PRIVACY POLICY
Privacy policy for Fellside Therapy
Last updated: June 2026
Who I am
Fellside Therapy is the private practice of Ella Smith. For the purposes of data protection law, I am the “data controller” for the personal information you share with me.
Contact details
Email: ella@fellsidetherapy.co.uk
What information I collect
If you contact me via my website form, email, phone, or in writing, I may collect:
Your name
Your email address and phone number
The content of your message
Basic scheduling information (appointment times, availability)
Any information you choose to share about what you are looking for
If we work together, I may also collect:
Administrative records (appointments, invoices, payments)
Session notes (brief notes for my own professional use)
Any relevant information you choose to share in sessions
Important note
Please avoid including highly sensitive personal information in the website contact form. There will be time to discuss anything important properly and confidentially once we have agreed to work together.
How I use your information
I use your information to:
Respond to enquiries and arrange appointments
Provide counselling and psychotherapy sessions
Maintain appropriate professional records
Manage fees, invoices and payments
Meet professional, ethical, and insurance requirements
Respond to complaints or concerns if needed
My lawful basis for processing
Under UK GDPR, I process personal data on the following lawful bases:
Legitimate interests: to respond to enquiries and manage my practice
Contract: to provide therapy services once agreed
Legal obligation: where I must keep records for legal, tax, or insurance reasons
Special category data: therapy-related information is usually “special category” personal data; where this applies, I process it because it is necessary for the provision of health or social care (or related support) and is handled with appropriate safeguards, and because you have provided it in the context of therapy
How your information is stored
Website contact form
My website is hosted by Squarespace. When you submit a contact form, the information is sent to me (typically via email) and may also be stored within my Squarespace account depending on my settings.
Email and documents
I receive messages via Gmail. I store necessary practice documents in a secure manner and limit access to them.
Online sessions
Online sessions are delivered via Zoom. I do not record sessions. If you use Zoom, your device and Zoom may process certain technical data to deliver the service. Please see Zoom’s own privacy information for further details.
Therapy practice management system
I use Kiku as my therapy practice management system. Kiku is used to help me manage client records, appointments, consent forms, therapy notes, invoices and other practice administration.
For the purposes of data protection law, I remain the data controller for the personal information I hold about you. Kiku acts as a data processor, meaning it processes information on my behalf and only in line with its contractual obligations and my instructions.
Kiku states that it is GDPR compliant as a data processor. Its platform uses encryption, password protection and two-factor authentication, and its systems are hosted on AWS Ireland servers. I use Kiku because it provides secure, therapy-specific practice management tools suitable for handling confidential client information.
Access to client records within Kiku is restricted to me and protected by login security. I only store information that is necessary for the provision, administration and record keeping of therapy services.
Payments and financial records
Payments are made by BACS directly into my business bank account. I do not collect or store client card details, and I do not use a third-party payment processor.
For payment administration, I may keep basic payment records, such as your name, invoice number, payment date, payment amount and whether an invoice has been paid. These records are used for invoicing, accounting, tax and practice administration.
Where payment or invoice records are stored in Kiku, my therapy practice management system, they are handled as part of my secure client administration records. Bank transaction records are also held by my bank in the usual way.
I may share limited financial and accounting records with my accountant, bookkeeper, bank, HMRC, or other relevant financial, tax, legal or regulatory authorities where this is necessary for accounting, tax, legal or regulatory purposes. I will only share the information needed for that purpose. For payment, invoicing, accounting and tax records, my lawful bases are that processing is necessary for the performance of our contract and, where relevant, to comply with legal obligations relating to accounting, tax and financial record keeping.
How long I keep your information
I keep personal information only for as long as necessary for the purpose it was collected. Typical retention periods:
Enquiries that do not become clients: 12 months, then deleted
Client administrative records (appointments, invoices): 6 years for tax and accounting purposes
Clinical notes: retained for a period consistent with professional standards and insurance guidance; 6 years after therapy ends.
You can ask for more detail about retention when you contact me.
Who I share your information with
I may share information only when necessary and appropriate, for example:
With my clinical supervisor, in anonymised or carefully limited form, as part of safe professional practice
With my insurer or professional adviser if required
If required by law, or where there is a serious risk of harm and disclosure is necessary to protect you or someone else
Confidentiality and its limits
Therapy is confidential, but confidentiality is not absolute. I may need to share information without your consent if:
There is a serious risk of harm to you or someone else
A child or vulnerable adult is at risk of serious harm
I am required to disclose information by law or court order
If possible, I will aim to discuss this with you first.
Your rights
You have rights under UK GDPR, including the right to:
Access your personal data
Request correction of inaccurate information
Request deletion in some circumstances
Object to certain processing
Request restriction of processing in some circumstances
Data portability in some circumstances
To exercise your rights, contact me using the details above.
How to complain about data protection
If you have a concern about how I collect, use, store, share, retain or delete your personal information, you can make a data protection complaint directly to me.
You can do this by emailing me at ella@fellsidetherapy.co.uk, using the contact form on this website, or raising it with me in session if you are already a client.
To help me respond, please include:
- your name and contact details
- a brief description of your concern
- any relevant dates
- what outcome you are seeking, if you know
Please avoid sending more sensitive personal information than is needed to explain the concern.
I will acknowledge receipt of your data protection complaint within 5 working days wherever possible, and always within 30 calendar days of receiving it. I will make appropriate enquiries without undue delay, keep you informed where further time is needed, and tell you the outcome of my response.
If I need to confirm your identity before responding, I will ask for only the information reasonably needed to do this. If someone complains on your behalf, I may need evidence that they have authority to act for you.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK regulator for data protection. In most cases, the ICO will expect you to raise the issue with me first so I have the chance to respond.
Data protection complaints
If your complaint is about how I handle your personal information, this will be treated as a data protection complaint.
You can make a data protection complaint by email, through the website contact form, or by raising it with me directly. You do not have to use legal language. It is enough to explain what you are concerned about and what you would like me to look into.
I will acknowledge your complaint within 5 working days wherever possible, and always within 30 calendar days. I will look into the concern without undue delay, keep you informed if I need more time, and explain the outcome once I have reviewed it.
I may need to confirm your identity before responding, particularly if the complaint involves access to, correction of, deletion of, or disclosure of personal information. If someone is complaining on your behalf, I may ask for evidence that they have your authority to do so.
If you remain unhappy after I have responded, you can raise the matter with the Information Commissioner’s Office (ICO), the UK regulator for data protection.
Changes to this policy
I may update this privacy policy from time to time. The latest version will be published on my website

