditions under the Data Protection Act 2018 apply.

  • Vital interests (Article 9(2)(c)) — where processing is necessary to protect someone’s life and the person is incapable of giving consent (used only in rare situations).

We aim to process only the minimum special category data necessary to provide therapy safely and professionally.

Confidentiality and limits to confidentiality

We treat the content of therapy as confidential and handle information in accordance with NCPS ethical principles and professional standards. However, confidentiality is not absolute. We may need to share information without your consent in certain circumstances, including where:

  • There is a serious risk of harm to you or another person (for example, risk of suicide, serious self-harm, or violence).

  • Safeguarding concerns arise relating to a child or vulnerable adult, including suspected abuse or neglect, or where a person may be at risk of significant harm.

  • We are required by law — for example, a court order, or other lawful requirement to disclose information.

  • Serious crime / prevention and detection — where disclosure is necessary and lawful in the public interest, assessed carefully and proportionately.

Where possible and appropriate, we will aim to discuss any need to share information with you in advance. We will only share what is necessary and relevant, and we will document our decision-making.

How session notes and records are handled

We keep records to support safe, ethical, and effective practice. Records may include:

  • Administrative records — contact details, appointment history, cancellations, invoices, consent forms, and relevant correspondence.

  • Clinical/therapy notes — brief notes to support continuity of care and reflective practice. These are typically factual and focused on therapeutic work, risk considerations, and agreed actions, rather than full transcripts of sessions.

We aim to keep notes proportionate and relevant. Session notes and records are stored securely, access is restricted, and we retain them only for as long as necessary (see “Data retention”).

Sharing information with third parties

We do not sell your personal data. We may share personal data with trusted third parties where necessary for the purposes in this policy, such as:

  • Professional supervision/consultation — therapists may use supervision to maintain safe and ethical practice. We aim to discuss cases anonymously or with minimal identifying information where possible, in line with NCPS principles and confidentiality requirements.

  • Service providers (processors) — for example, secure email hosting, practice management/online booking systems, video conferencing providers, cloud storage, accounting software, or IT support. These providers are required to protect your data and act only on our instructions.

  • Payment providers — if you pay by card or online transfer via a third-party platform, the provider will process payment information under its own privacy terms.

  • Healthcare professionals and agencies — such as your GP, NHS services, or safeguarding teams, where you ask us to share information or where sharing is necessary and lawful (for example, safeguarding).

  • Legal and regulatory bodies — where required to comply with law or to handle legal claims.

When we share data, we take steps to ensure an appropriate level of confidentiality and security, and we share the minimum necessary information.

Safeguarding and legal obligations

We take safeguarding seriously and follow relevant guidance and legal duties. Where we have concerns that a child or vulnerable adult may be at risk of significant harm, or where there is a serious risk to life or safety, we may share information with appropriate services (such as social care, safeguarding hubs, or the police), in line with UK law and professional standards.

We will consider proportionality, necessity, and the least intrusive approach. We will keep a record of safeguarding decisions and any disclosures made.

Email, website, online booking and remote therapy data

Email and messaging: Email and standard messaging are not always fully secure. If you contact us by email/text/online form, you acknowledge there is some risk in electronic communications. We will take reasonable precautions, but we cannot guarantee security of information sent over the internet. You can ask us about secure communication options.

Online booking/practice management systems: If we use an online booking or client portal system, it may process your contact details, appointment information, and messages. The provider acts as a service provider and should only use your data to deliver the service to us.

Remote therapy/video calls: If sessions are held remotely, relevant technical data may be processed by the video/telehealth provider (for example, device identifiers, call metadata). You are responsible for choosing a private location and secure network where possible. We encourage you to discuss any privacy concerns with us before remote sessions.

Website enquiries: If you submit a contact form, we will use the details you provide to respond and to manage your enquiry.

International transfers (if applicable)

We primarily store and process personal data in the UK. Some service providers (for example, email, cloud, booking, or video platforms) may store or process data outside the UK. Where international transfers occur, we will take steps to ensure appropriate safeguards are in place, such as UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), or other lawful transfer mechanisms, together with appropriate security measures.

If you would like more information about any international transfers linked to our service providers, please contact us.

Data retention

We keep personal data only for as long as necessary for the purposes set out in this policy, including to meet legal, regulatory, safeguarding, and professional obligations. Retention periods may vary depending on the type of record and the nature of the service provided. Our typical retention periods are:

  • Client therapy records (including session notes):

    • Adults: 7 years following discharge

    • Minors: Until client reaches the age of 25 (26 if 17 at time of discharge)

  • Contact/enquiry records (where you do not become a client): 12 months

  • Invoices and accounting records: 6 Years to comply with HMRC guidelines

  • Safeguarding records:

    • Adults: 8 years following discharge

    • Minors: Until client reaches the age of 25 (26 if 17 at time of discharge)

At the end of the relevant retention period, data will be securely deleted or destroyed, or anonymised where appropriate.

Data security

We take appropriate technical and organisational measures to protect personal data against accidental or unlawful loss, destruction, alteration, unauthorised disclosure, or access. Measures may include (as appropriate):

  • Secure devices and password protection (and multi-factor authentication where available).

  • Encrypted storage and/or secure cloud services where appropriate.

  • Access controls so only authorised people can access client information.

  • Secure disposal of paper records (for example, cross-cut shredding).

  • Regular review of security practices and service providers.

Despite precautions, no method of transmission or storage is completely secure. If a data breach occurs that is likely to result in a risk to your rights and freedoms, we will take appropriate steps, which may include notifying the ICO and/or affected individuals where required by law.

Clients’ data protection rights

Under UK GDPR, you have rights in relation to your personal data (subject to certain conditions and exemptions). These may include the right to:

  • Access — request a copy of your personal data (a “subject access request”).

  • Rectification — ask us to correct inaccurate or incomplete data.

  • Erasure — ask us to delete your personal data (this is not absolute and may be limited where we have legal/professional reasons to retain records).

  • Restriction — ask us to restrict processing in certain situations.

  • Data portability — receive certain data in a structured, commonly used format and have it transferred to another controller where technically feasible (applies in limited circumstances).

  • Object — object to processing based on legitimate interests or direct marketing (we do not generally use therapy data for marketing).

  • Rights relating to automated decision-making — we do not generally make decisions solely by automated means in psychotherapy services.

We may need to confirm your identity before responding to rights requests. We will respond within the time limits set by law.

How to withdraw consent or object

Where we rely on your consent to process personal data, you can withdraw your consent at any time by contacting us at sophie@devieuxpont.co.uk. Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.

Where we rely on legitimate interests, you may object to our processing. We will consider your objection and will stop processing unless we have compelling legitimate grounds to continue or we need to process data for legal claims or other lawful reasons.

Cookies and website analytics (if applicable)

If our website uses cookies or similar technologies, these may be used to enable site functionality, remember preferences, and (where enabled) help us understand how the site is used. Where required, we will ask for your consent for non-essential cookies/analytics. You can manage cookies through your browser settings and, where available, through our cookie preferences tool.

If we use third-party analytics services, they may collect information such as IP address, device type, pages visited, and time spent on pages. This data is typically aggregated and used to improve website performance and user experience.

Children and vulnerable adults

We may provide services to children/young people or vulnerable adults where appropriate and within professional competence. Where we work with minors, we will consider capacity to consent, parental responsibility, and safeguarding requirements, and we will explain confidentiality and its limits in an age-appropriate way.

If you are a parent/guardian making an enquiry, please note that a child/young person’s information may be confidential depending on their age, understanding, and the circumstances, and we must act in their best interests and in line with safeguarding duties and professional ethics.

Complaints and your right to contact the ICO

If you have concerns about how we handle your personal data, we encourage you to contact us first so we can try to resolve the issue promptly and fairly.

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK regulator for data protection. You can find guidance and contact details at https://ico.org.uk/.

Policy updates

We may update this Privacy Policy from time to time to reflect changes in law, guidance, or our services. The latest version will be available on our website at www.devieuxpont.co.uk and/or on request. Where appropriate, we will notify clients of significant changes.

Contact details

If you have questions about this Privacy Policy, want to exercise your data protection rights, or wish to raise a concern, please contact:

Sophie de Vieuxpont Psychotherapy

Email: sophie@devieuxpont.co.uk

Website: www.devieuxpont.co.uk