Last updated: 26th June 2025
Jeanette Whyman is a registered counsellor providing therapeutic services. Our contact address is 31 Park Road, Coventry, CV1 2LE. I am registered with the Information Commissioner’s Office (ICO).
Data Controller Contact Details:
- Email: hello@jeanettewhyman.co.uk
- Phone: 07832184989
Personal data I collect
I collect and process the following types of personal data:
Contact and appointment information:
- Name, address, phone number, email address
- Appointment dates, times, and attendance records
- Payment information and billing records
Therapeutic information:
- Session notes and clinical records
- Mental health history and current concerns
- Treatment plans and progress notes
- Information about family, relationships, and personal circumstances
- Any other information you choose to share during sessions
Website data:
- IP address and browser information
- Cookies and similar tracking technologies
- Contact form submissions and email communications
Legal basis for processing
We process your personal data under the following legal bases:
- Consent: For therapeutic services, we rely on your explicit consent
- Legitimate interests: For administrative purposes such as appointment scheduling and billing
- Legal obligation: To comply with professional regulatory requirements
- Vital interests: In exceptional circumstances where there are serious safeguarding concerns
How I use your personal data
I process your personal data for the following purposes:
- Providing counselling and therapeutic services
- Maintaining clinical records and treatment notes
- Scheduling appointments and managing our service
- Processing payments and maintaining financial records
- Communicating with you about your treatment
- Complying with professional and legal obligations
- Safeguarding purposes where there are concerns about harm to yourself or others
Special category data
As a counsellor, I process special category data relating to your mental health. This processing is necessary for:
- Healthcare provision under Article 9(2)(h) of GDPR
- Substantial public interest under Article 9(2)(g) where safeguarding concerns arise
Data sharing and disclosure
I maintain strict confidentiality but may share your information in limited circumstances:
With your consent:
- With other healthcare professionals involved in your care
- With your GP (if you have provided consent)
- For referrals to other services
Legal requirements:
- Where required by court order or legal proceedings
- To comply with statutory reporting requirements
- Where there are serious safeguarding concerns (duty of care)
Professional obligations:
- With clinical supervisors (anonymised where possible)
- For professional indemnity insurance purposes
- To regulatory bodies, if required
Data retention
I retain your personal data for the following periods:
- Adult clients: Clinical records held for 7 years after last contact
- Financial records: Held for 7 years in accordance with accounting requirements
- Website data: Cookies and similar data are held for a maximum 12 months
After these periods, all personal data is securely destroyed.
Data security
We implement appropriate technical and organisational measures to protect your personal data:
- All digital records are password-protected and encrypted
- Physical files are stored in locked cabinets
- Access to personal data is restricted to authorised personnel only
- Regular security reviews and updates are conducted
- Secure disposal of all records when retention periods expire
Your Rights Under GDPR
You have the following rights regarding your personal data:
Right of access: You can request a copy of the personal data we hold about you.
- Right to rectification: You have the right to request that we correct any inaccurate or incomplete data.
- Right to erasure: In certain circumstances, you can request deletion of your personal data.
- Right to restrict processing: You can ask us to limit how we use your personal data.
- Right to data portability: You can request your data in a portable format.
- Right to object: You can object to processing based on legitimate interests.
- Right to withdraw consent: You can withdraw consent at any time, though this may affect our ability to provide services.
Important Note: Some rights may be limited due to our professional obligations to maintain clinical records and comply with regulatory requirements.
Cookies and website data
My website uses cookies to:
- Ensure the website functions properly
- Remember your preferences
- Analyse website usage (if analytics tools are used)
You can control cookies through your browser settings.
Third-party services
I may use third-party services for:
- Website hosting and maintenance
- Appointment scheduling systems
- Payment processing
- Email communications
All third-party processors are carefully selected and must meet GDPR requirements through appropriate contracts and safeguards.
International transfers
I do not routinely transfer personal data outside the UK/EEA. If any transfers are necessary, we will ensure appropriate safeguards are in place and inform you of such transfers.
Complaints
If you have concerns about how I handle your personal data, you can:
- Contact me directly using the details at the top of this policy
- Contact the ICO:
- Website: ico.org.uk
- Phone: 0303 123 1113
- Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Professional standards
This privacy policy operates alongside our professional obligations under:
- BACP (British Association for Counselling and Psychotherapy) Ethical Framework
- Professional indemnity insurance requirements
This policy demonstrates our commitment to protecting your privacy while fulfilling our professional obligations as your counsellor.
