Website Privacy Notice
1. Who We Are (Data Controller)
Dr Nic Jones ("we", "us", "our") provides psychological services. We are the data controller for personal data collected via this website.
Contact details:
Email: dr.nic.jones@gmail.com
2. Important Note About Clinical Data
This privacy notice applies only to information collected via our website.
If you become a client, your personal and health information (including therapy records) will be handled in accordance with our Client Privacy Notice, which will be provided to you separately.
3. What Personal Data We Collect
a) Information collected automatically:
When you visit our website, we may collect:
- IP address
- Browser type and version
- Device type and operating system
- Date, time, and pages visited
b) Information you provide via contact:
If you contact us via our website or email, we may collect:
- Name
- Email address
- Telephone number (if provided)
- Any information you choose to include in your message
⚠️ Please avoid including sensitive personal or health information in initial contact messages where possible.
4. How We Use Your Personal Date
We use your data to:
- Respond to your enquiries
- Provide information about our services
- Manage and improve our website
- Monitor website usage
We do not use your website data for marketing purposes.
5. Legal Basis for Processing
Under UK GDPR, we rely on:
- Legitimate interests – to operate and improve our website
- Consent – for non-essential cookies (e.g. analytics)
- Pre-contractual steps – when responding to enquiries about our services
If you later become a client, we will process your health data under:
- Article 9(2)(h) (provision of health care)
- And/or explicit consent, where required
6. Cookies and Analytics
We use cookies to enhance your experience. These include:
- Strictly necessary cookies – essential for website functionality
- Analytics cookies – to understand how visitors use our site (via Google Analytics)
Google Analytics may process usage data such as IP address and browsing activity. This data may be transferred outside the UK; where this occurs, appropriate safeguards (such as Standard Contractual Clauses) are used.
You can accept or reject non-essential cookies via our cookie banner and can change your preferences at any time.
More information: https://www.google.com/policies/privacy/partners/
7. Data Sharing
We do not sell your personal data.
We may share limited data with:
- Website hosting and IT providers
- Analytics providers (e.g. Google)
- Legal or regulatory authorities where required
All third parties are required to keep your data secure and only process it on our instructions.
8. Data Retention
We retain personal data only as long as necessary:
- Website analytics data: up to 12 months
- General enquiries: up to 12 months after last contact
If you become a client, retention periods for clinical records will be explained in our Client Privacy Notice.
9. Data Security
We take appropriate technical and organisational measures to protect your data, including secure systems and restricted access.
However, please note that information sent via the internet is not completely secure.
10. Your Data Protection Rights
Under UK GDPR, you have the right to:
- Access your personal data
- Request correction of inaccurate data
- Request erasure (where applicable)
- Restrict or object to processing
- Request data portability
- Withdraw consent at any time (where applicable)
To exercise your rights, contact us at the email above.
11. Third-Party Links
Our website may contain links to external websites. We are not responsible for their privacy practices.
12. Changes to This Privacy Notice
We review this notice regularly and will post any updates on this page.
13. Complaints
If you have concerns about how we handle your data, please contact us first.
You also have the right to lodge a complaint with the UK supervisory authority:
Information Commissioner's Office (ICO)
https://ico.org.uk
