
Privacy Policy
At The hypno-garden, we are committed to protecting your privacy and handling your personal data with the utmost transparency and security. This policy explains our practices in compliance with UK-GDPR.
-
Privacy Policy: The Hypno Garden Ltd
-
1. Introduction
-
At The Hypno Garden I am committed to protecting your privacy and handling your personal data with the utmost transparency and security. This policy outlines how I collect, use, and store your information in compliance with the UK GDPR and the Data Use and Access Act 2025 (DUAA 2025).
-
2. Controller Contact Details
-
I am the Data Controller for this practice.
-
Name: Kasia Snelling
-
Business Address: 4 Greencroft close, Bd10 8xd
-
Email: kasisnelling@hotmail.com
-
ICO Registration Number: ZC044669
-
3. Data Collected
-
I collect and process the following information to provide safe and effective hypnotherapy:
-
Identity Data: Name, date of birth, gender.
-
Contact Data: Phone number, email address, home address.
-
Special Category (Health) Data: Medical history, lifestyle details, session notes, and psychological history.
-
Emergency Contact: Name and phone number of your GP or a next of kin.
-
4. Purpose & Lawful Basis for Processing
-
In accordance with the law, I process your data under the following legal bases:
-
Contract: To provide the hypnotherapy services you have requested.
-
Consent: For specific marketing or communication preferences you have opted into.
-
Health Care Exemption: (Article 9 UK GDPR) For the provision of health or social care or treatment.
-
Recognised Legitimate Interest (Safeguarding): As updated by DUAA 2025, I may process data without explicit consent where it is necessary for safeguarding an individual at risk or protecting your vital interests.
-
5. Data Sharing
-
Your data is strictly confidential. It is never sold or shared for marketing purposes. It is only shared under the following conditions:
-
Supervision: I may discuss your case with a professional supervisor. In these instances, all data is fully anonymised.
-
Legal/Safety Obligations: If I believe there is a risk of serious harm to yourself or others, or if I am legally compelled by a court of law.
-
Integrated Digital Services: Using verified, secure platforms for appointment booking or telehealth as permitted under DUAA 2025 standards.
-
6. Data Retention
-
I retain your records for a period of 7 to 8 years following your final session (or until age 25 if the client was a minor).
-
Deletion: After this period, digital files are permanently deleted using secure wiping software, and physical files are destroyed via cross-cut shredding.
-
7. Security Measures
-
I employ robust technical and organisational measures to ensure your data remains private:
-
Physical: Paper records and intake forms are kept in locked filing cabinets.
-
Digital: All emails are encrypted. Mobile devices and tablets used for scheduling are secured with biometric locks (FaceID/Fingerprint) and high-strength passwords.
-
Storage: Digital session notes are stored on encrypted, cloud-based platforms that meet UK data protection standards.
-
8. Your Data Subject Rights
-
Under the UK GDPR and DUAA 2025, you have the following rights:
-
Right of Access: You can request a copy of the data I hold about you.
-
Right to Rectification: You can ask me to correct inaccurate information.
-
Right to Erasure: Also known as the "Right to be Forgotten" (subject to legal retention requirements).
-
Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.
-
9. Complaints Process
-
If you have concerns about how I handle your data, please contact me directly so we can resolve the matter.
-
In line with the 2025 DUA amendments, which aim to streamline the complaints process, you have the right to lodge a formal complaint with the Information Commissioner’s Office (ICO) if you remain unsatisfied.
-
ICO Website: https://ico.org.uk