🔒 Privacy Policy
Speak to Lauren – Counselling with Lauren Reading-Gloversmith
1. Purpose of This Policy
This policy explains how I collect, store, use, and protect your personal information in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. My aim is to be transparent, keep your data safe, and meet all legal and ethical obligations.
2. Who I Am & Data Protection Contact
Speak To Lauren is a private counselling practice based in the UK.
I, Lauren Reading-Gloversmith, am a sole trader and the Data Controller for your information.
For all questions about your data or to exercise your rights under GDPR, you can contact me at:
📧 contact@speaktolauren.com
I am registered with the Information Commissioner’s Office (ICO) as a data controller (Registration number: ZB955481).
3. Who I Work With
I work with clients who book directly with me as well as clients referred via third-party organisations or agencies. For clients referred via Mindbase Therapy, I typically receive only basic contact information to arrange the session. For clients referred via Wellbeing In The Arts and Lewes Low Cost Counselling Service, I may receive more detailed information, such as assessment forms or notes from initial calls, to help provide safe and appropriate counselling. All information shared with me by referring organisations is handled in line with this privacy policy and used solely for arranging and delivering counselling sessions. I only provide counselling to clients aged 18 and over. I do not knowingly collect or store personal data relating to children.
4. What Data I Collect and Why
I only collect the information necessary to offer you safe, ethical, and effective counselling. This may include:
Contact details: name, phone number, email, home address
Emergency contact details: for use only in crisis or safeguarding situations
Date of birth: to ensure accurate identification
GP details: used only if needed in a serious risk or safeguarding situation
Relevant health information: e.g. mental health history, medication
Session notes: brief factual notes about what we discuss
Assessment forms: such as intake forms or optional screening tools (e.g. CORE-10)
Pre-therapy records: where counselling does not proceed, I may retain assessment forms, clinical notes, records of exploratory conversations and relevant correspondence where this is necessary to document clinical decision-making, risk assessment, safeguarding actions or signposting.
Payment records: for accounting purposes (no bank/card details are stored)
Referral and booking information: information provided by a referring organisation for the purpose of arranging and delivering counselling sessions. The amount of information shared may vary depending on the organisation, for example: Mindbase Therapy may provide contact details only, whereas Wellbeing In The Arts and Lewes Low Cost Counselling Service may provide assessment forms or notes from initial calls.
🔄 In addition: A clinical will is in place. This means that, in the unlikely event of my death or incapacity, an appointed executor will be able to contact my current clients and relevant professional contacts (such as my supervisor, referring agencies, ethical body, and insurer) to manage the closure or transfer of my practice. The executor already holds a secure link to this document but does not have the password to open it. Access would only be granted if necessary and with authorisation from a nominated trusted person.
5. Lawful Basis for Processing Your Data
I process your personal information under the UK GDPR and Data Protection Act 2018 using the following lawful bases:
Contractual necessity – to provide the counselling service you have requested.
Legal obligation – where I am required to retain records or disclose information by law.
Vital interests – where processing is necessary to protect life or prevent serious harm.
Legitimate interests – to ensure the safe, ethical and effective running of my counselling practice, including professional supervision, record keeping, documenting clinical decisions regarding prospective clients, risk management and business continuity arrangements.
As counselling involves processing sensitive (special category) information relating to health and wellbeing, I also rely on the additional lawful condition of:
Provision of health or social care – processing that is necessary for the provision of counselling and therapeutic support and the management of health-related services.
This means I do not rely on your consent as the primary basis for processing information necessary to provide counselling, as withdrawing consent would not always allow me to safely or lawfully delete records that I am professionally required to retain.
6. How Your Data is Stored and Protected
Your data is kept securely in the following ways:
🔄 Digital records: stored on a password-protected laptop with up-to-date antivirus software installed. Backup copies are stored on a secure external hard drive, which is kept in a locked box when not in use.
🔄 Cloud storage: confidential documents (e.g. my clinical will) are held on encrypted Microsoft OneDrive, protected by password and shared only with an appointed executor if required.
🔄 Counselling phone: messages and calls are handled via a dedicated SIM card within a dual-SIM phone, which is passcode- and biometric-protected. Messages are deleted once actioned unless they form part of the clinical record or are required for safeguarding, risk management or legal purposes. Where relevant, they are incorporated into the client's or prospective client's secure record before being removed from the device or email inbox where appropriate.
Emails: sent via Gmail and protected using appropriate account security measures. Emails are deleted once actioned unless they form part of the clinical record or are required for safeguarding, risk management or legal purposes. Where relevant, they are incorporated into the client's or prospective client's secure record before being removed from the device or email inbox where appropriate.
Online sessions: conducted via Doxy.me, a secure, GDPR-compliant platform
Online forms: I use Google Forms to collect information for client assessments at the beginning of counselling and for end-of-therapy feedback. Access to this information is restricted to me and protected through password-secured accounts and appropriate security measures.
I never share your data with anyone unless required by law or with your written consent. There are limited circumstances where confidentiality may need to be broken without your consent, for example where there is a serious risk of harm to you or others, where safeguarding concerns arise, or where disclosure is required by law. Wherever possible, I will discuss this with you first.
If your personal data is transferred outside the UK (for example, due to email or cloud storage systems), it will only be sent to countries with adequate data protection standards or safeguarded through approved measures such as Standard Contractual Clauses.
7. How Long I Keep Your Data
I only keep personal information for as long as it is necessary for the purpose for which it was collected and in accordance with my legal, professional and insurance obligations.
Retention periods include:
Client records (including assessments, clinical notes and correspondence forming part of the clinical record): retained for 7 years after counselling ends.
General enquiries where counselling does not proceed and no clinical assessment has taken place: normally deleted within 1 month.
Pre-therapy assessments where counselling does not proceed: where a clinical assessment has been completed, or where there are safeguarding, risk management, professional or legal reasons to retain records (including relevant correspondence), these records may be retained for up to 7 years to document clinical decision-making and protect both the prospective client and myself.
After the relevant retention period has expired, records are securely destroyed or permanently deleted.
8. Your Rights Under GDPR
You have the right to:
Be informed about how your data is used
Access the data I hold about you
Request correction of inaccurate information
Request deletion of your data (with some legal limitations)
Restrict or object to how your data is processed
Withdraw consent where applicable
Make a complaint directly to me about how your personal data is being handled
Requests can be made in writing and I will respond within one calendar month where required under UK GDPR.
9. What Happens in a Data Breach
If there is a data breach (e.g. loss, theft, unauthorised access), I will:
Inform you as soon as possible
Notify the Information Commissioner’s Office (ICO) within 72 hours if required
Take steps to contain the breach and prevent future incidents
10. Concerns or Complaints
If you have concerns about how I collect, use, store or protect your personal information, you have the right to make a data protection complaint directly with me.
Complaints can be submitted by email to:
I will:
• Acknowledge receipt of your complaint within 30 days
• Investigate the matter appropriately
• Keep you informed of progress where necessary
• Respond without undue delay and explain the outcome of my investigation
If you remain dissatisfied after receiving my response, you have the right to contact the Information Commissioner's Office (ICO):
🔁 Policy Review
This privacy policy is reviewed annually or sooner if legal or professional changes arise.
Policy created: August 2025
Last updated: 16 July 2026 (updated to clarify data retention periods for enquiries, pre-therapy assessments and clinical records, and to reflect the Data (Use and Access) Act 2025 complaints procedures effective from 19 June 2026).
Next review due: July 2027 (or sooner if legal, regulatory or professional requirements change)