Privacy Notice

1. Introduction

This privacy policy will inform you of how your personal information is processed from initial point of contact through to after your therapy has ended, including:

  • Why your information is able to be processed and what purpose it is processed for.

  • Whether or not you have to provide your information.

  • How long your information will be stored for.

  • Whether or not there are other recipients of your personal information.

  • Whether or not your information will be transferred to another country.

  • Whether or not automated decision-making or profiling is utilised.

  • What your data protection rights are.

‘Data controller' is the term used to describe the person/organisation that collects, stores and has responsibility for people's personal data. In this instance, the data controller is:

Jonah Woodley trading as Shades of Rose Counselling & Psychotherapy.

Registered with the Information Commissioner’s Office (ZC230918). Postal address: 8 New Street, Wall Heath, DY69AH

Phone number: 07894851640

Email address: [email protected]

If you have any questions about the privacy policy or your data protection please contact me via email at: [email protected]

a. The lawful basis for holding your information

The GDPR states that a business must have a lawful basis for processing your personal data and there are different lawful bases depending on the stage at which your data is being processed. These are as follows:

  • During initial contact and while therapy is taking place:

Your data will be processed where it is necessary for the performance of our contract. This applies to your name, contact details, and any other information shared to enable the counselling service to proceed. If you are considering therapy or are currently having sessions, this lawful basis ensures the service can be delivered as agreed between us.

Special category personal information (such as sensitive disclosures made during sessions relating to your health) is also protected under the GDPR. The lawful basis for processing this type of data is consent initially, combined with the provision of health or social care treatment by a health professional. This means your sensitive information is handled appropriately for the delivery of counselling or psychotherapy services.

  • After counselling has ended:

"Legitimate interests" will be the lawful basis for holding and using your personal information. Records are retained for seven years following the end of sessions to comply with professional body guidance and to defend against any potential legal claims that may arise within the limitation period. Throughout all stages, no personal data is processed without an identifiable lawful basis. If you withdraw consent, this will not affect the lawfulness of processing that occurred prior to withdrawal, but it may affect your ability to continue with therapy.

2. How your information is used

a. Initial contact

When you make contact, the following information will be collected to satisfy your enquiry:

  • Your full name

  • Your email address

  • A phone number

  • Any further information you provide in the contact form or via other communication method.

Alternatively, any other person or organisation who makes a referral on your behalf may disclose your information. If it is decided that our work together does not proceed, your personal information will be deleted within three calendar months and you may request it to be deleted sooner at any time.

b. While you are accessing counselling

While accessing counselling, the contents of our sessions are strictly confidential except in specific circumstances where confidentiality may have to be broken as outlined in the therapy contract you will have signed prior to session commencement. A record of your personal details will be kept to ensure the service runs smoothly and these details will be kept securely behind password protected/encrypted files and will not be shared with any third party.

Minimal written notes will be kept of each session, retained for up to seven years. Any text message or email correspondence will be deleted after six months unless important to retain. If necessary, the contents of important text messages or emails will be transcribed into relevant secure records.

c. After counselling has ended

Your records will be kept for seven years following the end of our counselling sessions and then securely destroyed.

3. Third-party recipients of personal data

a. General third party information

On rare occasions your information may be shared with third parties, for example, when contracted with a supplier to carry out specific tasks. In such cases the third party partners will be thoroughly vetted and contracted with to ensure they do not use your information for any other purpose than the task they have been contracted for.

b. Clinical supervision

To satisfy commitments to the BACP Ethical Framework and to ensure safe and effective practice, clinical supervision is undertaken. Work with clients is discussed with a supervisor in order to receive guidance, education, feedback and other support to maintain the quality of counselling services. Clinical supervisors are bound to the same confidentiality commitments as counsellors, and care is taken to minimise personal identification of clients discussed.

c. Digital Data Storage and Regulation

Encrypted digital services are used to store and process client information in the provision of counselling services. The primary service provider is Proton, a Swiss-based company headquartered in Geneva, Switzerland. Proton operates under Swiss privacy law, which provides some of the strongest data protection safeguards globally, shielding user data from US, EU, and UK surveillance jurisdictions. Specific services utilised include:

  • Proton Drive – Client notes, contracts, intake forms, and related documentation are stored in separate encrypted folders on Proton Drive. Files are end-to-end encrypted before leaving the device, meaning no one - not even Proton - can access the content. Proton Drive is ISO 27001 certified and SOC 2 Type II attested, and its endto-end encryption is compliant with GDPR, HIPAA, and CCPA regulations.

  • Proton Meet – Counselling sessions conducted remotely are hosted on Proton Meet, an end-to-end encrypted video conferencing service. Meetings utilise Messaging Layer Security (MLS) encryption, ensuring that audio, video, and chat content remains confidential. Meeting content is not collected for AI training, advertising, or third-party access.

  • Proton Mail – All email communications with clients are transmitted via Proton Mail, which implements zero-access encryption and end-to-end encryption by default. This ensures that neither Proton nor any third party can read the contents of correspondence.

  • Proton Sheets – Administrative records, scheduling, and session tracking are managed using Proton Sheets, which provides the same end-to-end encryption and zero-access architecture as the rest of Proton's ecosystem.

Proton's overarching security stance is founded on zero-access encryption and end-to-end encryption by default. This means that even in the event of a data breach or legal demand for data disclosure, only encrypted data exists on Proton's servers - the company does not possess the technical means to decrypt user content. Proton is also open-source and independently audited for transparency.

Create.net is the web host used to collect enquiries from the Shades of Rose website. Any data collected from the enquiry form on the website is held behind the password & 2FA protected web host for 30 days, during which it will be sent via email to your counsellor for the purpose of responding to your enquiry.

Regulation by the Information Commissioner's Office (ICO) in the United Kingdom applies, and registration under the UK General Data Protection Regulation (UK GDPR) is maintained. While Proton is based outside the UK/EU, the use of end-to-end encryption means that personal data is effectively pseudonymised at the point of storage and transmission, providing enhanced protections beyond standard data transfer mechanisms.

4. Your rights

You have the right to request that your personal data is deleted or edited/updated. You have the right to request that your personal data is no longer processed or to limit how your personal information is used. You have the right to request a copy of any information held about you and to object to the use of your personal data in some circumstances.

If a subject access request (SAR) is made, it will be fulfilled within one calendar month (30 days) (some exceptions apply).

If you would like to make any of these requests or have any concerns or questions about how your personal data is being processed please make contact at [email protected]

If you have any complaint about how I handle your personal data please do not hesitate to get in touch with me by writing or emailing to the contact details given above. I would welcome any suggestions for improving my data protection procedures.

If you want to make a formal complaint about the way I have processed your personal information you can contact the ICO which is the statutory body that oversees data protection law in the UK. For more information go to https://ico.org.uk/make-a-complaint.

5. Data security

a. Data security general information

Data security is taken incredibly seriously and every effort is made to ensure your data is stored securely. Your data is only kept in digital records on encrypted/password protected devices with no physical records being kept.

b. Data breach information

Should a personal data breach occur, the ICO will be notified within 72 hours of becoming aware of the breach, where feasible, in accordance with UK GDPR requirements. You will be informed without undue delay if the breach is assessed as likely to result in a high risk to your rights and/or freedoms. Given that counselling records constitute special category data under the UK GDPR, greater caution is applied in breach assessment and notification decisions.

A documented response process is maintained to ensure that any suspected breach is identified, contained, investigated, and recorded appropriately. Steps taken include immediate containment of the incident, assessment of the scope and impact, determination of whether notification is required, implementation of remedial measures to prevent recurrence, and provision of relevant information to affected parties. For clients concerned that their data may have been compromised, contact can be made with me directly via email or phone number. Alternatively, complaints may be logged with the ICO at https://ico.org.uk/concerns/. All security incidents are logged internally, and lessons learned are implemented to strengthen ongoing data protection practices.

6. Additional information

Like most websites, cookies are used to help the site work more efficiently. Some cookies are essential (required for the website to function properly and are always active), with others being optional, allowing you to opt out.

No user-specific data is collected. If you fill out a form on this website, your data will be temporarily stored on the web host (Password protected Create.net account) for 30 days after being sent to your counsellor.

Last updated: 21.09.2026


In Need of Urgent Help?

If in need of urgent mental health support call:

The non-emergency services: 111 or contact your GP

The emergency services: 999

The Samaritans: 116 123

Text SHOUT to 85258