Privacy Policy
Business Name: Loch and Lumen Therapy
Effective Date: 26 November 2025
Contact: kirsty@lochandlumentherapy.com
Purpose of This Policy
​
This Privacy Policy explains how I collect, use, store, and protect your personal information in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
​
What Information I Collect
I may collect the following types of data:
-
Identity Information: Name, date of birth
-
Contact Details: Address, phone number, email
-
Health Information: Therapy notes, treatment plans, GP details (special category data)
-
Payment Information: Bank details or invoicing data
-
Technical Data: IP address if using online forms or video platforms
​
How I Collect Your Data
-
Directly from you via phone, email, or in-person sessions
-
Through secure online booking or video platforms (if applicable)
​
Why I Collect Your Data
-
To provide CBT therapy services
-
To maintain accurate clinical records
-
To comply with legal and professional obligations
-
For invoicing and payment processing
​
Lawful Basis for Processing
-
Contract: To deliver therapy services you requested
-
Legal Obligation: For tax and record-keeping
-
Legitimate Interests: To manage my business effectively
-
Special Category Data: Processed under Article 9(2)(h) for health care purposes
​
How I Store and Protect Your Data
-
Electronic records stored on encrypted devices
-
Paper notes kept in locked cabinets
-
Access restricted to me only
-
Secure deletion after retention period
​
Data Retention
-
Clinical records: 7 years after last session (or as required by professional guidelines)
-
Financial records: 6 years for tax purposes
-
​
Sharing Your Data
I do not share your data with third parties unless:
-
Required by law
-
You provide explicit consent (e.g., referral to GP or another health professional)
-
Using secure third-party platforms (e.g., video conferencing, payment processors)
​
Your Rights
You have the right to:
-
Access your data
-
Request correction or deletion
-
Restrict processing
-
Object to processing
-
Data portability
-
Complain to the ICO if you believe your data is misused
​
Contact
For any questions or to exercise your rights, contact:
Email: kirsty@lochandlumentherapy.com
​​
Client-Friendly Summary
At Loch and Lumen Therapy, your confidentiality and trust are our top priorities.
We only collect the information needed to provide CBT therapy safely and effectively, such as your contact details and therapy notes.
Your data is:
-
Stored securely on encrypted systems or in locked files.
-
Never shared without your consent, unless required by law.
-
Kept only as long as necessary (usually 7 years for clinical records).
You have full control over your information, including the right to access, correct, or request deletion.
For any questions, email us at kirsty@lochandlumentherapy.com.
Read our full Privacy Policy for details.
​