When I work with you I collect personal information from you to enable me to provide safe and effective therapy.
I am bound by 2 sets of rules in handling this information, the General Data Protection Regulations (GDPR) and my professional body’s code of ethics. This page will explain how these affect the way I work.

If you have any questions about this please discuss with me before you book a session , or at a session that you have already booked.


1. I am registered with the ICO

2. I am the only person who works for the business, Philippa Selby Hypnotherapy, and I am both the Data Controller and the Data Protection Officer. My contact details are , Philippa Selby, email, telephone 07762962109

3. In most cases, the information about you that I collect comes from you, via an email, telephone call, online form or during face to face sessions.

If you are under 18 I may get some information from your parents or school.

If you are referred by someone else ( e.g. an employer or Anxiety UK) I may get some information from them.

4. I use your personal data in the following ways

  • To deliver therapy.
  • To reply to you if you contact me with questions about my services.
  • To contact you between therapy sessions if necessary.
  • To allow me to collect payments from you, and maintain my records and accounts.

5. You have no legal requirement to share any information with me, but if you do not do so I will not be able to work with you.

6. The categories of data/information I collect include: your name and contact details, your medical history, your family situation and support network, the nature of your employment, your hobbies and interests, your lifestyle, and details of the problem you would like me to help you with.

7. Collecting and using your personal information is essential to providing my therapy services safely and appropriately. You give me written consent to use your personal data in the ways specified here when you sign my terms and conditions at our first session.

8. I am the only person who has access to this information unless

  • There is a legal requirement for me to share the information (e.g. a court order or warrant is issued)
  • You ask me in writing to share your information with someone else.
  • The Duty of Care Provision from my Code of Ethics applies – see the notes about this further down.
  • I am working with you as part of a care team, or you have been referred to me by someone else (e.g. an employer or Anxiety UK), in which case pre-arranged levels of information will be shared with these relevant parties.

9. I keep the information you give me for 7 years, which is the length of time required by my professional body and my insurance company. After this time it is shredded and disposed of securely.

10. You have rights over the information I hold about you. These are

  • Portability- you can ask me to send your information to someone else.
  • Rectification- if you think my records are wrong you can ask me to change them.
  • Erasure- in some circumstances you can ask me to remove your details from my records( this is sometimes called the ‘right to be forgotten’)
  • Fair profiling- you can ask that any processes I automate are done by a person instead of a computer. I don’t automate any information processing although I do use online forms to collect information. If you prefer not to complete these, the information can be collected face to face at our first session.
  • Right of access- you can have a copy of the information I hold at any time, by requesting it in writing. If you do this it will be provided within 30 days and free of charge.
  • Restricting processing- in some circumstances you can request that I stop processing your information.
  • Objection- you can object to the way I process information (e.g. if it is used to send you direct marketing you don’t want to receive) and you can ask me to stop using it in that way.
  • Information- you have the right to understand how I collect information and process your information (hence this privacy notice)

11. If you are under 18 I will need permission from a parent or guardian before working with you, and if you are under 13 I will need to verify your date of birth.

You can learn more about these rights on

You can withdraw your permission for me to use your information at any time , this means ending your therapy.

You have a right to complain to the ICO if you have any problem with the way I store or use your data, or if you do not think your rights are being respected.


The GHR ask me to keep the information you give me private and confidential unless one of the following applies:

  • There is a legal requirement for me to share information as above.
  • There is good cause to believe that if I do not disclose information you or others would be exposed to a serious risk of harm.

These exceptions to the confidentiality rule come under a provision called the ‘duty of care’.

My Code of Ethics also allows me to share anonymous case histories verbally or in Hypnotherapy publications for the purposes of supervision or training. Anonymous means your personal details are removed and small details about your situation are changed so that you could never be recognised.

The duty of care provision applies to everyone but you can opt out of this other use of your information on the form you sign the first time we work together.