Kevin May Therapy

Privacy Policy and Data Protection

Introduction

I aim to protect your privacy and handle your personal data with sensitivity, care and respect. I adhere to the ethical standards of the British Association for Counselling & Psychotherapy (BACP) and comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

As a counsellor, I have a legitimate interest in processing personal data to provide safe and effective counselling services. This Privacy Policy explains what personal information I collect, why I collect it, how long it is stored, and your rights in relation to your data.

I am registered with the Information Commissioner’s Office (ICO), application number C2014208. I am the Data Controller responsible for your personal data.

Information that I collect

When you contact me, I will collect personal information to respond to your enquiry and, where appropriate, provide counselling services. This information may include:

* Your name
* Email address
* Phone number
* The content of your message
* Your availability
* Other relevant personal information including health

If you share sensitive personal information (including health or emotional wellbeing information), it will be handled with strict confidentiality and in accordance with data protection law.

I may also use Google Analytics to collect anonymised information about how visitors use my website, such as:

* Pages visited
* Time spent on pages
* Device/browser type
* General location data

This information does not identify you personally and is used to improve the website.

How I use information

I collect and use personal data to:

* Respond to enquiries
* Communicate with you about counselling services
* Provide counselling services
* Maintain appropriate professional clinical notes and records*
* Improve my website and services

I will only use your data for the purpose for which it was collected.

Lawful basis for processing

Under UK GDPR, I rely on the following lawful bases:

* Consent – you are giving me consent to process your data when you contact me or provide information voluntarily
* Legitimate Interests – to respond to enquiries and manage my practice
* Legal Obligation – where I am required to retain records

Where I process sensitive personal data (such as health information), I do so under your explicit consent for the provision of counselling services.

Confidentiality and ethical practice

As a member of the BACP, I work in accordance with its Ethical Framework.

Confidentiality is a fundamental part of counselling. All information shared is kept confidential, with the following exceptions:

* Where there is a legal requirement to disclose information
* Where there is a risk of serious harm to you or others
* Where information is discussed in professional supervision (in anonymised form)

Confidentiality and its limits will be discussed in more detail if we begin working together, and will form part of our counselling agreement.

Data sharing

I do not sell or share your personal data for marketing purposes.

Your data will not be shared with any other person or organisation without your knowledge and consent, unless there is a legal, ethical, or safeguarding obligation to do so as outlined above.

Limited data may be processed by third-party service providers (such as website hosting, analytics providers, video conferencing platforms) who are required to handle your data securely and in accordance with data protection law.

Cookies

This website uses cookies to:

* Ensure proper functionality
* Collect anonymous usage data via Google Analytics

You can manage or disable cookies through your browser settings.

Data retention

Website enquiries – personal data from enquiries is kept only as long as necessary to respond and for short-term follow-up.

Client records

If you become a client, your records will be retained in line with professional, ethical, and insurance requirements.

Typically:

* Records are kept for seven years after counselling ends. After this time, all personal data and data regarding sessions will be securely destroyed.
* This may vary depending on legal, safeguarding, or insurance requirements.

Data security

I take appropriate steps to protect your personal data and to prevent loss, misuse or unauthorised access. These include:

* Secure storage of records (both electronic and paper)
* Password-protected devices
* Encrypted email communication where possible
* Encrypted video consultations
* Limited access to personal information

While I take reasonable steps to secure communications, I cannot guarantee that all electronic communications will be completely secure or free from viruses.

Your rights

Under UK GDPR, you have the right to:

* Access your personal data
* Request correction of inaccurate data (i.e. change of address, misspellings)
* Request erasure (where applicable)
* Restrict or object to processing
* Withdraw consent at any time

To exercise your rights, please email me at kevinmaytherapy@gmail.com.

If you have any concerns about my use of your data, I encourage you to contact me first so I can try to resolve the issue. You also have the right to complain directly to the Information Commissioner’s Office (ICO).

Changes to this policy

This policy may be updated periodically. The most current version will always appear on this page.

Effective Date: August 2026