top of page
Blue Gradient

GDPR

Privacy Notice – Client Information and Data Protection

Privacy Notice

Your privacy is very important to me. This notice explains how I collect, use, store and protect your personal information in accordance with the:

  • UK GDPR

  • Data Protection Act 2018
    For the purposes of data protection law, I am the Data Controller responsible for the

    personal information you provide.

    What information I collect

    In order to provide a safe and professional service, I may collect the following information:

  • Your name

  • Address

  • Telephone number

  • Email address

  • Date of birth

  • GP details

  • Emergency contact details (where appropriate)

  • Relevant medical history

  • Information about your wellbeing

  • Brief notes about your sessions

    Some of this information, such as health-related information, is considered special category personal data and is protected with additional safeguards.

    Why I collect your information

    I collect your information so that I can:

  • Provide appropriate therapy

  • Contact you regarding appointments

  • Maintain accurate clinical records

  • Ensure your safety and wellbeing

  • Meet professional and legal responsibilities

  • Manage my practice effectively

    I only collect information that is necessary for these purposes.

    Lawful basis for processing your data

    Under UK data protection law, I process your information under the following lawful bases:

    Contract

    Processing is necessary to provide the therapy service you have requested.

    Legitimate interests

    Processing is necessary for the safe and efficient running of my practice.

    Special category data

    Health-related information is processed because:

  • you have given explicit consent, and/or

  • processing is necessary for the provision of health care services.

    How your information is stored securely

    I take appropriate steps to keep your information safe, including:

  • Password-protected devices

  • Secure email access

  • Locked storage for paper records

  • Limited access to client records

  • Secure deletion or destruction when records are no longer required Your information is treated as strictly confidential.

Confidentiality

Everything discussed during your sessions is confidential.

To support safe and ethical practice, I may discuss aspects of my work with a professional supervisor. Any information shared in supervision is anonymised wherever possible, and my supervisor is also bound by professional confidentiality and data protection obligations.

When information may be shared

Your information will not be shared with anyone without your explicit consent unless: • there is a legal requirement to do so
• there is a serious risk of harm to you or another person
• safeguarding concerns arise involving a child or vulnerable adult

• disclosure is required by a court or lawful authority Where possible, I will always aim to discuss this with you first.

Contact with other professionals

With your explicit consent, I may contact other healthcare professionals involved in your care, such as your GP, if this is considered beneficial to your treatment.

How long your information is kept

Client records are retained in accordance with professional requirements and insurance obligations.

Records are usually kept for:

  • 8 years after your final session

  • For children, records are kept until age 25

  • If therapy ends when a child is 17, records may be kept until age 26

    After this period, records are securely destroyed.

Your rights

Under UK GDPR you have the right to:

  • Request access to your personal data

  • Request correction of inaccurate data

  • Request restriction of processing

  • Object to processing in some circumstances

  • Request erasure of your data where appropriate

  • Withdraw consent where consent is relied upon

    Please note that some records may need to be retained where there is a legal, insurance or professional obligation to do so.

    Your right to complain

    If you have any concerns about how your information is handled, you can contact me directly.

    You also have the right to make a complaint to the: Information Commissioner's Office

    Contact details

    Data Controller:

    Gary Smith
    Best Mind Therapy Contact gary@bestmindherapy.Co.Uk 07359071210

    Updates to this notice

    This privacy notice may be updated from time to time to reflect legal or professional changes. The most current version will always be available on request.

About

My name is Gary Smith

I am a qualified psychotherapist, hypnotherapist and senior lecturer with extensive experience working with anxiety, trauma and behavioural change.

My work integrates evidence-based approaches including CBT, NLP, neuroscience and solution-focused therapy, allowing me to support a wide range of client presentations. 

Alongside my clinical work, I am involved in training and developing therapists, bringing both practical and theoretical depth into supervision.

GMD_3522_edited.jpg

Northbourne Road

St Andrews Ridge

Swindon 

Wiltshire

SN25 4YE

Tel. 07359 071210

Email me HERE

Monday to Thursday

8.30am -  8pm

​​​

  • Facebook
  • Instagram

Thank you for making contact. I will get back to you as soon as I am available. Kind Regards Gary

© 2025 Gary Smith Psychotherapy Swindon and Cirencester

bottom of page