top of page

Privacy Policy

At Hyp-ER, we are committed to protecting and respecting your privacy. We understand that seeking support for your mental health and well-being involves a high level of trust. This Privacy Policy explains how we collect, use, and protect your personal information in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1.Who We Are

Hyp-ER (“we”, “us”, “our”) is a clinical hypnotherapy practice providing services through our website, https://www.hyp-er.co.uk/. For the purposes of data protection law, we are the “Data Controller” of the personal information you share with us.

2.Information We Collect

To provide safe and effective hypnotherapy services, we collect several types of information:

  • Basic Details:

    • Name,

    • postal address,

    • date of birth,

    • contact information.

  • Sensitive Health Data (Special Category Data):

    • Medical history

    • lifestyle details

    • session notes.

  • Technical Data:

    • IP address

    • browser type

    • usage data when you visit our website.

3.How We Collect Your Data

We collect data through:

  • Direct Interaction:

    • Information you provide by filling in intake forms, booking appointments, or communicating with us via email or phone.

  • Consultations:

    • Information disclosed during clinical hypnotherapy sessions.

  • Automated Technologies:

    • Cookies and similar technologies used on our website to improve user experience.

4.How We Use Your Information

We use your data to:

  • Provide clinical hypnotherapy services tailored to your unique needs.

  • Manage appointments and billing.

  • Communicate with you regarding your treatment.

  • Comply with legal and insurance obligations.

  • With your explicit consent, provide updates or wellness resources that may benefit you.

5.Legal Basis for Processing

Under the UK GDPR, we rely on the following legal bases:

  • Contract:

    • Processing is necessary for the performance of our contract with you (providing therapy).

  • Legal Obligation:

    • We have a legal obligation to maintain medical and professional records.

  • Consent:

    • Where you have given clear permission (e.g., for marketing or specific data sharing).

  • Legitimate Interests:

    • To manage our business effectively and securely.

  • Special Category Processing:

    • We process sensitive health data under Article 9(2)(h) of the GDPR (the provision of health or social care or treatment).

6.Confidentiality and Data Sharing

Your privacy is our priority. We do not sell your data. We only share information with third parties in the following limited circumstances:

  • Professional Supervision:

    • As part of ethical clinical practice, cases may be discussed anonymously with a professional supervisor.

  • Terrorism:

    • Under the Terrorism Act 2000, we are legally required to disclose information if we have knowledge or suspicion of terror-related activity.

  • Safeguarding:

    • If we believe there is a risk of serious harm to yourself, a child, or a vulnerable adult.

  • Legal Obligation:

    • If we are served with a court order or other legal warrant, or otherwise required by law to disclose information.

  • Service Providers:

    • Secure platforms used for booking, accounting, or encrypted data storage.

7.Data Storage and Security

We have implemented strict security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorised way. This includes encrypted storage, secure filing systems, and password protection on all electronic devices. All records are stored securely, either in encrypted digital formats or locked physical files.

8.Data Retention

We retain clinical records for a period of 7 years following the conclusion of your treatment (or until age 25 if the client is a minor), in accordance with professional insurance requirements and industry standards. After this period, your data will be securely destroyed.

9.Your Legal Rights

You have the right to:

  • Request access to your personal data (a "Data Subject Access Request").

  • Request correction of any incomplete or inaccurate data we hold about you.

  • Request erasure of your personal data, subject to our legal and insurance obligations to retain records.

  • Object to processing or request restriction of processing.

  • Withdraw consent at any time where we are relying on consent to process your data.

10.Cookies

Our website uses cookies to distinguish you from other users and monitor website traffic. You can set your browser to refuse all or some browser cookies, but this may affect the functionality of the site.

11.Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at:

 

Hyp-ER

Contact: Andy Craddock (Director)

Email:     consult.hyp.er@gmail.com

Website: www.hyp-er.co.uk

 

You also have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK regulator for data protection issues (www.ico.org.uk).

 

Hyp-ER is registered with the ICO under the reference ZC125450.

bottom of page