Data protection policy, Complaints DUAA and processes

Data Protection information (Update 18.06.2026)

We keep minimal possible information on our clients and colleagues. since the pandemic (COVID) our systems radically changed to digital since COVID hygiene rules meant going “paper-free”. Increased data protection legislation has also meant an increased emphasis on only keeping information for as long as needed, and justifying that need. This also means ONLY keeping the information that is needed on a client, and securely deleting other information such as basic contracting information.

Data Use and Access Act (DUAA) Info:

https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/the-data-use-and-access-act-2025-what-does-it-mean-for-organisations/

ICO and DUAA compliance is outlined below in terms of client data. The most important factor is the healthcare regulation requirement (via CNHC registration) that requires clinical data and other data to be held in the long term for serious clinical cases.

We do not hold any marketing data or digital marketing data such as “cookies”. Clients and potential clients are advised that web platforms such as WordPress and Webhealer and their software may use cookies for ensuring a smooth browsing experience, and search engines and advertising directories that led you to our sites may also use these. These are third party platforms and not in our control, and although they are permitted by DUAA, we advise all clients and potential clients to use security settings on their browsers to delete these traces on exit of their browsers automatically, and to use security software to cleanse their systems of these. Clients and potential clients are also reminded that these issues effect all digital access systems, not just computers, and devices like tablets and smartphones should also be kept clear of these unwanted software traces.

Scotlandtherapy Partners is a HMRC registered sole trader partnership.  Scotlandtherapy is ICO registered.

  1. Email software may store contact details and emails until deleted, this is basic correspondence to enable clinical service. We need this to arrange support.
  2. Data is only shared for emergency support, in cases of extreme risk to public or personal safety, or if clinical data is needed for safe referral. This is guided by Safeguarding Policies and legal requirements.
  3. As a result of (and following) the COVID crisis we are keeping COVID (and post COVID general infection) consent forms in order to be able to ensure compliance with safety requirements, and in order to be able to cooperate with Government Track and Trace systems should these return.
  4. Initial assessment forms and other assessment forms will be kept in hard copy format in a locked filing cabinet. Clients may refuse to complete these but this may prevent service. As of April 2023 we have now securely shredded the majority of hard copy  contracting forms, since for several years new clients have been using digital forms instead. The handful of existing hard copies that need to be kept will be digitized or replaced with new forms during 2023 and then also shredded. For the last decade ongoing notes have been stored securely and digitally and these are kept longer (see paragraph 9).
  5. Assessment and other data is held in passworded email accounts and associated secure business cloud systems, with an extra level of access required via security application. All emails are encrypted by default (TLS).
  6. All out of date or non essential data will be deleted (digital) and or shredded (hard copy). we use encryption built into Gmail, encrypted deletion, extra security password protection and a full software suite of firewall and security protection on all computer and smartphone equipment.
  7. Virtual sessions are carried out with  Google meetings which has encryption compliance.
  8. Our legal basis for holding data is: clinical care, regulatory requirement and insurance coverage requirements in case of a complaint.
  9. At present CNHC regulator requirement for data holding is 8 years. Insurance requirement is less unless the person is of vulnerable mental state, in which case it is 5 years after that state ends. Long term serious conditions that are lifetime conditions or likely to be therefore mean indefinite holding of data (Contracting forms are not required as such, this is about client clinical data or “notes”. Non essential data is securely deleted / shredded and only the required data is kept.)
  10. You may withdraw consent to collect and store data at any time, but this may make provision of the service impossible because of the need to collect data for your treatment and safety.
  11. Fire safety data is collected in person using a digital tablet device when clients enter the physical building. Only a name and purpose of visit is collected, and this is deleted after 30 days automatically. This data is held by software on behalf of the Landlords for fire safety purposes only and will be shared with emergency services in the event of an emergency.
  12. Anonymous service data may be shared or used for research purposes (permitted by DUAA), but in the event more detailed data referring to your case is being considered for you, you will be contacted for permission, or invited to consider taking part directly.

Nominated person

Person responsible for data security is Stuart Morgan-Ayrs, Senior Partner. Stuart is also the lead Safeguarding Officer with responsibility for safeguarding information sharing decisions.

Age verification

Under adult age persons are not normally clients of our company, and then only if data is secured and signed by an adult and guardian. In the event of a young person using the service, an adult parent or guardian would be required to present age and ID verification.

Consent

Initial assessment forms set out how we handle and store data. Clients are informed as to use, handling and reason for that data. Clients are signposted to this resource in information files and emails.

Access

The only information held (apart from correspondence with the client) about the client are the assessment forms, already seen by the client. Emergency data from crisis situations is stored digitally and is available within 30 day limit. it is stored in secured and encrypted manner (see above) for the clinical safety and care of the client. Thus the client has sight of all materials about them naturally. The held material can be retrieved within the 30 day limit. Complex data may take longer, up to the 3 months permitted by the ICO

Complaints

You may complain to the ICO if you think we are not handling your data appropriately.

During the COVID crisis (and for following crisis of similar kind if they occur) attendance data and contact data may be shared with Track and Trace if required for health and safety reasons.

Scotlandtherapy Partners are ISO registered.

Contact via the contact us page HERE