

Data Protection
Data Protection Statement
At Amanda Graham Hypnotherapy, your privacy matters. I’m committed to protecting your personal data and being open about how and why it’s used.
This statement explains what information I collect, how it’s stored, and what your rights are under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
What personal data I collect
When you make an enquiry, book a session, or attend an appointment, I may collect:
-
Your name and contact details (email address and/or phone number)
-
Relevant health or wellbeing information that you choose to share
-
Notes from sessions, including progress and treatment goals
-
Payment or invoicing information (if applicable)
Why I collect your data
Your personal data is used to:
-
Book, manage, and follow up on appointments
-
Provide personalised hypnotherapy support
-
Contact you if needed about your sessions or account
-
Maintain accurate records in line with professional practice standards
Your information will never be used for marketing unless you’ve given explicit permission.
How your data is stored
Your data is stored securely using one or more of the following:
-
An encrypted smartphone used only by Amanda Graham Hypnotherapy
-
The secure database on the Wix website (for website form submissions)
-
Meta Business Suite (if you contact me via Facebook or Instagram)
-
Any information taken down in written form will be stored in a locked filing cabinet.
Only Amanda has access to your personal data. I take all reasonable steps to protect it from loss, misuse, or unauthorised access.
How long I keep your data
If you become a client, your data will be kept for up to seven years after your last session in accordance with professional insurance requirements. If you make an enquiry but do not proceed with sessions, your details will be deleted after 12 months.
Your rights
You have the right to:
-
Access the personal data I hold about you
-
Request correction of any inaccurate or incomplete data
-
Request erasure of your data (in certain circumstances)
-
Object to processing if you believe it’s causing you harm
-
Withdraw consent at any time (where consent is the legal basis for processing)
To exercise any of these rights, just email me at amandagrahamhypnotherapy@gmail.com
Sharing your data
Your information will never be shared with third parties unless:
-
You have given explicit consent
-
I’m legally required to do so (e.g. for safeguarding concerns or by court order)
If I believe you or someone else is at risk of serious harm, I may have a legal or ethical duty to share relevant information with the appropriate authorities. Wherever possible, this will be discussed with you first.
Making a complaint
If you have concerns about how your data is handled, please get in touch using the email above. If you’re not satisfied with the response, you can contact the Information Commissioner’s Office (ICO) at www.ico.org.uk.
In short
-
Your data is treated with care, confidentiality, and respect.
-
You’ll always know why it’s being collected and how it’s being used.
-
You have full control over your information – and your rights will always be respected.
Any updates to this policy will be posted on this page.
This policy was last updated in June 2025.