Privacy Notice
What Works Psychology Limited
Effective Date: 09/06/2025
Contact Details
- Business Name: What Works Psychology Limited
- Registered Address: Twelve Quays House, Egerton Wharf, Wirral, United Kingdom, CH41 1LD
- Email: contact@whatworkspsychology.co.uk
Summary
We collect only the information necessary to run our website, deliver psychological therapy, and respond to your enquiries. Your therapy records are confidential and stored securely. You can access or request changes to your data at any time by contacting us.
The Type of Personal Information We Collect
- Information you provide directly, such as when you:
- Schedule an appointment (online or in person)
- Complete intake forms
- Participate in therapy sessions (online or in person)
- Communicate with us via email, phone, or our website contact form
- Provide feedback or testimonials
- Information collected automatically when you visit our website, including:
- IP address
- Browser type and version
- Operating system
- Referral source
- Pages visited
- Date and time of your visit
How We Get Your Personal Information and Why We Collect It
Most personal information we process is provided directly by you. This includes:
- When you complete a contact form on our website
- When you email or phone us with an enquiry
- When you engage in psychological therapy
- When you subscribe to free downloads or mailing lists
Indirect collection (if applicable):
We may also receive information about you from other health or social care providers (e.g., a GP referral), but only with your consent or where legally permitted.
We use the information you provide to:
- Deliver and manage psychological therapy and assessments
- Maintain secure clinical records in line with HCPC and legal standards
- Contact you regarding appointments, reports, or services
- Share therapy reports with other professionals (with your consent)
- Deliver free resources and respond to website enquiries
- Improve our services and website functionality
Legal Basis for Processing Your Data
- (b) Contractual obligation: To deliver services you have requested
- (c) Legal obligation: To meet record-keeping and safeguarding requirements
- (f) Legitimate interest: To respond to your enquiries and improve services
We process special category data (e.g., health information disclosed in therapy) under:
- UK GDPR Article 9(2)(a) - Explicit consent
- UK GDPR Article 9(2)(h) – Processing is necessary for the provision of health care or treatment.
Note: Therapy clients are not required to provide marketing consent in order to receive psychological services. Our legal basis for processing therapy information is generally the provision of health care, and/or explicit consent.
Confidentiality in Therapy
All therapy information, including clinical notes, is treated as confidential and stored securely using encrypted systems (WriteUpp). These records are only accessed by your treating psychologist or authorised What Works Psychology team members where clinically necessary. We only share therapy information with others (e.g., your GP) with your consent, or where required by law (e.g., safeguarding concerns, legal duty to disclose).
Data Sharing
We do not sell or rent personal information. We only share data with the following third-party providers where necessary:
- DreamHost: Website hosting services
- Cloudflare: Domain management and security
- Jotform: User enquiries and contact forms
- SendFox: Email signup and marketing
- Google Drive: Hosting free downloadable content.
- Micrsoft Office: video conferencing and email communication.
- WriteUpp: Encrypted clinical record-keeping and therapy scheduling.
These providers are bound by strict data processing agreements and only process your data according to our instructions.
How We Store and Protect Your Personal Information
Your data is stored using encrypted and secure cloud-based services. Therapy notes are stored in WriteUpp, a UK-based platform compliant with GDPR.
- Therapy records: 7 years after your last session (or until age 25 for clients under 18), in line with HCPC guidelines
- Enquiries and mailing list data: Until you withdraw consent or request deletion
When data is no longer required, we securely delete or anonymise it using secure deletion protocols.
Your Data Protection Rights
Under UK data protection law, you have rights including:
- Access – Request a copy of your personal data
- Rectification – Ask us to correct inaccurate or incomplete data
- Erasure – Request deletion of your data (in some circumstances)
- Restriction – Ask us to limit how your data is used
- Objection – Object to certain types of processing
- Data Portability – Ask for a portable copy of your data
You are not required to pay a fee to exercise your rights. We aim to respond within one month.
To exercise your rights, contact: contact@whatworkspsychology.co.uk
Cookies
We use essential cookies for website performance. These do not collect personally identifiable data. You can manage cookies through your browser settings.
International Data Transfers
Some providers (e.g., Google) may transfer data outside the UK. All third-party services used by us ensure data transfers are protected by adequate safeguards such as Standard Contractual Clauses (SCCs).
How to Complain
If you are concerned about how we use your personal information, you can contact us at:
contact@whatworkspsychology.co.uk
If you are not satisfied, you can contact the Information Commissioner’s Office (ICO):
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
📞 0303 123 1113
🌐 www.ico.org.uk