Privacy Policy
Last updated: 1 July 2026
This page explains what personal information I collect when you contact me or work with me as a client, how I use it, how I keep it safe, and what rights you have over it. I’ve tried to keep it plain and jargon-free.
Who I am
I’m Jack O’Connor, a psychotherapist working in private practice in Hastings. I’m registered with the British Association for Counselling and Psychotherapy (BACP), membership number 413040, and I work within its Ethical Framework, including its rules on confidentiality.
For data protection purposes I am the “data controller” — the person responsible for your information. I’m registered with the Information Commissioner’s Office (ICO), registration number ZC135294.
You can contact me about anything on this page by email at [email protected].
The information I collect
When you enquire. If you email, call, or fill in the contact form, I collect your name, your contact details, and whatever you choose to tell me about why you’re getting in touch.
For example: if you email to ask about availability and mention you’ve been struggling with anxiety since a bereavement, I hold that message — including the health details in it — until we either start working together or I delete the enquiry.
When you become a client. I keep basic contact and identity details (name, address, date of birth, phone, email, and your GP’s details). I also keep brief written notes on our sessions.
Health information. Because therapy is about your mental and emotional health, most of what I hold counts as “special category” data — information the law says needs extra care. This includes what we discuss and any notes I make.
Payment information. I see the record of payments into my business bank account — for example, your name and the date and amount of a bank transfer. I don’t store or see card numbers.
Why I’m allowed to hold it (my lawful basis)
The law says I need a valid reason to use your information. Mine are:
- To provide therapy and run my practice — either to carry out our agreement to work together, or because I have a legitimate interest in running a professional practice (for example, replying to enquiries and keeping proper accounts).
- For your health information specifically — I rely on the part of the law that covers health care and treatment provided by a professional who is bound by confidentiality (UK GDPR Article 9(2)(h)). Where that doesn’t apply, I rely on your explicit consent.
- In an emergency — if there’s a serious risk to your life or someone else’s, I may rely on protecting someone’s vital interests (Article 6(1)(d) and 9(2)(c)).
How I keep session notes
I store clinical notes in a deliberately careful way. Your notes are kept separately from your name and contact details, using a reference rather than identifying information, so the two can’t easily be linked by anyone who shouldn’t see them. The record that connects the two is held in an encrypted, password-protected store that only I can open.
For example: my session notes might refer to “Client 14” rather than to you by name, and the key that links “Client 14” to your real identity lives in a separate encrypted file.
Who I share it with
I treat what you tell me as confidential. I don’t sell your information, and I never share it for marketing. There are a small number of situations where I do share, always limited to the minimum necessary:
- Clinical supervision. Like all responsible therapists, I discuss my work with a supervisor to make sure I’m working safely and well.
- My accountant and HMRC. For tax and bookkeeping — using only what’s needed, such as the fact that a payment was received, never what we discussed.
- The services I use to run my practice. For example, Google Workspace for email and secure note storage, and my accounting software. These act as “data processors” on my behalf, under contract, and can’t use your information for their own purposes.
- When the law requires it, or someone is at serious risk. If I believe there’s a serious risk to your life or someone else’s, or a court or safeguarding law requires it, I may share relevant information — for example, with your GP, emergency services, or a safeguarding team. Wherever it’s safe and possible to do so, I’ll talk to you about this first.
Where your information is stored
I use Google Workspace, which stores information securely and may process it on servers inside or outside the UK. Where your information leaves the UK, it’s protected by safeguards recognised under UK data protection law.
How long I keep it
I keep client records for 7 years after our last contact, in line with professional guidance, and then securely delete or destroy them. Enquiries that don’t turn into ongoing work are deleted sooner.
Your rights
You have the right to:
- ask for a copy of the information I hold about you;
- ask me to correct anything that’s wrong;
- ask me to delete information (though I may need to keep some — for example, records I’m legally or professionally required to retain);
- ask me to limit or stop certain uses of it;
- withdraw your consent where I’ve relied on it.
To use any of these, just contact me using the details above. I’ll respond within one month.
Cookies and this website
This website doesn’t use tracking cookies or collect analytics about your visit.
Complaints
If you’re unhappy with how I’ve handled your information, please tell me first so I can put it right. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK regulator, at ico.org.uk.
← Back to the homepage