top of page

PRIVACY NOTICE

Data Controller: Jonathan (Jonny) Lindsay

Effective Date: 5 August 2026

Review Date: By 5 August 2027

1. About this notice

I am Jonathan (Jonny) Lindsay, a sole-trader psychotherapist, counsellor and clinical supervisor. I am the data controller for personal information used in my private practice. This notice explains what I collect, why I use it, how long I keep it, who may receive it and your rights.

You can contact me using the professional contact details already supplied to you, or through the contact form at www.jonnylindsaycounselling.co.uk.

2. Information I may collect
  • identity and contact details, date of birth, GP details and an emergency contact;

  • enquiry, assessment, appointment, attendance, payment and correspondence information;

  • brief factual notes about counselling or supervision, agreed actions and significant risk or safeguarding decisions;

  • information you choose to share about health, relationships, identity, beliefs, sexuality or other sensitive matters;

  • information needed to make reasonable adjustments or work safely; and

  • limited technical information generated when you use my website, contact forms or online meeting services.

I normally obtain information directly from you. In limited circumstances I may receive relevant information from a referrer, GP, emergency contact, organisation, safeguarding professional or another person. I will tell you about this where appropriate and lawful.

3. Why I use information and my lawful bases

I use only the information reasonably needed to respond to enquiries, assess suitability, provide counselling or supervision, manage appointments and payments, keep appropriate records, meet professional and legal responsibilities, maintain service continuity and respond to concerns, complaints, safeguarding matters or legal claims.

The Article 6 UK GDPR bases I rely on depend on the purpose and may include:

  • contract, including steps you ask me to take before entering into a working agreement;

  • legitimate interests in running a safe, accountable private practice, maintaining proportionate records and establishing, exercising or defending legal claims;

  • legal obligation where the law requires particular processing or disclosure;

  • vital interests in a genuine life-threatening emergency; and

  • recognised legitimate interests or other lawful safeguarding grounds where these apply to protecting a person at risk.

Therapeutic information may include special-category data. Where required, I rely on an appropriate Article 9 condition, which may include explicit consent, provision or management of health or social care where applicable, protection of vital interests, substantial public interest safeguards, or the establishment, exercise or defence of legal claims. The condition used depends on the purpose and circumstances. Where I rely on explicit consent, I will obtain it clearly and you may withdraw it; withdrawal does not make earlier processing unlawful and does not require deletion where another lawful basis or legal exception applies.

I do not use personal information for solely automated decisions or profiling with legal or similarly significant effects.

4. Confidentiality and sharing

I do not sell personal information. I share only what is relevant and necessary. Information may be disclosed:

  • in professional supervision, normally without identifying you;

  • to service providers supporting my website, secure email and files, calendar, online meetings, practice administration, communications, accounting and banking;

  • to my confidential clinical executor if I become unable to contact clients or supervisees myself;

  • with your agreement to a GP, referrer or another professional;

  • where required by law, a court or a regulator; or

  • where necessary and proportionate in a serious-risk or safeguarding situation.

Where safe and practicable, I will discuss a proposed disclosure with you first. Any disclosure will be limited to what is necessary and recorded appropriately.

5. Digital services and international transfers

My practice currently uses Wix for the website and contact forms; Google Workspace services for professional email, calendar, file storage and Google Meet; Airtable for practice administration; telephone or messaging services for agreed communications; and banking or accounting services for payments and financial records. These organisations process information under their own security and privacy arrangements and, where acting for me, under data-processing terms.

Some providers may process or support data outside the UK. Where this occurs, I use providers that apply an approved transfer mechanism or another lawful safeguard. I review digital tools proportionately and do not put identifiable client or supervisee material into an AI tool without prior informed consent. AI is not used to make clinical, safeguarding, ethical or supervisory decisions.

6. Security

I use proportionate technical and organisational safeguards, including access controls, passwords and device security; restricted access to records; professional confidentiality; data minimisation; secure disposal; and separation of information where practical. No system can be guaranteed completely risk-free, but suspected personal-data breaches are assessed, contained, recorded and reported where the law requires.

7. How long I keep information

I keep information only for as long as it serves a clear purpose. The normal schedule is:

Enquiries not becoming a service user

Six months after the last substantive contact, unless needed longer for a complaint, risk concern or legal reason.

Counselling and supervision records

Six years after the final session, then securely deleted or destroyed. This is a practice decision informed by insurance, limitation and data-minimisation considerations; it is not presented as a universal statutory period.

Routine messages and scheduling

Deleted when no longer needed. Any content material to the professional record follows the six-year service-record period.

Financial and tax records

Kept for the period required by tax and accounting rules, normally six years after the relevant accounting period.

Website technical data

Kept according to the website provider’s settings and legal requirements; unnecessary contact-form content follows the enquiry period above.

Safeguarding, complaint or legal-claim material

Kept for the underlying service-record period or longer where a specific legal, regulatory, insurance or active-case reason requires it. The reason is documented and reviewed.

8. Your data-protection rights

Depending on the circumstances, you may have rights to be informed; obtain a copy of your information; correct inaccurate information; restrict or object to processing; request erasure; receive certain information in a portable format; and withdraw consent where consent is the basis used. These rights are not absolute, and confidentiality duties or legal exemptions may affect what can be disclosed or deleted.

Please contact me first if you wish to exercise a right or raise a concern. I may need to verify your identity. I normally respond within one month. You may also complain to the Information Commissioner’s Office at www.ico.org.uk or telephone 0303 123 1113.

9. Changes to this notice

I review this notice at least annually and sooner if my practice, technology, professional guidance or the law changes. Material changes will be brought to the attention of current service users before a new use begins where required.

10. Related documents
  • Counselling Agreement;

  • Safeguarding procedure and decision aids;

  • AI and Digital Tools Policy; and

  • Complaints information and other public practice policies.
     

Document status: Version 1.0 — adopted 5 August 2026. Owner: Jonathan Lindsay. Next scheduled review: by 5 August 2027.

bottom of page