Data & privacy
How I handle your information
This page explains how I collect, store and protect your personal data in line with UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025.
- HCPC registered · PYL331452
- ICO registered · ZA340930
Privacy policy
Who I am
I am Dr Sophie Mort (Dr Soph), an HCPC registered clinical psychologist (registration number PYL331452). I am the data controller for the personal data described here and am registered with the Information Commissioner’s Office (ICO) under registration number ZA340930. If you have any questions about how I handle your data, email soph@drsoph.com.
What personal data I collect
- Contact details: your name, email address and any other details you send me
- The content of enquiries you send through this website or by email
- If you sign up for a free guide or newsletter: your first name and email address
- If we work together in therapy: health and therapy-related information, session notes, emergency contact details and payment records
Health and therapy information is “special category data” under Article 9(1) UK GDPR. It receives enhanced legal protection, and I take particular care to keep it secure and confidential.
Why I process your data: lawful basis
- Enquiries: legitimate interest (Article 6(1)(f)) in responding to you.
- Free guides and newsletter: your consent (Article 6(1)(a)), which you can withdraw at any time using the unsubscribe link in every email.
- Therapy: performance of our therapy contract (Article 6(1)(b)). For health data, Article 9(2)(h), provision of health care by a health professional, with the condition in DPA 2018 Schedule 1, Part 1, paragraph 2.
- Financial records: legal obligation (Article 6(1)(c)).
Clinical supervision
As part of safe, ethical practice I discuss my clinical work in supervision. I do not share your name or identifying details, and my supervisor is bound by the same professional confidentiality obligations as I am.
Who I share your data with
I never sell your personal data. I use a small number of service providers:
- Kit (ConvertKit LLC, USA) to send free guides and emails you have signed up for
- A secure video platform for online therapy sessions
- Website hosting providers that run this site
- An accountant, who sees invoice data only for tax purposes
Where a provider transfers data outside the UK (for example to the USA), I rely on appropriate safeguards such as the UK International Data Transfer Agreement or Standard Contractual Clauses, in line with UK GDPR Chapter V.
Confidentiality and its limits
Everything you share in therapy is confidential. In limited circumstances I may need to share information: if there is a serious risk of harm to you or someone else, if there is a safeguarding concern about a child or vulnerable adult, or if disclosure is required by law or a court order. Wherever possible I will discuss this with you first, unless doing so would itself put someone at risk.
Keeping your data secure
Records are stored electronically with password protection, access controls and encryption where applicable. Access is restricted to me.
Data retention
| Type of record | Kept for | Reason |
|---|---|---|
| Therapy records (adults), including notes and agreement | 7 years after our last session | Limitation Act 1980 and professional indemnity insurance requirements |
| Financial records and invoices | 6 years from the end of the financial year | HMRC legal requirement |
| Enquiries from people who don’t become clients | 12 months from last contact | Legitimate interest in responding to enquiries |
| Free guide and newsletter sign-ups | Until you unsubscribe | Your consent |
After the retention period, electronic records are permanently deleted and any paper records are securely destroyed. The right to erasure is not absolute: I may need to keep therapy records until the end of the retention period where required by law, professional guidance or insurance.
Your rights under UK GDPR
- To be informed about how your data is used (this page)
- To access a copy of your data (a Subject Access Request). I will make a reasonable and proportionate search and respond within one month
- To have inaccurate or incomplete data corrected
- To ask for your data to be deleted, subject to the retention limits above
- To restrict or object to how your data is used in certain circumstances
- To data portability
- Not to be subject to decisions based solely on automated processing. I do not use automated decision-making
To exercise any of these rights, email soph@drsoph.com.
Make a data protection complaint
If you believe I have not handled your personal data in line with UK data protection law, you can complain to me directly by emailing soph@drsoph.com with the subject line “Data protection complaint”. Please include relevant dates and any previous contact about the matter.
I will acknowledge your complaint within 30 days, as required by the Data (Use and Access) Act 2025, and respond in full. Details you send are used only to handle your complaint.
If you are not satisfied with my response, you can contact the ICO:
- Website: ico.org.uk
- Telephone: 0303 123 1113
- Post: ICO, Wycliffe House, Water Lane, Wilmslow, SK9 5AF
Changes to this policy
I review this page annually and whenever my practices change. Last updated October 2026.
If you need urgent support, please see crisis help.