top of page

Privacy Policy

Effective Date: July 14, 2026

Last Updated: July 14, 2026

At The Covent Garden CBT Practice, we are committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal and clinical data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. The Data Controller

The Data Controller is Bernadette Ainsworth, trading as The Covent Garden CBT Practice.

2. What Personal Data We Collect

As a psychotherapy practice, we collect two types of data:

A. Personal Data (Basic Information)

  • Your name, date of birth, and contact details (email address, telephone number, home address).

  • Emergency contact/next of kin details.

  • Your GP’s contact details.

B. Special Category Data (Sensitive Health Information)

Under UK GDPR, mental health information is classified as "Special Category Data." This includes:

  • Pre-assessment questionnaires and medical histories.

  • Clinical session notes, treatment plans, and outcomes.

  • Correspondence regarding your care (such as letters to your GP, if explicitly agreed).

3. Our Lawful Basis for Processing Your Data

Under UK GDPR, we must have a lawful basis to hold and process your information. For this practice, those bases are:

  • Contract (Article 6(1)(b)): Processing is necessary to fulfill our contract with you to provide psychological therapy.

  • Health and Social Care (Article 9(2)(h)): Processing is necessary for the provision of health or social care or treatment, specifically managing your psychological therapy.

4. How We Use Your Information

We use your data strictly to:

  • Provide safe, professional, and ethical CBT and REBT therapy.

  • Manage your appointments, billing, and administrative requests.

  • Liaise with other medical professionals (only with your explicit consent, unless in an emergency safeguarding situation).

5. Data Security and Storage

Your privacy is treated with the utmost clinical confidentiality.

  • Digital Records: All digital notes, emails, and contact details are stored on secure, encrypted, and password-protected devices or GDPR-compliant clinical management platforms.

  • Paper Records: Any physical documents are kept in a locked filing cabinet accessible only by Bernadette Ainsworth.

  • Data Sharing: Your data is never sold, leased, or shared with third parties for marketing purposes.

6. How Long We Keep Your Data

In line with professional guidelines (BABCP/BACP) and professional liability insurance requirements in the UK, we retain adult client records for a period of 7 years after the termination of therapy. After this period, all physical and digital records are securely and permanently destroyed.

7. Your Rights under UK GDPR

You hold the following rights regarding your personal data:

  • The Right of Access: You can request a copy of the personal data and session notes we hold about you (known as a Subject Access Request).

  • The Right to Rectification: You can ask us to correct any inaccurate or incomplete information.

  • The Right to Erasure ("Right to be Forgotten"): You can ask us to delete your data, though please note this may be limited by our legal and professional duties to retain clinical records for 7 years.

  • The Right to Restrict Processing: You can ask us to limit how we use your data.

8. How to Complain

If you have any questions or concerns about how your data is handled, please contact Bernadette Ainsworth directly.

If you remain unsatisfied with our response, you have the right to lodge a complaint with the UK supervisory authority:

  • Information Commissioner’s Office (ICO)

  • Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

  • Website: ico.org.uk

bottom of page