Privacy Policy
Last Updated: 27 July 2026
Introduction
This Privacy Policy explains how Jamie White Therapy collects, uses, stores, and protects personal data obtained through this website.
I am committed to protecting your privacy and handling your personal data responsibly and in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable data protection legislation.
This Privacy Policy applies to visitors to this website and individuals who make enquiries through it. Information relating to ongoing therapy, including how personal information is collected, used, and stored during our work together, is explained separately in the Client Privacy Notice and Therapeutic Contract I provide before therapy begins.
Data Controller
The data controller responsible for this website is
Data Controller: James White (trading as Jamie White Therapy)
Email: jamie@jamiewhitetherapy.co.uk
Telephone: +44 7942 366929
ICO Registration No.: ZA895598
If you have any questions about this Privacy Policy or how your personal data is handled, please contact me using the details above.
Personal Data I Collect
Information You Provide
If you contact me through this website, I may collect:
Your name
Email address
Telephone number
Preferred method of contact
Information you choose to include in your enquiry
Please avoid sharing extensive personal or sensitive information through the contact form where possible. More detailed discussions can take place during an introductory conversation or therapy session.
Information Collected Automatically
When you visit this website, certain information may be collected automatically, including:
IP address
Browser type and version
Device information
Pages visited
Date and time of visits
General website usage information
This information helps maintain website security and improve website performance.
How Your Personal Data Is Used
I may use your personal data to:
Respond to enquiries
Arrange consultations and appointments
Communicate with you regarding services
Maintain the security and functionality of the website
Improve the performance and content of the website
Meet legal, regulatory, or professional obligations where required
Your personal information will not be sold or shared for marketing purposes.
Lawful Basis for Processing
Under UK GDPR, the lawful bases relied upon for processing personal data through this website include:
Legitimate Interests
To respond to enquiries, administer the website, and provide information about my services.
Consent
Where required, such as for non-essential cookies and website analytics. You may withdraw consent at any time where consent is the lawful basis for processing.
Legal Obligations
Where processing is necessary to comply with legal or regulatory requirements.
If you choose to include information about your health or well-being in an enquiry, I will process this information only where necessary and in accordance with applicable UK data protection law.
Website Analytics
This website uses Google Analytics 4 to help understand how visitors use the website and to improve the information and services provided.
Google Analytics may collect information such as:
Pages visited
Time spent on the website
Device and browser information
General geographic location based on IP address
Google Analytics cookies will only be activated where you have provided consent through the website's cookie banner.
Further information about how Google processes data can be found in Google's Privacy Policy.
Cookies
Cookies are small text files stored on your device when you visit a website.
This website uses:
Essential Cookies
These cookies are necessary for the website to function properly and cannot be switched off.
Analytics Cookies
These cookies help me understand how visitors use the website so that I can improve its performance and usability.
Analytics cookies will only be placed on your device if you choose to accept them through the cookie consent banner.
You can also manage cookies through your browser settings.
Online Booking and Third-Party Services
This website includes links to third-party services that support the running of the practice.
Online Booking
If you choose to book an introductory conversation online, you will be directed to Konfidens, which provides secure appointment booking on my behalf. Any information you provide through Konfidens will be handled in accordance with their privacy policy as well as my own.
External Websites
This website may also include links to external websites or services, such as Google Maps or social media platforms. If you choose to follow these links, those organisations are responsible for how they collect and use your personal information. I encourage you to review their privacy policies before using their services.
Email Communications
If you contact me by email or through the website contact form, your personal data will be processed and stored using Google Workspace.
Reasonable steps are taken to ensure personal data is stored securely and accessed only where necessary.
However, email should not be considered a completely secure method of communication. Please avoid sending highly sensitive personal information by email wherever possible.
How Long Personal Data Is Retained
General Website Enquiries
If you contact me but do not become a client, enquiry records will normally be retained for up to 12 months after the last communication before being securely deleted.
Client Information
Information relating to therapeutic work is retained in accordance with professional, legal, and insurance requirements and is covered separately within the Client Privacy Notice provided to clients.
Sharing Personal Data
Personal data will be treated confidentially and will not be sold or shared with third parties for marketing purposes.
Information may be shared where necessary with trusted service providers who support the operation of the website or practice, including:
Website hosting providers
Email service providers
Appointment booking providers
IT and security providers
Information may also be disclosed where required by law, court order, safeguarding obligations, or other legal requirements.
Data Security
Appropriate technical and organisational measures are in place to help protect personal data against unauthorised access, loss, misuse, alteration, or disclosure.
These measures include:
Secure website hosting
SSL/HTTPS encryption
Password-protected systems
Secure email services
Restricted access to personal data
While every effort is made to protect personal information, no method of electronic transmission or storage can be guaranteed to be completely secure.
Your Rights
Under UK GDPR, you have rights regarding your personal data, including:
The right to access your personal data
The right to request correction of inaccurate information
The right to request deletion of personal data in certain circumstances
The right to restrict processing in certain circumstances
The right to object to processing in certain circumstances
The right to data portability where applicable
The right to withdraw consent where consent is relied upon
I do not use automated decision-making or profiling in the processing of your data.
If you wish to exercise any of these rights, please contact me using the details provided above.
Complaints
If you have concerns about how your personal data is handled, please contact me in the first instance so that I can try to resolve the issue.
You also have the right to complain to the Information Commissioner's Office (ICO) if you believe your personal data has been processed unlawfully or your data protection rights have been infringed.
Further information is available on the ICO website.
Changes to This Privacy Policy
This Privacy Policy may be updated from time to time to reflect changes in legal requirements, professional obligations, or website functionality.
Any updates will be published on this page, and the revised version will take effect immediately upon publication.