
privacy policy (Updated September 2026)
Introduction
Reflexive Thinking Ltd, trading as Rethink Your Self, is committed to protecting and respecting your privacy. This notice explains how we collect, use, store, share and protect personal data when you use our website and services.
Data Controller
Reflexive Thinking Ltd, trading as Rethink Your Self, is the data controller. Our company registration number is 15620464 and our ICO registration number is ZB819229. You can contact us at hello@rethink-your-self.com.
Information We Collect
We may collect your name, email address, telephone number and other information you choose to provide. This may include information about your physical or mental health, wellbeing or personal circumstances where relevant to the services provided. We only collect information that is reasonably necessary to provide our services and meet our legal, professional and ethical responsibilities.
Lawful Basis for Processing
Depending on the purpose, we process personal data where this is necessary to take steps at your request or perform our contract with you; comply with a legal obligation; protect vital interests in an emergency; pursue our legitimate interests in operating and safeguarding the practice; or where you have given consent. Where we process health information or other special-category data, we do so only where an additional condition under UK data protection law applies. This includes where processing is necessary for the provision and management of therapy or coaching by a practitioner subject to professional confidentiality, or where explicit consent has been obtained where appropriate.
How We Use Your Information
We use personal data to respond to enquiries; arrange appointments; provide and manage contracted services; communicate with you; manage client risk and safety; meet legal and professional obligations; manage appointments, payments and administration; and support continuity of care and professional reflection during and between sessions.
Confidentiality
Therapy and coaching are confidential. Confidential personal information will not normally be disclosed without your knowledge or permission. Information may, however, need to be shared where:
-
there is a serious risk of harm to you or another person
-
there is a safeguarding concern involving a child or an adult at risk;
-
disclosure is required by law, court order or another legal process; or
-
there is a specific legal duty relating to matters such as terrorism or money laundering.
Wherever possible and appropriate, any proposed disclosure will be discussed with you first. Any information shared will be limited to what is relevant and necessary for the purpose.
Clinical Supervision
To support safe, ethical and effective practice, aspects of client work may be discussed with an appropriately qualified clinical supervisor. Identifying information is minimised wherever possible, and the clinical supervisor is bound by professional confidentiality obligations.
Clinical Will
Arrangements are in place for a trusted professional colleague to contact current clients and manage essential records if the therapist dies or becomes unable to continue working. That person would have access only to the minimum information necessary for this purpose and would be bound by confidentiality obligations.
Data Sharing
We do not sell personal data or use it for purposes unrelated to the services you have requested, operating the practice, meeting our legal and professional obligations, or protecting client safety. Personal information is shared only where this is necessary, proportionate and relevant to the purpose. Depending on the circumstances, limited information may be shared with:
-
an appropriately qualified clinical supervisor;
-
a GP, healthcare professional, safeguarding service or emergency service where necessary to address a serious risk or safeguarding concern;
-
a health insurer or another organisation funding services, where necessary to administer those services;
-
professional advisers, including accountants, insurers and legal advisers;
-
professional or regulatory bodies where required in connection with an ethical concern or complaint;
-
courts, law-enforcement agencies or other authorities where disclosure is legally required.
We may use carefully selected service providers to support the secure operation of the practice and service delivery, including website hosting, electronic communications, appointment scheduling, taking and processing payments, and document-storage. These providers may process information only for the relevant service and subject to appropriate contractual and security safeguards. Only information relevant to the particular purpose will be shared. Where a provider processes information outside the UK, we require an appropriate legal safeguard for the transfer.
Records and Digital Tools
We may keep brief records to support safe, ethical and effective practice management and to meet our legal and professional responsibilities. These may include session dates, contact and administrative information, relevant risk or safeguarding information, and significant decisions relating to the work. Sessions are never recorded or transcribed without your explicit consent. Digital tools, including paid-for, commercially licensed AI tools (e.g. Microsoft Copilot), may be used to support practice administration, professional reflection, learning and service improvement. Where such tools are used, appropriate safeguards are applied to protect confidentiality and personal information.
Systems We Use
Personal information may be processed or stored using:
-
Wix, for website hosting and website forms (information submitted through the website contact form is received and processed through Wix before being securely transferred into our business systems);
-
Microsoft 365 Business, including Outlook, OneDrive, SharePoint, Teams, Microsoft Bookings and other paid-for Microsoft applications;
-
Xero, for accounting and invoicing; and
-
Monzo banking and other payment providers used to receive and administer payments.
Appropriate contractual, technical and organisational safeguards are used when selecting and using these services.
Security Measures
We use appropriate technical and organisational measures to protect personal data and aim to use reputable business-grade providers that offer security, privacy and data-protection controls suitable for the services they provide. Our core business systems use a paid Microsoft 365 business account and its associated business security features, including anti-phishing, anti-spam and anti-malware protection, multi-factor authentication, secured electronic communications and protected document storage through OneDrive and SharePoint. We also use encryption, password protection, access controls, secured and regularly updated devices, data minimisation and restricted access to protect the confidentiality and integrity of personal data.
Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this notice and to meet our legal, professional, insurance and regulatory responsibilities. Enquiry information that does not result in services being provided is periodically reviewed and deleted when it is no longer required. Identifiable client records are normally retained for six years after services end. This may also support continuity if a client returns to therapy or coaching during that period. Particular information may be retained for longer where there is a legal, safeguarding, insurance, complaint-related or other justified reason. Financial records are retained for the period required for tax and accounting purposes. Personal information is securely deleted when it is no longer required.
Website Analytics and Cookies
This website is hosted by Wix. Wix collects limited technical and usage information to operate, secure and maintain the website, and to provide aggregated website analytics. This may include pages visited, approximate location, device and browser information, referring sources and general patterns of website use. This information is used to understand how the website is found and used, and to improve its content and performance. It is not used to identify individual visitors. The website uses cookies and similar technologies required for security and essential operation. We do not use third-party advertising pixels, retargeting technologies or cross-site marketing trackers, and session recording is not enabled. If the website’s systems or uses change in a way that requires consent, we will provide an appropriate choice before such technology is used.
Your Rights
Depending on the circumstances, you may have the right to:
-
access your personal data;
-
correct inaccurate information;
-
request deletion or restriction;
-
object to certain types of processing;
-
receive certain information in a portable format;
-
withdraw consent where processing is based on consent; and
-
raise concerns about how your personal information has been handled.
Withdrawing consent does not affect processing carried out before withdrawal. Some rights are not absolute and may be limited where information needs to be retained for legal, professional, safeguarding, insurance or complaint-related reasons. To exercise your rights, contact us at hello@rethink-your-self.com or submit an enquiry through the website.
Data Protection Concerns and Complaints
If you have concerns about how we use or handle your personal data, please contact us at hello@rethink-your-self.com. We will acknowledge a data-protection complaint within 30 days, investigate it appropriately, keep you informed where necessary and explain the outcome without undue delay. You may also raise concerns directly with the Information Commissioner’s Office: Information Commissioner’s Office website. Telephone: 0303 123 1113
Contact Us
If you have questions about this notice or how we use personal data, contact us at hello@rethink-your-self.com.
Changes to This Notice
We may update this notice when our services, systems, professional guidance or legal obligations change. The current version will be published on this page.