Your information and privacy
Privacy Policy
Last updated: 7 October 2026
This policy explains how I collect, use, store and share personal information when you visit this website, contact me about therapy or become a client. I aim to collect only what is reasonably needed and to explain clearly how your information is handled.
- I only collect information that is reasonably needed to respond to you, provide therapy and run the practice.
- I do not sell your personal information or use it for third-party advertising.
- Therapy information is treated confidentially within professional, ethical and legal limits.
1. Who I am
Data controller: Adam Lawrence-Rodriguez, trading as Relational Resonance.
Privacy contact: adam@relationalresonance.co.uk
2. What information I collect and where it may come from
Depending on how you use the website and my services, I may collect:
- Enquiry information: your name, email address, phone number where provided, availability and information you choose to include in a message or form.
- Therapy and intake information: personal, relational, family, health or background information relevant to your reasons for seeking therapy.
- Appointment and service information: contact details, scheduling records, attendance and information needed to administer sessions.
- Therapy records: brief clinical or administrative notes created as part of providing therapy.
- Payment information: invoices, payment status and transaction records. Where you pay by Direct Debit through GoCardless, GoCardless processes the contact, bank and transaction information needed to provide its payment service.
- Messages: information you send by email or, if you choose to use it, WhatsApp for practical enquiries.
- Website information: technical information such as IP address, browser type, device information, pages requested and security or server-log information.
Most information comes directly from you. In couples work, information about you may also be provided by your partner or co-client, for example where one person makes the initial enquiry or completes information that refers to both of you. Information may occasionally come from another person or professional who contacts me with your knowledge. Where required and appropriate, I will provide privacy information directly to the person concerned.
Please share only what feels necessary at the enquiry stage. If you provide information about another person, including a partner, child or family member, please avoid sharing more than is reasonably needed.
3. What I use your information for
- To respond to enquiries and arrange an initial consultation.
- To consider whether I can offer an appropriate and safe service.
- To provide and administer therapy if we agree to work together.
- To manage appointments, payments, records and practice administration.
- To communicate with you about practical matters connected with therapy.
- To meet legal, ethical, safeguarding and professional responsibilities where applicable.
- To maintain the security and integrity of the website and practice systems.
I do not sell personal information or share it for third-party advertising. I do not use personal information to make solely automated decisions about whether you can access therapy.
Some information is optional. However, I need enough information to communicate with you, consider whether I can offer an appropriate and safe service, administer therapy and arrange payment where applicable. If information reasonably necessary for these purposes is not provided, I may be unable to offer or continue a service.
4. Lawful bases for processing
I process personal information under one or more of the following UK GDPR lawful bases, depending on the purpose:
- Legitimate interests: responding to enquiries, considering whether I can offer therapy, maintaining appropriate practice records and running the practice safely and effectively.
- Contract: taking steps at your request before providing therapy and administering agreed services, appointments and payments.
- Legal obligation: where processing, record keeping or disclosure is required by law.
- Vital interests: in a rare emergency where processing is necessary to protect someone's life and another lawful basis is not suitable.
- Consent: where you have been given a genuine choice and have specifically agreed to an optional use of your information.
5. Special-category and criminal-offence information
Information shared when seeking or receiving therapy may include special-category data, such as information about physical or mental health, racial or ethnic origin, religious or philosophical beliefs, sex life or sexual orientation.
Where this information is necessary for the provision of therapy, I generally process it under Article 9(2)(h) of the UK GDPR for health or social care purposes, together with the relevant provisions of the Data Protection Act 2018, and subject to professional confidentiality. Where another Article 9 condition is required for a particular use, I will rely on an appropriate lawful condition.
Information about alleged or actual criminal offences is subject to additional legal requirements. If I need to process this type of information, I will do so only where there is an Article 6 lawful basis and an applicable condition under Schedule 1 of the Data Protection Act 2018, as required by Article 10 of the UK GDPR.
6. Confidentiality and its limits
If we work together, I treat what you share as confidential within professional, ethical and legal limits. Information may need to be disclosed in limited circumstances, including where there is a serious concern about safety, a safeguarding responsibility, a legal requirement or a valid court order. Where possible and appropriate, I would aim to discuss this with you first.
Further information about how I approach safeguarding concerns is available in the Relational Resonance Safeguarding Policy.
7. Who may receive or process your information
I use a small number of digital services to provide and administer the practice. These services may process personal information on my behalf or, in some circumstances, as separate data controllers.
- Jotform, where I use it to collect enquiry or client intake information. Information submitted through these forms is processed in order to provide the form service. You can read Jotform's privacy policy .
- Webflow and related website infrastructure providers, which may process technical information needed to host, deliver and secure this website.
- Email service providers, including Microsoft services such as Outlook or Hotmail where these are used to send, receive or store correspondence connected with the practice.
- Zoom, where online therapy sessions are held. Zoom processes information needed to provide and secure the video-conferencing service. Sessions are not routinely recorded.
- GoCardless, which I use to collect session fees by Direct Debit. GoCardless processes the personal and financial information needed to provide its payment services and may act as a separate data controller for aspects of that processing. You can read GoCardless's privacy information for payers .
- WhatsApp, provided by Meta, if you choose to use it to contact me about practical matters. WhatsApp and Meta may process information in accordance with their own privacy terms. I do not recommend WhatsApp for confidential clinical material or urgent support.
- cloud storage or practice-administration services where reasonably necessary to run the practice;
- my clinical supervisor, with identifying information limited or removed where reasonably possible;
- professional advisers, insurers or regulators where necessary;
- courts or other bodies where disclosure is legally required; and
- police, safeguarding services, health services or emergency services where disclosure is lawful and necessary.
Where another organisation processes information on my behalf, I take reasonable steps to use providers with appropriate confidentiality, security and data-protection arrangements.
8. International processing and transfers
Some of the digital services I use operate internationally. In particular, Jotform, Zoom, GoCardless and WhatsApp/Meta may store, access or otherwise process personal information outside the United Kingdom, either directly or through international group companies or service providers. Other technology providers may also process information internationally.
The countries and organisations involved can change as providers update their infrastructure and subprocessors. Where personal information is transferred from the UK to another country, I take reasonable steps to ensure that the transfer is made using a mechanism permitted by UK data-protection law.
Depending on the provider and destination, this may include UK adequacy regulations or appropriate safeguards under Article 46 of the UK GDPR, such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. Where applicable, a provider may also rely on an approved adequacy mechanism for eligible organisations, such as the UK Extension to the EU-US Data Privacy Framework.
These arrangements are intended to provide appropriate protection for personal information when it is processed outside the UK. However, privacy and surveillance laws in other countries may differ from those in the UK. You can contact me if you would like further information about the international-transfer safeguards relevant to a particular service I use.
9. Cookies and website tracking
I do not currently use behavioural advertising or analytics tools to build profiles of website visitors. The website and its infrastructure providers may use technical storage, server logs or strictly necessary cookies needed for security, delivery and basic operation.
Third-party services that you choose to interact with, such as an embedded form, may use cookies or similar technologies of their own. If I introduce non-essential cookies or tracking that requires consent, I will provide appropriate information and controls before those technologies are used.
10. How long I keep information
I do not keep personal information for longer than I reasonably need it.
- Therapy records: normally retained for seven years after therapy ends.
- Initial enquiries that do not proceed to a consultation: normally retained for up to 12 months after the last meaningful contact, unless there is a professional, legal, safeguarding, complaint or insurance reason to keep them for longer.
- Intake and consultation information: where you complete an intake form or attend an initial consultation, this information may form part of your clinical record and may be retained for up to seven years after our last professional contact, even if ongoing therapy does not follow.
- Financial records: retained for as long as required to meet applicable tax, accounting and legal obligations.
- Website and technical records: retained only for as long as reasonably necessary for security, troubleshooting, service operation and legal compliance. Some retention periods are determined by the relevant technology provider.
Information may be kept for longer where there is a legal, safeguarding, complaint, insurance or professional reason to do so. When information is no longer needed, it will be securely deleted or anonymised where reasonably possible.
11. Your data-protection rights
Depending on the circumstances and the lawful basis being used, you may have the right to:
- ask for a copy of your personal information;
- ask for inaccurate or incomplete information to be corrected;
- ask for information to be deleted in certain circumstances;
- ask for processing to be restricted;
- object to certain processing;
- receive certain information in a portable format; and
- withdraw consent where consent is the lawful basis.
These rights are not absolute and may be limited by legal, professional or third-party confidentiality obligations. To make a request, contact adam@relationalresonance.co.uk .
Where I rely on legitimate interests to process your personal information, you may have the right to object to that processing. If you want to object, contact me using the email address above and tell me which use of your information you are concerned about. I will consider your objection in accordance with UK data-protection law.
12. How to make a data-protection complaint
If you are concerned about how I have handled your personal information, you can make a data-protection complaint by emailing adam@relationalresonance.co.uk . It is helpful to put “Data protection complaint” in the subject line and explain what you are concerned about.
I will acknowledge a data-protection complaint as soon as reasonably possible and normally within seven days. I will take appropriate steps to investigate it without undue delay, keep you informed where appropriate and tell you the outcome.
You also have the right to complain to the Information Commissioner's Office (ICO). Information about making a complaint is available at ico.org.uk/make-a-complaint .
13. Security
I take reasonable technical and organisational steps to protect personal information. These include limiting access to information, using password-protected systems, keeping devices and software appropriately secured and selecting service providers with appropriate security and data-protection arrangements.
No method of electronic storage or transmission can be guaranteed to be completely secure.
14. Changes to this policy
I may update this policy when the way I work, the services I use or data-protection requirements change. The Last updated date at the top of this page will show when the policy was most recently revised.
Questions about this policy or how your information is handled? Contact adam@relationalresonance.co.uk .