Shifaá Healing Hearts Counselling:
REGULATION (EU) 2016/679 – General Data Protection Regulation
The General Data Protection Regulation (GDPR) is concerned with the personal information about you that I collect, store, and share. This page outlines how Shifaa Healing Hearts Counselling CIC (SHHC) complies with GDPR requirements.
What Personal Information SHHC Collects:
How SHHC Stores Your Personal Information
Storage Methods:
Paper- Written notes, including:
Electronic-
How SHHC Processes and Shares Your Information
Confidentiality
All information shared in therapy is treated as confidential. There are some exceptions where information may need to be shared:
Emergencies:
If I believe you are at risk of serious harm, and with your consent, I may contact appropriate emergency services.
If there is disclosure of serious intent to harm others or involvement in a serious crime (e.g. terrorism), I may be legally required to report this without your consent or knowledge (whistle-blowing).
Data Retention and Erasure
After we finish working together, I will retain your records (both written and electronic) for up to seven years, in line with ethical and legal requirements. This allows for continuity if you return to therapy. After this time, paper records will be securely shredded, and digital records deleted.
Your Rights Under GDPR
You have the right to:
This privacy statement is reviewed periodically to ensure it remains accurate and up to date.
Last updated: 25th March 2025