Privacy Policy

1. Who We Are

Legacy Therapy provides counselling services.

Data Controller: Louise Cummings

Contact: Louise@legacytherapy.co.uk | 07921 177391

2. What Information We Collect

We collect and process the following types of personal data

a) When You Make an Enquiry

Name, email address, phone number

b) When You Become a Client

additionally home address, date of birth, next of kin details, Health information relevant to counselling ser

3. Why We Collect Your Information (Purpose of Processing)

We use your personal data to:

Respond to enquiries and provide information about our services.

Deliver counselling services to you.

Maintain accurate and confidential records as required by professional standards.

Contact your next of kin in case of an emergency (with your consent).

Comply with legal and regulatory obligations.

4. Lawful Basis for Processing

Under the UK GDPR, we rely on the following lawful bases:

Contract: To provide the counselling services you request.

Consent: For processing special category data (health-related information).

Legitimate Interests: For business administration and communication.

Legal Obligation: For compliance with professional and legal requirements.

5. Special Category Data

Health-related information is considered special category data under UK GDPR.

We will obtain your explicit consent to process this information and keep it confidential in accordance with professional and legal standards.

6 .How We Store and Protect Your Data

Electronic records are stored securely using encrypted systems / password-protected devices

Paper records (if any) are kept in locked storage.

Access is restricted to authorised personnel only.

We implement appropriate technical and organisational measures to ensure data security.

7. Data Retention

We keep your personal data for a certain number of years as instructed by Balen's Insurance at the end of counselling in line with professional guidelines and legal obligations. After this period, your data will be securely deleted or destroyed.

8. Sharing Your Data

We will not share your personal data with third parties for marketing purposes.

We may share information only:

hen legally required (e.g., safeguarding concerns, court orders).

With your consent (e.g., referrals to other health professionals).

9. Your Rights Under UK GDPR

You have the right to:

Access your personal data (subject access request).

Request correction of inaccurate or incomplete data.

Request erasure of your data (where legally possible).

Restrict or object to processing of your data.

Data portability (receive your data in a structured format).

Withdraw consent at any time (where consent is the lawful basis).

Lodge a complaint with the Information Commissioner’s Office (ICO) if you believe your rights have been violated: https://ico.org.uk

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

©Copyright. All rights reserved.

We need your consent to load the translations

We use a third-party service to translate the website content that may collect data about your activity. Please review the details in the privacy policy and accept the service to view the translations.