Privacy Policy
Privacy Policy – Serenity Mindset Therapy
1. Introduction
Serenity Mindset Therapy is committed to protecting your personal data and respecting your privacy.
This Privacy Policy explains how your personal information is collected, used, and stored in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Data Controller
The data controller responsible for your personal data is:
Sian Payne
Serenity Mindset Therapy
4 Godra Bryn
Bettws
Bridgend
CF32 8TU
United Kingdom
Email: sianpayne@serenitymindsettherapy.co.uk
3. Information We Collect
We may collect and process the following personal data:
a) Contact Information
- Name
- Email address
- Telephone number (if provided)
b) Enquiry Information
- Details you provide when contacting us via email or contact form
c) Client Information (if you become a client)
- Personal details relevant to your therapy
- Session notes (kept securely and confidentially)
4. How Your Data Is Collected
Your data may be collected when you:
- Complete a contact form on this website
- Send an email enquiry
- Engage in therapy services
5. How We Use Your Information
Your personal data is used to:
- Respond to enquiries
- Provide counselling services
- Maintain client records
- Manage appointments and communication
- Meet legal and professional obligations
6. Lawful Basis for Processing
We process your data under the following lawful bases:
- Consent – when you contact us or agree to therapy
- Contract – to provide agreed services
- Legal obligation – where required by law
- Legitimate interests – to manage and improve services
7. Confidentiality
All client information is treated as confidential.
However, confidentiality may be broken if:
- There is a risk of serious harm to yourself or others
- Required by law (e.g. court order)
Where possible, this will be discussed with you first.
8. Data Storage and Security
Your data is stored securely and protected against unauthorised access, loss, or misuse.
Measures include:
- Password-protected systems
- Secure storage of records
- Limited access to personal data
9. Data Retention
- Enquiry data is kept only as long as necessary
- Client records are retained in line with professional guidelines (typically up to 7 years after the end of therapy)
10. Sharing Your Data
Your data will not be shared with third parties unless:
- Required by law
- Necessary to protect you or others from harm
We do not sell or share your data for marketing purposes.
11. Your Rights
Under UK GDPR, you have the right to:
- Access your personal data
- Request correction of inaccurate data
- Request deletion of your data (where applicable)
- Restrict or object to processing
- Lodge a complaint with the Information Commissioner’s Office (ICO)
12. Cookies
This website may use basic cookies to ensure it functions correctly.
You can control cookie settings through your browser.
13. Third-Party Services
If this website uses third-party services (e.g. website hosting, email providers), they may process your data on our behalf in compliance with data protection laws.
14. Contact
If you have any questions about this Privacy Policy or your data, please contact:
Email: [your email address]
15. Updates to This Policy
This Privacy Policy may be updated from time to time. Please review it periodically.
Last updated: April 2026