Legal Notice
GDPR Statement
Last updated: 22 June 2026
Our Commitment to Your Privacy
At Fern River I Dianne Harrison, believe that protecting your privacy is fundamental to the trust we build together in therapy. Your personal information is treated with the same care and respect as everything you share with me in our sessions. This statement explains, in plain terms, how I look after your data.
What Information I Collect
To provide you with therapy, I collect and keep:
- Your name and contact details (address, phone number, email)
- Emergency contact information
- Details about what brings you to therapy (your presenting issues)
- Notes from our sessions together
- Relevant medical or health history that helps me support you
- Payment and invoicing information
Why I Collect This Information
I need to collect and use your information to provide you with therapy. The legal basis for this is:
- Article 6(1)(b) UK GDPR — processing is necessary for the performance of the therapeutic contract between us.
Because therapy involves sensitive health-related information, there is an additional legal basis:
- Article 9(2)(h) UK GDPR — processing is necessary for the provision of health or social care treatment by a health professional. The additional DPA 2018 Schedule 1 condition is Part 1, paragraph 2 (health or social care).
Professional Obligations and Supervision
As part of maintaining professional standards, I discuss my work in clinical supervision. This is an essential part of providing you with safe, ethical therapy.
Your identity is protected in supervision: I do not share your name or identifying details with my supervisor. My clinical supervisor receives anonymised case material only and is bound by their own professional confidentiality obligations.
Who Else May See Your Information
Beyond myself, the following people or services may have limited access to your information:
- Clinical supervisor — anonymised case material only; your identity is not disclosed
- External accountant or bookkeeper — invoice data only, for accounting purposes
- EAP or referral platform — where you have been referred via an Employee Assistance Programme, limited information may be shared as part of the commissioning arrangement
- External IT support — incidental access only during system maintenance
- Service providers — I use Sentry (error monitoring), Wix (website hosting), Zoom, Microsoft Teams, Google Meet (video sessions), and Calendly (appointment booking). These services may process limited technical or booking data
- Statutory authorities — only where I am legally required to share information
Clinical Will Arrangements
I am currently putting arrangements in place for a clinical will — this ensures your records would be handled appropriately by a designated professional colleague if I were ever unable to continue practising due to illness or death. Once these arrangements are finalised, I will let you know.
When I Might Need to Break Confidentiality
Everything you share with me is confidential, with very limited exceptions. I may need to share information without your consent if:
- There is a risk of serious harm to you or someone else
- There are child or vulnerable adult safeguarding concerns
- I receive a court order requiring disclosure
Wherever possible, I will always try to discuss this with you first.
How Long I Keep Your Records
I keep your therapy records for 7 years after our last session, in line with the Limitation Act 1980 and standard professional indemnity insurance requirements.
If you were under 18 when we worked together, I keep your records until you reach the age of 25, or for 7 years after our last session — whichever is longer.
Make a data protection complaint
If you believe Fern River has not handled your personal data in accordance with UK data protection law, you can submit a formal complaint using the contact form, titled complaint
You will receive an automatic acknowledgement email. Your complaint will be investigated and you will receive a response. If you are not satisfied, you have the right to escalate to the Information Commissioner's Office (ICO).