Privacy Policy

Privacy Policy

1. Introduction
Your privacy is very important to me. I am committed to protecting your personal information and handling it in a safe, secure, and responsible way.
This Privacy Notice explains how I collect, use, store, and protect your personal data in line with:
    • UK General Data Protection Regulation (UK GDPR)
    • Data Protection Act 2018It applies from your initial enquiry through to after therapy has ended.

2. Data Controller
Name: Jude Sutton
Practice Name: Ripple Within Counselling and Therapy
Email: hello@ripplewithin.co.uk
Phone: 07831 058639
ICO registration number: ZC199670 

3. What Information I Collect
To provide a safe and effective counselling service, I may collect:

Personal Information
    • Name
    • Date of birth
    • Contact details (phone, email, address)

Sensitive (Special Category) Data
    • Emotional and mental health information
    • Personal history relevant to therapyAdditional Information
    • Emergency contact details • GP details (where appropriate)
    • Brief session notes
    • Appointment and payment records

4. How I Use Your Information
Your information is used only to:
    • Provide counselling safely and ethically
    • Maintain appropriate clinical records
    • Manage appointments and communication
    • Meet legal, professional, and insurance requirements

Your data is not used for marketing or shared for commercial purposes.

5. Lawful Basis for Processing Personal Data
    • Article 6(1)(b) Performance of a contract
    • Article 6(1)(f) Legitimate interests in providing safe and effective counselling
    • Article 6(1)(c) Compliance with legal obligations (for example tax and accounting records)Special Category Data • Article 9(2)(h) Provision of health or social care

6. Confidentiality
Your information is treated as confidential. Confidentiality will only be broken where necessary, including: • Risk of serious harm to you or others
    • Safeguarding concerns
    • Legal obligations (e.g. court order)Where possible, this will be discussed with you first.

Client work may be discussed in clinical supervision:
    • Information is anonymised
    • Your identity is protected

7. Use of Technology and AI
To support safe and effective practice, digital tools, including AI-assisted technologies, may be used for administrative or reflective purposes (for example, drafting documents or supporting clinical thinking).

No identifiable client information is entered into AI tools.  All information is anonymised, and confidentiality is maintained at all times. 

AI tools are not used to replace professional judgement. All clinical decisions remain the responsibility of the counsellor.

8. How I Store Your Data

I take appropriate steps to keep your data secure:
    • Password-protected digital systems
    • Locked storage for any paper records
    • Limited and necessary data recording only
    • Separation of identifying details and notes where possible

9. Data Retention
Your records are kept for 7 years after the end of therapy, in line with professional guidance.

Financial records may be retained for longer where required by HMRC or other legal obligations.

If you choose not to proceed after an initial enquiry, your data will be deleted within 30 days.

10. Business Continuity and Professional Executor
In the unlikely event of my serious illness, incapacity, or death, arrangements are in place to ensure the continuity of care where possible and the secure management of client records.  A trusted professional colleague, acting as my Professional Executor, may be given limited access to your name and contact details solely for the purpose of informing you of the situation and discussing any appropriate arrangements regarding your ongoing care or the secure management of your records.

The Professional Executor will only access the minimum information necessary to fulfil this role and will remain bound by the same duties of confidentiality and data protection that apply to me.   Any access to your information will be managed in accordance with UK GDPR, the Data Protection Act 2018, and my professional and ethical obligations.

11. Data Breaches
In the unlikely event of a data breach, appropriate action will be taken to:
    • Contain and assess the breach
    • Protect affected data
    • Notify the relevant authorities, including the Information Commissioner's Office (ICO), where required
    • Inform affected individuals if there is a risk to their rights or safety

All breaches are documented and reviewed to improve data protection practices.

12. Third Parties
I may use trusted third-party services.  These may include secure email providers, encrypted video consultation platforms, practice management software, accounting software, secure cloud storage providers and payment processing services. 

These providers:
    • Only process data on my instruction
    • Are required to maintain confidentiality and security

Your data is never sold or used for marketing.

13. Online Counselling

If we work online:
    • You are responsible for ensuring your privacy
    • Sessions must not be recorded
    • A secure platform will be used where possible

Please be aware that no online communication is completely secure.

14. Website Use and Cookies
Ripple Within Counselling and Therapy’s website uses cookies to help it function correctly and to provide a smooth browsing experience.

Essential cookies may be used to remember your preferences and enable core website functions.  Where the website uses optional cookies, such as website analytics, these will only be used with your consent where required by law.

Most web browsers allow you to manage or disable cookies through your browser settings.  Please note that disabling certain cookies may affect the functionality of parts of the website.

If you have any questions about the use of cookies on the website, please reach out using the details provided on the Contact page.

15. Your Rights

You have the right to request access to the personal information and records I hold about you in accordance with UK GDPR and the Data Protection Act 2018.  Subject access requests should normally be made in writing.  I will carry out reasonable and proportionate searches of relevant records and respond within the timescales required by law.

You have the right to:
    • Access your personal data
    • Request correction of inaccurate data
    • Request erasure (in certain circumstances)
    • Restrict or object to processing
    • Request transfer of your data

You may be asked to provide proof of identity before personal information is released.

16. Complaints
If you have concerns about how your personal information has been handled, please contact me in the first instance.  I will acknowledge your complaint within 30 days and respond without undue delay wherever possible.

You also have the right to complain to the Information Commissioner's Office (ICO):
Website: https://ico.org.uk
Phone: 0303 123 1113

17. Changes to This Privacy Notice
This Privacy Notice may be updated to reflect changes in practice or legal requirements.
The latest version will always be available on request.

Reviewed: Jul 2026

ENDS

Scroll to Top