We are covered by all major insurers, including Bupa, Axa, Cigna, WPA, Aviva and others

Privacy policy

Effective date: 14 July 2026 | Version: 2.0

In brief

  • Your information is held securely and confidentially, and seen only by the people involved in your care.
  • Your own therapist is responsible for your clinical records; the clinic handles the admin around them.
  • We never sell your data, and we never advertise to you.
  • You can ask to see, correct or delete your information at any time, and we respond within a month.
  • AI never makes decisions about you. Our AI ethical use policy explains exactly how AI is and is not used.
  • Any questions or worries, email info@thetunbridgewellspsychologist.co.uk. You can also go to the ICO at any time.

Contents

1Introduction

This policy explains how we, Thriving Minds Collective Ltd (trading as The Tunbridge Wells Psychologist, Company No. 16358249), collect, use and protect your personal information in the course of providing psychological therapy services. We have written it to be clear and readable rather than legalistic, because you should be able to understand exactly what happens to your information without a law degree.

2Who is the data controller?

Thriving Minds Collective Ltd is the data controller for information collected and processed in connection with clinic administration, including handling enquiries, sending initial communications, and managing bookings through our practice systems. Dr Rachel Whatmough, Director, is responsible for overseeing data protection compliance on behalf of the clinic. Thriving Minds Collective Ltd is registered with the Information Commissioner's Office, registration ZB902327.

When you engage with an associate clinical psychologist for clinical services, your psychologist becomes the data controller for the personal data they collect and process in the course of therapy. Each therapist is individually responsible for their clinical records, maintains their own privacy policy, and is separately registered with the ICO. Thriving Minds Collective Ltd does not act as the central data controller for clinical records: all clinical information and records are the sole responsibility of the individual therapist you work with.

Shared access to client records

All therapists securely store client information in Halaxy, a GDPR-compliant practice management system used for session notes, appointment scheduling and record-keeping. Individual therapists cannot access each other's client records. As practice owner and Clinical Director, Dr Rachel Whatmough has full administrative access to the practice systems, which she uses only for operational purposes, such as managing enquiries, appointments and invoicing, and for keeping the service safe and running properly.

Digital tools and AI

Some therapists may, with your explicit consent, use supplementary digital tools such as Heidi, an AI-assisted medical scribe that helps clinicians write up sessions accurately. No audio is ever stored: speech is processed in real time and discarded immediately after transcription, and your therapist reviews and approves every note before it is saved to your record. Heidi is used in NHS services to reduce admin time and improve clinician focus, and your therapist will always ask for your consent before using it.

Our full AI ethical use policy explains everything about how AI is and is not used in this practice, in plain English. The short version: AI helps with paperwork, never with decisions about your care, and nothing AI-related happens in your sessions without your consent.

3Information we collect

A. Personal data

  • Name, address, phone number, email address
  • Date of birth
  • GP contact details (if provided)

B. Sensitive personal data (special category data)

  • Health information relevant to therapy
  • Therapy session notes and assessments
  • Referral details and treatment history

Questionnaires and structured information

As part of assessment and therapy we may ask clients (or parents, if the client is a child) to complete questionnaires that help us understand their experiences, difficulties and background. These may include mood and wellbeing questionnaires for adults, age-appropriate questionnaires for children and young people, parent questionnaires about a child's emotional, behavioural and developmental history, background information such as family relationships and early development, and details about the mental and physical health of family members where relevant. We collect this only with explicit consent and store it securely within Halaxy or another GDPR-compliant system used by your therapist.

What we need, and what is optional

Some information is essential for us to work with you safely, such as your contact details, and health information relevant to your therapy. If you prefer not to share something essential we will talk it through with you, though it may limit what we can safely offer. Anything beyond that is optional, and choosing not to share it never affects the care you receive.

C. Website, analytics and payment data

Website enquiry forms: if you complete a web enquiry or triage form, we collect your name, contact details and the information you choose to give us, so the right clinician can be found for you. Your answers go directly to our clinical team.

Payments: payment for therapy is typically made by online bank transfer directly to your therapist or to Thriving Minds Collective Ltd. Some therapists or services may also offer card payment through a secure third-party payment processor (Stripe). With your consent, a card can also be saved on file when you register, in case of missed payments or late cancellations under our cancellation policy. Saved cards are held securely by Stripe, never by us: we cannot see your full card details, and every transaction is processed under Stripe's data security standards.

Website analytics: we use Google Analytics and Microsoft Clarity to understand how visitors use our website. Both are anonymised, do not identify you, and only run if you accept analytics cookies. See our cookie policy for the detail.

Independent Clinical Psychologists and data responsibilities

All Clinical Psychologists delivering services through The Tunbridge Wells Psychologist operate as independent sole traders. They are individually responsible for ensuring the security and confidentiality of client information they manage, in compliance with GDPR.

4Lawful basis for processing your data

Under UK GDPR we must have a lawful basis for processing personal data. The bases relevant to our work are:

  • Consent: when you give consent for us to process your data, for example for referrals you request or optional tools.
  • Contractual necessity: processing needed to provide your therapy and manage your appointments.
  • Legal obligation: when required by law, for example safeguarding duties or financial record-keeping.
  • Legitimate interests: the day-to-day running of the practice and maintaining high-quality services.

Health information is special category data, and we process it under Article 9(2)(h) of UK GDPR (provision of healthcare, under a duty of confidentiality) and, where relevant, your explicit consent.

5How we use your information

We use your data to:

  • Provide therapy and maintain appropriate clinical records.
  • Manage appointments and communicate with you.
  • Where relevant, process payments securely.
  • Comply with legal and ethical obligations, such as safeguarding.

We never sell your data. We never advertise to you. The only marketing-type contact we will ever make, such as inviting you to leave a review after therapy ends, happens with your agreement.

6Data sharing and confidentiality

Information about you is stored securely and treated as confidential. It will not be shared with others except in specific circumstances:

With your consent: if you ask us to share information with another professional, for example letters to GPs or psychiatrists, or reports for insurers.

Legal or safeguarding obligations: if there is a risk of harm to you or others, or when we are legally required to disclose information. Wherever possible we would discuss this with you first.

When working as part of a multidisciplinary team, for example if you are referred through a service.

Schools and referrals: we work with schools and other educational settings to provide psychological support. If a school refers a child for therapy, we obtain parental consent where required. Any information shared between therapists and schools is discussed with the child and/or their parents beforehand, except in safeguarding situations. Schools do not have access to therapy session notes unless explicitly agreed.

Obtaining information from other agencies: with your explicit consent, we may obtain information from others involved in your or your child's care, such as GPs, previous mental health workers or teachers, where useful for your treatment.

Client referrals to associates: if you consent to being referred to one of our associates, we share your contact details and the relevant information from your enquiry and triage, plus details of any appointments booked, unless you ask otherwise.

Administrator access: to support the running of the clinic, an administrator has access to emails and our practice systems. They work under a confidentiality agreement and only access what is necessary for tasks such as managing appointments, invoices and enquiries.

7The systems we use

Everything that holds your information is chosen for security and bound by data processing agreements and appropriate safeguards:

  • Halaxy (practice management): appointments, clinical records and invoicing. Encrypted, EU-hosted, acting as a data processor.
  • Our practice dashboard (practice-owned software): we operate our own secure dashboard for appointment management, enquiries and practice administration. It is practice-owned software running on practice equipment in the UK, not a third-party service, so your information never leaves our control. Clinical notes and personal details held in it are encrypted, access is role-based (clinicians see only their own clients), and clinical records are also maintained in Halaxy.
  • Stripe (payments): card payments and secure card-on-file where offered. Saved cards are held by Stripe, never by us, and are only charged in line with our booking and cancellation policy.
  • Google Workspace (email and documents): our email and documents are protected by Google's security and encryption under Google's own terms. As with any email provider anywhere, email as a medium is never completely secure end to end, so we suggest keeping deeply personal detail for your sessions rather than email.
  • Cloudflare (website and enquiry forms): processes your enquiry when you submit our online forms.
  • WhatsApp Business: if you contact us on WhatsApp, your messages are handled under WhatsApp's own terms; we bring the content into our practice systems so we can respond properly.
  • Zoom / Microsoft Teams (online sessions): encrypted, GDPR-compliant, and sessions are never recorded. You can review the Zoom privacy statement and the Microsoft privacy statement.
  • AI-assisted administration: AI tools help our team run the practice behind the scenes, covered in full in our AI ethical use policy. Client data is never used to train AI models.
  • Encrypted backups: practice data is backed up regularly to secure storage to protect against loss.

8International transfers

We keep data in the UK or EEA wherever possible. Where a provider processes data outside the UK (Google, Stripe, Cloudflare, Anthropic), transfers rely on UK GDPR-approved mechanisms: the UK-US Data Privacy Framework or Standard Contractual Clauses with the UK addendum.

9Data security

  • Encrypted storage of clinical records, in Halaxy and in our own practice systems.
  • Role-based access: your therapist controls access to your clinical data, and clinic staff see only what their role requires.
  • Secure, private settings for all online therapy, with no session recording.
  • Secure disposal of information at the end of its retention period.

10How long we keep your information

  • Adults: therapy records are kept for 7 years after the last session.
  • Children and young people: until age 25, or 7 years after therapy ends, whichever is longer.
  • Financial records: 6 years, as required by HMRC.
  • Website analytics: anonymised and retained per Google's and Microsoft's standard periods.

After the retention period, records are securely deleted.

11Your rights

Under UK GDPR you have the right to:

  • Access: request a copy of the information we hold about you (a subject access request).
  • Rectification: ask us to correct anything inaccurate.
  • Erasure: ask us to delete information, subject to the legal and professional duty to retain clinical records for the periods above.
  • Restriction and objection: restrict or object to certain processing.
  • Portability: receive your data in a portable format.
  • Withdraw consent: at any time, without affecting your care.

To exercise any of these rights, email info@thetunbridgewellspsychologist.co.uk. We will respond within one month. If your request is complex we may extend this by up to two months, and we will tell you if so. There is no charge.

12Automated decision-making

We do not make any decision with legal or similarly significant effect about you by automated means. Administrative automation, such as appointment reminder emails, never affects your access to care or any clinical decision.

13If something goes wrong

If a personal data breach occurs we investigate immediately, record it, and report to the Information Commissioner's Office within 72 hours where the legal threshold is met. If a breach is likely to put you at high risk we will tell you directly and promptly: what happened, what information was involved, and what we are doing about it. If you ever suspect a problem with your data, contact us and we will investigate.

14Cookies

Our website uses a small number of cookies: essential cookies for functionality and security, analytics cookies (Google Analytics and Microsoft Clarity, only if you accept them via the banner), and Cloudflare Turnstile to protect our forms from spam. We do not use advertising or marketing cookies. You can change your choice at any time, and the full detail, including how long each cookie lasts, is in our cookie policy.

15Third-party websites

Our website may link to third-party websites and services. We are not responsible for their content or practices, and their handling of your data is governed by their own privacy policies, which we recommend reviewing.

16Children and young people

Our website is not specifically aimed at under-16s and we do not knowingly collect personal data from children through the website without parental consent. We do provide therapy to children and young people, with appropriate consent from a parent or legal guardian where required. If we become aware that a child under 16 has provided personal data through our website without parental consent, we will delete it promptly.

17Contact and complaints

Questions or concerns about this policy, or about how your information has been handled:

We take every concern seriously, will acknowledge you promptly, and will investigate and respond without undue delay. You also have the right to complain to the Information Commissioner's Office at any time, whether or not you have raised it with us first: ico.org.uk, 0303 123 1113.

18Changes to this policy

We update this policy when our systems or the law change. The version number and effective date at the top always tell you what is current, and we will communicate significant changes clearly. This version (2.0) was published on 14 July 2026 and replaces the version dated 28 June 2025.

Effective date: 14 July 2026  |  Version: 2.0

Call us Book free consultation