Privacy Policy
Last updated: 12/09/2026
Nurturing Branch Therapy
Privacy Policy
I, Judit Acsai, am a qualified counsellor registered with the British Association for Counselling and Psychotherapy (BACP), I am the owner of the website Nurturing Branch Therapy. I am the data controller for the personal data described in this policy and am registered with the Information Commissioner's Office (ICO), registration number ZB967298.
If you have any questions about this policy or how I handle your personal data, please contact me by email provided to you after you contacted me.
Nurturing Branch Therapy customer privacy notice
This privacy notice tells you what to expect me to do with your personal information.
-
Contact details
-
What information I collect, use, and why
-
Lawful bases and data protection rights
-
Where I get personal information from
-
How long I keep information
-
Who I share information with
-
Sharing information outside the UK
-
How to complain
Contact details - Email
Judit[at]nurturingbranch.co.uk (replace [at] with @ when emailing)
What information I collect, use, and why
I collect or use the following information:
-
Contact details - name, address, telephone number, and email address
-
Gender
-
Date of birth
-
Next of Kin details (Emergency use only)
-
Health information (including medical conditions)
-
Session notes; my clinical notes from our sessions
-
Consent records - records of the consent you gave for therapy
-
Payment records - invoices and records of payments received
-
Safeguarding records - any records relating to safeguarding concerns, disclosures, or referrals
Article 6(1)(b) UK GDPR; processing is necessary for the performance of the therapeutic contract between us. When you engage me as your therapist we enter into a contract for therapy services, and I need to process your personal data to fulfil that contract; including keeping records, arranging appointments, and providing therapy itself.
Special category (health) data
Article 9(2)(h) UK GDPR — processing is necessary for the provision of health or social care treatment by a health professional. As a qualified counsellor I am subject to obligations of confidentiality under the BACP Ethical Framework for the Counselling Professions.
The additional condition required under UK law is met through the Data Protection Act 2018, Schedule 1, Part 1, paragraph 2 (health or social care). This applies because the processing is carried out by a health professional who is bound by professional confidentiality obligations.
Lawful bases and data protection rights
Under UK data protection law, I must have a “lawful basis” for collecting and using your personal information. There is a list of possible lawful bases in the UK GDPR. You can find out more about lawful bases on the ICO’s website.
Which lawful basis I rely on may affect your data protection rights which are set out in brief below. You can find out more about your data protection rights and the exemptions which may apply on the ICO’s website:
-
Your right of access - You have the right to ask me for copies of your personal information. You can request other information such as details about where I get personal information from and who I share personal information with. There are some exemptions which means you may not receive all the information you ask for. Read more about the right of access.
-
Your right to rectification - You have the right to ask me to correct or delete personal information you think is inaccurate or incomplete. Read more about the right to rectification.
-
Your right to erasure - You have the right to ask me to delete your personal information. Read more about the right to erasure.
-
Your right to restriction of processing - You have the right to ask me to limit how I can use your personal information. Read more about the right to restriction of processing.
-
Your right to object to processing - You have the right to object to the processing of your personal data. Read more about the right to object to processing.
-
Your right to data portability - You have the right to ask that I transfer the personal information you gave me to another organisation, or to you. Read more about the right to data portability.
-
Your right to withdraw consent – When I use consent as my lawful basis you have the right to withdraw your consent at any time. Read more about the right to withdraw consent.
If you make a request, I must respond to you without undue delay and in any event within one month.
To make a data protection rights request, please contact me using the contact details at the top of this privacy notice.
Lawful bases for the collection and use of your data
Lawful bases for collecting or using personal information in Counselling are:
-
Consent - I have permission from you after I have given you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.
-
Contract – I have to collect or use the information so I can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
-
Legal obligation – I have to collect or use your information so I can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object and the right to data portability.
-
Vital interests – collecting or using the information is needed when someone’s physical or mental health or wellbeing is at urgent or serious risk. All of your data protection rights may apply, except the right to object and the right to portability.
Where I get personal information from
-
Directly from you
How long I keep information
Type of Record: Client therapy records
How Long I Keep It: 7 years after our last session
Reason: Limitation Act 1980 and professional indemnity insurance requirements
Type of Record: Enquiries from people who do not become clients
How Long I Keep It: 12 months after last contact
Reason: To respond to follow-up enquiries and for legitimate record-keeping
Type of Record: Financial records and invoices
How Long I Keep It: 6 years after the transaction
Reason: HMRC legal requirement
Type of Record: Insurance records
How Long I Keep It: 7 years
Reason: Professional indemnity insurance requirements
After the applicable retention period ends, paper records are securely destroyed and electronic records are permanently deleted. I cannot delete your records before the end of the applicable retention period, even if you request this, as retention is required by professional guidelines, insurance requirements, and/or law.
Records are stored securely: electronic records on password-protected devices with access restricted to me, and any paper records in a locked cabinet in a secure location.
For more information on how long I store your personal information or the criteria I use to determine this please contact me using the details provided above.
Who I share information with
Data processors
Google Mail
This data processor does the following activities for me: Store and process email transmissions.
Wix
This data processor does the following activities for me: Website host/provider. Forwards contact message and form details to Gmail, and retains a record of the messages and contact details.
Google Meet
Video platform used for online therapy sessions.
Each of these services is bound by a data processing agreement (where applicable) and operates under its own privacy policy. Links are available on request.
Others I may share personal information with
-
Organisations I need to share information with for safeguarding reasons
-
Emergency services
-
Clinical Supervisors
Duty of confidentiality
I am subject to a common law duty of confidentiality. However, there are circumstances where I will share relevant health and care information. These are where:
-
you’ve provided me with your consent (I have taken it as implied to provide you with care, or you have given it explicitly for other uses);
-
I have a legal requirement (including court orders) to collect, share or use the data;
-
on a case-by-case basis, the public interest to collect, share and use the data overrides the public interest served by protecting the duty of confidentiality (for example sharing information with the police to support the detection or prevention of serious crime);
-
If in England or Wales – the requirements of The Health Service (Control of Patient Information) Regulations 2002 are satisfied; or
-
If in Scotland – I have the authority to share provided by the Chief Medical Officer for Scotland, the Chief Executive of NHS Scotland, the Public Benefit and Privacy Panel for Health and Social Care or other similar governance and scrutiny process.
Sharing information outside the UK
The platforms that I use (“data processors”) such as Wix, Gmail and Google Meet may transfer personal data outside of the United Kingdom, including to the United States. Where this happens, it is either reliant on a UK adequacy decision, or in some cases on Standard Contractual Clauses (SCCs) or International Data Transfer Agreements (IDTAs) as appropriate safeguards, in line with UK GDPR Chapter V and the Data (Use and Access) Act 2025. You can request a copy of the relevant safeguards by contacting me.
For further information or to obtain a copy of the appropriate safeguard for any of the transfers below, please contact me using the contact information provided above.
Organisation name: Google (Gmail; Meet)
Category of recipient: Email hosting service; video communications platform
Country the personal information is sent to: United States
How the transfer complies with UK data protection law: The country or sector has been assessed as providing adequate protection to data subjects (also known as Adequacy Regulations or UK data bridge)
Organisation name: Wix
Category of recipient: Website host and service provider
Country the personal information is sent to: Israel / Europe and/or United States
How the transfer complies with UK data protection law: The country or sector has been assessed as providing adequate protection to data subjects (also known as Adequacy Regulations or UK data bridge)
How to complain
If you have any concerns about my use of your personal information, you can make a data protection complaint to me:
Email: judit[at]nurturingbranch.co.uk
If you remain unhappy with how I’ve used your data after raising a complaint with me, you can also complain to the ICO.
The ICO’s address:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113
Website: https://www.ico.org.uk/make-a-complaint
Website Cookies
What are cookies?
Cookies are small pieces of data stored on a site visitor's browser. They are typically used to keep track of the settings users have selected and actions they have taken on a site.
How are cookies used on this website?
This website may use basic cookies to support functionality or anonymous analytics. Cookies do not collect personal information unless you choose to provide it. The cookies present on the Nurturing Branch Therapy website arise from the essential functioning of the website, as hosted on the Wix platform.
A list of expected cookies and their purpose is provided below.:
Changes to This Policy
This policy may be updated from time to time. The most recent version will always be available on this website.