PRIVACY NOTICE
Privacy notice – Cherry on Top Hypnotherapy Services
This notice was last updated April 2026
Privacy Notice
I take your privacy seriously and follow UK GDPR, the Data Protection Act 2018, and the AfSFH Ethical Framework. This summary explains how your information is used when you work with me.
What information I collect
To provide safe and effective hypnotherapy, I collect:
- Your contact details
- Basic information about important others (e.g., emergency contact)
- Your goals for therapy and brief session notes
- Relevant medical information, including your GP details
I only collect what is necessary for your care.
Lawful basis for processing
I process your personal data under Legitimate Interests, as it is required to provide hypnotherapy safely and responsibly.
Any health‑related or special category information is processed under Explicit Consent, which you provide before or during our initial consultation.
How your information is stored
Your information is kept securely:
- Digital files are encrypted and password‑protected
- Paper notes are stored in a locked cabinet
- Initials or case numbers are used wherever possible
I never share your information without your written consent unless required by law or duty of care.
How long I keep your information
In line with AfSFH and insurance requirements:
- Adults: Records are kept for 8 years after your final session
- Children/young people:
- Until their 25th birthday, or
- Until their 26th birthday if therapy ended at age 17
Records are securely destroyed in the January following the retention period.
Your rights
You have the right to:
- Request a copy of your data
- Ask for corrections
- Withdraw consent for contact
- Request deletion (after the minimum retention period)
I will respond to data requests within 30 days.
Confidentiality
Everything you share is confidential. The only exceptions are:
- Serious risk of harm to yourself or others
- Legal requirements (e.g., police warrant)
- Professional supervision (no identifying details are shared)
If we meet outside sessions
To protect your privacy, I won’t approach you unless you approach me first.
Sharing information with other professionals
I will only contact your GP or another professional with your written consent, unless there is a serious safeguarding concern.
Data Controller
Stephanie Martin‑Halls
Church St, Halstead, Essex, CO9 3BA
ICO Registration Number: ZB659294
