Privacy Policy
Last updated: 6 September 2026
This policy explains how Wendy Kinloch, trading as Therapy for Change (“I”, “me”, “the practice”), handles personal information you provide through this website. It is written in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who is responsible for your data
I am the data controller for any personal information you share through this site. You can reach me at:
- Email: wendy@therapyforchange.scot
- Postal address: 12 Carmaben Brae, Dolphinton, West Linton, Peeblesshire EH46 7HF
- ICO registration: I am registered with the Information Commissioner’s Office as a data controller, reference ZC235123.
2. What information I collect
I only collect what I need to respond to you and run the practice. Specifically:
- Contact form submissions: the name, email address, and message you provide.
- Direct correspondence: any details you send by email, phone, or post.
- Reviews: if I invite you to leave a review and you choose to, the name you ask to be shown by and the words you write. Leaving one is entirely optional and declining changes nothing about your care.
- Booking information: the name, contact details, and preferred times you give me when arranging a session. Bookings are arranged by email directly with me — there is no third-party scheduling service and no online payment.
- Website analytics: anonymous, aggregate visit information collected via Plausible Analytics, and only if you accept analytics on the cookie banner. No personal identifiers, IP addresses, or cross-site tracking are stored. See section 6 below.
I do not collect special category data (such as health information) through this website. Any clinical information you share during sessions is held under separate professional confidentiality and record-keeping practices.
This practice is for adults aged 18 and over. I do not offer sessions to under-18s and I do not knowingly collect personal information from anyone under 18 through this website.
3. Why I use it (lawful basis)
Under UK GDPR I rely on the following lawful bases:
- Consent — for analytics cookies, for publishing a review you have chosen to leave, and for any optional newsletter or follow-up I might issue.
- Legitimate interests — to reply to your enquiry and to keep my own records of correspondence.
- Contract — to arrange and provide therapy sessions you have booked.
- Legal obligation — to keep accounting and professional records as required by HMRC and by my professional body.
4. Who I share it with
I do not sell your data. I share it only with service providers I rely on to run the practice:
- OVH — an email service based in France that passes contact-form messages to my inbox.
- Vercel — hosts this website.
- Plausible Analytics — processes anonymous traffic statistics, only with your consent.
Each of these providers acts as a processor under contract and is obliged to handle your data in line with UK GDPR. I do not transfer personal data outside the UK or EEA to providers without appropriate safeguards.
5. How long I keep it
- Enquiries that do not lead to a session: not retained. Once I have replied and it is clear we will not be working together, I delete the message and your details.
- Client records (active and former clients): kept for 7 years after the last session, in line with professional and insurance guidance.
- Financial records: kept for 6 years from the end of the relevant tax year, as required by HMRC.
- Reviews: a published review stays on the site until you ask me to remove it, which you can do at any time, for any reason, without giving one. A review I decide not to publish is deleted. Unused invitation links stop working after 60 days.
- Analytics data: aggregate only, retained by Plausible and not linked to you.
6. Cookies and tracking
This site sets no tracking cookies and no advertising cookies. Nothing here follows you from site to site, and nothing about your visit is sold or passed to advertisers.
The one cookie the site does set. Until the site opens to the public it sits behind a password. If you type that password in, the site saves one small cookie, named tfc_preview, so you do not have to type the password again on every page. It holds a scrambled version of the password — never the password itself, and nothing at all about you. It lasts 30 days, and it goes away for good when the site goes live. A cookie like this is strictly necessary to let you through the door, so it does not need your consent.
How your answer to the banner is remembered. When you press Accept or Decline, your answer is saved in your own browser under the name tfc.consent. It is kept in the browser’s local storage rather than in a cookie, which means it is never sent to me or to anyone else. All it does is stop the banner asking you the same question on every visit.
Analytics, and only if you say yes. If you press Accept, the site loads Plausible Analytics so I can see which pages people find useful. Nothing is loaded before you press Accept, and if you press Decline nothing is loaded at all. Plausible sets no cookies whatsoever, stores no IP addresses, and does no cross-site tracking — it counts visits, not people. Plausible states that it stores its data on servers in the European Union, in Germany.
Changing your mind. I should be straight with you: there is no button on the site to reopen the banner once you have answered. To change your answer, clear this site’s stored data in your browser settings. That removes the saved answer, so no analytics will load again, and the banner will ask you the question afresh on your next visit.
7. Your rights
Under UK GDPR you have the right to:
- Request a copy of the personal data I hold about you.
- Have inaccurate data corrected.
- Have data erased, where I am not required to keep it.
- Restrict or object to processing.
- Withdraw consent at any time, where consent is the lawful basis.
- Lodge a complaint with the Information Commissioner’s Office (ICO): ico.org.uk/make-a-complaint.
To exercise any of these rights, please contact me at the address in section 1.
8. Security
I use providers that apply industry-standard encryption in transit and at rest. Local records are kept secured in line with my professional body’s guidance.
9. Changes to this policy
If this policy changes I will update the “Last updated” date at the top. Material changes will be flagged on the home page for 30 days.