ILLUMINATED THINKING

Counselling | Coaching | Psychology Assessments in Glasgow

Privacy Policy

1. Introduction
At Illuminated Thinking, we are committed to protecting the privacy and confidentiality of our clients. This Privacy Policy outlines how we collect, store, use, and share personal data in accordance with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Data Controller Information
Illuminated Thinking is the data controller for the personal data collected and processed as part of our services. If you have any questions about this policy, you can contact us at:

Email: info@illuminatedthinking.co.uk
Address: Illuminated Thinking Ltd, Mearns Castle Golf Academy, Waterfoot Road, Glasgow, G77 5RR

3. Personal Data We Collect
We may collect and process the following types of personal data:
– Basic Contact Information: Name, address, email, and phone number.
– Health and Therapy-Related Data: Session notes, assessment reports, referral letters, and outcome measures.
– Financial Data: Payment details if applicable.
– Correspondence: Any emails or messages sent to us regarding your care.

4. Lawful Basis for Processing Data
We process personal data under the following lawful bases:
– Contract: To provide therapy and assessment services.
– Legal Obligation: Compliance with professional regulatory requirements.
– Legitimate Interest: For efficient administrative management of the practice.
– Consent: In cases where explicit consent is required for data sharing.

5. How We Use Personal Data
Your data is used to:
– Provide psychological assessment and therapy services.
– Maintain clinical records as required by professional guidelines.
– Process payments and manage appointments.
– Communicate with you regarding appointments or relevant information.
– Ensure compliance with legal and ethical obligations.

6. Use of Third-Party Systems
We use the following third-party platforms to securely manage client data and ensure efficient service delivery:
– Cliniko: A secure practice management system used for scheduling appointments, storing clinical notes, and managing invoices. Cliniko complies with GDPR and employs encryption and access controls to protect your data.
– Heidi AI: An AI-powered clinical scribe tool that transcribes and summarises therapy session notes. Heidi operates under strict security and confidentiality policies to ensure compliance with professional and legal obligations.
– ProtonMail: A secure, encrypted email service used for sensitive communications to protect your confidentiality.

These systems are used solely for the purpose of providing effective and secure psychological services. If you have any concerns regarding their use, please contact us for further details.

7. Data Retention Period
We retain data only as long as necessary:
– Basic contact information: Deleted within six months after therapy ends.
– Health-related records: Retained for seven years post-therapy, then securely deleted.
– Financial records: Retained for six years for accounting purposes.

8. Data Sharing and Confidentiality
We keep your data confidential and do not share it without your consent, except in the following situations:
– Health insurance providers: If applicable and with prior consent.
– Legal obligations: Where required by law, such as safeguarding concerns.
– Clinical supervision: To ensure quality of care, anonymised data may be discussed in professional supervision.

9. Data Security Measures
We implement appropriate security measures, including:
– Encryption and secure storage of records.
– Password protection on all electronic devices storing personal data.
– Secure email services for sensitive communications.

10. Your Rights
You have rights regarding your personal data, including:
– Access: You can request a copy of your data.
– Rectification: You can request corrections if data is inaccurate.
– Erasure: You can request deletion, subject to professional and legal obligations.
– Restriction: You can request limits on how your data is processed.
– Objection: You can object to data processing under certain circumstances.

11. Complaints and Contact Information
If you have concerns about your data, you can contact us at [Your Contact Email]. If you are unsatisfied, you can lodge a complaint with the Information Commissioner’s Office (ICO):

Website: www.ico.org.uk
Phone: 0303 123 1113

12. Changes to This Privacy Policy
We may update this policy from time to time. Any changes will be posted on our website, and significant updates will be communicated where necessary.

13. Use of Cookies
Our website uses cookies to improve user experience and analyse website traffic. Cookies are small text files stored on your device that help us understand website usage and improve our services.

Types of Cookies We Use:
– Essential Cookies: Required for website functionality (e.g., security, login).
– Analytics Cookies: Help us understand how visitors interact with our website (e.g., Google Analytics).
– Marketing Cookies: Used to track browsing habits for targeted advertising.

Managing Cookies
By using our website, you consent to the use of essential cookies. Non-essential cookies will only be used if you provide consent via our cookie banner. You can manage or disable cookies through your browser settings.

Effective Date: 30th January 2025

Skip to content