TERMS AND CONDITIONS 

Payment 

Payment will be taken a minimum of 48 hours in advance for all appointments booked (this includes full  payment for packages). Unpaid appointments will be cancelled 48 hours prior. Hypnofiles121 will  endeavour to give notice where possible in terms of holidays or of any other need to cancel a future  appointment. 

Cancellation and missed session  

If you are unable to attend your appointment, please let us know as soon as possible. We will endeavour to offer you an appointment within 7 days. The required notice for cancellation is 48 hours. If there is  less notice, or if you fail to attend your appointment, the full fee is not refundable. We hope clients  appreciate it is rarely possible to fill these appointments at such short notice, which is why we are  obliged to charge for the Therapy time. 

Confidentiality 

Confidentiality is an integral part of hypnotherapy and is essential to building the therapeutic  relationship. The therapeutic process encourages the client to be as open and honest as possible. Inevitably personal experiences and sensitive information are disclosed. It is vital the client can trust that discussions will remain confidential. Information will remain confidential unless both the client and  therapist agree for disclosure with a third party. The only circumstance where confidentiality will be broken would be if there was a serious risk to the client’s life or if another person’s life was at risk;  alternatively, in the rare instance where the therapist was liable to civil or criminal court proceedings if  they did not disclose client information. If possible, this would be discussed with the client beforehand  to safeguard client confidentiality. 

Clients under 18 years of age 

Clients who are under 18 years of age and who wish to undertake hypnotherapy are entitled to the same  level of privacy as their adult counterparts. Clients under 18 will require the written consent of a parent  or guardian. Any clients under 18 years of age will have their files retained until they reach the age of 25, in line with medical industry guidelines. 

Online Therapy 

Online therapy requires the same consent as in person therapy, and those wishing to undergo online  therapy will be expected to complete the same consent forms.

HYPNOFILES121 

Handling of Personal Information (GDPR compliance) 

Hypnofiles121 holds all records securely and ensures the utmost confidentiality in the treatment of any  information held about its clients. No information will be disclosed without the client’s express permission,  except under certain rare legal circumstances (outlined above). Hypnofiles121 subscribes to the NCH  (National Council of Hypnotherapy) code of ethics for Hypnotherapists. A Copy of this code is available on  request. The Hypnofiles121 practice is fully insured for professional liability and maintains regular  supervision courses.  

The GDPR identifies the following individual rights: 

To know what information is held about you and the measures taken to protect your privacy To access yourinformation (Written requestto be sentto hypnofiles121@gmail.com. The initial  access is free and subsequent access will be charged at the hourly appointment rate.  To amend or rectify information if recorded inaccurately 

To withdraw your consent to use your personal information 

To identify specific contexts where you do not wish to receive communication 

To request permission to transfer your information to a third party 

To erase your personal data (There is a legal obligation to hold records for a minimum of 7 years and  will be securely destroyed after this) 

To use the data provided for the stated purpose only. If it is my professional opinion that there is an  immediate risk of harm presented to you or to others by not disclosing information, the ‘greater  good’ rule will be applied, and confidentiality will no longer be paramount. In these instances, I may  be required to contact your GP or other appropriate third parties. Only information to ensure your  safety or that of others will be shared. Data can be disclosed without your consent for the prevention  or detection of a crime. 

Not to be subjected to automated-decision making including profiling. 

Storage of Data: 

Information is received at hypnofiles121 in many forms including but not limited to text messages, in  person, social media, voicemail and email. 

The personal data is then secured using the following mechanisms: 

Written data is stored in a secure locked storage unit. 

Electronic information is stored on password protected devices (including business phone and  laptop). 

All social media accounts including Facebook are password protected and accessed via password protected devices (mobiles or laptops). 

Voicemail is linked to a business phone and is password protected 

Internet security measures 

Personal data will be stored on servers within the European Economic Area (EEA). The GDPR restricts data  transfers to countries outside the EEA in order to ensure that the level of data protection afforded to  individuals by the GDPR is not undermined. 

Legal basis for processing the data 

There is consent of the data subject from the online opt-in 

Legitimate reasons where individuals are seeking therapy and is necessary to carry out the task Legal obligation where insurance and governing bodies require personal data to be held for a  minimum period.

HYPNOFILES121 

Sharing of Data: 

Your personal data will not be shared without your permission unless there is a legal duty to do so. This has been outlined in Client’s Rights section. 

Your data may be shared with service providers in order to complete administrative tasks such as sending  you appointment reminder message via social media platform or to process financial transaction. These  services will have access to limited relevant information to provide the required service on the company’s  behalf. They are not entitled to use the information for any other purpose. Any service providers will adhere  to GDPR and ICO regulations. 

The Code of Conduct as set out by the NCH and requires regular supervision, this includes case discussion. This does not require disclosure of names and therefore individual identities remain protected. 

Your information will remain confidential unless you have given explicit permission to share (with the  exceptions identified above). 

Express written permission will be required to share testimonials and can be withdrawn at any time. 

Clients under the age of 16 are entitled to privacy, please refer to the guidance note in relation to working  with young people. 

Data Breaches: 

Where a data breach occurs and results in the potential risk to the individual’s rights and freedoms including  but not limited to financial loss, loss of confidence, damage to reputation or any other social or economic  disadvantage, the ICO and the individuals will be informed within 72 hours. All other breaches will be  reviewed internally and recorded and held indefinitely.