Privacy Notice
Your privacy is very important to me and you can be confident that your personal information will be kept safe and secure and will only be used for the purpose it was given to me. In order to provide you with the best service possible I need to hold your personal contact details and records of your therapy sessions. This privacy notice informs you about what I will do with your personal information from initial point of contact during and after therapy. I adhere to current data protection legislation, including the General Data Protection Regulation (EU/2016/679) (the GDPR) and the Data Protection Act 2018. I also adhere to the ethical guidelines regarding protecting client privacy and confidentiality as outlined in the Psychological Society of Ireland code of ethics.
My lawful basis for holding and using your personal information
The GDPR states that I must have a lawful basis for processing your personal data. There are different lawful bases depending on the stage at which I am processing your data. If you have had therapy with me and it has now ended, I will use legitimate interest as my lawful basis for holding and using your personal information. If you are currently having therapy or if you are in contact with me to consider therapy, I will process your personal data where it is necessary for the performance of our contract. The GDPR requires that I look after any sensitive personal information that you may disclose to me appropriately. This type of information is called ‘special category personal information’. The lawful basis for me processing any special categories of personal information is that it is for provision of health treatment (in this case therapy sessions) and necessary for a contract with a health professional (in this case, a contract between me and you).
How I use your information
I will never use your personal data for any purposes other than the administration of the therapy service that I am providing to you i.e. to arrange, cancel and rearrange appointments. I will only retain your personal information for as long as is necessary. This is in line with guidance from the Data Protection Commission.
Initial contact: When you contact me to book your first appointment I will collect some brief information to help me to process your enquiry. This will include your name so that I can book the appointment into my diary and also a contact method, for example an email address or phone number. This information is requested so that you can be informed if I was unable to attend an appointment due to unforeseen circumstances. If you do not want to be contacted under any circumstances you do not need to provide a contact method. Alternatively, an organisation such as your employer, GP/other professional, insurance company, may send me your details when making a referral. If an enquiry is made and you decide not to proceed I will ensure that all of your personal data is deleted within one month. If you would like me to delete this information sooner please let me know.
While you are accessing therapy: Your email address or phone number will be used to provide you with confirmation of your appointment times. Sleep diaries, assessment/evaluation forms will be sent to your email address. Before or at the beginning of your first therapy session I will ask you to complete a personal details form containing such information as your name, address, date of birth, emergency contact information, GP contact details, medications.
I keep written notes of each session. All personal data including session records are stored and held securely on WriteUpp, a Practice Management Software System. You can view the WriteUpp privacy policy at https://www.writeupp.com/privacy-policy.pdf
Although what is discussed in therapy is confidential, there are limits to confidentiality which are in place to help keep you and others safe, namely:
• When there is known or suspected risk of harm to yourself or others
• When there is known or suspected risk or potential concern regarding abuse, neglect or safety of a child or vulnerable adult
• When there is a legal obligation to disclose information
I will always try to speak to you about this first, unless there are safeguarding issues that prevent me from doing so.
Psychologists are required to attend regular clinical supervision to discuss their work with another psychologist. Your identity will not be disclosed as part of this process.
After therapy has ended: Therapy records will be kept for a period of 7 years after therapy has ended at which point all records will be deleted from the practice management system. In the case of minors, records will be kept for a period of 7 years after the client’s 18th birthday.
Third party recipients of personal data
I will never pass on your contact details to any third party organisations for the purposes of sales, marketing or research.
If your appointments are paid for or arranged via a third party, for example, your employer the only information shared with the third party are your dates of attendance and non-attendance for invoicing and payment purposes. Details about what is discussed at your appointments will remain confidential and can only be shared if you give me your written consent to do so.
Data security
I take the security of the data that I hold about you very seriously. My email account is password protected as is the mobile phone and laptop used to respond to your emails password protected along with anti-virus software. Any email correspondence will be deleted within one month if it is not necessary to keep it.
Website visitors
When someone visits my website, I use a third party service, Bridgeweb to collect standard internet log information and details of visitor behaviour patterns. I do this to find out things such as the number of visitors to the various parts of the site. This information is only processed in a way that does not identify anyone. I do not make, and do not allow Bridgeweb to make any attempt to find out the identities of those visiting my website. I use legitimate interests as my lawful basis for holding and using your personal information in this way when you visit my website.
By accessing my website, you are consenting to the information collection practices described in this privacy notice. Should you choose to contact me using the contact form on the website none of the data that you supply will be stored by the website or passed to any third party data processors. Instead the data will be collated into an email and sent to me over the Simple Mail Transfer Protocol (SMTP). SMTP servers are protected by TLS (sometimes known as SSL) meaning that the email content is encrypted before being sent across the internet. The email content is then decrypted by local computers and devices.
The website uses cookies and Google Analytics. Almost all websites use cookies which are small files put on your computer by websites as you surf them. These cookies can store lots of information which can have privacy implications. Google Analytics is a service provided by Google that gathers anonymous data on how people are using websites and then provides visitor statistics, details of page views etc. This service is used by many website owners as the data helps website owners to improve their websites.
Some page elements are embedded from trusted third parties in order to provide you with Interactive Maps.
This makes the website more helpful to you as a site visitor however most of these come with their own cookies. This applies to Google Maps. I do not control these cookies so I cannot guarantee what they do. In many cases the cookies are used to generate identical information to Google Analytics and indeed use Google Analytics, so opting-out of Google Analytics will also opt you out of these cookies too. You can opt out of Google analytics and other Google services here – http://tools.google.com/dlpage/gaoptout and https://www.google.com/dashboard/.
This document only serves as a privacy policy for this website. If you visit another website via a link on this website it’s imperative that you read the privacy documents supplied by the other websites.
Additionally, if you have accessed this website via an external link on another site, then I cannot guarantee that they have the same privacy policy, so make sure you read their privacy documents to ensure that their practices are in line with your expectations.
Your rights
Under GDPR, 2018 guidelines you have the following rights: The right to request access to the personal information that I store and process about you. You can ask for corrections to be made to the information held or for your personal information to be deleted. You can also ask me to restrict the processing of your personal information or to object to the processing of it altogether in some circumstances. You can read more about your rights at https://www.dataprotection.ie/en/individuals/rights-individuals-under-general-data-protection-regulation.
If you would like to make a request relating to any of the rights above, please send a request by email to info@insomniatherapy.ie. Please be aware that in certain situations counsellors may be unable to comply with the above requests. For example, if compelled to retain the records by a court of law. You will not be required to pay a fee to access your personal information (or exercise any of your other rights). However, please be aware that there may be a reasonable charge if your request for access is clearly unfounded or excessive in nature.
Queries
“Data controller” is the term used to describe the person or organisation that collects and stores and has responsibility for people’s personal data. In this instance, John Duffy is the data controller and WriteUpp the practice management system is the “data processor”. If you have any questions about this privacy policy please email info@insomniatherapy.ie
Complaints
If you have a complaint about how I handle your personal data please do not hesitate to get in touch with me by email at info@insomniatherapy.ie. If you want to make a formal complaint about the way I have processed your personal information you can contact the Data Protection Commission.
Changes to privacy notice
This privacy notice may be updated from time to time, so please check occasionally for any updates.