Privacy Policy
Last updated: 16 July 2026 • Version: 1.0
1. Who I am
I am Vanessa Lorkins, a counsellor trading as Healing Roots. I am the data controller for the personal information described in this policy, which means I decide how and why your information is used.2. Who this policy covers
This policy explains how I handle personal information belonging to: people who enquire about counselling; current and former clients; visitors to my website; and people who subscribe to my mailing list. A shorter summary of the key points also appears in the client agreement you sign before counselling begins.3. What information I collect
Enquiries
Your name, contact details, and anything you choose to tell me about what brings you to counselling, whether you get in touch by the website contact form, email or phone. Please note that enquiries made this way are not covered by therapeutic confidentiality in the way counselling sessions are, so it is best to keep sensitive details to a minimum until we speak.Clients
- Identity and contact details: name, date of birth, address, phone number, email.
- Health and therapy information: the reasons you are seeking counselling, relevant personal and medical history, risk information, and brief notes made after each session (see section 5). This is “special category” data under UK data protection law and receives extra protection.
- Your GP’s name and practice, and an emergency contact, collected at the start of our work together.
- Appointment and payment records: dates of sessions, invoices, and payment history. I do not store your card details; payments are handled by bank transfer.
- Correspondence between us, such as emails or texts about appointments.
- Recordings of sessions, made only with your prior written consent (for example for training, CPD, or supervision purposes, using a separate recording consent form), stored securely and deleted within 28 days or once the related supervision or assessment is complete, whichever is soonest.
Website visitors and subscribers
- Technical data collected through cookies and similar technologies, with your consent where required (see section 11).
- If you join my mailing list: your name, email address, and a record of your consent.
4. Why I use your information, and the legal bases
UK GDPR requires me to have a lawful basis for using your personal information, and an additional condition for health information. I rely on the following:- Providing counselling (contract – Article 6(1)(b)): arranging and delivering sessions, communicating with you about appointments, and taking payment.
- Keeping proper clinical records (legitimate interests – Article 6(1)(f)): maintaining accurate records is essential to safe, ethical practice, is required by my professional body and insurer, and protects both of us if questions later arise about the care provided.
- Legal obligations (Article 6(1)(c)): for example retaining financial records for HMRC, or making disclosures required by law.
- Marketing (consent – Article 6(1)(a)): I will only send you marketing emails if you have opted in, and you can withdraw consent at any time using the unsubscribe link or by contacting me.
5. AI-assisted note-taking
I use WriteUpp, a secure, UK GDPR-compliant practice management system, to keep my clinical records. WriteUpp includes an AI-assisted note-taking feature which generates a draft session summary from my dictated or typed notes or transcribes and summarises the session audio.- I will explain this to you before we start and ask for your written consent. You are free to say no, and this will not affect the counselling you receive — I will simply write my notes manually.
- If audio is processed: Session audio is used only to generate the note and is deleted within 24 hours afterwards. I review and edit every AI-generated note before it is saved; the record remains my own professional note.
- WriteUpp acts as my data processor under a written data processing agreement, and data is stored in the EU. Your information is not used to train AI models confirm this with WriteUpp and their AI sub-processor.
- You can withdraw your consent at any point in our work together.
6. Who I share your information with
Counselling is confidential. I do not sell your information, and I share it only in the limited circumstances below.Service providers (data processors)
Trusted providers who process data on my instructions under contract: WriteUpp (practice management and clinical notes); GoDaddy (website host); Gmail (email provider); Starling Bank. I remain responsible for your data.Clinical supervision
Like all BACP registrants, I discuss my work in regular clinical supervision. My supervisor is bound by the same confidentiality requirements, and I do not share your name or identifying details.Limits of confidentiality
In rare situations, I may need to share information without your consent. Wherever possible, I will discuss this with you first. These situations are:- I believe you or someone else is at serious risk of harm — for example, I may contact your GP or emergency services;
- There is a safeguarding concern involving a child or an adult at risk;
- I am required to disclose by a court order; or
- The law requires disclosure — for example under the Terrorism Act 2000 or the Proceeds of Crime Act 2002.
If I can no longer practise
In line with good practice, I have appointed a clinical executor — a trusted, qualified colleague who, in the event of my sudden death or incapacity, will access my client contact records solely to inform clients, signpost support, and arrange the secure retention or destruction of records.7. International transfers
I aim to keep your data in the UK. Where a provider stores data outside the UK , transfers are protected by UK adequacy regulations or the International Data Transfer Agreement/Addendum, with additional safeguards where needed.8. How long I keep your information
- Clinical records (adults): 7 years from the end of our work together, in line with professional and insurance requirements, then securely destroyed.
- Clinical records (clients under 18): until the client’s 25th birthday, or 26th if they were 17 when counselling ended.
- Session recordings (where you have consented): deleted within 28 days/once the related supervision or assessment is complete.
- Enquiries that do not lead to counselling: deleted after 6 months.
- Financial records: 6 years plus the current tax year, as required by HMRC.
- Mailing list data: until you unsubscribe or after 24 months of inactivity.
9. How I keep your information secure
Clinical records are held in WriteUpp, which is encrypted in transit and at rest and protected by two-factor authentication. My devices are encrypted and password-protected, and any remaining paper records are kept in a locked cabinet in my home office in Hampshire. Email is not a fully secure medium, so I keep identifying and clinical detail in email to a minimum and encourage you to do the same.10. Your rights
Under UK GDPR you have the right to:- access a copy of the information I hold about you (a “subject access request”);
- have inaccurate information corrected;
- ask for your information to be deleted;
- restrict or object to how I use your information;
- receive certain information in a portable format; and
- withdraw consent at any time, where consent is the basis I rely on (for example, marketing or AI note-taking).