APF Wellness – Privacy Policy

1. Introduction and Who We Are

Welcome to APF Wellness. APF Wellness is a brand operated by APF Business Ltd. For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, APF Business Ltd is the “Data Controller” of your personal information.

We are committed to protecting the privacy, confidentiality, and security of our clients seeking online counselling and psychotherapy services.

2. What Personal Data We Collect and Our Lawful Basis

Due to the sensitive nature of psychotherapy, we collect standard personal data as well as highly sensitive health data (known legally as “Special Category Data”).

  • Standard Personal Data: This includes your name, contact details, billing information, and web enquiries.
    • Lawful Basis: We process this data to fulfil our contract with you for bookings and sessions (Article 6(1)(b) UK GDPR) and where necessary to respond to your enquiries (Article 6(1)(f) – Legitimate Interests).
  • Special Category Data (Mental Health): This includes information concerning your mental and physical health, intake forms, and Clinical Notes.
    • Lawful Basis: We process this highly sensitive data on the basis of your explicit consent (Article 9(2)(a) UK GDPR) and for the provision of healthcare services (Article 9(2)(h) UK GDPR and DPA 2018 Schedule 1).

3. Limits of Confidentiality and Safeguarding

Counselling is a strictly confidential space. However, in accordance with professional ethical guidelines (e.g., BACP, UKCP) and UK law, there are limits to this confidentiality. We may be legally or ethically required to share your data with appropriate third parties (such as your GP, emergency services, or local safeguarding authorities) without your consent if:

  • We believe you are at serious risk of harm to yourself or others;
  • You share information regarding the abuse or neglect of a child or vulnerable adult (Safeguarding);
  • We are compelled to do so by a UK court of law.

Wherever clinically appropriate and safe, we will attempt to discuss this with you before breaching confidentiality.

4. Third-Party Processors and International Transfers

To deliver our professional services, we use a suite of secure, industry-standard third-party processors. We ensure that all providers are GDPR-compliant and, where data is transferred outside the UK/EEA (for example, to US-based servers), we ensure appropriate safeguards—such as Standard Contractual Clauses (SCCs) or reliance on UK Adequacy Decisions—are strictly in place.

We engage with specific categories of processors to manage different aspects of your care:

  • Clinical Management: We use specialised Practice Management Systems to securely store your intake forms, appointment history, and Clinical Notes.
  • Telehealth and Communication: We utilise secure Video Conferencing platforms for all therapy sessions, and professional Email/Productivity suites for administrative correspondence.
  • Financial Transactions: We use encrypted Payment Gateways to process session fees. Please note that APF Wellness does not store your full credit card or payment credentials in our systems; the provider handles these entirely.
  • Administrative Records: We use professional Accounting and Invoicing software to manage our business records and tax obligations.

For a detailed list of the specific platforms and sub-processors used in our technical infrastructure, you may request our Data Processing Register from our Data Protection Officer (DPO).

5. Digital Engagement, Analytics and Advertising

We maintain a professional presence on social media platforms, such as Facebook and LinkedIn, for community engagement and information sharing. To ensure our website remains user-friendly and effective, we utilise certain digital insight tools:

  • Website Analytics: We use industry-standard web analytics and heatmapping tools to monitor website traffic and user behaviour. These tools help us understand how visitors navigate our site so we can improve our service delivery. Where possible, this data is processed in an anonymised format.
  • Digital Advertising: We utilise search and social media advertising platforms to reach potential clients. These platforms may use cookies or tracking pixels to measure the effectiveness of our outreach campaigns.

Note on Privacy and Tracking: We hold a strict policy against “retargeting” or “surveillance” advertising. We do not use pixels to track your specific mental health interests or browsing history across the web. In compliance with PECR (Privacy and Electronic Communications Regulations), any non-essential tracking or advertising cookies are strictly subject to your explicit, prior consent via our cookie banner.

6. How Long We Keep Your Data

Data Retention and Storage

In line with professional psychotherapy standards, clinical governance, and our professional indemnity insurance requirements, we adhere to strict storage limitation principles. We do not retain data longer than is legally or professionally necessary.

  • Clinical Records: Information held within our Practice Management Systems (including intake forms, session summaries, and Clinical Notes) is retained for 7 years following the conclusion of your final therapy session. This period is required to meet our regulatory and legal obligations.
  • Administrative and Financial Records: Data related to billing, invoicing, and transaction records (held within our Accounting and Payment systems) is retained in accordance with UK tax and financial regulations.
  • Communications and Enquiries: Information provided via web enquiries or email that does not result in an active clinical relationship is securely deleted after 6 months.

After these mandatory retention periods expire, we permanently and securely delete all digital records and destroy any physical documentation.

7. Your Legal Rights

Under the UK GDPR, you have the right to:

  • Access your data (requesting a copy of the personal data we hold about you);
  • Rectify inaccuracies in your data;
  • Erase your data (noting that this does not include clinical data we are legally or professionally obliged to keep for administrative, legal, or security purposes);
  • Restrict or Object to the processing of your data; and
  • Request Data Portability.

8. Contact Information and Complaints

If you have any questions or wish to exercise your legal rights, please contact our Data Protection Officer:

Data Protection Officer: Beata Anna Faff
Email: [email protected]

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) (www.ico.org.uk) if you believe we are mishandling your data.