Effective Date: 16 June 2025
At Heal&Grow Therapy (“we,” “us,” “our”), your privacy and data protection rights are central to everything we do. This Privacy Policy explains how we collect, use, share, and safeguard your personal information when you use our therapy services, website, or communicate with us.
We are committed to full compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other relevant legislation. We also uphold the strictest standards of confidentiality, as required by professional ethical guidelines.
1. Who We Are
Heal&Grow Therapy is the data controller of your personal data. We determine the purpose and means of processing your personal data under this Privacy Policy. For any queries regarding this policy, please contact us.
2. Definitions
- Personal Data: Any information that identifies or relates to an identifiable individual.
- Special Category Data: Sensitive personal data, including mental health or therapy-related information.
- Processing: Any operation performed on personal data (e.g., collecting, storing, or sharing).
- Services: Our website, online therapy sessions, retreats, communications, and associated activities.
3. What Data We Collect
- Personal Identification Information – Full name, date of birth, email address, phone number, postal address.
- Health and Therapy Information (Special Category Data) – Mental health history, therapy notes, assessments, self-reported information, and treatment progress.
- Technical and Usage Data – IP address, browser type, device ID, referral source, pages visited, session duration, cookies.
- Payment Information – Card or account details provided during transactions. These are handled securely via third-party processors (e.g., Stripe or PayPal).
- Communications Data – Emails, chat logs, contact form submissions, and client feedback.
4. How We Use Your Data
- Deliver Therapy Services: booking, conducting, and documenting online therapy sessions.
- Retreat Management: scheduling, coordination, and logistics of retreat participation.
- Support & Administration: responding to queries, providing technical help, and record keeping.
- Service Improvement: monitoring usage data to improve our client experience and our service offerings.
- Legal Obligations: complying with safeguarding duties and professional record-keeping rules.
- Marketing (with Consent): sending updates about new services or offers only if you have opted in.
5. Lawful Basis for Processing
- Consent – For marketing or where legally required.
- Contract – To deliver our agreed therapy services.
- Legal Obligation – For professional or statutory compliance.
- Legitimate Interests – For operating and improving our services, balanced against your rights.
Special category data (e.g., therapy records) is processed only with your explicit consent or under legal/ethical obligations related to mental health practice.
6. Data Sharing and Disclosure
- Trusted Service Providers: for hosting, video conferencing (e.g., Zoom), payment processing, and IT support, all under strict confidentiality agreements.
- Legal Authorities: where legally required or to protect vital interests (e.g., serious risk of harm).
- Emergency Services: if urgent intervention is necessary for your safety or the safety of others.
- Business Changes: in case of a merger or restructure, data may transfer under equivalent protections.
7. International Data Transfers
Some of our service providers and retreat activities may involve transferring data outside the UK or EEA, including India and the United States. Where this occurs, we ensure your data is protected by Standard Contractual Clauses (SCCs) approved by the UK ICO, and verified providers who comply with strong data protection frameworks (e.g., Stripe, Zoom, Google).
8. Cookies and Tracking Technologies
Our website uses cookies and similar technologies to enhance user experience and collect anonymised analytics data. You may manage or disable cookies via your browser settings. For more information, please see our full Cookie Policy.
9. Data Security
We use technical and organisational safeguards to protect your data, including end-to-end encryption for therapy communications, secure data storage and backups, access controls and device-level security, and regular security audits and compliance reviews. Despite our efforts, no system can be guaranteed 100% secure. We accept the inherent risks of online communication.
10. Data Retention
- Therapy records: retained for 7 years from the last session, in accordance with professional guidelines (e.g., HCPC/BACP).
- Contact, communications, and session logs: retained for a maximum of 2 years, unless legal or clinical obligations require longer.
- Marketing consent records: until you withdraw consent.
You may request deletion of your data, unless we are legally required to retain it.
11. Your Data Protection Rights
You have the right to: access your data and request a copy; correct inaccurate or incomplete data; erase your data (“right to be forgotten”) in certain circumstances; restrict how your data is used in certain circumstances; object to data processing based on legitimate interests; data portability – receive your data in a structured, readable format; withdraw consent at any time for consent-based processing; and complain to the ICO if you feel your rights are being violated.
To exercise any of these rights, please contact us. We aim to respond within 30 days.
12. Children's Privacy
Our services are not intended for individuals under 18 years of age. We do not knowingly collect or store data from minors. If you believe a minor has submitted data to us, please contact us immediately for removal.
13. Additional Details on Comments, Embedded Content, and User Accounts
Comments and User-Generated Content
- When you leave comments on our site, we collect the data shown in the comment form as well as your IP address and browser user agent string to help detect spam.
- Your comment and its metadata are retained indefinitely to recognise and approve any follow-up comments automatically.
- If you have an account and log in to our website, your account information (including your username and profile data) is stored and may be visible publicly depending on your settings.
- You may edit or delete your personal information by accessing your account profile, except your username.
Embedded Content from Other Websites
- Articles on our website may contain embedded content (e.g., videos, images, articles) from third-party platforms.
- This embedded content behaves as if you visited the third-party website directly, meaning these third parties may collect data about you, use cookies, and track your interactions.
- We encourage you to review the privacy policies of those third-party sites to understand their practices.
Data Retention for User Content and Accounts
- Comments and related metadata are retained indefinitely unless you request removal.
- User account data is retained as long as the account is active or as needed to comply with legal obligations.
- You can request deletion or correction of your personal data related to user-generated content by contacting us.
14. Changes to This Policy
We may update this Privacy Policy occasionally to reflect changes in law or our operations. The updated version will always be posted on this page with a new “Effective Date.” Please review it regularly to stay informed.
15. Contact Us
For any questions, requests, or concerns about this Privacy Policy or your personal data, contact us at Heal&Grow Therapy.
End of Policy