Privacy Policy

Last updated:

8 July 2026

Who we are

Rai Counselling is a private counselling practice run by Raimonda Stephens. I am registered with the Information Commissioner’s Office (ICO) under registration number ZB878029.

If you have any questions about how I handle your personal data, you can contact me at contact@raicounselling.co.uk

What personal data we collect

I collect and process the following types of personal data:

Contact information

Your name, address, telephone number, and email address Emergency contact details

  • Your reason for seeking therapy and presenting concerns
  • Information about your mental and emotional health
  • Relevant medical history you choose to share
  • Session notes and records of our therapeutic work together
  • Your therapy agreement and consent forms

Health and therapy data is classified as “special category data” under Article 9(1) of the UK GDPR. This means it receives enhanced legal protection because of its sensitive nature.

Website enquiries

  • Your name and email address when you submit our contact form
  • Details of your enquiry

How we collect your data

I collect personal data directly from you:

  • When you first contact me to enquire about therapy
  • During our initial consultation and intake process
  • Throughout our therapeutic work together during sessions
  • Via email, telephone, or video call communications
  • When you submit the contact form on my website
  • I do not collect personal data about you from third parties without your knowledge.

Why we process your data — lawful basis

Under UK GDPR, I need a lawful basis to process your personal data. For therapy services, I rely on two separate legal bases:

Article 6 basis (general personal data)

Article 6(1)(b) UK GDPR — processing is necessary for the performance of the therapeutic contract between us. When you engage me as your therapist, we enter into a contract for therapeutic services. I need to process your personal data to fulfil my obligations under that contract.

Article 9 basis (special category health data)

Article 9(2)(h) UK GDPR — processing is necessary for the provision of health or social care treatment by a health professional. Counselling and psychotherapy constitute health care, and I process your health-related information in order to provide that care.

The additional condition required under UK law is set out in DPA 2018 Schedule 1, Part 1, paragraph 2 (health or social care). This condition applies because processing is carried out by a qualified counsellor subject to the professional obligation of confidentiality under the BACP Ethical Framework for the Counselling Professions.

Professional obligations and CPD

I am required by BACP to attend regular clinical supervision as part of maintaining ethical and effective practice. I may discuss our therapeutic work with my supervisor. When I do so:

  • Your name and any identifying details are not shared with my supervisor
  • I use anonymised or pseudonymised case material only
  • My clinical supervisor is a qualified professional bound by the same confidentiality obligations as I am
  • My supervisor is bound by their own professional code of ethics and practice

Clinical supervision helps me reflect on my practice, ensures I am working safely and effectively, and ultimately benefits the quality of care I provide to you.

Clinical will — what happens to your records if I am unable to practise

I am currently putting arrangements in place to appoint a clinical executor — a trusted fellow therapist who would manage my client records if I were to become incapacitated or die unexpectedly.

Once these arrangements are complete, I will inform clients and update this policy. The purpose of a clinical executor is to ensure your records are handled appropriately and that you are contacted sensitively if I am no longer able to practise.

Who we share your data with

I take your confidentiality seriously and only share your data when necessary.

Clinical supervision

As explained above, I discuss anonymised case material with my clinical supervisor. No identifying information about you is shared.

Third-party services

I use the following third-party services which may process your data:

  • Google Meet — for online therapy sessions
  • Google Calendar — for appointment scheduling
  • Google Analytics — to understand how visitors use my website (with your consent)
  • Google Maps — embedded on my website to show my location
  • Psychology Today — displays a verification badge on my website

Each of these services is bound by a data processing agreement and publishes its own privacy policy with further detail.

I never sell your personal data.

International data transfers

The following third-party services I use may transfer personal data outside the United Kingdom:

  • Google Analytics (Google LLC, USA)
  • Google Maps (Google LLC, USA)
  • Google Meet (Google LLC, USA)
  • Google Calendar (Google LLC, USA)

Where data is transferred to the USA, I rely on Standard Contractual Clauses (SCCs) or International Data Transfer Agreements (IDTAs) as appropriate safeguards, in accordance with UK GDPR Chapter V and the updated requirements of the Data (Use and Access) Act 2025.

The USA does not currently have a UK adequacy decision. Details of these safeguards are set out in each provider’s own privacy documentation.

How long we keep your data

I retain your personal data only for as long as necessary. The retention periods are:

Type of record Retention period Reason
Therapy records (including session notes and therapy agreement) 7 years after our last session In line with the Limitation Act 1980 and standard professional indemnity insurance requirements
Financial records 6 years HMRC legal requirement
Website enquiries (non-clients) 12 months Legitimate interest in responding to enquiries

Your rights under UK GDPR

You have the following rights regarding your personal data:

Right to be informed You have the right to know how I collect and use your personal data. This privacy policy fulfils that right.

Right of access You can request a copy of the personal data I hold about you. This is known as a subject access request. Under the Data (Use and Access) Act 2025, I will conduct a reasonable and proportionate search to locate your data.

Right to rectification If any personal data I hold about you is inaccurate or incomplete, you can ask me to correct it.

Right to erasure You can ask me to delete your personal data. However, this right is not absolute — I may need to retain your records until the end of the applicable retention period where required by professional guidelines, insurance requirements, or law.

Right to restrict processing You can ask me to limit how I use your data in certain circumstances.

Right to data portability You can ask for your data in a commonly used, machine-readable format so you can transfer it to another service.

Right to object You can object to certain types of processing, including processing based on legitimate interests.

Rights related to automated decision-making You have the right not to be subject to decisions based solely on automated processing. I do not use automated decision-making in my practice.

To exercise any of these rights, please contact me at contact@raicounselling.co.uk

Data protection complaints — your right under the Data (Use and Access) Act 2025

You have the right to make a data protection complaint directly to me. If you are concerned about how I have handled your personal data, please let me know so I can try to resolve the matter.

You can submit a complaint at https://raicounselling.policydiary.co.uk (Make a complaint tab) or contact me at contact@raicounselling.co.uk

If you are not satisfied with my response, you have the right to escalate your complaint to the Information Commissioner’s Office (ICO):

Confidentiality exceptions

Everything you share with me in therapy is confidential. However, there are limited circumstances where I may need to share information without your consent:

  • Risk of serious harm — if I believe you or someone else is at immediate risk of serious harm
  • Safeguarding concerns — if I become aware of concerns about a child or vulnerable adult being at risk of abuse or neglect
  • Legal requirement — if I receive a court order requiring me to disclose information

In most circumstances, I will try to discuss any disclosure with you first, unless doing so would itself put someone at risk.

Changes to this policy

I review this privacy policy annually and whenever my practices change. If I make significant changes that affect how your data is processed, I will inform you directly.

For the latest version of this policy, please visit https://raicounselling.policydiary.co.uk

Cookie Policy

Last updated:

8 July 2026

What are cookies

Cookies are small text files that websites place on your device when you visit. They help websites remember your preferences and understand how visitors use the site. Some cookies are essential for the website to work properly, while others are used for analytics or advertising purposes.

Cookies we use

These cookies are strictly necessary for the website to function. They do not collect any information that could be used for marketing purposes.

Cookie name Purpose Duration
policydiary_consent Remembers your cookie consent choice so we do not ask you again on every visit 12 months

These cookies and embedded content are only loaded after you click “Accept” on our cookie banner. If you reject non-essential cookies, they are never set and the website continues to work normally.

Google Analytics

We use Google Analytics to understand how visitors use our website, such as which pages are most popular and how people navigate the site. This helps us improve your experience. Google Analytics sets cookies and sends anonymised data to Google LLC in the USA. This service is only activated if you give your consent.

When you first visit our website, a consent banner appears offering you the choice to “Accept” or “Reject non-essential” cookies.

  • If you accept: Non-essential cookies including Google Analytics are activated.
  • If you reject: Non-essential cookies remain switched off. You can still use the website without any loss of functionality.

Your choice is stored in the essential preference cookie (policydiary_consent) and remembered for 12 months, so you will not be asked again on every visit.

How to change your choice or manage cookies

If you change your mind about cookies, simply delete this website’s cookies in your browser settings. The next time you visit, the consent banner will appear again and you can make a different choice.

Managing cookies in your browser

Most web browsers allow you to control cookies through their settings. You can usually find these options in your browser’s “Privacy” or “Settings” menu. For detailed guidance on managing cookies in different browsers, visit aboutcookies.org.

Your rights

Your consent for non-essential cookies is freely given. You may refuse or withdraw consent at any time without affecting your ability to use this website. Rejecting non-essential cookies does not prevent you from accessing any part of our services.

Updates

I will update this policy if my use of cookies changes. Any significant changes will be reflected here.

Contact

If you have any questions about how this website uses cookies, please contact me:

Raimonda Stephens, Rai Counselling Email: contact@raicounselling.co.uk

You can also view my full privacy documentation at: https://raicounselling.policydiary.co.uk

Data Retention Policy

Last Updated

8 July 2026

This policy explains how long I keep your personal information, why I keep it, and what happens to it afterwards. I have written this in plain English so you can understand exactly how your data is handled.

Why We Retain Data

I retain personal data for several important reasons:

  • Legal obligations — UK law requires me to keep certain records, including financial records for HMRC purposes
  • Professional standards — As a BACP member, I follow the BACP Ethical Framework for the Counselling Professions, which requires me to maintain appropriate records of our therapeutic work
  • Insurance requirements — My professional indemnity insurance requires me to retain records in case a claim arises after therapy ends
  • Your protection and mine — Accurate records protect both of us if questions arise about our work together in the future
  • Continuity of care — If you return to therapy with me, your previous records help me provide better support

Retention Periods

Type of Record Retention Period Reason
Client therapy records (adults) 7 years after our last session In line with the Limitation Act 1980 and standard professional indemnity insurance requirements
Enquiry and contact data (non-clients) 12 months from last contact Allows reasonable time for you to decide whether to begin therapy
Financial records and invoices 6 years from the end of the financial year HMRC legal requirement
Insurance records 7 years To support any potential insurance claims
Website contact form submissions 12 months Unless the enquiry becomes a client relationship, in which case the client retention period applies

What We Retain

The records I keep may include:

  • Session notes — Brief notes about themes discussed in our sessions, written to support your therapy
  • Contact details — Your name, email address, phone number, and address where provided
  • Consent and agreement records — Your signed therapy agreement and any consent forms
  • Correspondence — Emails and messages between us relating to your therapy
  • Payment records — Invoices and records of payments made
  • Assessment information — Any initial assessment or intake forms you completed

I keep only what is necessary for your care and my professional and legal obligations.

How Data is Stored

I take the security of your information seriously:

  • Electronic records are held on password-protected devices with access restricted to me only
  • Paper records are kept in a locked filing cabinet in a secure room, with access restricted to me only
  • Supervisor access — I discuss my clinical work with a qualified clinical supervisor to ensure I provide you with the best possible care. When I do this, I share only anonymised case material — your name and identifying details are not disclosed

No one else has access to your identifiable records without your explicit consent, unless required by law.

Your Right to Erasure

Under UK GDPR, you have the right to request that your personal data be deleted. However, this right is not absolute. I may need to retain your records until the end of the applicable retention period where this is required by:

Professional guidelines under the BACP Ethical Framework Professional indemnity insurance requirements Legal obligations, including the Limitation Act 1980 If you ask me to delete your data and I am unable to do so immediately, I will explain clearly why retention is necessary and confirm when your records will be securely destroyed.

Secure Disposal

When the retention period ends:

  • Paper records are securely destroyed
  • Electronic records are permanently deleted from all devices and backup systems

I do not keep any client records beyond the stated retention periods unless there is a specific legal reason to do so.

Clinical Will Arrangements

I am currently putting arrangements in place for a clinical will — a plan that ensures your records are handled appropriately and confidentially if I become unable to continue practising due to serious illness or death. Once these arrangements are finalised, I will update this policy and inform clients accordingly.

Data Protection Complaints

If you have any concerns about how I handle your data, please contact me first so I can try to resolve the issue:

Email: contact@raicounselling.co.uk

You can also submit a concern via the compliance page at https://raicounselling.policydiary.co.uk

If you remain dissatisfied, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):

My ICO registration number is ZB878029.

Contact

Raimonda Stephens Rai Counselling

Email: contact@raicounselling.co.uk

Website: https://raicounselling.co.uk

GDPR Statement

Last updated:

8 July 2026

Our Commitment to Your Privacy

At Rai Counselling, I believe that protecting your privacy is fundamental to the trust that makes therapy work. When you share personal and sensitive information with me, you need to know it will be handled with care, respect, and professionalism. This statement explains clearly how I look after your information.

What Information I Collect

To provide you with effective therapy, I collect and keep:

  • Your name and contact details (address, phone number, email)
  • Information about why you’ve come to therapy and what you’d like to work on
  • Notes from our sessions together
  • Relevant medical or health history that may affect our work
  • Payment information and records
  • Emergency contact details

Why I Collect This Information

I have a legal basis for collecting and using your information under UK data protection law:

For providing therapy services: I process your personal information under Article 6(1)(b) UK GDPR — processing is necessary for the performance of the therapeutic contract between us.

For your health-related information specifically: Because therapy involves sensitive health data, I rely on Article 9(2)(h) UK GDPR — processing is necessary for the provision of health or social care treatment by a health professional. The additional DPA 2018 Schedule 1 condition is Part 1, paragraph 2 (health or social care).

Professional Supervision

As part of maintaining professional standards expected of counsellors and psychotherapists in private practice, I discuss my work in clinical supervision. This helps ensure you receive the best possible care.

Your identity is protected in supervision: I do not share your name or identifying details with my supervisor. My clinical supervisor receives anonymised case material only and is bound by their own professional confidentiality obligations.

Clinical Will Arrangements

I am currently putting clinical will arrangements in place to ensure your records would be handled appropriately in the unlikely event I became unable to continue practising. Once these arrangements are complete, I will let you know the details.

Who Else May See Your Information

Beyond myself, your information may be accessed by:

Beyond myself, your information may be accessed by:

  • Clinical supervisor — anonymised case material only, as described above
  • Service providers I use:
    • Google Meet (for online sessions)
    • Google Calendar (for appointment scheduling)
    • Google Analytics (website usage — anonymised, and only with your consent)
    • Google Maps (embedded on my website)
    • Psychology Today (professional listing verification)
  • Statutory authorities — only where I am legally required to share information

When I Might Need to Break Confidentiality

What you share in therapy is confidential, but there are rare circumstances where I may need to share information without your consent:

  • If I believe there is a serious risk of harm to you or someone else
  • If there are safeguarding concerns about a child or vulnerable adult
  • If I receive a court order requiring disclosure

Wherever possible, I will discuss this with you first and explain what I need to share and why.

How Long I Keep Your Records

I keep your therapy records for 7 years after our last session together. This retention period is in line with the Limitation Act 1980 and standard professional indemnity insurance requirements.

After this period, paper records are securely destroyed and electronic records are permanently deleted.

Your Rights

You have important rights over your personal information:

  • See your records — you can ask for a copy of the information I hold about you
  • Correct errors — if anything is inaccurate, let me know and I’ll put it right
  • Request deletion — you can ask me to delete your information, though please be aware this right is not absolute; I may need to retain records until the end of the 7-year retention period where required by professional guidelines, insurance, or law
  • Object to processing — in certain circumstances, you can object to how I use your information
  • Data portability — you can ask for your data in a format that can be transferred elsewhere

Making a Complaint

If you’re unhappy about how I’ve handled your information, please talk to me first. I take concerns seriously and will do my best to resolve any issues.

You can contact me at contact@raicounselling.co.uk or visit my compliance page at https://raicounselling.policydiary.co.uk

Under the Data (Use and Access) Act 2025, you also have the right to complain directly to the Information Commissioner’s Office (ICO):