Privacy Policy

 

Practice address: 282 Earls Court Road, Kensington, London, SW5 9AS.

Practitioner: Dr Nikos Tsigaras, registered with the HCPC [Registration Number] and the British Psychological Society [Membership Number].

ICO registration: [ICO Registration Number].

Contact for data protection queries: [Contact Email].

Last updated: [Date]. This policy is reviewed at least annually.

 

  1. Who we are and what this policy covers

This privacy policy explains how Dr Nikos Tsigaras, trading as Kensington Counselling (referred to as “we”, “us”, or “the practice” throughout), collects, uses, stores, and protects your personal information when you receive psychological services from the practice, or when you visit our website at kensingtoncounselling.com.

For the purposes of UK data protection law, Dr Nikos Tsigaras is the data controller for all personal data processed in connection with the practice.

We are bound by the ethical and professional codes of the Health and Care Professions Council (HCPC) and the British Psychological Society (BPS), and by UK data protection law including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).

 

  1. What information we collect

The personal information we hold about you may include:

  • Identifying information: your name, date of birth, home address, email address, and phone number.
  • Next of kin or emergency contact details.
  • Your GP’s name and contact details.
  • Clinical information: referral information, presenting concerns, notes from our sessions, risk-related information, and any correspondence about your care.
  • Special category data under UK GDPR: information relating to your mental and physical health, and where relevant to the work, information about your sexual life, religious or philosophical beliefs, political opinions, racial or ethnic origin, or trade union membership.
  • Billing and payment information: invoices, payment confirmations, and (where applicable) insurer details and policy numbers.
  • Session audio and transcripts processed via Heidi Health (see Section 5).
  • Website usage data: see Section 10.

 

  1. Our lawful bases for processing

Under UK GDPR, we rely on the following lawful bases:

  • Article 6(1)(b) — performance of a contract: to deliver the therapy service you have engaged us to provide, and to manage billing.
  • Article 6(1)(c) — legal obligation: for example, tax, accounting, and safeguarding obligations.
  • Article 6(1)(f) — legitimate interests: for clinical record-keeping as required by our professional regulators, for practice administration, and where relevant for the prevention of serious harm.

Because therapy records contain health data (special category data under Article 9), we additionally rely on:

  • Article 9(2)(h) — provision of health or social care, carried out by a health professional bound by a duty of professional secrecy under UK law.
  • Article 9(2)(c) — protection of vital interests: in rare circumstances where disclosure is necessary to protect life.

Where we rely on your consent for a specific processing activity (for example, cookies or the use of Heidi Health for AI-assisted documentation), we will tell you so at the time and you may withdraw that consent at any time without affecting the lawfulness of processing already carried out.

 

  1. Why we use your information

We use your personal information for the following purposes:

  • To provide psychological assessment and therapy to you.
  • To keep accurate clinical records, as required by HCPC and BPS professional standards.
  • To bill you or your insurer for services provided, and to meet our tax and accounting obligations.
  • To communicate with you about appointments, treatment, and administrative matters.
  • To protect you or others from serious harm where there is a clinical or legal duty to do so.
  • To improve the service, evaluate our practice, and respond to enquiries or complaints.

 

  1. AI-assisted clinical documentation (Heidi Health)

With your separate written consent, we use Heidi Health as an AI-assisted documentation tool during therapy sessions. Heidi transcribes session audio in real time and generates structured clinical notes from the transcript, which are then reviewed and finalised by your practitioner.

Heidi Health Ltd acts as a data processor on our behalf. Based on Heidi Health’s published UK privacy policy and safety information, the following applies:

  • Heidi Health states that no audio recording of the session is saved; your words are transcribed as you speak and the audio is not retained.
  • Heidi Health states that transcripts are automatically deleted from its platform after 24 hours. Clinical notes retained in our record are kept for as long as we require them and can be deleted at any time.
  • Heidi Health states that data from UK users is held on UK-based servers, with any onward processing by its third-party service providers restricted to the UK or European Economic Area.
  • Heidi Health states that it applies bank-industry encryption to all data at rest and in transit, holds ISO 27001 certification, and adheres to UK compliance frameworks including DCB0129, DTAC, DSPT, Cyber Essentials, and the Data Protection Act 2018.
  • Heidi Health states that no patient data is used to train, develop, or improve its AI models, and that patient data is not sold.

 

You are provided with a separate, detailed consent form before Heidi is used. Your consent is entirely voluntary, you may decline without affecting your care, and you may withdraw consent at any time. Heidi Health’s current privacy policy is available at: heidihealth.com/en-gb/legal/privacy-policy.

Automated decision-making: although Heidi generates draft notes automatically, those notes are always reviewed and, where necessary, corrected by your practitioner before being saved to the clinical record. No decision affecting you is made solely by automated means.

 

  1. Who else processes your data

We only share your personal information with third parties where it is necessary and lawful to do so. In addition to Heidi Health (above), the practice may use the following categories of processor — please ask if you would like the current specific providers to be named:

  • An email and document storage provider [GoogleMail, Proton Drive).
  • A practice-management or scheduling system, if in use [specify or state “none”].
  • An accounting / invoicing system or accountant [specify].
  • A payment processor for card payments [e.g. Stripe, GoCardless — specify].

Each of these acts as a data processor under written contract. Where any of these providers are based outside the United Kingdom, we rely on UK adequacy decisions (including the UK-US Data Bridge), Standard Contractual Clauses, or other valid safeguards as set out in UK GDPR.

 

  1. When we share information with other parties

We treat everything you share in therapy as confidential. We will not normally share your personal information with anyone else. There are limited circumstances in which we may need to:

  • If you are funding therapy through a health insurance policy, we will share appointment schedules with that insurer for billing, and may share treatment updates if required by your policy.
  • If there is a need-to-know clinical reason to communicate with another health professional involved in your care (for example, your GP), we will seek to discuss this with you first.
  • If disclosure is required by law — for example, under a court order, or to prevent a miscarriage of justice.
  • If we become seriously concerned about a risk of harm to you, to another adult, or to a child. Where possible and safe to do so, we will discuss any proposed disclosure with you first. We will not do so if we believe it would increase the risk to anyone.

 

We do not sell your personal information, and we do not share your personal information for marketing purposes.

 

  1. How long we keep your information

Your clinical records are kept for the duration of your therapy and, in line with HCPC and BPS professional guidance, for seven years after the therapy has ended. This applies to adult clients.

Billing and tax records are retained for the period required by HM Revenue and Customs (currently six years from the end of the relevant financial year).

After these periods, records are securely deleted.

 

  1. How we store and protect your information

We take information security seriously. Our measures include:

  • Encrypted storage of clinical records on encrypted devices that meet recognised security standards.
  • Strong, unique passwords and two-factor authentication on work accounts.
  • Restricted access — only the practitioner accesses your clinical records, unless you explicitly agree otherwise.
  • Written data-processing agreements with all third-party processors.
  • Prompt notification to the ICO (and to you, where required) in the event of a personal data breach that is likely to result in a risk to your rights.

 

  1. Website, cookies, and analytics

Our website, kensingtoncounselling.com, may use cookies and similar technologies. Cookies are small text files placed on your device when you visit a website. Some cookies are strictly necessary for the site to function; others help us understand how the site is used.

Under PECR and UK GDPR, we ask for your consent before any non-essential cookies are placed on your device. You can give, refuse, or withdraw consent through the cookie banner on the site, or by adjusting your browser settings.

Specifically:

  • Strictly necessary cookies are used to enable the site to load and display correctly. These do not require consent.
  • Analytics: if analytics are enabled, we use [specify — e.g. Google Analytics 4 with IP anonymisation / Plausible / Fathom]. Analytics cookies are set only with your consent. Analytics data helps us understand site usage but is not used to identify individual visitors.
  • Advertising / remarketing cookies (such as Facebook / Meta Custom Audiences) are only set if you give specific consent. If you prefer, you can decline these entirely and the site will still function normally.

Where analytics or advertising providers process data outside the United Kingdom (for example, in the United States), we rely on recognised transfer mechanisms under UK GDPR, including the UK extension to the EU-US Data Privacy Framework (the UK-US Data Bridge), Standard Contractual Clauses, or equivalent safeguards.

You can read the current cookie list, and the privacy policies of any third-party analytics or advertising providers we use, on the relevant section of the website.

 

  1. Your rights

Under UK GDPR and the Data Protection Act 2018, you have the following rights in relation to your personal information:

  • Right of access — to request a copy of the personal information we hold about you.
  • Right to rectification — to have inaccurate or incomplete information corrected.
  • Right to erasure — to ask for your information to be deleted, subject to the professional retention obligations set out in Section 8.
  • Right to restriction — to ask us to limit how we use your information in certain circumstances.
  • Right to object — to object to processing based on our legitimate interests.
  • Right to data portability — where processing is carried out by automated means on the basis of consent or contract.
  • Right to withdraw consent — where we rely on your consent for a specific activity (such as use of Heidi Health, or non-essential cookies), without affecting the lawfulness of processing before withdrawal.
  • Right to complain to the Information Commissioner’s Office if you believe your data has been mishandled: http://www.ico.org.uk/concerns or 0303 123 1113.

To exercise any of these rights, please contact us at [Contact Email]. We will respond within one calendar month, as required by UK GDPR. There is no fee for making a request in most circumstances.

 

  1. Children and young people

 

The practice provides services to adults only (aged 18 and over). We do not knowingly collect or process personal information from children.”

 

  1. Changes to this policy

We review this policy at least annually and may update it from time to time to reflect changes in our practice or in the law. The date at the top of this policy will show when it was last updated. Material changes will be communicated to current clients where appropriate.

 

  1. How to contact us

If you have any questions about this policy or how your information is handled, please contact Dr Nikos Tsigaras at nikos.tsigaras@kensingtoncounselling.com, or by post at the practice address above.