FANNI JAVOR THERAPY
Privacy Policy
Last updated: July 2026 · Data Controller: Fanni Javor, trading as Fanni Javor Therapy
This Privacy Policy explains what personal data I collect, why I collect it, how it is stored, and your rights. I comply fully with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. WHAT DATA I COLLECT AND WHY
I collect only the information necessary to provide my services safely and professionally:
| Data | Purpose |
| Name and age | To identify you and tailor sessions appropriately |
| Contact details (email, phone) | To communicate about sessions and related matters |
| Next of kin / medical professional details | Held securely; accessed only in cases of serious concern for your safety |
| Session notes |
Brief records of our work together, kept for professional accountability |
| Health information | To identify any contraindications before we begin |
My lawful basis for processing your data is the performance of our contract and my legitimate interests in providing a safe, effective, and professionally accountable service.
2. THIRD-PARTY PLATFORMS
In delivering my services, I use the following platforms, which may process your personal data under their own privacy policies:
– Google Meet — online session delivery
– WhatsApp / Messenger — client communication
– BunnyDocs — electronic agreement signing
– Stripe — payment processing
– Zcal — appointment scheduling via my website
I have taken reasonable steps to ensure these platforms provide appropriate safeguards. If you have concerns about any platform, please raise this before we begin.
3. HOW I SHARE YOUR DATA
I will never sell your data or use it for marketing without your explicit consent. Your data may be shared only in the following circumstances:
– Where required by law, court order, or legal authority
– Where there is a genuine risk of serious harm to you or another person
– In professional supervision, where all identifying details are removed
– With a referring GP or healthcare professional, if a report has been requested (a copy will be made available to you)
4. STORAGE & SECURITY
Your data is stored electronically on a password-protected device, accessible only by me. I take all reasonable technical and organisational steps to protect your information against unauthorised access, loss, or disclosure.
5. HOW LONG I KEEP YOUR DATA
I retain your personal data for five years from the end of our therapeutic relationship, as required by my professional indemnity insurer. After this period, all electronic files are permanently deleted and any paper records are securely destroyed.
6. YOUR RIGHTS
Under UK GDPR, you have the right to:
– Access the personal data I hold about you
– Correct any inaccurate data
– Request deletion of your data (subject to legal and professional obligations)
– Object to or restrict certain types of processing
To exercise any of these rights, please contact me directly. If you are not satisfied with how your data is handled, you may lodge a complaint with the Information Commissioner’s Office (ICO) at www.ico.org.uk.
7. UPDATES
This Privacy Policy may be updated from time to time. Any significant changes will be communicated to existing clients in writing.
Data queries: [email protected]