Privacy Policy
Last updated: 14 August 2026
Pamoyo Therapy Ltd ("we", "us") is committed to protecting your privacy. This policy explains what personal data we collect through this website and during therapy, why, how it's protected, and your rights over it, in line with UK GDPR and the Data Protection Act 2018.
Who's responsible for your data
Pamoyo Therapy Ltd acts as the data controller for all client information. Our ICO registration number is 00013289688, searchable on the ICO's public register .
What we collect
Through this website:
- Contact form submissions: name, email, phone number (if given), and your message
- "Stay connected" signups: your email address
- Basic website analytics (pages visited, general location, device type)
Once you book an assessment or start therapy, we also collect:
- Name, date of birth, address, email and phone number
- Your GP's details and an emergency contact
- Special category data: mental health information, risk information, clinical notes, and relevant medical history, and any questionnaires or outcome measures you complete
Only information necessary for therapeutic purposes is collected. Where required, we ask for your explicit consent before collecting special category data.
Why we process it
Personal data is processed on these lawful bases under UK GDPR:
- Contract (Article 6(1)(b)), to provide therapy services you've asked for
- Legal obligation (Article 6(1)(c)), where we're required to keep or disclose records
- Provision of health treatment (Article 9(2)(h)), which allows us to process special category health data as part of delivering therapy
How we store and protect it
- Clinical notes are kept in an encrypted electronic health record system (WriteUpp)
- Client data isn't stored on personal devices unless encrypted and password-protected
- Devices used to access client information are password-protected, with two-factor authentication where available
- Any paper documents are kept in a locked cabinet
- Email is conducted through secure, password-protected accounts
Clinical records and retention
Session notes and assessment records are kept securely and confidentially, in line with BABCP ethical guidelines, for 7 years after therapy ends (or longer where required by professional insurance or legal guidance), after which they're securely deleted or destroyed. They're not shared with third parties without your consent, except where required by law, for safeguarding reasons, or where there is a serious risk to your safety or someone else's. Where clinical information is discussed in supervision, it's anonymised wherever possible.
Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request erasure, where legally applicable
- Restrict or object to certain processing
- Lodge a complaint with the Information Commissioner's Office (ICO)
To exercise any of these rights, contact enquiries@pamoyotherapy.com in writing. We aim to respond within one month.
If something goes wrong
In the event of a data breach, it's assessed immediately; where there's a risk to your rights and freedoms, we notify the ICO within 72 hours and let affected clients know where required, alongside taking steps to reduce further risk.
Third parties
We work with a small number of trusted providers to run this practice, each only holding the data they need to do their job:
- Resend, to send emails triggered by the contact form and "Stay connected" signups
- WriteUpp, our practice management system, to store clinical records and handle appointment booking and invoicing
- Stripe, to process card payments where used, via WriteUpp
We don't sell personal data to third parties. Your data isn't transferred outside the UK unless it's with a provider operating in a country the UK considers to have adequate data protection, such as the EEA, and always in line with UK GDPR safeguards.
Contact
Questions about this policy can be sent to enquiries@pamoyotherapy.com.