Privacy policy

1. Introduction

This Privacy Notice explains how ROP Therapy collects, uses, stores and protects your personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and professional obligations relating to psychotherapy practice.

Rebecca Oben-Pepra is registered with the Information Commissioner’s Office (ICO) as a data controller. www.ico.org.uk ICO Registration Number: ZC086111.

Rebecca Oben-Pepra is the Data Controller responsible for the personal information processed as part of providing therapy services.

Your privacy and confidentiality are central to the therapeutic relationship. This notice explains what information is collected, why it is collected, how it is stored, and your rights regarding your personal data.

2. What personal data I collect

In order to provide safe and effective therapy, I may collect and process the following information:

Personal and contact information

  • Name

  • Address

  • Email address

  • Telephone number

  • Date of birth

  • Emergency contact details

 

 Health and therapy information

  • GP details (will only be used with your consent or where there is a safeguarding concern requiring action)

  • Relevant personal history

  • Presenting difficulties

  • Mental Health information

  • Therapy session notes

  • Information you chose to share during therapy

Administrative information

  • Appointment details

  • Payment records

  • Correspondence by e-mail, telephone, text message, Whatsapp or voicemail.

  • Insurance or referral information where applicable.

3. Lawful basis for processing

Under UK GDPR, the lawful bases I rely on for processing your data are:

  • Contract – to provide therapy services, manage appointments and communicate with you.

  • Legitimate interests – to maintain appropriate clinical records, manage my professional practice and ensure safe therapeutic care.

  • Legal obligation – where safeguarding or legal duties (e.g. court orders) apply

  • Consent – where explicitly required (e.g. contacting your GP)

Because therapy records contain health and sensitive personal information, which is classed as special category data under UK GDPR, I process this information under the relevant UK GDPR conditions relating to healthcare provision and the management of healthcare services.

4. How your Information is stored and protected

I take appropriate technical and organisational measures to protect your personal information.

Records may be stored in:

  • Secure paper files stored in locked storage

  • Password‑protected electronic devices

  • Secure digital systems

  • Encrypted services where available.

I regularly review my data security arrangements and take all reasonable steps to Prevent unauthorised access, loss, misuse, or disclosure of personal information. Email is not completely secure, and clients should avoid including sensitive personal information in emails unless necessary.

I use trusted third-party service providers to support my practice administration. These providers act as data processors and only process information on my instructions. Examples may include secure email providers, accounting services and insurance billing platforms. Some providers I use may process data outside the UK. Where this occurs, I ensure appropriate safeguards are in place in accordance with UK GDPR requirements. I currently use: Zoom, Gmail, Microsoft Teams, Google Meets and Healthcode.

5. Confidentiality and its limits

Everything you share in therapy is confidential. However, confidentiality may be broken if:

  • There is a serious risk of harm to you or another person

  • A safeguarding concern arises involving a child or vulnerable adult

  • I am required by law or court order to disclose information

Where possible, I will discuss any disclosure with you before taking action.

Where there are concerns relating to the safety of a child or vulnerable adult, information may be shared with appropriate agencies without consent where there is a legal or ethical requirement to do so.

6. Supervision

As part of good clinical practice, I partake in regular professional supervision. Aspects of our therapeutic work may be discussed within supervision in an anonymised manner, with all identifying details removed. My clinical supervisor and peer-supervisor are bound by confidentiality and adhere to the BACP Ethical Framework.

7. How long I keep your data

  • Therapy records are retained for 7 years after the end of therapy. This includes clinical notes, administrative records, relevant correspondence and payment records where required.

  • After this period, records are securely destroyed

This retention period follows professional and insurance guidance.

 

8. Sharing your data

Your personal information will not be shared with third parties without your consent, except where required by law or for safeguarding reasons.

I do not sell or use your data for marketing purposes.

Information may be shared in the following circumstances:

Healthcare and professional purposes:

Where appropriate and with your consent, information may be shared with:

·      Your GP

·      Other healthcare professionals involved in your care

Insurance funded therapy and Third-Party Referrals:

If therapy is funded through a private medical insurer or a third-party referral company, relevant administrative information may be shared for the purpose of authorising and processing sessions.

This may include:

·      Your name

·      Claim information

·      Session dates

·      Number of sessions authorised

·      Billing information

·      End of therapy report

9. Your rights

Under UK GDPR, you have the right to:

  • Request access to the personal data I hold about you

  • Request correction of inaccurate data

  • Request erasure of your data (where applicable)

  • Restrict or object to processing

  • Make a complaint to the Information Commissioner’s Office (ICO) [www.ico.org.uk](https://www.ico.org.uk/)

Some rights may be limited due to legal and professional obligations.

10. Contact and complaints

If you have any questions about this Privacy Notice or how your data is handled, please contact me directly:

Email: Rebeccaobenpepra@gmail.com

If you are not satisfied, you have the right to complain to the Information Commissioner’s Office:

Information Commissioner’s Office (ICO)

Website: www.ico.org.uk
Telephone: 0303 123 1113

11. Website enquiries

If you contact me via my website or email, your details will be used solely to respond to your enquiry and will not be retained unnecessarily if therapy does not proceed. Website enquiries are normally deleted after 6 months if therapy does not commence, unless there is a legitimate reason to retain them.

I aim to respond to enquiries within 2–3 working days.

12. Security breach notification

If a personal data breach occurs, I will assess the risk and take appropriate action, including notifying the ICO and affected individuals where legally required.

13. Payments and financial records

If you pay for sessions by bank transfer (BACS), any identifying information used may appear within my Banking Records. Receipts and payment records may include your name and details of payments made.

Financial records are retained in accordance with HMRC requirements and may be accessed by my Accountant or HMRC where legally required.

Where third parties pay for your sessions (e.g. insurance providers or referral companies), I will use their systems to invoice.

 

14. International Transfers

Some digital service providers may process information outside the UK. Where this occurs, I ensure appropriate safeguards are in place in accordance with UK GDPR requirements.

This Privacy Notice may be updated from time to time. Clients will be informed of any significant changes.