Neuropsychology Dorset Ltd
Privacy Policy
Last reviewed: July 2026
1. Who we are and what service we provide
Neuropsychology Dorset Ltd is a company registered in England and Wales, providing psychological assessment and therapy both online and face to face, including from our clinic space, The Poundbury Practice, The Pediment, 17 Buttermarket, Poundbury, Dorset.
Our team includes a Clinical Psychologist registered with the Health and Care Professions Council (HCPC), and may include other clinicians and assistant practitioners working under our supervision or in association with us. ‘We’ refers to Neuropsychology Dorset Ltd and all clinicians who work within it. Every clinician working with us follows this policy in full.
2. Data protection and privacy
We are registered with the Information Commissioner’s Office (ICO), the UK’s independent authority upholding information rights in the public interest. If you are unhappy with how we have handled your information, you have the right to complain to the ICO — for example, if your information is inaccurate, has been lost, disclosed to someone else without appropriate basis, or if you have not been given access to your personal data.
We comply with UK GDPR and the Data Protection Act 2018. This policy explains how.
3. How you consent to us storing your data
Before collecting your personal information, we explain what we are asking you to consent to. Where we collect information for a specific purpose, we use it only for that purpose. If we wish to use your information for a secondary purpose, such as marketing, we will ask for your explicit consent or give you a clear opportunity to decline.
If you change your mind after opting in, you may withdraw your consent to further collection, use, or disclosure of your information at any time by contacting us at info@neuropsychologydorset.co.uk.
4. Why we need your personal data
As registered health professionals, we are required to keep records of our clinical work. We collect and store only the information that is relevant to your assessment or care. We routinely audit the effectiveness of our service, which involves retaining anonymised outcome data, such as questionnaire scores or number of sessions attended. If you do not wish your anonymised data to be used in this way, please let us know and we will exclude it.
5. What information we store
When you begin assessment or therapy with us, we ask you to complete a personal information form, including your name, age, contact details, next of kin, and GP details. This is the only document on which your full name and contact details appear. In all subsequent clinical documentation, we use your initials and/or a unique reference number rather than your full name.
During assessment and subsequent sessions, you will share information about your life, experiences, thoughts and feelings. This is recorded in note form, identified only by initials, and includes our shared understanding of your difficulties (formulation) and any treatment plan.
We apply appropriate technical and organisational measures to protect your data and only hold information that is strictly necessary to carry out our work (data minimisation). Any third-party providers we use will only collect, use and disclose your information to the extent necessary to deliver their service to us. We are not responsible for the privacy practices of third-party websites or platforms, and we encourage you to review their own privacy policies.
6. How we use your data
We use the data we hold to arrange and manage your appointments, and to maintain accurate clinical notes of our work together. This supports continuity of care and helps us provide you with a better, safer service.
7. How we store and protect your data
No method of transmission over the internet or electronic storage is completely secure. We take reasonable, industry-standard precautions to reduce the risk of your information being lost, misused, accessed, disclosed, altered, or destroyed without authorisation.
-
Electronic client records: individually password protected and stored on a password protected device, accessible only by your clinician.
-
Paper notes: taken during sessions without identifiable personal information, stored in a locked filing system at the clinician's private residence, accessible only to that clinician.
-
Questionnaires: stored as password protected documents on a password protected device, without personal identifying details, accessible only by your clinician.
-
Video calls: conducted via encrypted video conferencing platforms such as Zoom, Google Meet, or Psychology Today Sessions.
-
Email: correspondence is handled via our published address, info@neuropsychologydorset.co.uk, or the professional email account of your assigned clinician.
-
Appointment scheduling: arranged via the email address or telephone number you provide to us when you first make contact.
8. Who else can see your information
We treat all information you share with us as confidential. We will only disclose confidential information if:
-
we have your permission;
-
the law requires or permits it;
-
it is necessary to protect you from serious harm; or
-
it is necessary to protect public safety or prevent harm to others.
Wherever possible, we will notify you and discuss this with you before any such disclosure. There may occasionally be circumstances where this is not possible or appropriate.
As part of our professional obligations, we participate in clinical supervision, discussing cases with another qualified practitioner to ensure we continue to practise to a high standard and in accordance with professional guidelines. During supervision, we refer to you by first name only, and information is exchanged verbally. Our supervisor(s) do not hold, or have access to, your clinical records, and are bound by the same confidentiality obligations we are. If you would prefer we did not use your first name in this context, please let us know and we will use an alternative identifier.
9. Use of AI in report preparation
As part of our commitment to quality and clarity, we use AI-powered tools to support the preparation of our reports. These tools are used solely for quality assurance, grammar, and readability, helping to ensure our reports are clear, well-structured, and free from error.
Before any information is processed using an AI tool, it is fully anonymised. All identifying details, including your name, date of birth, address, and any other information that could identify you or a family member, are removed beforehand. No personally identifiable information is ever entered into or processed by an AI tool.
All clinical opinions, interpretations, analyses and conclusions contained in our reports are formed entirely by your clinician. AI tools play no role in clinical decision-making, diagnosis, or the professional judgements made about you or your child. These remain, in every instance, the sole responsibility and product of the assessing clinician.
10. How long we store your information
In addition to ICO requirements, we are bound by the professional guidelines of the Health and Care Professions Council (HCPC) and the British Psychological Society (BPS), which require us to keep full, clear and accurate records for everyone we assess or treat. As these records form part of your medical history and may be required by you, your GP, or your wider healthcare team in future, we retain electronic client records for 8 years after treatment ends, in line with UK best practice for adult health and social care records.
11. How you can amend the data we hold
You have the right to request amendments to the data we hold about you. Requests to amend or withdraw permission for us to hold your personal data must be made in writing. We routinely share draft letters and reports with clients before they are finalised, giving you an opportunity to request corrections at that stage.
12. How you can access your data
You have the right to request to see the data we hold about you, including how it is processed, where it is held, and for what purpose. We are legally required to respond within 30 days of your request. Where we provide access to your data, we will do so in a commonly used, machine-readable format, free of charge. You have the right to have this data transmitted to a third party, provided any other party referenced in the records has given written permission.
13. How you can withdraw consent to hold your records
We retain your personal information and health record for 8 years, after which it is securely destroyed. You have the right to withdraw consent for us to hold and process your records before this time. Please contact us if you wish to do so, and we will discuss the implications for your ongoing care.
14. What happens in the event of a data breach
If a breach occurs in how your information is stored or shared, we will take immediate corrective action and notify the ICO within 72 hours. We will also inform you of the breach, how it occurred, what information was affected, and the steps taken to address it. If you believe we have breached data security in any way, please notify us immediately by email.
The most common cause of a data breach is an email sent to the wrong recipient. To reduce this risk, we check email addresses carefully before sending, and where practical, reply within an existing email thread rather than starting a new one. Email is generally used only for appointment arrangements or general information sheets; it is not our practice to include sensitive personal information in emails, except by prior arrangement, in which case reports or letters are sent via a secure or password protected method.
If we do send information to the wrong recipient in error, we will:
-
contact the recipient as soon as possible and request deletion of the information;
-
notify the ICO within 72 hours and follow their guidance; and
-
notify you of the breach as soon as possible, and within 72 hours.
15. Changes to this policy
We may update this privacy policy from time to time. Where we make material changes, we will notify you by email so that you remain aware of what information we collect, how we use it, and the circumstances in which we may disclose it.
16. How to raise a complaint
Our work is carried out in accordance with the law of England and Wales, and any disputes are subject to it. If you have concerns about the care we have provided, we encourage you to raise this with us directly in the first instance.
If you feel we have acted harmfully or unethically and would prefer not to raise this with us directly, you can contact the Health and Care Professions Council: hcpc-uk.org
Complaints relating to the handling of your personal data should be directed to us in the first instance, at info@neuropsychologydorset.co.uk, for the attention of our Compliance Officer. We aim to respond to all complaints within 30 days.
To raise a complaint directly with the ICO, visit: ico.org.uk/make-a-complaint
17. Questions and contact information
If you would like to access, correct, amend, or delete any personal information we hold about you, or if you have any questions about this policy, please contact us at info@neuropsychologydorset.co.uk.
