Privacy policy
Effective date: 14 July 2026 | Version: 2.0
In brief
- Your information is held securely and confidentially, and seen only by the people involved in your care.
- Your own psychologist is responsible for your clinical records; the practice handles the admin around them.
- We never sell your data, and we never advertise to you.
- You can ask to see, correct or delete your information at any time, and we respond within a month.
- AI never makes decisions about you. Our AI ethical use policy explains exactly how AI is and is not used.
- Any questions or worries, email [email protected]. You can also go to the ICO at any time.
Contents
1Introduction
This policy explains how we, Thriving Minds Collective Ltd (trading as The Online Psychologists, Company No. 16358249), collect, use and protect your personal information in the course of providing online psychological therapy services. We have written it to be clear and readable rather than legalistic, because you should be able to understand exactly what happens to your information without a law degree.
2Who is the data controller?
Thriving Minds Collective Ltd is the data controller for information collected and processed in connection with practice administration, including handling enquiries, sending initial communications, and managing bookings through our practice systems. Dr Rachel Whatmough, Director, is responsible for overseeing data protection compliance. Thriving Minds Collective Ltd is registered with the Information Commissioner's Office, registration ZB902327.
When you engage with a clinical psychologist for clinical services, your psychologist becomes the data controller for the personal data they collect and process in the course of therapy. Each psychologist is individually responsible for their clinical records, is registered with the Health and Care Professions Council (HCPC), and is separately registered with the ICO. Thriving Minds Collective Ltd does not act as the central data controller for clinical records: all clinical information and records are the sole responsibility of the individual psychologist you work with.
Shared access to client records
All psychologists securely store client information in Halaxy, a GDPR-compliant practice management system used for session notes, appointment scheduling and record-keeping. Individual psychologists cannot access each other's client records. As practice owner and Clinical Director, Dr Rachel Whatmough has full administrative access to the practice systems, which she uses only for operational purposes, such as managing enquiries, appointments and invoicing, and for keeping the service safe and running properly.
Digital tools and AI
Some psychologists may, with your explicit consent, use supplementary digital tools such as Heidi, an AI-assisted medical scribe that helps clinicians write up sessions accurately. No audio is ever stored: speech is processed in real time and discarded immediately after transcription, and your psychologist reviews and approves every note before it is saved to your record. Heidi is used in NHS services to reduce admin time and improve clinician focus, and your psychologist will always ask for your consent before using it.
Our full AI ethical use policy explains everything about how AI is and is not used in this practice, in plain English. The short version: AI helps with paperwork, never with decisions about your care, and nothing AI-related happens in your sessions without your consent.
Independent Clinical Psychologists and data responsibilities
All Clinical Psychologists delivering services through The Online Psychologists operate as independent sole traders. They are individually responsible for ensuring the security and confidentiality of client information they manage, in compliance with GDPR.
3Information we collect
A. Personal data
- Name, email address, phone number
- Date of birth
- GP contact details (if provided)
B. Sensitive personal data (special category data)
- Health information relevant to therapy
- Therapy session notes and assessments
- Referral details and treatment history
- Assessment and outcome measure data
What we need, and what is optional
Some information is essential for us to work with you safely, such as your contact details, and health information relevant to your therapy. If you prefer not to share something essential we will talk it through with you, though it may limit what we can safely offer. Anything beyond that is optional, and choosing not to share it never affects the care you receive.
C. Website, analytics and payment data
Enquiry forms: if you complete our enquiry or matching form, we collect your name, contact details and the information you choose to give us, so the right psychologist can be found for you. Your answers go directly to our clinical team.
Payments: payment for therapy is typically made by bank transfer. Where card payment is offered it is processed through Stripe, a secure payment provider, and with your consent a card can be saved on file when you register, in case of missed payments or late cancellations under our cancellation policy. Saved cards are held securely by Stripe, never by us: we cannot see your full card details, and we retain only transaction references and invoicing records.
Website analytics: we use Google Analytics and Microsoft Clarity to understand how visitors use our website. Both are anonymised, do not identify you, and only run if you accept analytics cookies. See our cookie policy for the detail.
4Lawful basis for processing your data
Under UK GDPR we must have a lawful basis for processing personal data. The bases relevant to our work are:
- Consent: when you give consent for us to process your data, for example for referrals you request or optional tools.
- Contractual necessity: processing needed to provide your therapy and manage your appointments.
- Legal obligation: when required by law, for example safeguarding duties or financial record-keeping.
- Legitimate interests: the day-to-day running of the practice and maintaining high-quality services.
Health information is special category data, and we process it under Article 9(2)(h) of UK GDPR (provision of healthcare, under a duty of confidentiality) and, where relevant, your explicit consent.
5How we use your information
We use your data to:
- Respond to your enquiry and match you with an appropriate psychologist.
- Deliver and manage your therapy sessions and maintain appropriate clinical records.
- Where relevant, process payments securely.
- Comply with legal and ethical obligations, such as safeguarding.
We never sell your data. We never advertise to you. The only marketing-type contact we will ever make, such as inviting you to leave a review after therapy ends, happens with your agreement.
6Data sharing and confidentiality
Information about you is stored securely and treated as confidential. It will not be shared with others except in specific circumstances:
Your matched psychologist: who will have access to the information relevant to your care, including your enquiry and anything shared during the matching process.
With your consent: if you ask us to share information with another professional, for example letters to GPs or psychiatrists, or reports for insurers. Where your therapy is funded by an insurer, we share only what the insurer requires to authorise and invoice your sessions.
Legal or safeguarding obligations: if there is a risk of harm to you or others, or when we are legally required to disclose information by law, court order, or to comply with the requirements of the HCPC. Wherever possible we would discuss this with you first.
Administrator access: to support the running of the practice, an administrator has access to emails and our practice systems. They work under a confidentiality agreement and only access what is necessary for tasks such as managing appointments, invoices and enquiries.
7The systems we use
Everything that holds your information is chosen for security and bound by data processing agreements and appropriate safeguards:
- Halaxy (practice management): appointments, clinical records and invoicing. Encrypted, EU-hosted, acting as a data processor.
- Our practice dashboard (practice-owned software): we operate our own secure dashboard for appointment management, enquiries and practice administration. It is practice-owned software running on practice equipment in the UK, not a third-party service, so your information never leaves our control. Clinical notes and personal details held in it are encrypted, access is role-based (clinicians see only their own clients), and clinical records are also maintained in Halaxy.
- Stripe (payments): card payments and secure card-on-file where offered. Saved cards are held by Stripe, never by us, and are only charged in line with our booking and cancellation policy.
- Google Workspace (email and documents): our email and documents are protected by Google's security and encryption under Google's own terms. As with any email provider anywhere, email as a medium is never completely secure end to end, so we suggest keeping deeply personal detail for your sessions rather than email.
- Resend (email delivery): sends our automated emails, such as enquiry acknowledgements, on our behalf. It processes only the recipient's name, email address and the message itself, never your clinical records.
- Cloudflare (website hosting and enquiry forms): hosts our website and processes your enquiry when you submit our online forms, including Cloudflare Turnstile for spam protection.
- Secure video platforms (such as Zoom or Microsoft Teams): all therapy sessions run on encrypted, GDPR-compliant video, sessions are never recorded, and your psychologist works from a private, secure setting.
- AI-assisted administration: AI tools help our team run the practice behind the scenes, covered in full in our AI ethical use policy. Client data is never used to train AI models.
- Encrypted backups: practice data is backed up regularly to secure storage to protect against loss.
8International transfers
We keep data in the UK or EEA wherever possible. Where a provider processes data outside the UK (Google, Stripe, Cloudflare, Anthropic), transfers rely on UK GDPR-approved mechanisms: the UK-US Data Privacy Framework or Standard Contractual Clauses with the UK addendum.
9Data security
- Encrypted storage of clinical records, in Halaxy and in our own practice systems.
- Role-based access: your psychologist controls access to your clinical data, and practice staff see only what their role requires.
- Encrypted video for every session, with no recording, conducted from private and secure settings.
- Secure disposal of information at the end of its retention period.
- Regular review of our security practices.
10How long we keep your information
- Enquiry and contact form data: up to 2 years after your last interaction with us, then securely deleted.
- Clinical records: a minimum of 7 years after the last session, in line with HCPC guidelines and NHS best practice, or longer where clinically appropriate.
- Payment records: 7 years, to meet HMRC requirements.
- Website analytics: anonymised and does not identify individual users.
After the retention period, records are securely deleted. You can request deletion of your data at any time, subject to our legal and professional obligations to retain certain records.
11Your rights
Under UK GDPR you have the right to:
- Access: request a copy of the information we hold about you (a subject access request).
- Rectification: ask us to correct anything inaccurate.
- Erasure: ask us to delete information, subject to the legal and professional duty to retain clinical records for the periods above.
- Restriction and objection: restrict or object to certain processing.
- Portability: receive your data in a portable format.
- Withdraw consent: at any time, without affecting your care.
To exercise any of these rights, email [email protected]. We will respond within one month, and we aim to acknowledge all data protection queries within 48 hours. If your request is complex we may extend the response by up to two months, and we will tell you if so. There is no charge.
12Automated decision-making
We do not make any decision with legal or similarly significant effect about you by automated means. Our online enquiry and matching forms are structured questionnaires reviewed by our clinical team, and administrative automation, such as appointment reminder emails, never affects your access to care or any clinical decision.
13If something goes wrong
If a personal data breach occurs we investigate immediately, record it, and report to the Information Commissioner's Office within 72 hours where the legal threshold is met. If a breach is likely to put you at high risk we will tell you directly and promptly: what happened, what information was involved, and what we are doing about it. If you ever suspect a problem with your data, contact us and we will investigate.
14Cookies
Our website uses a small number of cookies: essential cookies for functionality and your consent choice, analytics cookies (Google Analytics and Microsoft Clarity, only if you accept them via the banner), and Cloudflare Turnstile to protect our forms from spam. We do not use advertising or marketing cookies, and we never track you across other websites. You can change your choice at any time, and the full detail, including how long each cookie lasts, is in our cookie policy.
15Third-party websites
Our website may link to third-party websites and services. We are not responsible for their content or practices, and their handling of your data is governed by their own privacy policies, which we recommend reviewing.
16Contact and complaints
Questions or concerns about this policy, or about how your information has been handled:
- Email: [email protected]
We take every concern seriously, will acknowledge you promptly, and will investigate and respond without undue delay. You also have the right to complain to the Information Commissioner's Office at any time, whether or not you have raised it with us first: ico.org.uk, 0303 123 1113.
17Changes to this policy
We update this policy when our systems or the law change. The version number and effective date at the top always tell you what is current, and we will communicate significant changes clearly. This version (2.0) was published on 14 July 2026 and replaces the version dated March 2026.
Effective date: 14 July 2026 | Version: 2.0