Legal
Privacy policy
What I collect, why I collect it, who else ever sees it, how long I keep it and what you can ask me to do about it. Written to be read, not skipped.
Effective date: 1 October 2026. This is version 2.9 and it replaces all earlier versions. The version history is at the bottom of the page.
The short version
I hold two very different kinds of information and keep them separate. What I hold about website visitors is minimal: the site counts page visits without cookies and does not track you. What I hold about clients is a confidential clinical record, including health information, kept in line with the British Psychological Society’s practice guidelines.
I do not sell data, share it for advertising, or use clinical material to train anything. If you want to know what I hold, ask me.
The rest of this page is long because the law asks a privacy policy to be complete. Most people need only this box and section 10, your rights.
1. Who is responsible for your information
The data controller is Anxiety CBT Ltd, registered in England and Wales, company number 16639179. The company is registered with the Information Commission (the ICO) as a data controller, registration reference ZB980265, which you can check on the ICO’s public register. The person responsible for data protection is Dr Daniel O’Rourke, Director. There is no separate Data Protection Officer: I am not required to appoint one, and I deal with these questions myself.
I am a Clinical Psychologist registered with the Health and Care Professions Council (registration PYL043844) and a Chartered Psychologist with the British Psychological Society. That matters because your information is governed not only by data protection law but by professional standards of confidentiality and record-keeping that sit on top of it.
How to contact me about your information
- Email: drdannycbt@proton.me
- Phone or text: 07455 827405
- Postal address: Anxiety CBT Ltd, 61 Bridge Street, Kington HR5 3DJ. That is the registered office and is an administrative address rather than a consulting room. I practise in Nottinghamshire, at my office in Ravenshead and in clients’ own homes, and a correspondence address for clinical post is available on request.
Please put “data protection” in the subject line if your message is about your information rather than therapy, so it does not sit behind clinical email.
2. The two kinds of processing, kept separate
Most privacy policies are confusing because they mix these two things together. They are not the same and are not governed the same way.
(a) Website visitors
If you read this site and do nothing else, the information involved is limited, technical and contains nothing about your health, and never goes beyond what is strictly necessary to serve the page and keep it secure.
(b) Enquirers and clients
If you contact me, and particularly if you go on to be seen, the information becomes personal, detailed and usually health information: what the law calls special category data, subject to stricter rules, higher security and professional duties of confidentiality.
3. If you visit the website
What is collected
This site is deliberately light: no embedded social media widgets, no advertising pixels, no third-party fonts and no tracking scripts. The only measurement is a cookieless visit count, described below.
- Server and security logs. The site is hosted and delivered through Cloudflare, which processes technical information such as your IP address, the page requested, the time of the request, your browser type and referring page. This is necessary to deliver the website, keep it available and defend it against attack.
- One cookie. The site’s own code sets a single cookie,
acbt_consent, with the valuev1:seen, which remembers for 182 days that you have seen the cookie notice. It holds nothing about you. Cloudflare may add a security cookie, lasting from 30 minutes to a year, as set by Cloudflare, if its bot protection is switched on or you are shown a security check. - Visit counts, without cookies. The site uses Cloudflare Web Analytics to count page visits. It sets no cookie and stores nothing on your device. For each page view it records the page, the page you came from, your browser and device type, how quickly the page loaded, and the country derived from your IP address, and Cloudflare turns that into totals. It does not identify you, it does not follow you to other sites, and I see only the totals. I use them to learn which pages people find useful. The lawful basis is my legitimate interest in running the website (Article 6(1)(f)); because nothing is stored on or read from your device, the cookie rules (PECR regulation 6) do not require consent for it.
The lawful basis, stated plainly
For serving and securing the website, and for counting visits, the lawful basis is my legitimate interests under Article 6(1)(f) UK GDPR. The interest is that the website works, stays online, is not defaced or overwhelmed, and that I can see which pages are read. This is a narrow, low-risk use of technical data.
The full detail, including a table of every cookie, is on the cookie policy page.
Visitor statistics
This site collects none today. UK law changed in February 2026. Simple, privacy-friendly visitor statistics can now be collected without a consent banner, as long as the site explains it and offers an easy opt-out. Anything that goes further, including Google Analytics, advertising or profiling, still needs your consent first.
If I add statistics, my first choice will be a tool that uses no cookies, does not identify you and does not share data with advertisers. I will explain it here and give you a one-click opt-out. If I ever use a tool that places cookies or passes data to a company for its own purposes, it will be switched off by default and will run only if you choose Accept. Any choice you made on an earlier version of the cookie notice will not be carried over: you will be asked afresh.
4. If you send an enquiry
What is collected
Whatever you put in the contact form, an email, a text message, a WhatsApp message or a voicemail. Typically: your name, your email address, sometimes a phone number, whether the enquiry is about yourself or a child, and a short description of what has been happening.
The contact form is delivered by Formspree, Inc., a United States company, which acts as my processor. Formspree receives your message on its servers in the United States and emails it to me. The form is set so that Formspree does not keep a copy of submissions, so once the email has been sent the message is held only in my inbox. If you would rather your message did not pass through a US company, email, phone or text me instead.
Email is provided by Proton, based in Switzerland, which stores messages with zero-access encryption, meaning Proton cannot read them at rest. Email sent to me from other providers is not end-to-end encrypted while it travels, which is why I ask you to keep clinical detail out of it.
You can also reach me on WhatsApp. WhatsApp messages are encrypted end to end, but WhatsApp’s owner, Meta, can see that you contacted me and when. WhatsApp is not my processor: it decides for itself how it handles that information, under its own privacy policy.
Whichever route you use, please keep clinical detail brief at the enquiry stage. There is no need to set out the whole history before we have even spoken.
Email, text and messaging apps
Ordinary email, text messages and messaging apps are not secure ways to send health information: a message can be read on any device signed in to your account and passes through your provider on the way. I protect what reaches me (section 9), but I cannot protect your side of the exchange, and I am not responsible for a message being seen or kept by someone else before it reaches me or after I reply. If you would rather not put something sensitive in writing, say so and we can cover it by phone or in the first session.
Messages are not read in real time
This is a single-clinician practice. I check messages between sessions, not continuously, and the practice is not an emergency or crisis service. If you or someone else is in immediate danger, call 999; for urgent mental health help, call NHS 111, Samaritans on 116 123, or text SHOUT to 85258. These numbers are at the foot of every page.
Information I did not ask for
If you send more than I need, such as reports from other services or details about a partner, parent or child, I handle it under this policy and the same retention rules as the rest of your enquiry or record. Where you give me information about someone else, you are responsible for being entitled to share it. I do not contact them to say you have.
The lawful basis
- Article 6(1)(f) legitimate interests. Responding to someone who has asked me a question is the obvious and expected use of their message.
- Article 6(1)(b) steps prior to entering a contract, where the enquiry is plainly a step towards booking a first session.
- Where an enquiry contains health information, as most do, the additional condition is Article 9(2)(h), the provision of health care and treatment, on the basis that you have approached a health professional in order to be assessed and treated. Where that does not apply, I will ask for your explicit consent under Article 9(2)(a) before doing anything further with the health information.
If you do not go on to become a client
Enquiries that do not lead to treatment are deleted within twelve months, and usually sooner, so that if you come back months later I have some idea what we discussed. If you would rather I deleted yours straight away, say so.
5. If you become a client
What I hold
- Your name, date of birth, address, contact details, and GP details where you give them.
- For work with a child or young person, the same for the parents or carers involved.
- What you tell me: the history, the difficulties, the context, what you have already tried.
- Clinical notes made during and after each session, and the formulation and treatment plan.
- Standardised outcome measures and questionnaires completed at the start of treatment and during it, and their scores.
- Correspondence with your insurer, where you are claiming, and a record of any contact made in the safety situations described in section 6.
- Risk information where relevant.
- Appointment records, invoices and payment records.
Records are kept to the standards expected of an HCPC-registered practitioner: they are contemporaneous, factual and proportionate. They are working clinical documents, not a commentary. They contain facts, such as what was said and done and when, and they also contain my professional opinion, such as a formulation, a diagnosis where one is given, an assessment of risk and my view of how treatment is going. The two are not treated the same way when you ask for something to be changed: see the right to rectification in section 10.
Recordings of sessions
Sessions are not recorded by me, as section 7 sets out. Please do not record a session, in person or online, without my agreement in advance. A recording made without agreement is not part of the clinical record, and I may end a session if I find one being made. Where we agree that a recording of part of a session is useful to your treatment, for example a recording of an exposure task or of instructions you will practise between sessions, you make that recording on your own device and it is your own information, held by you. It does not form part of the record held by Anxiety CBT Ltd, I do not hold a copy unless we agree otherwise in writing, and keeping it safe or deleting it is your responsibility.
The lawful bases, and why two are needed
Health information is not ordinary personal data. Under UK GDPR it may not be processed at all unless a condition in Article 9 applies. So two things are always in play: an Article 6 basis, which permits the processing generally, and an Article 9 condition, which permits health information specifically. Neither works alone.
| What I am doing | Article 6 basis | Article 9 condition (health data) |
|---|---|---|
| Assessing and treating you; keeping clinical records | 6(1)(b) performance of a contract with you | 9(2)(h) provision of health care and treatment, and management of health care systems and services |
| Invoicing an insurer and dealing with a claim | 6(1)(b) contract | 9(2)(h), and 9(2)(a) explicit consent where the insurer requires clinical detail |
| Clinical supervision and case discussion (anonymised or pseudonymised) | 6(1)(f) legitimate interests | 9(2)(h). Supervision is a professional requirement of safe practice |
| Keeping accounting and tax records | 6(1)(c) legal obligation | Not applicable. No clinical detail is held in accounting records |
| Responding to a complaint, a regulator, my professional indemnity insurer or a legal claim, and keeping records for as long as that needs | 6(1)(f) legitimate interests, or 6(1)(c) legal obligation where a regulator or court requires it | 9(2)(f) establishing, exercising or defending legal claims |
| Disclosing information to prevent serious harm | 6(1)(d) vital interests, or 6(1)(c) legal obligation | 9(2)(g) substantial public interest, with Schedule 1, Part 2, paragraph 18 of the Data Protection Act 2018 (safeguarding of children and individuals at risk), for safeguarding disclosures; 9(2)(c) vital interests only where you cannot consent; or 9(2)(h) |
Article 9(2)(h) is relied on as UK law requires: the processing is carried out by, or under the responsibility of, a professional subject to a legal duty of confidentiality. The Data Protection Act 2018 sets that out at Schedule 1, Part 1, paragraph 2.
One consequence is often misunderstood: because clinical records are not held on the basis of your consent, withdrawing consent does not delete them. You can stop treatment at any moment and for any reason, but the record of the treatment that took place still has to be retained, for your protection as much as mine.
Complaints, claims, regulators and insurers
If you make a complaint about me, if a complaint or concern about me is raised with the HCPC or another regulator, if a legal claim is made or threatened by you or on your behalf, or if I need to notify my professional indemnity insurer about a matter involving you, I may use your clinical record, my correspondence with you and my own notes of events to respond, and I may share the parts that are relevant with my insurer, my legal advisers, the regulator and, where there are proceedings, the court or tribunal. This is permitted under Article 9(2)(f) UK GDPR, which covers establishing, exercising or defending legal claims, and it does not need your consent. I disclose no more than the matter requires, and the record is kept for as long as the matter is open and for any period after it that the law allows for a further claim, even if that is longer than the ordinary retention period in section 8.
6. Confidentiality, and where it ends
What you tell me is confidential. That holds in almost every case, but it is not absolute, and you are entitled to know the limits before you tell me anything rather than after.
I would break confidentiality, with or without your agreement, in three situations.
- Risk of serious harm to you. If I believed you were at real risk of serious harm, including taking your own life or seriously harming yourself, I would act to keep you safe.
- Risk of serious harm to someone else. The same applies if I believed another person was at real risk of serious harm.
- Safeguarding. If I had reason to believe a child or a vulnerable adult was being abused or neglected, I have a professional duty to pass that on to the people whose job it is to look into it. That means the local authority’s safeguarding team, or the police in an emergency.
I would also disclose information if ordered to by a court. A court order is not something I can decline, though I would limit what was released to what was actually required.
I must also disclose information where a specific law requires it. Examples are information about acts of terrorism, and, as a regulated health professional, the duty to report to the police if I learn that a girl under 18 has undergone female genital mutilation.
Two things in practice. First, this is rarer than people fear: intrusive thoughts about harm, the everyday currency of OCD, are not the same as risk, and telling one from the other is much of what I was trained to do. Second, unless it would increase the risk, I will tell you what I am going to do, who I am going to tell and why, before I do it.
Working with children and young people
Young people have their own right to confidentiality, and it grows as they do. I agree the rules at the start with everyone in the room: what will routinely be shared with parents, what will not, and the safety exceptions above, which apply to everybody. A teenager who believes everything goes straight back to their parents will not tell you the thing that matters.
Where a young person is competent to make their own decisions about their care, their rights over their own record are theirs to exercise, not their parents’.
7. Who else ever sees your information
This is a single-clinician practice, with no administrative team and no shared database. The list of people and organisations who see anything is short.
Where a company handles information for me as a processor, I have a written data processing agreement with it. The one exception today is Formspree, the contact form provider: I am obtaining its data processing agreement, and until that is in place the form is set so that Formspree does not store messages. Some services I use, such as WhatsApp, are not my processors: they decide for themselves how they handle the limited information they receive, under their own privacy policies.
| Who | What they handle | Why |
|---|---|---|
| Cloudflare | Website hosting, delivery and security logs | To serve this website and protect it from attack |
| Formspree, Inc. (United States) | Contact form messages. Formspree receives each message in the United States and emails it to me. It is set not to store submissions | To deliver enquiries sent through the website form |
| Proton (Proton Mail, Switzerland) | Email and calendar | Correspondence. Messages are stored with zero-access encryption, so Proton cannot read them at rest |
| WriteUpp (practice management and clinical records system) | Clinical records, appointments, invoices and video sessions. Hosted in Ireland and the Netherlands | To keep your clinical record and run the practice. WriteUpp acts as my processor |
| eSignatures.com | The treatment agreement, and your signature, name, email address and IP address at signing | So the treatment agreement can be signed online. No clinical notes are involved |
| WhatsApp (Meta) | Your phone number and profile name, and the record that we were in contact and when. Message and call content is encrypted end to end and WhatsApp cannot read or hear it | Only if you choose to message me on WhatsApp, or we agree to use it for a session. WhatsApp is an independent controller, not my processor, and its own privacy policy applies |
| WriteUpp video consultation, or WhatsApp where that is not workable for you | The live audio and video of an online session, plus your name or display name and connection details | To deliver online therapy. Sessions normally run on the video consultation built into WriteUpp, which already holds your records, so no additional company is involved. WriteUpp states the connection runs directly between us, is encrypted end to end, and that it does not see or store session content. Where that is not workable for you I may use WhatsApp instead, and I will tell you which before your first online session. WhatsApp calls are also encrypted end to end, so WhatsApp cannot see or hear the session, but the record that a call took place, and its time and length, is not encrypted. Sessions are not recorded, not transcribed, and no automatic summary or artificial intelligence feature is used. If a recording were ever clinically useful I would ask you first and you would have to agree in writing |
| Your insurer (BUPA, AXA Health, Aviva, Vitality, WPA) | Dates of appointments, fees, authorisation codes, and the minimum clinical information they require | Only where you are claiming. They are a separate data controller once information reaches them, and their own privacy policy applies |
| Your GP, the local authority or the police | The minimum information needed to deal with the risk | Only in the safety situations described in section 6. I do not otherwise write letters or reports to GPs, schools or other clinicians |
| Clinical supervisor | Case material with your name and other identifying details removed. The supervisor does not see your record and does not know who you are | Supervision is a professional requirement of safe practice. The clinical problem can be discussed without your identity, and my supervisor is a qualified professional who is bound by a duty of confidentiality in respect of everything discussed |
| Accountant and HMRC | Invoices and payment records only | Statutory accounting and tax obligations. No clinical detail |
| Professional indemnity insurer and legal advisers | Only what is necessary, only if a claim or complaint arises | Establishing, exercising or defending legal claims |
I do not sell your information or share it with advertisers, data brokers or social media platforms. I do not put clinical material into a public AI tool or use it to train any model. Where AI tools are used in running the practice, it is for general administrative or website work involving no client information. If I ever use software that drafts, summarises or transcribes clinical material, I will tell you first, use only tools that do not train on your information and are covered by a data processing agreement, and you will be able to say no without it affecting your care.
If unpaid fees were ever referred to a debt recovery service, only your name, contact details and the amount outstanding would be passed on. No clinical information would be disclosed for that purpose.
If you claim through an insurer
Insurers do not pay for treatment without information about it. If you ask me to invoice your insurer, or you claim back fees you have paid me, I will give the insurer what it needs to process the claim: your name and policy or membership number, the dates you attended, the fee for each session, invoices, any authorisation or pre-authorisation code, and, where the insurer requires it as a condition of paying, a diagnosis or a short summary of the treatment and how it is progressing. By asking me to bill your insurer, or by submitting a claim for my fees, you authorise me to share this information with it. The insurer is a separate data controller: once information reaches it, how it is used, how long it is kept and whether it affects future cover is governed by your policy and the insurer’s own privacy policy, not by me. If you would rather your insurer did not receive clinical information, the alternative is to pay for treatment yourself.
International transfers
Some of the services above operate outside the United Kingdom. Proton is in Switzerland, which has a UK adequacy decision, so your data is treated as receiving equivalent protection. My clinical records system, WriteUpp, is supplied by a British company but stores records in Dublin and Amsterdam; both Ireland and the Netherlands have UK adequacy decisions. Cloudflare and Formspree are United States companies, and eSignatures.com may also process data outside the UK. WhatsApp is based outside the United Kingdom too, so if you message me there, or we use it for a session, some of the data involved may be processed abroad.
Where information leaves the UK to a company acting as my processor, it should be covered by one of the safeguards recognised in law: an adequacy decision, the International Data Transfer Agreement, or the UK Addendum to the European Commission’s standard contractual clauses. Formspree is the one where that is not yet settled: I am obtaining its data processing agreement with the UK transfer terms. Until I have it, the protection I can honestly point to is that the form is set so that Formspree does not store messages, and that you can avoid the form altogether by emailing, phoning or texting me.
Clinical records are held in WriteUpp, which encrypts them in transit and at rest and restricts staff access under ISO 27001 controls. I do not keep clinical records in email, messaging apps or general cloud storage.
8. How long I keep things
Health records are kept longer than people expect, for a good reason: if you need to come back, or if a question about your care arises years later, the record needs to still exist. The periods below follow the retention conventions used across UK health care. They are conventions rather than fixed legal limits, because the law sets no single retention period for private health records.
| Record | Retention period |
|---|---|
| Adult clinical records | Seven years after the last contact, following British Psychological Society guidance for independent practitioners. Records are kept longer than this where there is an open complaint, an insurance or legal matter, or any other reason I am required to keep them, and in that case they are destroyed once the matter has finished. You can ask me at any time what the position is for your own record |
| Clinical records for a child or young person | Until their 25th birthday, or their 26th birthday if they were 17 when treatment ended. If treatment continued past their 18th birthday, the adult rule applies from then. This is the standard UK health-records convention, and it exists so that a young person can access their own record as an adult |
| Enquiries that do not become clients | Deleted within 12 months, and usually sooner |
| Free introductory calls that do not lead to treatment | A brief note only, deleted within 12 months |
| Invoices, payment and accounting records | Six full financial years, as company and tax law requires |
| Website server and security logs | Short-term only, as set by the host, typically days to a few weeks |
At the end of the retention period, records are securely and permanently destroyed. Any record, including a child’s record and an enquiry, is kept beyond the period above where it is needed to deal with a complaint, a regulator, my insurer or a legal claim, as section 5 explains, or where a court or a law requires it, and is destroyed once that reason has ended.
If I sell or close the practice
If I ever sell, merge or wind up the practice, or if I stop practising, records will be transferred only to a clinician or organisation bound by the same duties of confidentiality, or securely retained and destroyed at the end of their retention period. I will tell current and recent clients before any transfer.
9. How your information is kept safe
- Devices are encrypted, password-protected and kept up to date.
- Clinical records are held in WriteUpp, encrypted in transit and at rest. Within the practice, only I can open them.
- Email is Proton, with zero-access encryption at rest.
- Any paper notes are kept in a locked cabinet, and are the exception rather than routine.
- Multi-factor authentication is used on every account that supports it.
- No one else has access to client records, and there is no administrative staff.
Sessions in your own home
Some clients are seen in their own homes. I do not leave notes or papers at your home; anything I write during a home session leaves with me and goes into your record. Your home is not a space I control, so you decide who else is in the house during a session and whether they can overhear it, and I am not responsible for what another person there hears or sees. If I think a session cannot be confidential where we are, I will say so and we can rearrange it.
Online sessions
For video sessions I use the platforms described in section 7, from a private room. The other end of the connection is yours: I cannot secure your device, network or notifications, and I am not responsible for anyone who can see or hear your side of the session or for a recording made on your device. Join from a private space, on a device only you can open, and avoid a shared or public network.
If something goes wrong
If your information were lost, disclosed or accessed without authorisation, I would contain it first (stop the cause, wipe a lost device where possible, ask a wrong recipient to delete what they received), assess what was involved and what harm could follow, and keep a written record. Where the breach was likely to put your rights at risk I would report it to the Information Commission (the ICO) within 72 hours, and where the risk to you was high I would tell you directly: what happened, what it could mean for you and what I was doing about it. A breach at a processor such as WriteUpp or Proton is handled the same way once it tells me.
10. Your rights
These are your rights under UK GDPR. I will respond within one month, and exercising them will not affect your care. I may extend the one-month period by up to two months for complex requests, and the clock pauses while I wait for information I need to confirm who you are or what you are asking for. Requests are free unless they are manifestly unfounded or excessive. Where a request is manifestly unfounded or excessive, for example because it repeats a request I have recently answered, or is made to disrupt rather than to obtain your information, Article 12(5) UK GDPR allows me either to charge a reasonable fee based on the administrative cost of dealing with it or to refuse it. If I do either, I will tell you why and that you can complain to the ICO.
The right to be informed
To know what is held and why. That is what this document is for.
The right of access
You can ask for a copy of your records. This is a subject access request and can be made verbally or in writing. I may ask you to confirm your identity. What you receive is a copy: the original record stays with Anxiety CBT Ltd, because I am required to keep it. A copy is normally provided electronically in the format the records are held in, and where you ask for something different, such as a printed copy, I will meet the request where I reasonably can.
In rare cases some material can be withheld. First, the Data Protection Act 2018, at Schedule 3, Part 2, allows health information to be withheld where releasing it would be likely to cause serious harm to your physical or mental health or to that of another person. The Act requires that judgement to be made by, or on the opinion of, an appropriate health professional. As an HCPC-registered clinical psychologist I am that professional for records I have made, and I would seek the opinion of another appropriate health professional where that is the right course. Second, information that identifies another person, such as a family member, a referrer or another professional, may be redacted or withheld where that person has not consented and it is not reasonable to disclose it without their consent. Third, where a request is made on behalf of a child or young person, I apply the child’s own rights and best interests as section 6 describes, and I may decline to release the child’s record to a parent where the child is competent to decide and does not agree, or where release would not be in the child’s interests. If I withhold or redact anything, I will tell you that I have done so and, where I can without undoing the reason for withholding it, why.
The right to rectification
If something factual in your record is wrong, such as a date, a name, a medication or an event that did not happen as recorded, tell me and I will correct it. The right to rectification applies to inaccurate facts. It does not extend to my professional opinion, such as a formulation, a diagnosis, an assessment of risk or my view of progress, because an opinion is not inaccurate merely because you disagree with it, and a clinical record cannot be rewritten after the event. Where we disagree about an opinion, I add a note of your disagreement, in your words if you wish, to the record, so that anyone reading it later sees both. The original entry stays as it was, marked as disputed, and nothing is removed.
The right to erasure
Often called the right to be forgotten, and it is not absolute. Enquiry emails, form submissions and marketing information will be deleted on request. Clinical records generally cannot be deleted during the retention period, because they are held to meet legal and professional obligations rather than on the basis of consent: the exemption at Article 17(3) applies.
The right to restrict processing
You can ask me to pause using your information while a dispute about its accuracy, or about my grounds for holding it, is sorted out.
The right to object
You can object to processing based on legitimate interests. You can object to direct marketing at any time and that objection is absolute: it stops immediately, with no balancing exercise.
The right to data portability
Where processing is based on consent or a contract and is carried out by automated means, you can ask for your data in a structured, commonly used, machine-readable format, or ask for it to be sent to another provider.
The right to withdraw consent
Where I rely on your consent (for example a specific disclosure to a third party, or a recording) you can withdraw it at any time, and withdrawal must be as easy as giving it. It does not undo processing that already lawfully happened, and, as above, it does not delete a clinical record held under a different basis.
Rights relating to automated decision-making
There is none. No decision about you, clinical or otherwise, is made by automated processing or profiling. Decisions about your care are made by me.
How to exercise any of them
Email drdannycbt@proton.me or call 07455 827405. You do not need a particular form of words, or to explain why.
11. If you are unhappy with how I have handled your information
You have a legal right to complain to me about how I have handled your information. You can do that by email, phone, text or letter, in any words you like. I will acknowledge your complaint within five working days (the law allows 30 days), look into it without delay, keep you informed, and give you a full response in writing within 28 days.
If you are not satisfied, or at any point if you prefer, you can complain to the Information Commission (the ICO), the UK regulator for data protection. The ICO will usually expect you to have raised the matter with me first.
Information Commission (known as the ICO)
Website: ico.org.uk
Helpline: 0303 123 1113
4th Floor, No.3 Circle Square, 5 Hawkshaw Street, Manchester M1 7BL
If you contact them about this practice, my registration reference is ZB980265.
Complaints about my professional conduct, as opposed to my handling of data, go to the Health and Care Professions Council, as set out on the terms of use page.
12. Children and this website
This website is written for adults and young people aged 16 or over seeking help for themselves, and for parents and carers seeking help for a child. It is not designed for children to submit personal information through, and I ask that they do not.
Young people aged 16 and 17 can contact me themselves, because in the UK they can usually consent to their own treatment. An enquiry about a child under 16 should come from a parent or carer. If I receive a message that appears to have come from someone under 16, I will not engage with it clinically. I will reply once to explain that I need to hear from a parent or carer, point them to Childline (0800 1111) and Shout (text 85258), and then delete the message, unless it suggests they are at risk.
This does not mean a young person should not get help; it means the first contact should involve an adult who can consent to it.
13. Marketing and newsletters
I do not run a mailing list, and I do not advertise to you based on your health information. If I start a newsletter, joining will be a separate, optional step that you take yourself: it will never be a condition of treatment and I will never add client or enquiry email addresses to it. Every message will have a working unsubscribe link, and the list will be held with a provider under a data processing agreement. I will not use anything I know about your health to decide what to send you.
14. Links to other websites
This site links out to organisations such as the NHS, the HCPC, OCD-UK and charities. Once you follow a link you are on someone else’s site and their privacy policy applies. I have no control over how they handle your data and cannot be responsible for it.
This site also links to screenbalanceprogram.com, which I co-own through a separate United States business, Elevating Parenthood LLP. Nothing you tell Anxiety CBT Ltd is shared with it, and nothing you enter there is shared with this practice. It has its own privacy policy, and this one does not apply to anything you do there.
The same applies to any service run by someone else that this site links to or, if I add one in future, embeds in a page: a YouTube video, a map, a booking widget or a payment page. Once you watch, click or type into it, the company that runs it collects whatever its own privacy policy says, whether or not you leave this site, and that is outside my control and outside this policy. A link from this site is not a recommendation of how that organisation handles your information. No third-party service is embedded in this site today; if that changes, section 3 and the cookie policy will say so.
15. What happens if you do not give me information
Some information is necessary. Without a name, contact details and enough clinical history to understand the problem, I cannot assess or treat safely, and I would have to say so rather than proceed. Most other things, such as whether you complete a particular questionnaire, are yours to decline, and declining them will not be held against you.
16. Services I may add later
The way I work changes over time. I may in future add tools for visitor statistics, online booking, video sessions, card payments or a newsletter. None of these is in use today unless this policy says so elsewhere. Before I switch on anything that handles your information in a new way, I will:
- choose a provider that offers a written data processing agreement and, where possible, stores data in the UK or Europe;
- carry out a risk assessment where the law requires one;
- update this policy and the version history below, with the date; and
- tell current clients directly if it affects them.
If a new tool needs your consent, it will stay off for you until you give it.
Online booking
At present, appointments are arranged with me directly. If I add online booking, it will be through my practice management system, WriteUpp, or a comparable provider under a data processing agreement. The booking page will collect only what is needed to arrange the appointment (name, contact details, who the appointment is for, and a preferred time), and will show a link to this policy at the point you enter your details.
Video sessions
Sessions currently run on the video tool built into WriteUpp, or on WhatsApp where we have agreed that in advance. If I change or add a platform, it will be one that encrypts calls, is offered under terms suitable for health care, and does not record, transcribe or analyse sessions unless you have asked for that in writing. I will tell you which platform we are using before your first online session and whenever it changes.
Payments
Fees are currently paid by bank transfer or by your insurer, so I do not handle card details. If I add card or online payments, they will be taken by a payment provider authorised in the UK. Card details will go directly to that provider and will never be seen or stored by me. The provider will receive your name, the amount, and a payment reference that does not describe your treatment. Payment providers act as independent controllers for fraud prevention and legal compliance, and their own privacy notices will apply to that part.
Visitor statistics are covered in section 3, newsletters in section 13, software that handles clinical material in section 7, and a change of ownership in section 8.
17. Changes to this policy
This policy is reviewed periodically and whenever I change something material, such as adding a new system that handles your information. Updated versions are posted here with a new effective date at the top. If a change materially affects current clients, I tell them directly rather than relying on them to notice.
For website visitors and enquirers, the version in force is the one posted here on the date your information is collected, and continuing to use the site or to contact me after a new effective date means the new version applies to you. For clients in treatment, a material change, meaning one that alters who sees your information, what it is used for or how long it is kept, is told to you directly, by email or at a session, before it applies to your record. A change that only clarifies wording, corrects an error or describes something already in practice takes effect when it is posted. Earlier versions are summarised in the version history below.
Version history
- Version 2.9, 1 October 2026. Clauses added on insecure channels, home sessions, subject access limits, professional opinion in notes, legal claims, insurer disclosures, recordings, third-party links, breaches and changes.
- Version 2.8, 30 September 2026. Lawful bases for supervision and safeguarding corrected; wording made first person; referral wording aligned with the rest of the site; cookieless visit counting (Cloudflare Web Analytics) added to section 3.
- Version 2.7, 29 September 2026. Letters and reports to GPs, schools and other clinicians removed, because I do not write them; contact with a GP, the local authority or the police is now described only for the safety situations in section 6. The regulator is now named the Information Commission (still known as the ICO), with its Manchester address. Young people aged 16 and 17 can now make contact themselves.
- Version 2.6, 23 September 2026. Formspree storage of contact form messages switched off. The contact form and processor sections now say that Formspree passes each message on by email and does not keep a copy.
- Version 2.5, 21 September 2026. Contact form section rewritten to say plainly that Formspree stores a copy of each message in the United States. WriteUpp (as the clinical records system), eSignatures.com and WhatsApp added to the list of who sees information. Security and encryption statements made more precise. Complaints and request-timing sections updated for the Data (Use and Access) Act 2025. Statutory disclosure duties added. Analytics wording updated, and Google Analytics removed because it is not used. Sections added on services that may be added later, newsletters, and what happens to records if the practice closes or changes hands.
- Version 2.4, 11 September 2026. Previous version.
Related pages
This policy is written to be accurate and genuinely useful rather than to be long. It is general information about how I handle your data, and it is not legal advice.