Last updated: 29th June 2026
Your privacy is very important to me, and you can be confident that your personal information will be kept safe and secure, and used only for the purposes it was provided for. I comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
This notice explains what happens to your personal information, from your first point of contact with me through to after our work together has ended, including:
why I'm able to process your information, and for what purpose
whether you have to provide it to me
how long I keep it for
whether anyone else receives it, including anywhere outside the UK
whether I carry out any automated decision-making or profiling
your data protection rights
I'm happy to talk through any questions about this notice — you can reach me by email at ilbarrand@outlook.com.
The "data controller" is the person responsible for deciding how and why your personal information is processed. In this case, that's me, Isabella Barrand, trading as Isabella Barrand Counselling & Clinical Supervision. I am registered with the Information Commissioner's Office (registration number ZB671878). I do not have a Data Protection Officer (DPO). As a sole practitioner, I am not required to appoint one under UK GDPR. I handle all data protection matters personally.
UK GDPR requires me to have a lawful basis for processing your personal data, and this differs depending on the stage of our contact:
Initial enquiry: when you first get in touch, I process your details on the basis of legitimate interests — to respond to your enquiry and work out whether I can help. I have carried out a Legitimate Interests Assessment and am satisfied that this interest is balanced against your rights and freedoms.
While we are working together: I process your personal data because it is necessary for the performance of our contract for counselling services.
Special category data (for example, information about your mental health or other sensitive matters shared in session): processing is carried out under substantial public interest for the purposes of health care provision, in accordance with Schedule 1, Part 1 of the Data Protection Act 2018. This is the appropriate lawful basis for health records that I am professionally required to maintain.
After our work together ends: I retain your records on the basis of legitimate interests — specifically, to comply with my professional body's guidance and my insurance provider's requirements. I have carried out a Legitimate Interests Assessment and am satisfied that this interest is balanced against your rights and freedoms. Where special category data is retained, the additional condition relied upon is substantial public interest for health care purposes (DPA 2018, Schedule 1, Part 1), as well as the establishment, exercise, or defence of potential legal claims.
When you contact me with an enquiry, I'll collect information to help respond to it. This might come directly from you, via a referral from a GP or other health professional, or from a trusted person making an enquiry on your behalf.
If you decide not to go ahead, I will delete your personal data within six months. If you'd like it deleted sooner, just let me know.
Everything you share with me is confidential. The only routine exception is that I discuss my work anonymously with my clinical supervisor, as all counsellors are required to have regular supervision to keep their work safe, ethical, and effective. My supervisor is bound by the same confidentiality requirements as I am, and by BACP's ethical framework.
Confidentiality will only be broken without your knowledge if I believe there's an immediate risk to your safety or someone else's, or where I'm required to by law (i.e., in relation to terrorism, drug trafficking and money laundering). Wherever possible, I will talk to you about this first.
I keep a record of your personal details and written notes from each session, stored securely on Google Workspace. I don't retain text messages or emails for long after they're received — anything relevant is transferred into this system and the original message is then deleted.
As required of all counsellors, I hold a Clinical Will, setting out what should happen to my client records, and how clients should be informed, if something happened to me and I were unable to tell you myself. My supervisor (or a nominated fellow counsellor if they're unavailable) is the executor of this, and would, in that situation only, have access to your contact details in order to inform you.
Records may include your contact details, contracts, session notes, and relevant correspondence. These are kept for 7 years from the end of our work together, and then securely destroyed.
Financial records, such as invoices issued, payment records and receipts, are retained for 5 years following the 31 January submission deadline of the relevant tax year, in line with HMRC's record-keeping requirements for sole traders. The lawful basis for retaining these specific records is legal obligation.
If you'd like your information deleted sooner than this, let me know and I will action this unless I'm required to retain it for legal reasons.
Where I use a service to support a session, take a payment, or manage a booking, that service will process some of your personal data on my behalf. Currently these include:
Google Workspace (Google Drive, Docs and Sheets) — I use this to write and store clinical notes and to hold emergency contact details. Data is held within a password-protected Workspace account. Google LLC is a US-based company and transfers are covered by Standard Contractual Clauses.
Microsoft Outlook — I use this for scheduling and calendar management. Your name, email address and appointment details may be stored here. Microsoft Corporation is a US-based company and transfers are covered by Standard Contractual Clauses.
Cal.com — I use this for appointment scheduling. When you request an intro call or make a booking, your name and contact details are collected through the Cal.com platform. I use Cal.com's European servers, meaning your data is stored and processed within Europe. You can view their privacy policy at cal.com/privacy.
Starling Bank — for processing session fees. Your bank account details or payment information are handled directly by Starling Bank and are not stored by me.
Google Meet or Microsoft Teams — for online sessions. These platforms may process connection data during the session. I do not record sessions.
None of these providers use your data for their own marketing purposes, and none of your information is sold to anyone.
Some of the providers listed above may store or process data outside the UK (for example, in the US). Where this happens, I only use providers that offer a safeguard recognised under UK GDPR, such as the UK extension to the EU–US Data Privacy Framework or standard contractual clauses. You can ask me for more detail about a specific provider's safeguards at any time.
I do not use any automated decision-making or profiling in relation to your personal data.
I take the security of your information seriously. This includes keeping records on platforms that use encryption and multi-factor authentication, restricting day-to-day access to your information to myself only, and reviewing my security practices regularly.
You have the right to:
ask for a copy of the information I hold about you
ask me to correct anything that's inaccurate
ask me to delete your information
ask me to restrict how I use it, or object to its use
ask for it in a portable format, where relevant
To make a request, please email ilbarrand@outlook.com. I won't charge for this unless the request is excessive, and I will ask you to verify your identity first. You can read more about your rights at ico.org.uk/your-data-matters.
Step 1 — Contact me first
If you have a concern about how I have handled your personal data, please raise it with me directly in the first instance by emailing ilbarrand@outlook.com.
Please describe your concern clearly so I can look into it properly. I will acknowledge your email within 5 working days and provide a full response within 30 days.
Step 2 — Escalate to the ICO
If you are not satisfied with my response, or if I fail to respond within 30 days, you have the right to escalate your complaint to the Information Commissioner's Office (ICO), the UK's independent supervisory authority for data protection.
You can contact the ICO:
Online: ico.org.uk/make-a-complaint
By phone: 0303 123 1113 (Monday–Friday, 9am–5pm)
By post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
The ICO will expect you to have raised your concern with me first before they investigate.
I will update this notice from time to time as required by changes in the law or my practice. The date at the top of the page reflects when it was last revised.
© 2022-2026 Isabella Barrand (Isabella Barrand Counselling & Clinical Supervision)