Introduction
The Yellow Room Therapy is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, and store your personal information. It applies when you visit our website, contact us, or use our therapy services.
Who We Are
The Yellow Room Therapy is a therapy practice based in the UK. We are a registered member of the Information Commissioner's Office (ICO) and comply with the UK General Data Protection Regulation (GDPR) and the Data Protection Act 2018.
Information We Collect
We may collect and process the following personal data:
- Personal Information: Your name, email address, phone number, postal address, and other contact details when you contact us via our website or to arrange therapy sessions.
- Health Information: Sensitive personal information, including health data, that you share with us during therapy sessions.
- Website Usage Information: Information about how you interact with our website, including IP addresses, browser type, and browsing behaviour (collected via cookies, with your consent).
How We Use Your Information
We may use your personal information for the following purposes:
- To provide therapy services in accordance with our contract.
- To contact you regarding appointments, changes to services, or other necessary communications.
- To maintain accurate and secure records of your therapy.
- For legal, regulatory, and safeguarding obligations where applicable.
- To improve our website and the services we offer.
Legal Basis for Processing
We process your personal data under the following legal bases:
- Consent: For any data you explicitly agree to provide (e.g., subscribing to newsletters).
- Contract: To deliver therapy services you have requested.
- Legal Obligation: Where we are required by law to process certain data (e.g., safeguarding or tax obligations).
- Legitimate Interests: To operate our business effectively, such as scheduling appointments or keeping records, while ensuring minimal impact on your privacy.
Sharing Your Information
We will not share your personal data with third parties for marketing purposes. We may share your information with:
- Therapy Supervisors: On a need-to-know basis, strictly for professional supervision.
- Safeguarding Authorities: In cases where there is a duty to disclose for safeguarding purposes.
- IT and Website Providers: For the secure hosting and maintenance of our website and electronic records.
We ensure that all third parties comply with UK GDPR regulations.
Data Retention
We will retain your personal information only as long as necessary:
- Therapy records will be kept for a minimum of 7 years after your last session, as required by our professional regulatory body.
- Website usage data is retained according to our cookie policy, which you can review on our website.
Your Data Rights
Under the UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Rectify any inaccurate or incomplete data.
- Request Erasure of your data, unless we are legally required to retain it.
- Restrict Processing of your data in certain circumstances.
- Data Portability, to receive a copy of your data in a structured, commonly used format.
- Withdraw Consentwhere we rely on consent to process your data.
To exercise any of these rights, please contact us at theyellowroomtherapy@outlook.com
Security
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse. All sensitive health data shared during therapy is stored securely in encrypted files, and we comply with confidentiality obligations.
Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page, and where necessary, we will notify you via email or other communication channels.
Contact Us
If you have any questions about this Privacy Policy or how we handle your data, please contact:
The Yellow Room Therapy
theyellowroomtherapy@outlook.com
If you believe we have not handled your data correctly, you have the right to contact the Information Commissioner’s Office (ICO): [www.ico.org.uk](https://ico.org.uk).