Privacy Policy
This Privacy Notice explains how I, Katie Deacon, collect, use, store and protect your personal data in line with UK data protection law, including the UK General Data Protection Regulation (UK GDPR).
I am committed to protecting your privacy and handling your information in a transparent, respectful and secure way.
Who I Am?
Katie Deacon
Data Controller
ICO Registration Number: C1480964
If you have any questions about this policy or your data, you can contact me at: katie@katiedeacon.co.uk
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you are unhappy with how your data is handled.
What Information I Collect
When you contact me or use my services, I may collect:
- Name
- Email address
- Telephone number
- Information you choose to share about your enquiry
If you become a client, I may also collect:
- Date of birth
- Address
- GP details
- Relevant health information
- Session notes
You may also choose to share limited information about other individuals (for example, a partner or family member). This will only be recorded where it is relevant to your therapy.
Some of this information (such as health data) is classified as special category data under UK GDPR.
How I Use Your Information
I use your information to:
- Respond to your enquiry
- Provide therapy services
- Arrange and manage appointments
- Send session-related materials (e.g. recordings)
- Ensure safe and appropriate care
- Improve my services
I will only contact you for marketing or wellbeing information if you have given explicit consent.
Lawful Basis for Processing
Under UK GDPR, I rely on the following lawful bases:
- Contract – to provide therapy services
- Legitimate interests – to manage and improve my practice
- Explicit consent – for health information and marketing
- Legal obligation – for record keeping and insurance requirements
Confidentiality
All sessions are confidential.
However, confidentiality may be broken where:
- There is a risk of serious harm to you or others
- Disclosure is required by law
- Information is needed for the prevention or detection of crime
In some cases, anonymised information may be shared with a professional supervisor for support and best practice.
How Your Data Is Stored
Your data may be stored:
- In locked physical storage
- On password-protected devices
- Using secure digital systems
I take appropriate steps to protect your data, including security software and restricted access.
Data Sharing
I do not sell or share your data for marketing purposes.
Your information may be shared, where necessary, with:
- Your GP (with your knowledge, unless there is a serious risk to safety or legal requirement to do so)
- Professional supervisors (in anonymised form only)
- Legal, insurance, or regulatory bodies where required by law
- IT, email and communication providers, including WhatsApp, which may be used to send therapy-related audio recordings. While appropriate steps are taken to protect your data, clients should be aware that WhatsApp is a third-party platform and use it at their discretion.
International Transfers
Some digital services I use may store or process data outside the UK.
Where this occurs, I ensure appropriate safeguards are in place to protect your information.
How Long I Keep Your Data
I retain client records for 8 years in line with professional and insurance requirements.
After this time, your data will be securely destroyed.
Your Rights
Under UK GDPR, you have the right to:
- Be informed about how your data is used
- Access your personal data
- Request correction of inaccurate data
- Request erasure (where applicable)
- Restrict processing
- Object to processing
- Data portability
- Not be subject to automated decision-making
To exercise any of these rights, please contact me.
Data Breaches
In the unlikely event of a data breach, I will notify affected individuals and the ICO where required.
Cookies
My website may use cookies to improve your experience and analyse website traffic.
You will be asked to consent to non-essential cookies when you first visit the site. You can manage or disable cookies through your browser settings.
Links to Other Websites
My website may contain links to other websites. I am not responsible for their privacy practices, and you should review their policies separately
Updates to This Policy
This policy may be updated from time to time to reflect legal or operational changes.




