Data Protection

As a client, you should be confident that your personal information is being kept securely at all times.

Accessible Privacy Policy

An accessible privacy policy document will be provided to you before we begin counselling. This outlines all the information you need to know about how your data is processed in an easy-to-read format.

Disclaimer

In as far as they are able to Frances Moxon Counsellor follows GDPR guidelines with two main exceptions. Firstly, under the Vietnamese Law on Network Information Security No. 86/2015/QH13, explicit consent in required before data maybe processed and, secondly, all data breaches must be reported to the subject.

Information Goverance Policies and Procedures for the General Data Protection Regulation

Contents

Section A

  • Introduction
  • Aim and Purpose
  • Information Governance Framework Principles for HK Consuting

Section B

  • Privacy Notice: Use of information
  • Retention Schedule
  • Data Processing

Section C

  • Data Breach
  • Subject Access Request
  • Right to Erasure
  • Complaints
  • Safeguarding your privacy

Section A

Introduction

Data held by Frances Moxon Counsellor will be held lawfully and for the retention periods set out in section B of this policy document. This document refers to:

  • Written Documents
  • Spreadsheets
  • Database entries
  • Images
  • Recordings
  • Emails
  • Text messages
  • Supervision notes
  • Visits to the organisations website
  • Social media communication

Aim and Purpose

The purpose of this document is to ensure that Frances Moxon Counsellor has a framework that ensures the rights and freedom of individuals in relation to their personal data (Article 1) and adheres to best practice in the management of client information and business records.

Information Governance sets out the way in which information collated by an organisation is managed and ensures that any information collected;

  • is the right information
  • is in the right place
  • at the right time
  • with the right people
  • for the right reasons

This is a live document and may be updated at any time to reflect changes in law or growth of the business, and therefore should be revisited regularly to check for any updates.

Frances Moxon Counsellor is fully committed to ensuring clients privacy and data protection rights.

For the purpose of this policy Frances Helen Moxon is the named Data Protection Officer/Controller and Head of Organisation.

Information Governance Framework Principles for HK Consulting

• Assessment needs for Information Governance (IG) Training have been identified and fully met, with a 75 minute GDPR CPD Course provided by the Clinical Hypnotherapy School (www.clinicalhypnotherapyschool.com) completed. Refresher training is completed every two years.

• Any changes to the business processes and/or operations will be planned and will comply with the framework to ensure any risks to personal and sensitive information are minimised.

• Any data collected is solely for the purpose of providing individual counselling services to an individual client.

• The Caldicott Principles are used to provide guidance in best practice when handling personal data, alongside the ICO’s Office Codes of Practice.

• All technology used to store or facilitate information and communication is maintained according to the Data Retention Policy for Frances Moxon Counsellor.

• All records are identifiable, locatable, retrievable, and intelligible according to regulations set out by GDPR.

• It is the responsibility of the Data Controller to ensure sufficient resources are in place to prioritise adhering to Data Protection Legislation in the business.

• Any electronic devices where personal or sensitive, confidential information is held will be password protected.

• Procedures have been put in place to ensure the General Data Protection Regulations are met. These can be found in Section C.

Section B

Privacy Notice: Use of information

In accordance with this data retention schedule there may be occasions when data is not destroyed due to ongoing investigation, ligation or enquiry. The data will be deleted upon confirmation that it is no longer required.

  • No personal information is collated or stored in hardcopy by Frances Moxon Counsellor.
  • Any document containing personal data will state “Official-sensitive, private and confidential” clearly.
  • All emails will contain a privacy statement.

Under the General Data Protection and Retention (2018) legislation, regarding how your personal data is processed, all individuals have;

  • the right to be informed;
  • the right of access;
  • the right to rectification;
  • the right to erasure;
  • the right to restrict processing;
  • the right to data portability;
  • the right to object; and
  • the right not to be subject to automated decision-making including profiling.

Please note that Frances Moxon Counsellor does not use automated decision-making tools, including profiling.

If any information held is noted to be incorrect an individual can request a correction be made to their own personal information. If you wish for your data to be provided to another service provider, you may also request this in writing.

Website Visitors

When an individual visits therapyvietnam.com, Frances uses Google analytics, who are considered a third party service, to collect information about what visitors do when they click on her website, e.g. which page they visit the most. Google analytics only collect non-identifiable data which means she or they cannot identify who is visiting. Google analytics privacy notice can be found here: https://policies.google.com/privacy

Squarespace is a third-party service that hosts HK Consulting’s website. When an individual visits therapyvietnam.com, Frances uses Squarespace analytics to collect non-identifiable data about what visitors do when they click on her website. Squarespace also hosts the initial contact form, which is emailed to Frances’ secure email account. No personal data is stored on Squarespace. Squarespace’s privacy policy can be found here: https://www.squarespace.com/privacy.

Acuity Scheduling hosts the online session booking function on HK Consulting’s website. Acuity is owned by SquareSpace and subject to the above privacy policy. This software is GDPR-compliant. No other data apart from your name, age, email, phone number and appointment type and time are stored on Acuity. A copy of your appointment booking is sent to Frances’ secure email account.

Social Media

Frances keeps a Facebook Page for her professional practice. She uses Facebook Insights to collect data about interactions with her Page or Posts. Facebook’s privacy notice can be found here: https://www.facebook.com/about/privacy/previous. To protect client confidentiality, she do not accept clients as Friends on Facebook.

Frances Moxon will always be transparent when it comes to collecting personal data and will be clear about how that data is processed.

Retention Schedule

  • Emails (including sent items) are retained until annual review period every January, any remaining live data untouched until following review period.
  • Policies are retained until new policy has been put into place.
  • Client records including session notes, initial consultation notes and client overview form are retained, in accordance with BACP regulations, for 3 years after final treatment session has ended.
  • Safeguarding records are retained, in accordance with BACP regulations, for 3 years after final treatment session has ended.
  • Waiting lists are retained until annual review period every January, old waiting list destroyed and new waiting list developed with any remaining live data transferred to new live document.
  • Continual Professional Development Records are retained when worker is in service and until 10 years afterwards.
  • Counsellor's supervision records are retained when worker is in service and until 10 years afterwards.
  • Service evaluation records are transferred to anonymised data within 6 months of collection.
  • Bbusiness records (name, the date and number of sessions & bank details) are retained for 7 years.
  • Tax returns are retained for 7 years from the end of the financial period to which they pertain to.
  • Incident/Accident reports are retained for 40 years from date report was closed.
  • Insurance policies are retained for 40 years from date policy ended.
  • Complaints are retained for 3 years from complaint being resolved.
  • Right to Erasure Request are retained for 3 years from request being submitted and completed.
  • Subject Access Request are retained for 3 years alongside session notes unless application was made up to 2 years and 11 months after the end of treatment. In which case the SAR will be held for a further two years after closure of SAR.

Data Processing

What are the lawful basis for processing data at HK Consulting?

  • The individual has given clear consent for their data to be processed for the specific purpose/s detailed in the consent form stored in their personal file.
  • Processing is necessary in order to protect the vital interests of the data subject or of another natural person.

Description of processing

The following is a broad description of the way Frances Moxon Counsellor processes personal information. Clients wishing to understand how their own personal information is processed may choose to read the Accessible Privacy Policy, which compliments the policies detailed here.

Reasons/purposes for processing information

Frances Moxon Counsellor processes personal information to enable the provision of Psychotherapy and Counselling, to advertise services and to maintain accounts and records.

Types of information processed

Frances Moxon Counsellor processes information relevant to the above reasons/purposes. This information may include:

  • personal details
  • family, lifestyle and social circumstances
  • goods and services
  • financial details
  • employment and education details

Frances Moxon Counsellor also processes sensitive classes of information that may include:

  • physical or mental health details
  • racial or ethnic origin
  • religious or other beliefs of a similar nature
  • offences and alleged offences

Frances Moxon Counsello processes personal information about:

  • clients
  • suppliers
  • business contacts
  • professional advisers
  • supervisors

Section C

Data Breach

All personal and sensitive data held by Frances Moxon Counsellor is held securely. Electronic data stored on a computer is stored on a password protected computer, in password protected documents held on the C: Drive of the computer. This supports the ability to retrieve data in the event of faults.

In the case of a data breach Frances Moxon Counsellor shall comply with the regulations set out under Article 33 of the GDPR stated below;

  • In the event that a data breach will likely cause a risk to the rights and freedoms of client data, the data controller must communicate the nature of the breach in clear, concise and plain language, to the client/s involved, without delay.
  • If a breach occurs and the data controller has gone to appropriate lengths to protect the data held on the client (e.g. password encryption of electronic files), or if the data controller has taken subsequent action to prevent the risk (e.g. immediately blocking a mobile device) the client will still be notified as required under the Vietnamese Law on Network Information Security No. 86/2015/QH13.

Subject Access Request

A Subject Access Requests (SAR) permits individuals to request a copy of their personal information.

A SAR must be acted upon within one month, at the most within two months, any longer and reasonable reason must be provided. There are no fees unless there is a disproportionate fee to the organisation for sending out the information. Application for SAR should be held alongside session records, unless application was made up to 2 years and 11 months after the end of treatment. In which case the SAR will be held for a further two years after closure of SAR.

A SAR request will include information we hold about you, Frances Moxon Counsellor will:

  • give you a description of it;
  • tell you why we are holding it;
  • tell you who it could be disclosed to; and
  • let you have a copy of the information in an intelligible form.

SAR requests should be put in writing to HK Consulting, by letter or email.

If any information held is noted to be incorrect an individual can request a correction be made to their own personal information. If you wish for your data to be provided to another service provider, you may also request this in writing.

Frances may have a legal basis to continue to hold your data and will notify you of this if that is the case. Any requests should be made in writing to HK Consulting.

Right to Erasure

Any person may put in a request for their personal data to be removed (the ‘right to be forgotten’ or the ‘right to erasure’). Any electronic data will be permanently deleted. The client will be notified of the completion. The request for deletion of data and the confirmation of completion will be held securely until three years after the request was made. In some instances Frances’ supervisory body may require her to lawfully hold your files until the end of their retention period. If this arises she will notify you at her earliest opportunity.

Complaints

Frances Moxon Counsellor hopes to the meet the highest quality standards when processing personal and sensitive data. Complaints can help identify areas for improvement and therefore Frances Moxon Counsellor would welcome you raising any concerns you have.

These Information Governance Policy documents were created to be as transparent and understandable as possible. It will not be completely exhaustive of all aspects of data collection. If you would like further information about a specific process, please contact Frances Moxon.

If you feel you would like to make a complaint about how your personal and sensitive data is handled by Frances Moxon Counsellor you can contact Frances Moxon directly.

Safeguarding your privacy

In the event of Frances' death or sudden illness, her supervisor will contact existing clients and archive any client files in accordance with General Data Protection Regulations.

This may mean having any electronic documents saved on a hard drive professionally wiped or destroyed by a GDPR complaint technician.

unsplash-image--likB8H-IFk.jpg