SHIRLEY MARAIS COUNSELLING & AFFILIATES
PRIVACY NOTICE
Last Updated: 18 June 2026
Introduction
Shirley Marais Counselling & Affiliates is committed to protecting your privacy and handling your personal information responsibly, lawfully and transparently.
This Privacy Notice explains how we collect, use, store, protect and share personal information when you:
- Contact us regarding counselling services
- Attend counselling sessions
- Work with one of our affiliate counsellors
- Visit our website
- Communicate with us by telephone, email, text message or online platforms
This Privacy Notice has been prepared in accordance with:
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018
- Privacy and Electronic Communications Regulations (PECR)
- Current guidance issued by the Information Commissioner’s Office (ICO)
Who We Are
Shirley Marais Counselling & Affiliates provides counselling and psychotherapy services both in person and online.
For the purposes of UK data protection legislation, Shirley Marais Counselling & Affiliates is the Data Controller responsible for determining how personal information is collected, used and protected.
Contact Details
Email:
Telephone: 07488 351411
Website:
www.shirleymaraiscounselling.co.uk
ICO Registration Number: [ZA139089ICO Registration Number]
Working with Affiliate Counsellors
Shirley Marais Counselling may work with self-employed affiliate counsellors who provide counselling services through the practice.
Where you are allocated to an affiliate counsellor, relevant personal information may be shared for the purposes of:
- Providing counselling services
- Arranging appointments
- Maintaining professional records
- Safeguarding
- Clinical supervision
- Meeting legal and professional obligations
Affiliate counsellors are required to:
- Comply with UK GDPR and the Data Protection Act 2018
- Maintain appropriate professional membership and insurance
- Follow recognised ethical frameworks
- Protect client confidentiality
- Maintain secure records
Depending on the circumstances, affiliate counsellors may act as separate Data Controllers in relation to the information they hold and process.
Where appropriate, you may also receive a separate privacy notice from your affiliate counsellor.
Information We Collect
When you contact us, we may collect:
- Your name
- Email address
- Telephone number
- Information contained within your enquiry
- Availability preferences
- Preferred counselling format
If counselling begins, we may also collect:
- Address
- Date of birth
- GP details
- Emergency contact details
- Relevant health and well-being information
- Information about your personal history, relationships, family circumstances and reasons for seeking counselling
- Clinical notes
- Attendance records
- Payment information
- Correspondence between us
Special Category Data
Some information collected may be classified as Special Category Data under UK GDPR.
This may include information relating to:
- Physical health
- Mental health
- Sexuality
- Ethnicity
- Religion or belief
- Disability
- Neurodiversity
We only collect information necessary to provide counselling safely, ethically and professionally.
Where we process Special Category Data, processing is undertaken in accordance with Article 9 UK GDPR and Schedule 1 of the Data Protection Act 2018.
How We Use Your Information
We may use your personal information to:
- Respond to enquiries
- Arrange appointments
- Provide counselling services
- Maintain appropriate records
- Communicate regarding appointments
- Manage payments and invoices
- Meet professional and ethical obligations
- Manage risk and safeguarding concerns
- Comply with legal requirements
- Maintain insurance and accounting records
- Respond to complaints or data protection requests
We do not sell personal information.
Lawful Bases for Processing
Under UK GDPR, we rely upon one or more of the following lawful bases:
Contract
To arrange and provide counselling services.
Legitimate Interests
To operate the practice safely, effectively and professionally.
Legal Obligation
Where we are required to process or disclose information by law.
Consent
Where consent is appropriate, we will explain how it is used and how it can be withdrawn.
Confidentiality
Counselling is confidential, but confidentiality is not absolute.
Information may be shared where:
- There is a serious risk of harm to you or another person
- There is a safeguarding concern involving a child, young person or adult at risk
- Disclosure is required by law
- A court order requires disclosure
- Disclosure is necessary to prevent or detect serious crime
- A medical emergency requires information to protect life
- Consultation with a clinical supervisor is required
Where possible, we will discuss disclosure with you beforehand.
Safeguarding
We may share information without consent where this is necessary, lawful and proportionate to safeguard:
- A child or young person
- An adult at risk
- A member of the public
- The client themselves
Clinical Supervision
All counsellors working within the practice engage in clinical supervision.
Information may be discussed anonymously or with minimal identifying information to support safe and ethical practice.
Supervisors are bound by professional confidentiality and ethical requirements.
Clinical Notes and Records
We maintain clinical records to support safe and effective counselling.
Records may include:
- Session dates
- Attendance records
- Brief themes discussed
- Risk or safeguarding information
- Clinical observations
- Agreed actions
- Administrative information
We do not keep verbatim transcripts of counselling sessions.
How Long We Keep Information
Information is retained only for as long as necessary.
As a general guide:
|
Record Type |
Retention Period |
|
Enquiries where counselling does not commence |
6 months |
|
Adult client records |
7 years after counselling ends |
|
Children and young people’s records |
Until age 25 (or 26 where appropriate) |
|
Financial records |
Minimum 6 years |
|
Complaints records |
7 years |
|
Safeguarding records |
As required by law and safeguarding guidance |
Records may be retained longer where necessary for:
- Legal claims
- Insurance requirements
- Safeguarding matters
- Professional conduct investigations
- Regulatory obligations
Legal Claims
We may retain and process information where necessary for the establishment, exercise or defence of legal claims.
Where Your Information Is Stored
Information may be stored using:
- Website contact forms
- Secure email systems
- Secure electronic client records
- Password-protected devices
- Encrypted cloud storage
- Zoom
- Microsoft Teams
- Google Meet
- Starling Bank payment records
- Apple iCloud
We use appropriate technical and organisational measures to protect information.
These measures include:
- Password protection
- Device security
- Restricted access
- Two-factor authentication where appropriate
- Secure storage systems
Online Counselling
Where counselling is provided online, sessions may take place via:
- Zoom
- Microsoft Teams
- Google Meet
These platforms may process technical information such as:
- IP addresses
- Device information
- Connection data
Clients are encouraged to access sessions from a private and confidential environment.
Electronic Communications
Whilst reasonable steps are taken to protect confidentiality, email, SMS and messaging services cannot be guaranteed to be completely secure.
Clients should consider this when choosing how to communicate with the practice.
Artificial Intelligence and Digital Tools
We do not record, transcribe or use AI systems to process counselling sessions.
We may use digital tools for administration, planning, education and business purposes.
We do not upload identifiable client information into public artificial intelligence systems.
Website Visitors and Cookies
When you visit:
www.shirleymaraiscounselling.co.uk
certain technical information may be collected automatically, including:
- IP address
- Browser type
- Device information
- Pages visited
- Time spent on the website
The website is hosted by 20i UK.
Cookies may be used to:
- Enable website functionality
- Improve performance
- Support security
- Understand visitor behaviour
Where required by law, consent will be obtained before non-essential cookies are used.
Third-Party Service Providers
We use carefully selected third-party providers to support the operation of the practice.
These providers may process information on our behalf and are required to maintain appropriate security and confidentiality standards.
Sharing Your Information
We may share limited information where necessary with:
- Clinical supervisors
- Affiliate counsellors involved in your care
- Professional advisers
- Accountants
- Insurers
- Legal advisers
- Professional membership bodies
- Safeguarding agencies
- Emergency services
- Courts or legal authorities
- Clinical executors
- Trusted technology providers
Only information that is necessary and proportionate will be shared.
Clinical Executor
In the event of death, serious illness or incapacity, an appointed professional clinical executor may access limited information necessary to:
- Contact clients
- Manage appointments
- Secure records
- Fulfil professional obligations
Any appointed executor will be bound by confidentiality and data protection requirements.
International Transfers
Where service providers process information outside the United Kingdom, we ensure appropriate safeguards are in place in accordance with UK GDPR requirements.
Your Rights
Under UK data protection law, you have the right to:
- Be informed
- Access your personal information
- Correct inaccurate information
- Request deletion in certain circumstances
- Restrict processing
- Object to processing
- Lodge a complaint
Certain rights may be limited by legal exemptions.
Information may be withheld where disclosure:
- Identifies another individual
- Is legally privileged
- Relates to confidential references
- May prejudice safeguarding processes
- Falls within exemptions under the Data Protection Act 2018
Personal Data Breaches
We maintain procedures for identifying, investigating and managing personal data breaches.
Where required by law:
- Breaches will be reported to the Information Commissioner’s Office.
- Affected individuals will be informed.
Data Protection Concerns and Complaints
If you have concerns about how your information has been handled, please contact us in the first instance.
If you remain dissatisfied, you may contact the:
Information Commissioner’s Office
Website: www.ico.org.uk
Telephone: 0303 123 1113
Changes to This Privacy Notice
This Privacy Notice is reviewed annually and may be updated to reflect:
- Changes in legislation
- Professional guidance
- Technology
- Practice arrangements
The most current version will always be available on our website.
Version: 1.0
Effective Date: 18 June 2026
Review Date: 18 June 2027



