Privacy Policy

Privacy Notice

Ros Dodd Wellbeing  ·  Last updated: 28 July 2026

1. Who I am

Ros Dodd Wellbeing is the trading name of Ros Dodd, a sole trader providing hypnotherapy and integrative psychotherapy services. I am registered with the Information Commissioner's Office (ICO) as a data controller, registration number ZB533993.

For any questions about this notice or how your data is handled, contact me at:

ros@rosdodd.com 

Ros Dodd Wellbeing, Pembroke House, 18 The Crescent, Leatherhead, Surrey, KT22 8EE

2. What information I collect

  • Contact details (name, email, phone, address) via the client intake form and booking system

  • Health and therapy-related information you share at intake and during sessions, including presenting concerns, relevant medical or psychological history, and clinical session notes

  • For clients seen between the ages of 16 and 18: date of birth and, where relevant, a parent or guardian's contact details

  • Payment information (processed via my payment/booking provider — I do not store card details myself)

  • Correspondence between us, such as emails and messages

3. Why I process your data, and my lawful basis

I process your personal data:

  • To provide therapy/hypnotherapy services to you — necessary for our contract (Article 6(1)(b) UK GDPR)

  • Because most of what you share is health-related ‘special category’ data, I rely on the condition for provision of health or social care by a health professional under a duty of confidentiality (Article 9(2)(h)), and/or your explicit consent (Article 9(2)(a)), which I'll ask you to confirm at intake

  • To meet my legal and professional obligations, e.g. under the CNHC Code of Conduct, Performance and Ethics, and safeguarding law (Article 6(1)(c))

  • For legitimate business purposes such as invoicing and practice administration (Article 6(1)(f))

4. Special category (health) data

Because therapy involves discussing your mental and physical health, most of the data I hold about you is special category data under UK GDPR. I only use it to provide your care, for anonymised clinical supervision, and to meet my legal and professional obligations — never for marketing or any unrelated purpose.

5. How your data is stored and kept secure

  • Client records are held in Konfidens, an encrypted practice management system, with data encrypted both in transit and at rest

  • Some correspondence takes place by email

  • Appointments are held in a locked, access-controlled calendar

I take reasonable technical and organisational steps to keep your information secure and limit access to it to what's necessary for your care.

6. Who I share your data with

  • My clinical supervisor, for the purpose of case supervision — discussed on an anonymised or pseudonymised basis wherever possible

  • Konfidens, as the processor hosting my client records

  • SUMUP - payment provider

  • Squarespace: website and booking platform, if you have booked via there

  • Gmail workspace: email provider. 

  • Professional bodies (such as the CNHC) or legal authorities, only where required by law, a safeguarding duty, or a court order

I do not sell your data, and I do not share it for marketing purposes.

7. If you are aged 16–18

If you are 16 or 17, the law generally recognises your right to consent to your own treatment. At intake, we'll agree — and I'll record — how much, if anything, is shared with a parent or guardian. This is separate from my safeguarding duty, which may require me to share information without consent where there is a risk of serious harm to you or someone else.

8. How long I keep your data

  • Adult clients: records are retained for 7 years after the end of therapy, in line with professional guidance, then securely destroyed

  • Clients seen between the ages of 16 and 18: records are retained until your 25th birthday, reflecting extended limitation periods that apply to minors

  • Retention period for enquiries/intake forms for those who don’t go on to become clients are 12 months. 

9. Your rights

Under UK GDPR you have the right to: access the data I hold about you, ask me to correct it, ask me to erase it (subject to my professional record-keeping obligations), restrict or object to my processing of it, and receive a copy in a portable format. To exercise any of these rights, contact me using the details in section 1.

10. Complaints

If you're unhappy with how I've handled your data, please see my Data Protection Complaints Procedure, which sets out how to raise this with me directly. You also have the right to complain to the Information Commissioner's Office (ICO) at any time — see ico.org.uk or call 0303 123 1113.

11. Changes to this notice

I may update this notice from time to time; the ‘last updated’ date at the top will always reflect the current version.