Legal
Privacy policy
What I collect, why I collect it, who else ever sees it, how long I keep it and what you can ask me to do about it. Written to be read, not to be skipped.
Effective date: August 2026. This is version 2.0 and it replaces all earlier versions.
The short version
I am a clinical psychologist in private practice. I hold two very different kinds of information and I keep them separate. Information about people who simply visit this website is minimal, and nothing is tracked until you say yes. Information about people who become clients is detailed, includes health information, and is treated as a confidential clinical record under the same standards I would apply in the NHS.
I do not sell data. I do not share your information for advertising. I do not use your clinical material to train anything. If you want to know what I hold, ask me and I will tell you.
1. Who is responsible for your information
The data controller is Anxiety CBT Ltd, a company registered in England and Wales, company number 16639179. The person responsible for data protection within the company is Dr Daniel O’Rourke, Director. There is no separate Data Protection Officer; the practice is not required to appoint one, and I deal with these questions myself.
Dr O’Rourke is a Clinical Psychologist registered with the Health and Care Professions Council (registration PYL043844) and a Chartered Psychologist with the British Psychological Society. That matters here because it means the handling of your information is governed not only by data protection law but by professional standards of confidentiality and record-keeping that sit on top of it.
How to contact me about your information
- Email: drdannycbt@proton.me
- Phone or text: 07455 827405
- Postal address: the practice is based near Ravenshead, Nottingham. I do not publish a street address on the website, but the registered office is on the public register at Companies House and the correspondence address is available on request — just ask and I will give it to you.
Please put “data protection” in the subject line if your message is about your information rather than about therapy, so it does not sit behind clinical email.
2. The two kinds of processing, kept separate
Almost every confusing privacy policy is confusing because it mixes these two things together. They are not the same and they are not governed the same way.
(a) Website visitors
If you read this site and do nothing else, you are a website visitor. The information involved is limited and technical, no health information is involved, and nothing beyond what is strictly necessary to serve the page happens unless you have given consent.
(b) Enquirers and clients
If you contact me, and particularly if you go on to be seen, the information involved becomes personal, detailed and in most cases health information — what the law calls special category data. It is subject to stricter rules, a higher standard of security, and professional duties of confidentiality.
The sections below deal with each in turn.
3. If you visit the website
What is collected
This site is deliberately light. There are no embedded social media widgets, no advertising pixels, no third-party fonts and no tracking scripts loaded by default.
- Server and security logs. The site is hosted and delivered through Cloudflare, which processes technical information such as your IP address, the page requested, the time of the request, your browser type and referring page. This is necessary to deliver the website, to keep it available and to defend it against attack.
- Analytics, only if you agree. Google Analytics may be used to understand which pages people find useful. It is not switched on unless and until you click Accept on the cookie banner. If you never accept, no analytics cookie is set and no analytics data is collected about you.
The lawful basis, stated plainly
For serving and securing the website, the lawful basis is my legitimate interests under Article 6(1)(f) UK GDPR — the interest being that the website works, stays online and is not defaced or overwhelmed. This is a narrow, low-risk use of technical data and it is what the law expects.
For analytics, the lawful basis is your consent under Article 6(1)(a) UK GDPR. It is never legitimate interests. I mention this explicitly because a great many UK websites get it wrong: the Privacy and Electronic Communications Regulations require consent before a non-essential cookie or similar technology is placed on your device, and dressing analytics up as a legitimate interest does not cure that. Consent means a positive action by you, freely given, and as easy to withdraw as it was to give.
The full detail, including a table of every cookie, is on the cookie policy page.
4. If you send an enquiry
What is collected
Whatever you put in the contact form, in an email, in a text message or on a voicemail. Typically that is your name, your email address, sometimes a phone number, whether the enquiry is about yourself or a child, and a short description of what has been happening.
The contact form is provided by Formspree, which passes the message to my email. Email is handled by Proton Mail, based in Switzerland, which provides end-to-end and zero-access encryption.
Please keep clinical detail brief at the enquiry stage. Not because I am not interested, but because ordinary email is not a secure channel and there is no need to put a detailed account of your child’s difficulties into one before we have even spoken. There is time for all of that on the call.
The lawful basis
- Article 6(1)(f) legitimate interests — responding to someone who has asked me a question is the obvious and expected use of their message, and it is what you wanted to happen when you sent it.
- Article 6(1)(b) steps prior to entering a contract — where the enquiry is plainly a step towards booking an assessment.
- Where an enquiry contains health information — and most do, because that is the nature of the enquiry — the additional condition is Article 9(2)(h), the provision of health care and treatment, on the basis that you have approached a health professional in order to be assessed and treated. Where that does not apply, I rely on Article 9(2)(a) explicit consent.
If you do not go on to become a client
Enquiries that do not lead to an assessment are deleted within twelve months, and usually sooner. I keep them for that period only so that if you come back to me six months later I have some idea what we discussed. If you would rather I deleted your enquiry straight away, say so and I will.
5. If you become a client
What I hold
- Your name, date of birth, address, contact details, and GP details where you give them.
- For work with a child or young person, the same for the parents or carers involved.
- What you tell me — the history, the difficulties, the context, what you have already tried.
- Clinical notes made during and after each session, and the formulation and treatment plan.
- Standardised outcome measures and questionnaires completed at assessment and during treatment, and their scores.
- Correspondence with GPs, schools, colleges, other clinicians and insurers, where agreed with you.
- Risk information where relevant.
- Appointment records, invoices and payment records.
Records are kept to the standards expected of an HCPC-registered practitioner. That means they are contemporaneous, factual and proportionate. They are working clinical documents, not a commentary.
The lawful bases, and why two are needed
Health information is not ordinary personal data. Under UK GDPR it is prohibited from being processed at all unless a condition in Article 9 applies. So there are always two things in play: an Article 6 basis, which permits the processing generally, and an Article 9 condition, which is the thing that actually permits health information to be handled. Neither works alone.
| What I am doing | Article 6 basis | Article 9 condition (health data) |
|---|---|---|
| Assessing and treating you; keeping clinical records | 6(1)(b) performance of a contract with you | 9(2)(h) provision of health care and treatment, and management of health care systems and services |
| Writing to your GP, school or another clinician | 6(1)(b) contract | 9(2)(h), with your agreement to the contact in each case |
| Invoicing an insurer and dealing with a claim | 6(1)(b) contract | 9(2)(h), and 9(2)(a) explicit consent where the insurer requires clinical detail |
| Clinical supervision and case discussion (anonymised or pseudonymised) | 6(1)(c) legal obligation and 6(1)(f) legitimate interests | 9(2)(h) — supervision is a professional requirement of safe practice |
| Keeping accounting and tax records | 6(1)(c) legal obligation | Not applicable — no clinical detail is held in accounting records |
| Disclosing information to prevent serious harm | 6(1)(d) vital interests, or 6(1)(c) legal obligation | 9(2)(c) vital interests, or 9(2)(f) legal claims, or 9(2)(h) |
| Website analytics | 6(1)(a) consent | Not applicable — no health data is involved |
Article 9(2)(h) is relied on in the manner UK law requires: the processing is carried out by, or under the responsibility of, a professional subject to a legal duty of confidentiality. The Data Protection Act 2018 sets that out at Schedule 1, Part 1, paragraph 2.
One consequence is worth stating clearly, because it is often misunderstood: because clinical records are not held on the basis of your consent, withdrawing consent does not delete them. You can stop treatment at any moment and for any reason, and no explanation is owed to anyone. The record of the treatment that took place still has to be retained, for your protection as much as mine.
6. Confidentiality, and where it ends
What you tell me is confidential. That is the starting position and it holds in almost every case. But it is not absolute, and you are entitled to know the limits before you tell me anything rather than after.
I would break confidentiality, with or without your agreement, in three situations.
- Risk of serious harm to you. If I believed you were at real and immediate risk of taking your own life or seriously harming yourself, I would act to keep you safe.
- Risk of serious harm to someone else. The same applies if I believed another person was at real risk of serious harm.
- Safeguarding. If I had reason to believe a child or a vulnerable adult was being abused or neglected, I have a professional duty to pass that on to the people whose job it is to look into it.
I would also disclose information if ordered to by a court. A court order is not something I can decline, though I would limit what was released to what was actually required.
Two things about how that works in practice. First, it is rarer than people fear. Intrusive thoughts about harm — which are the everyday currency of OCD — are not the same thing as risk, and I am not going to mistake one for the other. That distinction is a large part of what I was trained to make. Second, unless doing so would increase the risk, I will tell you what I am going to do, who I am going to tell and why, before I do it. Being informed is the norm; being blindsided is not.
Working with children and young people
Young people have their own right to confidentiality, and it grows as they do. In practice I agree the rules at the start with everyone in the room: what will routinely be shared with parents, what will not, and the safety exceptions above, which apply to everybody. A teenager who believes everything goes straight back to their parents will not tell you the thing that matters, and treatment then fails for a reason that had nothing to do with the treatment.
Where a young person is competent to make their own decisions about their care, their rights over their own record are theirs to exercise, not their parents’.
7. Who else ever sees your information
This is a single-clinician practice. There is no administrative team and no shared database. The list of people and organisations who see anything is short, and every processor is bound by a written contract that limits them to acting on my instructions.
| Who | What they handle | Why |
|---|---|---|
| Cloudflare | Website hosting, delivery and security logs | To serve this website and protect it from attack |
| Formspree | Contact form submissions, in transit to my email | To deliver enquiries sent through the website form |
| Proton (Proton Mail, Switzerland) | Email and calendar | Correspondence, with zero-access encryption at rest |
| Google Analytics | Anonymised website usage statistics | Only if you consent. Not enabled at the time of writing |
| Video consultation software | The live audio and video of an online session | To deliver online therapy. A platform with end-to-end encryption is used and sessions are not recorded unless you have specifically asked for a recording and agreed to it in writing |
| Your insurer (BUPA, AXA Health, Aviva, Vitality, WPA) | Dates of appointments, fees, authorisation codes, and the minimum clinical information they require | Only where you are claiming. They are a separate data controller once information reaches them, and their own privacy policy applies |
| Your GP, school or other clinician | Letters, reports and clinical summaries | Only with your agreement, other than in the safety situations above |
| Clinical supervisor | Case material, anonymised wherever possible | Supervision is a professional requirement. Your name is not needed to discuss the clinical problem |
| Accountant and HMRC | Invoices and payment records only | Statutory accounting and tax obligations. No clinical detail |
| Professional indemnity insurer and legal advisers | Only what is necessary, only if a claim or complaint arises | Establishing, exercising or defending legal claims |
I do not sell your information. I do not share it with advertisers, data brokers or social media platforms. I do not put your clinical material into a public AI tool, and I do not use it to train any model. If AI tools are used at all in the running of the practice, it is for general administrative or website work that involves no client information.
In the very unlikely event that unpaid fees were referred to a debt recovery service, only your name, contact details and the amount outstanding would be passed on. No clinical information would be disclosed for that purpose.
International transfers
Some of the services above operate outside the United Kingdom. Proton is in Switzerland, which has a UK adequacy decision, meaning your data is treated as receiving equivalent protection. Cloudflare, Formspree and Google are United States companies and may process data outside the UK.
Where information leaves the UK, I rely on one of the safeguards recognised in law: an adequacy decision, or the International Data Transfer Agreement or the UK Addendum to the European Commission’s standard contractual clauses, with a transfer risk assessment where one is required. In practical terms this means clinical records are kept in encrypted systems and no clinical record is stored on a platform that could read it.
8. How long I keep things
Health records are kept longer than people expect, and there is a good reason for it: if you need to come back, or if a question about your care arises years later, the record needs to still exist. The periods below follow the retention conventions used across UK health care.
| Record | Retention period |
|---|---|
| Adult clinical records | A minimum of eight years after the end of treatment, in line with professional guidance for health records |
| Clinical records for a child or young person | Until their 25th birthday, or their 26th birthday if they were 17 at the last contact — whichever is later. This is the standard UK health-records convention and it exists so that a young person can access their own record as an adult |
| Enquiries that do not become clients | Deleted within 12 months, and usually sooner |
| Free introductory calls that do not lead to an assessment | A brief note only, deleted within 12 months |
| Invoices, payment and accounting records | Six full financial years, as company and tax law requires |
| Website server and security logs | Short-term only, as set by the host, typically days to a few weeks |
| Analytics data, where consented to | Up to 14 months |
At the end of the retention period, records are securely and permanently destroyed.
9. How your information is kept safe
- Devices are encrypted, password-protected and kept up to date.
- Clinical records are held in encrypted storage, accessible only to me.
- Email is Proton, with zero-access encryption at rest.
- Any paper notes are kept in a locked cabinet and are the exception, not the routine.
- Multi-factor authentication is used on every account that supports it.
- No one else has access to client records. There is no administrative staff.
If a data breach ever occurred that was likely to result in a risk to your rights and freedoms, I would report it to the Information Commissioner’s Office within 72 hours, and I would tell you directly if the risk to you was high. I would tell you what had happened, what it meant and what I was doing about it.
10. Your rights
These are your rights under UK GDPR. They are free to exercise, and I will respond within one month. Exercising them will not affect your care in any way.
The right to be informed
To know what is held and why. That is what this document is for.
The right of access
You can ask for a copy of your records. This is a subject access request and it can be made verbally or in writing. There is no fee. I may ask you to confirm your identity. In rare cases some material can be withheld — where releasing it would be likely to cause serious harm to your physical or mental health, or where it would identify a third party who has not consented. If I withhold anything, I will tell you that I have.
The right to rectification
If something factual in your record is wrong, tell me and I will correct it. Clinical records cannot be rewritten after the event, so if we disagree about a professional opinion rather than a fact, your account of the disagreement will be added to the record so that anyone reading it later sees both.
The right to erasure
Often called the right to be forgotten, and it is not absolute. Enquiry emails, form submissions and marketing information can be deleted on request, and will be. Clinical records generally cannot be deleted during the retention period, because they are held to meet legal and professional obligations rather than on the basis of consent — the exemption at Article 17(3) applies. This protects you as well as me.
The right to restrict processing
You can ask me to pause using your information while a dispute about its accuracy or my grounds for holding it is sorted out.
The right to object
You can object to processing based on legitimate interests. You can object to direct marketing at any time and that objection is absolute — it stops immediately, with no balancing exercise.
The right to data portability
Where processing is based on consent or on a contract and is carried out by automated means, you can ask for your data in a structured, commonly used, machine-readable format, or ask for it to be sent to another provider.
The right to withdraw consent
Where I rely on your consent — cookies, marketing, a specific disclosure to a third party — you can withdraw it at any time and it must be as easy to withdraw as it was to give. Withdrawal does not undo processing that already lawfully happened, and, as above, it does not delete a clinical record held under a different basis.
Rights relating to automated decision-making
There is none. No decision about you, clinical or otherwise, is made by automated processing or profiling. Decisions about your care are made by a person, and that person is me.
How to exercise any of them
Email drdannycbt@proton.me or call 07455 827405. You do not need a particular form of words and you do not need to explain why.
11. If you are unhappy with how I have handled your information
Please tell me first. Most problems are misunderstandings and are quicker to fix directly. I would genuinely rather hear it.
But you do not have to come to me first, and you never lose the right to go elsewhere. You can complain at any time to the Information Commissioner’s Office, the UK regulator for data protection.
Information Commissioner’s Office
Website: ico.org.uk
Helpline: 0303 123 1113
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Complaints about my professional conduct, as opposed to my handling of data, go to the Health and Care Professions Council. That route is set out on the terms of use page.
12. Children and this website
This website is written for adults — for people seeking help for themselves, and for parents and carers seeking help for a child. It is not designed for children to submit personal information through, and I ask that they do not.
An enquiry about a child or a young person under 18 should come from a parent or carer, or from a professional such as a GP or a school with the family’s knowledge. If I receive a form submission that appears to have come from a child, I will not engage with it clinically and will delete it, other than to respond appropriately if it suggests the child is at risk.
None of this means a young person should not get help. It means the first contact should involve an adult who can consent to it.
13. Marketing
I do not run a mailing list, I do not send newsletters and I do not advertise to you based on your health information. If that ever changes, it will be opt-in, it will be separate from your care, and there will be an unsubscribe link that works.
14. Links to other websites
This site links out to organisations such as the NHS, the HCPC, OCD-UK and charities whose information is worth reading. Once you follow a link you are on someone else’s site and their privacy policy applies. I have no control over how they handle your data and cannot be responsible for it.
15. What happens if you do not give me information
Some information is genuinely necessary. Without a name, contact details and enough clinical history to understand the problem, I cannot assess or treat safely, and I would have to say so rather than proceed. Most other things — whether I write to your GP, whether you complete a particular questionnaire — are yours to decline, and declining them will not be held against you.
16. Changes to this policy
This policy is reviewed periodically and whenever the practice changes something material, such as adding a new system that handles your information. Any updated version is posted on this page with a new effective date at the top. If a change materially affects current clients, I will tell them directly rather than relying on them to notice.
Related pages
This policy is written to be accurate and genuinely useful rather than to be long. It is general information about how this practice handles your data, and it is not legal advice. The practice reviews these documents periodically and updates them when the law or the way the practice works changes.