Privacy policy

Last updated: 29 August 2026

Therapy asks you to share things you may never have said aloud. It would be strange to ask that of you and then be vague about what happens to your information. So this page sets out plainly what I collect, why, who else sees it, and how long I keep it.

If anything here is unclear, or you would rather ask me directly, write to info@alexgoldingtherapy.com and I will answer properly.

The short version

  • I collect only what I need to arrange and provide therapy, and to run a lawful business.
  • I never see your card details. Payments go through Stripe or Wise, who handle them directly.
  • What you say in sessions is confidential, held under the BACP Ethical Framework, with the limited exceptions set out below.
  • I keep clinical records for seven years after our last session, then destroy them securely.
  • I do not sell your data, and I do not use it for advertising.

Who is responsible for your information

I am Alex Golding, a psychosynthesis counsellor and psychotherapist practising as Alex Golding Therapy, a sole trader based in London. I am a registered member of the British Association for Counselling and Psychotherapy (BACP) and work within its Ethical Framework.

I am the data controller for the information described on this page.

Contact: info@alexgoldingtherapy.com

What I collect

When you enquire or book

Through the booking form or by email, phone or text: your name, email address, phone number, the service and location you have chosen, the date and time, and anything you choose to tell me in a message field. Booking information is stored within this website, which is hosted by Namecheap.

When you pay

The amount, date and reference of your payment, and a record for my accounts. Card payments are processed by Stripe and bank transfers by Wise. I never receive or store your card number or bank login details - those go directly to the payment provider, who is responsible for them.

When we work together

Brief clinical notes: dates of sessions, themes, the direction of the work, and anything relevant to your safety or care. These are kept to what is necessary - they are working notes, not a transcript.

Before ongoing work begins I will ask you to read and sign a counselling agreement. That form records your name, address, telephone number, email address, date of birth, your GP’s details and an emergency contact. The GP and emergency contact details are held solely in case I have serious concern for your safety.

When you use this website

This site uses Google Analytics to understand, in aggregate, how people find and move around it - which pages are read, roughly where visitors are in the world, what device they use. This is statistical. I cannot identify you from it, and it is never connected to anything you tell me as a client.

Health information, and why the law treats it differently

Information about your mental and physical health is “special category data” under UK GDPR and carries extra protection. That is right, and it matches how I think about it anyway.

My lawful bases are:

  • Article 6(1)(b) - processing necessary to enter into and perform our agreement, for booking, arranging and delivering sessions.
  • Article 6(1)(f) - legitimate interests, for responding to enquiries that do not become bookings, and for keeping this website secure and working.
  • Article 6(1)(c) - legal obligation, for the financial records HMRC requires.
  • Article 9(2)(h) - for health information: processing necessary for the provision of health treatment, by a professional bound by an obligation of professional confidentiality.

Where I rely on consent - for example if you ask me to write to your GP - you can withdraw it at any time, and I will stop.

Confidentiality, and its limits

Data protection law and clinical confidentiality are not the same thing. Confidentiality is the stronger of the two, and it is the one that matters between us.

What you bring to sessions stays between us. There are a small number of exceptions, which I would always try to discuss with you first wherever it is safe and possible to do so:

  • If I believe there is a serious risk to your life or to someone else’s.
  • Where a child or vulnerable adult may be at risk of harm.
  • Where I am required to disclose by law, for example by a court order, or under legislation covering terrorism or money laundering.

Supervision. Like every ethically practising therapist, I discuss my work regularly in clinical supervision. This is a requirement of BACP membership and it protects the quality and safety of your therapy. My supervisor is bound by the same confidentiality I am, and I present the work anonymously - without your name or details that would identify you.

Who else handles your information

I use a small number of established providers to run the practice. Each processes data only on my instructions, under a contract.

NamecheapWebsite and email hosting, including the booking system
StripeCard payments
WiseBank transfers
ZoomOnline sessions (sessions are never recorded)
Google CalendarMy appointment diary
WhatsAppMessages from clients about practical arrangements
Google AnalyticsAnonymous website statistics

Some of these companies are based in, or transfer data to, the United States. Where that happens the transfer is covered by the UK’s approved safeguards - either an adequacy regulation or the standard contractual clauses with an international data transfer addendum.

I do not sell your information, share it for advertising, or pass it to anyone else without your knowledge.

How long I keep things

Clinical recordsSeven years after our final session, then securely destroyed
Enquiries that do not lead to workTwelve months
Booking and payment recordsSix years, as HMRC requires
Email correspondenceDeleted in line with the records it relates to

Seven years is the period commonly used in UK private practice and is what professional indemnity insurers expect. It exists so that, if a question about our work ever arose, there would be an accurate record - including one that protects you.

Your rights

Under UK GDPR you can ask me to:

  • Give you a copy of the information I hold about you.
  • Correct anything inaccurate.
  • Delete it - though where I am required to keep clinical or financial records for the periods above, I may not be able to erase everything immediately. I will always explain what I can and cannot do, and why.
  • Restrict or object to how I use it.
  • Provide it in a portable format, or send it to another practitioner.

Just write to info@alexgoldingtherapy.com. I will respond within one month, and there is no charge.

A note on requesting your notes: you are entitled to them, and I will never refuse out of awkwardness. But clinical notes are working shorthand and can read strangely out of context. I would usually suggest we go through them together, which tends to be more useful than an envelope arriving on its own.

Cookies

This site uses cookies that keep it working and secure, and Google Analytics cookies that count visits anonymously. You can block or delete cookies through your browser settings at any time; the site will still work.

Keeping your information safe

I keep written records to a minimum - the less that exists, the less there is to protect.

Devices and accounts are protected by strong, unique passwords and two-factor authentication, and records held electronically are encrypted. This website runs over an encrypted connection (HTTPS) and is protected by a firewall and malware scanning.

Any paper notes are kept at my home, in a private consulting room that no one else uses.

No system is perfect, and I will not pretend otherwise. If there were ever a breach affecting your rights and freedoms, I would tell you and report it to the Information Commissioner’s Office within 72 hours.

If you are unhappy

Please tell me first - write to info@alexgoldingtherapy.com and I will take it seriously and respond properly.

If you would rather not, or you are not satisfied with my answer, you can complain to the Information Commissioner’s Office, the UK regulator for data protection, at ico.org.uk/concerns or on 0303 123 1113.

If your concern is about my conduct as a therapist rather than your data, you can also raise it with the BACP at bacp.co.uk.

Young people

I work mainly with adults. I occasionally see young people aged 16 or 17, where I am satisfied they understand the work well enough to consent to it themselves.

In those cases we agree at the outset what stays between us and what I might need to share, and whether a parent or carer is involved at all. A young person of that age has the same rights over their information as anyone else, and I do not share it with a parent as a matter of course.

I do not work with children under 16, and this website is not directed at them.

Changes to this policy

If I change how I handle information, I will update this page and change the date at the top. If the change is significant and affects current clients, I will tell you directly rather than expecting you to notice.