A Promise of your Privacy.

I believe in building a relationship with you based on trust, and that starts with being open and honest about how I handle your personal information. This privacy policy explains in simple terms how I, Laura McLaughlin, as a sole practitioner at McLaughlin Hypnotherapy, collect, use, store, and protect your data.

1. About Me

As the sole operator of McLaughlin Hypnotherapy, I am responsible for handling and protecting your personal information. If you have any questions or concerns about this policy or your data, please contact me at: mclaughlinhypnotherapy@gmail.com

2. What Data I Collect

To provide you with tailored and effective hypnotherapy, I collect and keep a record of your personal details and relevant history for a minimum of seven years, as required by my insurance. This may include:

  • Personal information: Your name, address, age, email, phone number, occupation, and family/relationship details.

  • Health history: Information about your physical and mental health, and the reasons you have chosen to seek therapy.

  • Session notes: A handwritten record of information you share in sessions, along with notes relevant to your therapy.

3. How and Why I Use Your Information

With your explicit consent, I use the information you provide to:

  • Customise your hypnotherapy: To create a therapy plan suited to your needs.

  • Ensure continuity of care: To refer back to previous sessions for consistency.

  • Meet professional and legal obligations: To comply with ethical guidelines and insurance requirements.

  • Manage appointments: Using your contact details for scheduling and administrative matters.

4. Confidentiality and Supervision

What we discuss in our sessions is strictly confidential. However, there are rare exceptions:

  • Duty of care: If I believe you or others are at risk of serious harm, I have a professional and legal duty to act, which may require breaking confidentiality. I will always aim to discuss this with you first.

  • Professional supervision: To ensure best practice, I discuss my work with a clinical supervisor. Identifying details are removed to protect your anonymity.

5. How I Store and Retain Your Information

  • Hardcopy records: All session records are handwritten and stored in secure, locked physical storage.

  • Emails:  Any initial enquiry and ongoing correspondence is managed through my Gmail account, which is protected with two-step authentication to help keep your information secure.

  • Retention period: I retain records for seven years after our last session, in line with insurance requirements. For children, records are kept for seven years after their 18th birthday. 

6. Your Rights

Under UK GDPR, you have the right to:

  • Access: Request a copy of the information I hold about you.

  • Rectify: Ask for corrections if information is inaccurate or incomplete.

  • Erase: Request deletion of your personal data in certain circumstances.

  • Object: Object to the processing of your data.

7. Who I Share Your Data With

I will never sell or share your personal information with third parties without your explicit consent. The only exceptions are when I am legally required to do so or in safeguarding emergencies, as outlined above.

8. Complaints

If you have concerns about how your data is handled and we cannot resolve them together, you have the right to contact the Information Commissioner’s Office (ICO): www.ico.org.uk 

 9. Website Cookies, effective July 2025

 Cookies are small text files that are placed on your computer’s hard drive by your web browser when you visit any website. They allow information gathered on one web page to be stored until it is needed for use on another, allowing a website to provide you with a personalised experience and the website owner with statistics about how you use the website so that it can be improved.  I use necessary cookies to track how you use my website.

Some cookies may last for a defined period of time, such as one day or until you close your browser. Others last indefinitely. Your web browser should allow you to delete any you choose. It also should allow you to prevent or limit their use.