Privacy Policy & GDPR Statement
At NKM Therapies, your privacy and wellbeing are our top priorities. We are committed to handling your personal data with care, transparency, and in full compliance with the UK General Data Protection Regulation (GDPR) and the Data Protection Act 2018.
- Who We Are
We offer a range of supportive services, including:
- Clinical hypnotherapy / Visualisation and Relaxation Therapy
- Mindset and wellbeing coaching
- Menopause coaching
- Talking therapy
- One-to-one therapy (in person and online)
- Workshops and group sessions
- What Information We Collect
To support you safely and effectively, we may collect:
- Contact details: name, address, phone number, email
- Emergency Contact: name. Phone number
- Health information: relevant medical or wellbeing history, including GP details.
- Session records: brief notes and progress summaries
- Booking & payment info: appointments, invoices, receipts
- Digital data: website enquiries, emails, online platform usage
- Marketing preferences: if you opt in to receive updates or resources
- Why We Collect Your Data
We use your data for the following purposes:
- To provide therapeutic services tailored to your individual needs
- To communicate with you regarding appointments, session updates, and relevant information
- To manage payments and scheduling efficiently and securely
- To comply with legal and professional obligations including record-keeping and safeguarding
- To improve our services by understanding client needs and preferences
- To respond to your inquiries and provide support when requested
- We treat all personal data with the utmost care and confidentiality, in line with GDPR and ethical standards.
- How We Store Your Data
- Your information is stored securely:
- Digital records: encrypted devices and GDPR-compliant platforms
- Paper notes: locked storage
- Access: restricted to the practitioner (Nicky Munson)
- Online sessions: conducted via secure, GDPR-compliant platforms
- How Long We Keep Your Data
- Therapy notes: up to 7 years after treatment ends
- Financial records: 6 years (for tax/accounting)
- General enquiries: deleted after 12 months
- Marketing data: kept until you withdraw consent
- Sharing Your Data
We do not sell or share your data for marketing. We may share data only:
- If required by law (e.g. court order, safeguarding)
- In cases of serious risk to yourself or others, with appropriate professionals
- Your Rights Under GDPR
You have the right to:
- Access your personal data
- Request corrections
- Request deletion (unless legally required to retain it)
- Restrict or object to processing
- Request data portability
- Withdraw consent for marketing at any time
- Confidentiality in Therapy
All sessions are confidential. We will only break confidentiality if:
- There is a risk of harm to you or others
- We are legally required to disclose (e.g. safeguarding, terrorism, money laundering)
Where possible, we will always discuss this with you first.