
Your privacy is of great importance to Within + Beyond. We are committed to complying with the terms of the General Data Protection Regulation (GDPR) regarding the responsible and secure use of your data.
We have a legitimate interest in processing personal data in order to provide psychological services. The purpose of this statement is to let you know what personal information we collect and hold, why this data is collected, how long it is kept, and what your rights are with regards to this personal data.
When you are referred or refer yourself for psychological services with us, you will be asked to consent to the processing of your data under the terms of this policy. We will be responsible for data management, we will abide by this privacy statement, and we will hold our own privacy statement that complies with the GDPR terms.
We collect personal data including:
Name
Address
Date of birth
GP/medical practitioner details
Telephone numbers and email addresses
We also collect any data that you give regarding personal and family background, brief session notes, alongside potentially sensitive data relating to medical and mental health conditions.
We will use your information in the following ways:
To provide clients with psychological services requested.
To notify you about changes to your appointments.
To fulfil any administrative, legal, ethical, and contractual obligations.
We will not share any information about you with other organisations or people, except in the following situations:
Consent: We may share information with relevant medical professionals or others whom you have requested or agreed we need to contact.
Serious harm: We may share your information with the relevant authorities if we have reason to believe that this may prevent serious harm being caused to you or another person.
Compliance with law: We may share information when the law requires us to (i.e., safeguarding, terrorism, drug trafficking, and serious crime).
Supervision: It is an ethical requirement for any clinician offering psychological services to have regular supervision. Any supervisor used is an accredited member of the relevant accrediting body and works within their ethical framework. No information is divulged to identify the client.
All information you provide to us is stored as securely as possible. We will take all reasonable precautions to prevent the loss, misuse, or alteration of information given.
All paper forms and correspondence are kept in locked filing cabinets.
Formal reports are password protected.
Whilst we endeavour to keep our systems and communications protected against viruses and other harmful effects, we cannot bear responsibility for all communications being virus-free.
Retention Policy: Client notes and other documentation are destroyed seven years after the end of the psychological services offered.
Access Requests: Any requests for personal data need to be made through a data subject access request and will be supplied within one month.
Website: The website, withinbeyondpsychology.com, is maintained by Rhino Hosting; your details are not stored on their systems for any contact requests made through them.
Under the GDPR, you have the right to:
Access your personal data.
Rectify, erase, or restrict your data.
Object to the processing of your data.
Request transfer of data (data portability).
Withdrawing Consent: You may withdraw your consent for us to hold and process your data at any time. However, if you do this while actively receiving psychological services, the services would have to end. You can withdraw your consent by stating this via email to:
cristy@withinbeyondpsychology.com or
lynne@withinbeyondpsychology.com
This policy is a work in progress and may be modified over time.
Would you like me to create a shortened "Client Consent Form" based on this policy that clients can sign?
© Within + Beyond | Design By: SDDS Web