Privacy Policy
Therapist: Claire Franks
Professional Status: Qualified Therapeutic Counsellor (BACP Registered Member)
ICO Registration: ZC161924
Contact: claire@clairefrankscounselling.co.uk
Â
This Privacy Policy applies to visitors to my website as well as clients engaging in counselling with me.
Â
1. Purpose of This Privacy Policy
​
This Privacy Policy explains how I collect, use, store, and protect your personal information when you engage in counselling with me. I aim to be open and transparent so you can feel confident about how your information is handled.
​
I follow:
​
-
UK GDPR (2021)
-
Data Protection Act (2018)
-
BACP Ethical Framework for the Counselling Professions
​
Your privacy and trust matter deeply, and I take my responsibilities seriously.
Â
Â
Â
2. What Information I Collect and Why
​
I collect only the information that is necessary for safe, ethical, and effective counselling.
2.1 Personal Information
​
-
Name
-
Date of birth
-
Contact details
-
GP details
-
Emergency contact
-
Parent/carer details (for CYP)
-
Relevant medical or educational information (if shared)
Why: To contact you, keep you safe, and provide appropriate therapeutic support.
​
2.2 Therapeutic Information
​
-
Brief session notes
-
Assessment information
-
Goals for therapy
-
Risk or safeguarding information (if relevant)
Â
Why: To support the therapeutic process, track progress, and ensure safe practice.
I keep notes minimal, factual, and separate from your personal details.
2.3 Website or Email Enquiries
​
If you contact me through my website or email, I may collect:
-
your name
-
your email address
-
any information you choose to share
Â
Why: To respond to your enquiry and arrange an initial appointment.
​
​
​
3. Lawful Basis for Processing Your Data
​
Under UK GDPR, I rely on the following lawful bases:
​
3.1 Contract
​
To provide counselling services you have requested.
Â
3.2 Legitimate Interests
Â
To maintain records, manage appointments, and ensure safe practice.
Â
3.3 Legal Obligation
Â
For safeguarding, court orders, or legal reporting requirements.
Â
3.4 Vital Interests
Â
If there is a risk of serious harm to you or someone else.
Â
3.5 Consent
Â
For children and young people where parental consent or Gillick‑competent consent is required.
​
​
​
4. How Your Information Is Stored
Â
I store your information securely using:
-
encrypted digital storage
-
password‑protected devices
-
locked storage for paper documents
-
separate storage for personal details and session notes
Â
Only I have access to your information.
​
​
​
5. How Long Your Information Is Kept
Â
I keep your records for:
-
7 years after therapy ends (adults)
-
7 years after the young person turns 18 (CYP)
Â
These timeframes follow insurance and professional guidelines.
Â
After this period, your records are securely destroyed.
​
Â
Â
6. Confidentiality & When Information May Be Shared
Â
Everything you share with me is treated with care and respect. I will not share your information unless:
Â
6.1 You or someone else is at risk of serious harm
Â
I may need to contact your GP, emergency contact, or safeguarding services.
Â
6.2 A child or vulnerable adult is at risk
Â
I follow local safeguarding procedures.
Â
6.3 I am required by law
Â
For example:
-
court orders
-
terrorism
-
money laundering
Â
6.4 Supervision
Â
I discuss my work in clinical supervision to ensure safe and ethical practice. Your identity is protected. I will always aim to discuss any need to share information with you first, unless doing so would increase risk.
​
​
​
7. CYP‑Specific Privacy Information
Â
Children and young people have the same rights to privacy as adults.
Â
7.1 Confidentiality
Â
I do not routinely share session content with parents/carers.
Â
7.2 When I may share information
-
safeguarding concerns
-
risk of harm
-
legal requirements
​
7.3 Data Rights
Â
Young people aged 13+ have their own data rights under UK GDPR. A full Parental Involvement & Communication Policy is available.
​
​
​
8. Your Rights Under UK GDPR
Â
You have the right to:
-
access your information
-
request corrections
-
request deletion (in some circumstances)
-
restrict processing
-
object to processing
-
request transfer of your data
-
withdraw consent (where consent is the lawful basis)
Â
To exercise these rights, please contact me directly.
​
​
​
9. Online Sessions (Adults Only)
Â
For online therapy, I use a secure, encrypted platform. You are responsible for ensuring privacy at your end. I do not record sessions.
Â
A full Online Therapy Policy is available.
​
​
​
10. Third‑Party Services
Â
I may use third‑party services for:
-
email
-
invoicing
-
secure storage
-
website hosting
Â
These providers comply with UK GDPR and do not have access to your therapeutic content.
I do not sell or share your information for marketing.
​
​
​
11. If There Is a Data Breach
​
If a data breach occurs that risks your rights or freedoms, I will:
-
notify you as soon as possible
-
inform the ICO within 72 hours (if required)
-
take steps to minimise harm
​
​
​
12. Complaints
Â
If you have concerns about how your data is handled, please speak to me first.
Â
If unresolved, you can contact:
Â
Information Commissioner’s Office (ICO)
www.ico.org.uk
Â
​
​
13. Updates to This Policy
Â
I may update this Privacy Policy to reflect changes in law or practice.
The most current version will always be available on request
​
​
​
14. Agreement
Â
By engaging in counselling, you acknowledge that you have read and understood this Privacy Policy.
Â
Last Updated on 24 April 2026
​​