Privacy policy
Latest Update: October 2025
This Privacy Policy describes how this website (“the Website”) collects, uses, and protects personal data of visitors and clients in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
By using this Website, you agree to the terms described below.
1. Types of Data Collected
This Website may collect the following categories of personal data:
Personal Identification Data: name, email address, phone number, and country of residence (when completing contact or intake forms).
Usage Data: information such as browser type, device, IP address, referral source, pages visited, and time spent on the Website.
Cookies: small text files stored on your device to improve user experience and analytics.
Communications Data: information provided when subscribing to newsletters, responding to emails, or completing online contact forms.
Sensitive health data is never collected or stored via this Website. Clinical information is only obtained and processed securely during formal therapy engagements, in line with professional ethical codes (HCPC, BPS, and BABCP).
2. Mode and Place of Processing the Data
Methods of Processing
Data is processed using appropriate security measures to prevent unauthorised access, disclosure, alteration, or destruction.
Processing is carried out using computers and/or IT-enabled tools, following organisational procedures strictly related to the stated purposes.
Place
Data is processed at the Website owner’s operating offices in the United Kingdom and on secure hosting servers located within the UK or European Economic Area (EEA).
3. Legal Basis for Processing
Data is processed under one or more of the following legal bases:
The User has given consent for one or more specific purposes (e.g., to receive a reply or newsletter).
Processing is necessary for the performance of a contract or pre-contractual measures (e.g., scheduling consultations).
Processing is necessary for compliance with a legal obligation.
Processing is necessary for the purposes of the legitimate interests pursued by the Website owner (e.g., improving services and website functionality).
4. Retention Period
Personal Data is retained only for as long as necessary to fulfil the purposes for which it was collected, unless a longer retention period is required by law or professional regulation.
Contact form data: up to 12 months.
Newsletter subscriptions: until the user unsubscribes.
Analytics data: typically 26 months (as per Google Analytics’ default setting).
5. Purposes of Processing
Data is collected to enable the Website owner to:
Respond to contact and enquiry forms.
Schedule consultations or assessments.
Manage mailing lists and send newsletters.
Analyse website traffic and improve content and functionality.
Maintain the Website’s security and performance.
Comply with professional and legal obligations.
6. Analytics
Google Analytics (Google Inc.)
This Website uses Google Analytics, a web analysis service provided by Google Inc. (“Google”). Google uses cookies to collect usage data that helps the Website understand how visitors interact with the site.
This data may include IP addresses (anonymised within the EU/UK), pages visited, session duration, and referral sources.
Users can opt out by installing the Google Analytics Opt-Out Browser Add-on:
https://tools.google.com/dlpage/gaoptout
Analytics Collected Directly (This Website)
The Website may also collect anonymised metrics directly (e.g., visit counts or form submissions) for internal performance tracking.
7. Contacting the User
Mailing List or Newsletter
By subscribing to the newsletter or mailing list, the User’s email address is added to a list that may receive occasional updates, articles, or announcements.
Users can unsubscribe at any time via the link in each email or by contacting the Website owner directly.
8. Interaction with External Social Networks and Platforms
LinkedIn Button and Social Widgets (LinkedIn Corporation)
This Website may include LinkedIn social widgets that allow interaction with the LinkedIn platform.
Data collected through these widgets is governed by LinkedIn’s privacy policy:
https://www.linkedin.com/legal/privacy-policy
TikTok Button and Social Widgets (TikTok, Inc.)
The Website may integrate TikTok widgets that enable sharing or viewing content.
Use of these features is subject to TikTok’s privacy policy:
https://www.tiktok.com/legal/page/row/privacy-policy/en
9. Managing Contacts and Sending Messages
Personal data collected through contact forms or email enquiries is used exclusively to reply to requests or arrange consultations.
No information is shared with third parties for marketing purposes, and messages are stored securely and confidentially.
10. The Rights of Users
Users may exercise the following rights regarding their data:
Access: obtain confirmation as to whether their data is being processed and receive a copy.
Rectification: request correction of inaccurate or incomplete data.
Erasure: request deletion of personal data (“right to be forgotten”).
Restriction of processing: request that processing be limited in specific circumstances.
Data portability: receive their data in a structured, machine-readable format.
Withdraw consent: at any time, without affecting the lawfulness of processing before withdrawal.
11. Right to Object to Processing
Users have the right to object to processing of personal data based on legitimate interests or direct marketing.
If an objection is raised, the Website owner will cease processing unless compelling legitimate grounds are demonstrated.
12. How to Exercise These Rights
To exercise any of the above rights, users may contact the Website owner at:
📧 drew@andrewstockhausen.com
Requests are handled within 30 days in accordance with data protection laws.
13. Cookie Policy
This Website uses cookies to enhance the user experience. Cookies are small data files stored on the user’s device.
Users can manage or delete cookies through their browser settings.
By continuing to use this Website without changing your settings, you consent to the use of cookies in accordance with this policy.
14. Definitions and Legal References
Personal Data (Data): Any information relating to an identified or identifiable natural person.
Usage Data: Information collected automatically through this Website (or third-party services).
Data Subject (User): The individual using this Website who is the subject of Personal Data.
Data Controller (Website Owner): The natural or legal person responsible for determining the purposes and means of processing personal data.
15. Contact Information
Data Controller / Website Owner:
Andrew Stockhausen
Counselling Psychologist in Doctoral Training / BABCP Accredited CBT Therapist
Bentinck House, 3–8 Bolsover Street, London W1W 6AB
📧 drew@andrewstockhausen.com
This Privacy Policy may be updated from time to time to reflect legal or operational changes. Users are encouraged to review this page periodically.