Data Protection & GDPR Policy
Your privacy matters. Your personal information — and your conversations with me — are treated with the utmost care, confidentiality, and legal protection.
Introduction
Best Mind Therapy is committed to protecting the privacy and security of your personal data. This policy explains how I collect, use, store, and protect your information in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Data Controller: Gary Smith, Best Mind Therapy
Email: gary@bestmindtherapy.co.uk
Telephone: 07359 071210
Registered practice: Swindon, Wiltshire, United Kingdom
What Information I Collect
📋 Information You Provide Directly
- Your name, contact details (email, phone number, address)
- Basic health and wellbeing information you share during sessions
- Appointment history, booking notes, and consent forms
- Payment details and transaction records
- Messages sent via contact forms, email, or booking systems
🌐 Information Collected Automatically
- Website usage data (pages visited, time on site — no personal identification)
- Email open/click tracking — where you have consented
- Technical data such as IP address and browser type — used only for site security and improvement
How I Use Your Information
I process your data only for lawful bases and for specific, clear purposes:
- Performance of contract: To provide therapy sessions, manage appointments, and communicate regarding our work together
- Consent: Where you have agreed — for example, to receive emails, newsletters, or follow-up support
- Legal obligation: Keeping financial records for HMRC and professional body requirements
- Legitimate interests: Improving the website, sending relevant service updates where you haven't opted out, and maintaining the security of the business
Confidentiality — Your Sessions Are Protected
As a member of the National Council for Hypnotherapy (NCH) and the Association for Solution Focused Hypnotherapy (AfSFH), I operate under strict professional codes of ethics and confidentiality:
- Everything shared in sessions is strictly confidential
- Session notes are kept secure, separate from any other systems, and never shared without your explicit written consent
- Notes are stored securely and retained only as required by professional standards and UK law
- Exceptions apply only where there is a serious risk of harm to you or others, or where I am legally compelled to disclose information — in which case I will always inform you where legally possible
Who Has Access to Your Data
Only me. I do not sell, rent, or trade your personal information with third parties for marketing purposes. Limited trusted service providers may process data on my behalf — all under strict data processing agreements:
- Calendly — appointment booking system (data processed in the UK/EEA)
- Formspree — secure form delivery
- Email and hosting providers — all GDPR-compliant
- Accountant — financial data only, covered by professional confidentiality obligations
How Long I Keep Your Data
- Session notes & clinical records: Retained for 7 years after our final session — in line with NCH and UK healthcare professional standards — then securely shredded or permanently deleted
- Financial records: Retained for 6 years as required by HMRC
- Marketing preferences: Retained until you unsubscribe or request removal
- Enquiry data: If we do not begin working together, enquiry details are retained for 12 months then deleted
Your Rights Under GDPR
You have the following rights regarding your personal data. To exercise any of these, simply contact me using the details above — there is no fee for legitimate requests:
- Right to access: Request a copy of all personal data I hold about you
- Right to rectification: Have incorrect or incomplete information corrected
- Right to erasure: Request deletion of your data — where no legal or professional retention requirement applies
- Right to restriction: Request processing be paused — for example, while accuracy is verified
- Right to data portability: Request machine-readable transfer of data you have provided
- Right to object: Object to processing based on legitimate interests or direct marketing
- Right to withdraw consent: Withdraw any consent previously given — this does not affect processing done before withdrawal
- Right to complain: If you are unhappy with how your data has been handled, you have the right to raise concerns with the Information Commissioner's Office (ICO)
Cookies & Website Tracking
This website uses only essential cookies required for the site to function. No personal profiling or third-party advertising cookies are used. You may disable cookies in your browser settings, though some site functionality may be limited.
Updates to This Policy
This policy may be updated occasionally to reflect legal changes or operational improvements. The version date below indicates when it was last revised. Significant changes will be communicated via this website or directly to clients where appropriate.
Last updated: 20 September 2026