Privacy Notice
How we look after your personal information
| Controller | London Trusted Therapy Harley Street Ltd |
| Data Protection Lead | Jonathan Edwards, Head of Operations |
| Company number | 14859705 |
| Data Protection Lead | Jonathan Edwards |
| ICO Registration Number | ZC083133 |
| Reference | LTT-POL-PN-01 |
London Trusted Therapy (“LTT”, “we”, “us”, “our”) respects your privacy and is committed to protecting your personal data. This notice explains how we look after your personal data when you visit our website, contact us, or receive services from us, and tells you about your privacy rights and how the law protects you.
Please read this notice alongside any other privacy information we may give you on specific occasions when we are collecting or processing your personal data, so you are fully aware of how and why we use it. This notice supplements, and does not override, those other notices.
1. Who We Are
Controller
This notice is issued by London Trusted Therapy Harley Street Ltd, a multi-disciplinary psychology and therapy practice operating from three London sites: Pinero House, 115a Harley Street; 30 Welbeck Street; and 1 Quality Court, Chancery Lane. London Trusted Therapy Harley Street Ltd is the controller responsible for your personal data.
We have appointed a Data Protection Lead, Jonathan Edwards (Head of Operations), who oversees questions relating to this notice. If you have any questions, including a request to exercise your legal rights, please contact him via the details published on www.londontrustedtherapy.com.
You have the right to complain at any time to the Information Commissioner’s Office (ICO), the UK’s supervisory authority for data protection (www.ico.org.uk). We would appreciate the opportunity to address your concerns before you approach the ICO, so please contact us first wherever possible.
Changes to this notice
This notice was last updated on the effective date shown above. We will review it at least annually, or sooner where our practices or the law change, and the current version will always be available on our website. Please keep us informed if your personal details change.
Third-party links
Our website may contain links to third-party websites. We do not control these sites and are not responsible for their privacy practices. We encourage you to read the privacy notice of any website you visit after leaving ours.
2. The Information We Collect About You
Personal data means any information about an individual from which they can be identified. We may collect, use, store and share different kinds of personal data about you, grouped as follows:
- Identity Data — name, title, date of birth and, where relevant, gender.
- Contact Data — home address, email address and telephone number, and emergency contact details where provided.
- Technical Data — IP address, browser type, device information and similar data collected when you visit our website.
- Referral Data — how you heard about us, and information shared by a referrer (such as a school, GP, insurer or previous clinician) with your knowledge and consent.
- Health and Clinical Data — assessment notes, session notes, diagnostic reports, treatment plans and information shared by previous or current healthcare providers relevant to your care. This is special category data under UK GDPR.
- Payment and Transaction Data — billing information and records of payments made for our services; we do not store full card details ourselves.
- Insurance Data — the minimum information necessary to process insurer-funded treatment, where applicable.
- Legal Data — information needed to manage complaints, safeguarding concerns or legal and regulatory obligations.
- Marketing and Communications Data — your preferences in receiving communications from us.
We collect special category data about you (principally health data) where this is necessary to assess your needs and provide appropriate care. We do not collect other special category data unless you choose to share it with your clinician as part of your care, and we do not collect information about criminal convictions or offences.
If you do not provide personal data we need in order to provide our services, we may not be able to proceed with your care, and we will let you know if that is the case.
3. How Your Personal Data Is Collected
We collect data from you in the following ways:
- Direct interactions — when you enquire about our services, complete our website contact form, correspond with us by phone or email, or provide information as part of your assessment and treatment.
- Automated technologies — as you interact with our website, we may automatically collect Technical Data using cookies and similar technologies.
- Third parties — with your consent, from referrers, insurers, or previous healthcare providers involved in your care.
4. How We Use Your Personal Data
We will only use your personal data when the law allows us to. Most commonly we rely on: performance of a contract with you (to provide our services); legitimate interests, provided these do not override your own interests and rights; explicit consent, particularly for special category health data and for marketing; and compliance with a legal or regulatory obligation.
The table below sets out the main purposes for which we use your data and the lawful basis we rely on for each.
| Purpose / activity | Type of data | Lawful basis |
| To assess your needs and match you with an appropriate clinician | Identity; Contact; Referral; Health | Performance of a contract with you; Article 9(2)(h) UK GDPR for health data, and/or your explicit consent. |
| To provide ongoing therapy, assessment or treatment | Identity; Contact; Health; Clinical | Performance of a contract with you; Article 9(2)(h) UK GDPR, and/or your explicit consent. |
| To manage appointments, reminders and billing | Identity; Contact; Payment | Performance of a contract with you; legitimate interests (practice administration). |
| To liaise with insurers processing your funded treatment | Identity; Health; Insurance | Your explicit consent; performance of a contract. |
| To liaise with referrers or other professionals involved in your care (e.g. GP, psychiatrist, school) | Identity; Health; Referral | Your explicit consent. |
| To meet safeguarding, legal and professional record-keeping obligations | Identity; Health; Legal | Compliance with a legal obligation; legitimate interests. |
| To administer and secure our website and IT systems | Technical | Legitimate interests (running our business, IT and network security). |
| To send you marketing communications (only with your consent) | Contact; Marketing and Communications | Consent. |
Marketing
We will only send you marketing communications with your consent, and you may withdraw that consent at any time by contacting us or using the opt-out link in any marketing message. Opting out of marketing will not stop us sending service-related communications necessary for your care.
Cookies
Our website may use cookies to improve your browsing experience and understand how our site is used. You can set your browser to refuse cookies, though this may affect some website functionality.
Email, SMS and Messaging
We may use email, and occasionally SMS or secure messaging, to communicate appointment reminders, confirmations and administrative updates. Clinical or sensitive information is not sent by SMS. Messaging channels are not monitored for emergencies — if you are in crisis or at risk of harm, please contact emergency services on 999, or the Samaritans on 116 123.
Payment Processing
We use a third-party payment provider to process card payments for our services. Our payment provider processes your billing and transaction data for the purposes of handling payments, fraud prevention and compliance with legal obligations, in accordance with its own privacy notice.
Call Recording
Where any administrative calls are recorded for training or quality purposes, you will be informed at the start of the call and may choose not to continue if you do not agree.
5. Who We Share Your Personal Data With
We only share your information where necessary, and only with your knowledge. This may include:
- Your treating clinician(s) at LTT, and, with your consent, other professionals involved in your care.
- Insurers, where your treatment is funded via an insurance policy (for example, Cigna, Allianz, AXA or WPA).
- Service providers who process data on our behalf under contractual data protection terms, including our practice management system (WriteUpp), Microsoft 365 (email and document storage), Proton Drive (secure storage of client-specific documents), and our payment processor.
- Professional advisers, including our accountants, insurers and, where necessary, legal advisers.
- Regulators, professional bodies and public authorities, including HM Revenue & Customs, where required by law.
Where a clinician who is not directly employed by LTT provides care to you, they may act as an independent controller for the clinical records they personally create, and are responsible for their own professional and data protection obligations in relation to those records.
We require all third parties to respect the security of your data and only permit them to process it for specified purposes, in accordance with our instructions and, where they are processors, a written data processing agreement.
6. International Transfers
Some of our service providers may store or process data outside the UK. Where this happens, we ensure an equivalent level of protection is in place, by relying on UK adequacy regulations for the destination country, or appropriate contractual safeguards such as the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses. Please contact us if you would like further information about a specific transfer.
7. Data Security
We have put in place appropriate technical and organisational measures to prevent your personal data being accidentally lost, used, accessed, altered or disclosed without authorisation. Access to clinical records is limited to those who need it to provide or support your care, and all staff and clinicians are bound by confidentiality obligations. We have procedures in place to identify and respond to any suspected data breach, and will notify you and the ICO where we are legally required to do so.
8. Data Retention
We retain clinical records in line with relevant professional body guidance and legal requirements — typically a minimum of seven years from the end of treatment for adult clients, with longer retention periods applying to records relating to children. Basic contact, identity and billing records are retained for a similar period unless a longer period is required for legal, safeguarding or regulatory reasons. Enquiry data for people who do not go on to become clients is retained for a limited period and then securely deleted. Our full retention schedule is set out in our internal Data Protection Policy, available on request.
Where you ask us to erase your data (see Section 9), we will do so unless we are required to retain it for legal, safeguarding or professional record-keeping reasons, in which case we will explain why.
9. Your Legal Rights
Under UK data protection law, you have the right to:
- Request access to the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request erasure of your data, where there is no good reason for us to continue processing it.
- Object to processing based on legitimate interests, or to direct marketing at any time.
- Request restriction of processing in certain circumstances.
- Request transfer (portability) of data you have provided to us, where technically feasible.
- Withdraw consent at any time, where we rely on consent as our lawful basis — this will not affect the lawfulness of processing carried out before you withdrew it.
To exercise any of these rights, please contact Jonathan Edwards, Head of Operations. We do not charge a fee for most requests, though we may charge a reasonable fee or decline a request that is clearly unfounded, repetitive or excessive. We may need to verify your identity before responding. We aim to respond within one month, and will let you know if a more complex request will take longer.
10. Glossary
Legitimate interests
The interest of our business in operating effectively so we can provide you with a safe and reliable service. We balance this against your own interests and rights, and do not rely on it where those rights override our interest, unless we have another lawful basis to do so.
Performance of a contract
Processing that is necessary to deliver the services you have asked us to provide, or to take steps at your request before entering into an agreement with us.
Legal or regulatory obligation
Processing that is necessary for us to comply with a law or regulatory requirement we are subject to, such as safeguarding duties or professional record-keeping standards.
Special category data
Particularly sensitive personal data, including data about health. We only process this where we have both a lawful basis under Article 6 and an additional condition under Article 9 of the UK GDPR — in our case, the provision of health or social care under Article 9(2)(h), and/or your explicit consent.