Privacy Policy – Good Therapy Ltd
Version 1.1 | Last Updated: 17th August 2025
Business Information
Company Name: Good Therapy Ltd (trading as Plum Psychology and Dr Claire Plumbly, Clinical Psychologist)
Company Number: 14469820ICO
Registration Number: ZB641652
Registered Address: Wessex House, 66 High Street, Honiton, England, EX14 1PD
Website: www.drclaireplumbly.com | www.plum-psychology.com
Email Address: hello@plum-psychology.com
About this Privacy Policy
We are committed to protecting your privacy and complying with the Data Protection Act 2018, the UK GDPR, and other applicable UK legislation (“Data Protection Law”).
When you interact with us or use our websites, Good Therapy Ltd acts as the data controller of your personal data. This means we decide how and why your personal data is used.
We may update this policy from time to time. The latest version will always be published on our websites.
Who This Policy Applies To
-
Website visitors
-
Prospective clients
-
Clients (including those supported by associates)
-
Referral sources (e.g., GPs, insurers, partners)
-
Newsletter subscribers
-
Suppliers and contractors (including associates, VAs, marketing team, accountant, web designer)
This policy does not apply to staff employment records.
Data Protection Principles
We process your personal data according to these principles:
-
Lawfulness, fairness, and transparency
-
Purpose limitation
-
Data minimisation
-
Accuracy
-
Storage limitation
-
Integrity and confidentiality
-
Accountability
Data We Collect and Why
Note: Multiple lawful bases may apply to one purpose.
How We Collect Data
-
Directly from you – via enquiry forms, intake forms, email, phone, or during therapy sessions.
-
From referrers (e.g., GPs, insurers, or referral partners).
-
Through our websites (forms, cookies, analytics).
-
Via email marketing sign-ups.
Legal Grounds for Processing
We rely on:
-
Consent – e.g., for marketing communications.
-
Contract – to provide psychological services.
-
Legitimate Interests – e.g., to ensure service quality, respond to enquiries.
-
Legal Obligation – e.g., tax compliance, safeguarding duties.
-
Vital Interests – e.g., sharing information to protect life or safety.
-
Special Category Data – processed under Article 9(2)(h) UK GDPR (provision of health care).
Sharing Your Data
We may share your data with trusted third parties, including:
-
Clinical Associates – associates delivering therapy within Plum Psychology practice ( under Good Therapy Ltd).
-
Supervisors – anonymised or limited information may be discussed for professional supervision.
-
Practice Management & IT Systems – WriteUpp (client notes), Heidi Health AI Notetaker, Zoom (online sessions), Xero (accounting), Mailerlite (email marketing), Wix (website hosting), Click-Up (referral management).
-
Professional Support – Accountant, VAs, marketing team, website designer, IT support.
-
Referral Partners – where you have been referred via a GP, insurer, or partner organisation.
-
Legal, safeguarding, or emergency services – where required by law or to protect safety.
All third parties are bound by Data Processing Agreements or confidentiality contracts.
Third-party Links
Our websites may link to other sites. We are not responsible for their privacy practices. Please review their privacy policies.
Security Measures
-
Secure, encrypted cloud storage (WriteUpp).
-
SSL encryption, password protection, role-based access.
-
Regular backups, audit trails, and data minimisation.
-
All personal data incidents, including near misses, are recorded and investigated.
-
Breach notification process in place; ICO and affected individuals will be informed where required.
Special Category Data
We process special category health data in line with:
-
Article 9(2)(h) UK GDPR – provision of health care and treatment.
-
Professional codes of practice (HCPC).
-
Additional safeguards including encryption, access restrictions, and anonymisation where possible.
Children’s Data
We do not provide services directly to children or process children’s data.
Your Rights
You have the right to:
-
Be informed
-
Access your data
-
Rectify inaccurate or incomplete data
-
Erase your data (subject to clinical/legal obligations)
-
Restrict processing
-
Data portability
-
Object to processing (including marketing)
-
Withdraw consent at any time
Requests will be responded to within one month. Some rights may be limited if records must be retained for legal or clinical reasons.
Use of Automation and AI
We use automation and AI for:
-
Clinical note support (Heidi Health AI Notetaker - where your explicit consent is given)
-
Practice management (WriteUpp reminders, scheduling)
-
Email marketing and website analytics
Safeguards:
-
DPIAs completed for AI tools
-
AI tools set to internal-only learning where possible
-
No significant clinical or legal decisions made solely by AI
-
Sensitive client data only entered into AI tools with appropriate safeguards
Data Retention
-
Clinical records: 7 years after last contact (HCPC requirement)
-
Financial records: 6 years (legal requirement)
-
Marketing data: until consent is withdrawn
-
Website analytics/cookies: up to 3 years or until withdrawn
Complaints
If you are unhappy with how we handle your data, please contact us at hello@plum-psychology.com.
You also have the right to complain to:
Information Commissioner’s Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
www.ico.org.uk
You may also raise concerns with the HCPC (Health and Care Professions Council).
Updates
We may update this policy from time to time and will publish the latest version on our websites.




