PRIVACY POLICY
Privacy policy.
Maria Christie Hypnotherapy | mariachristiehypnotherapy.com
Last updated: July 2026
Note: This policy has been updated to reflect the Data (Use and Access) Act 2025 (DUAA), which came into force in stages from February 2026, including the new data protection complaints procedure effective 19 June 2026.
This privacy notice provides you with details of how we collect and process your personal data through your use of our site mariachristiehypnotherapy.com
By providing us with your data, you warrant to us that you are over 16 years of age.
Maria Christie Hypnotherapy is the data controller and we are responsible for your personal data (referred to as “we”, “us” or “our” in this privacy notice).
Contact Details
Maria Christie
Email: hello@mariachristie.co
WHAT DATA WE COLLECT, FOR WHAT PURPOSE AND ON WHAT GROUNDS WE PROCESS IT
Personal data means any information capable of identifying an individual. It does not include anonymised data.
We may process the following categories of personal data about you:
Communication Data
Includes any communication that you send to us whether through the contact form on our website, through email, text, social media messaging, social media posting or any other communication that you send us. We process this data for the purposes of communicating with you, for record-keeping and for the establishment, pursuance or defence of legal claims. Our lawful ground for this processing is our legitimate interests which in this case are to reply to communications sent to us, to keep records and to establish, pursue or defend legal claims.
Customer Data
Includes data relating to any purchases of goods and/or services such as your name, title, billing address, email address, phone number, contact details, purchase details and payment details. We process this data to supply the services you have purchased and to keep records of such transactions. Our lawful ground for this processing is the performance of a contract between you and us and/or taking steps at your request to enter into such a contract.
Special Category (Health) Data
As a hypnotherapy and coaching practice, we collect and process health-related information, including mental health history, emotional wellbeing, and personal background, through our pre-session questionnaire and during the course of therapy. This is special category data under UK GDPR. Our lawful ground for processing this data is that it is necessary for the provision of health treatment and for the management of health treatment systems, under Article 9(2)(h) UK GDPR, and is carried out subject to professional confidentiality obligations. We will never share this information without your explicit consent except where required by law.
User Data
Includes data about how you use our website and any online services. We process this data to operate our website and ensure relevant content is provided to you, to ensure the security of our website, to maintain backups of our website and/or databases and to enable publication and administration of our website. Our lawful ground for this processing is our legitimate interests which in this case are to enable us to properly administer our website and our business.
Technical Data
Includes data about your use of our website and online services such as your IP address, your login data, details about your browser, length of visit to pages on our website, page views and navigation paths, details about the number of times you use our website, time zone settings and other technology on the devices you use to access our website. The source of this data is from our analytics tracking system. We process this data to analyse your use of our website and other online services, to administer and protect our business and website, to deliver relevant website content to you and to understand the effectiveness of our marketing. Our lawful ground for this processing is our legitimate interests which in this case are to enable us to properly administer our website and our business and to grow our business and to decide our marketing strategy.
Marketing Data
Includes data about your preferences in receiving marketing from us and your communication preferences. We process this data to enable you to partake in our promotions, to deliver relevant website content to you, and to measure the effectiveness of our marketing. Our lawful ground for this processing is either your consent or our legitimate interests (namely to grow our business).
HOW WE COLLECT YOUR PERSONAL DATA
We may collect data about you by you providing the data directly to us (for example by filling in forms on our site, completing our pre-session questionnaire, or by sending us emails). We may automatically collect certain data from you as you use our website by using cookies and similar technologies. Please see our cookie policy for more details.
We may receive data from third parties such as analytics providers such as Google based outside the UK, advertising networks such as Facebook based outside the UK, and search information providers such as Google based outside the UK.
SENSITIVE DATA AND THERAPEUTIC RECORDS
As a hypnotherapy and coaching practice, we handle sensitive personal information with the utmost care and in accordance with our professional obligations.
The pre-session questionnaire, your contact details, and brief session notes are stored securely on a password-protected computer. Session notes are anonymised using initials only.
We use Zoom for online therapy sessions. Zoom is securely encrypted. The recording function will not be used. Chat transcripts and therapeutic email exchanges will be destroyed either after the session or after therapy has finished, as agreed between us.
As part of our commitment to providing a professional service, we attend regular training. This is bound by a confidentiality contract and your identity will never be disclosed.
MARKETING COMMUNICATIONS
Our lawful ground for processing your personal data to send you marketing communications is either your consent or our legitimate interests (namely to grow our business). Under the Privacy and Electronic Communications Regulations, we may send you marketing communications if you made a purchase or asked for information from us about our services, or you agreed to receive marketing communications, and in each case you have not opted out.
Before we share your personal data with any third party for their own marketing purposes we will get your express consent.
You can ask us or third parties to stop sending you marketing messages at any time by emailing us at hello@mariachristie.co
DISCLOSURES OF YOUR PERSONAL DATA
We may have to share your personal data with the parties set out below:
Service providers who provide IT and system administration services
Professional advisers including lawyers, bankers, auditors and insurers
Government bodies that require us to report processing activities
Our executors in the event of our incapacity or death, solely for the purpose of notifying you and destroying your records
We require all third parties to whom we transfer your data to respect the security of your personal data and to treat it in accordance with the law. We only allow such third parties to process your personal data for specified purposes and in accordance with our instructions.
In the event of our incapacity or death, your personal contact information will be disclosed to our executors so that they can notify you. Your contact information and notes will then be destroyed.
If we are under a duty to disclose or share your personal data in order to comply with any legal obligation, for example if we are subpoenaed to court, or as a legal requirement such as safeguarding children or vulnerable adults, terrorism or money laundering, we may be required to do so.
INTERNATIONAL TRANSFERS
Where we transfer your personal data to third parties outside of the UK, we ensure appropriate safeguards are in place in accordance with UK GDPR.
The UK has been granted an adequacy decision by the European Commission, renewed in December 2025 and valid until 27 December 2031, meaning personal data can flow freely between the UK and the European Economic Area (EEA).
For transfers to other countries, we rely on appropriate transfer mechanisms including adequacy regulations made by the UK government, or standard contractual clauses where required. We ensure that any such transfers provide a level of protection that is not materially lower than that provided under UK GDPR.
DATA SECURITY
We have put in place security measures to prevent your personal data from being accidentally lost, used, altered, disclosed, or accessed without authorisation. We also allow access to your personal data only to those who have a business need to know such data.
We have procedures in place to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so. We have a legal obligation to report a data breach to you and the Information Commissioner’s Office (ICO) within 72 hours.
DATA RETENTION
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
For tax purposes, the law requires us to keep basic information about our customers (including Contact, Identity, Financial and Transaction Data) for six years after they stop being customers.
Pre-session questionnaires and brief session notes will be retained for as long as we are working together and for a further five years after therapy has finished, as required by our indemnity insurance, after which documents will be destroyed.
Text communications are deleted immediately. Emails are purged once a month. Phone numbers are deleted from our smartphone after therapy has finished.
YOUR LEGAL RIGHTS
Under data protection laws you have rights in relation to your personal data that include the right to request access, correction, erasure, restriction, transfer, to object to processing, to portability of data and (where the lawful ground of processing is consent) to withdraw consent. All requests will be responded to within one month.
You will not have to pay a fee to access your personal data (or to exercise any of your other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive.
Your right to make a data protection complaint
If you believe we have not handled your personal data correctly, you have the right to make a complaint directly to us first. Please email hello@mariachristiehypnotherapy.com with details of your concern. We will acknowledge your complaint within 30 days of receipt and provide a full response without undue delay.
If you remain unhappy with how we have handled your complaint, you may contact the relevant supervisory authority for your country of residence:
Cyprus and EU: Cyprus Commissioner for Personal Data Protection (CPDP) at dataprotection.gov.cy or +357 22 818 456. EU residents may alternatively contact the data protection authority in their own member state.
United Kingdom: Information Commissioner's Office (ICO) at ico.org.uk or 0303 123 1113.
United States: While there is no single federal data protection authority, residents of California may contact the California Privacy Protection Agency (CPPA) at cppa.ca.gov. Residents of other US states may contact their state Attorney General's office.
Australia: The Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or 1300 363 992.
All other countries: You may contact the relevant data protection or privacy authority in your country of residence. A global directory of data protection authorities can be found at the International Association of Privacy Professionals (IAPP) at iapp.org.
AUTOMATED DECISION MAKING
We do not carry out automated decision making or any type of automated profiling.
THIRD-PARTY LINKS
This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy notice of every website you visit.
COOKIES
You can set your browser to refuse all or some browser cookies or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of this website may become inaccessible or not function properly.
What is a cookie?
A cookie is a piece of information that is stored on your computer’s hard drive and which records how you move your way around a website so that, when you revisit that website, it can present tailored options based on the information stored about your last visit. Cookies can also be used to analyse traffic and for advertising and marketing purposes.
How we use cookies
We use cookies to track your use of our website. This enables us to understand how you use the site and track any patterns with regards to how you are using our website. This helps us to develop and improve our website as well as products and services in response to what you might need or want.
Types of cookies we use
Session cookies: stored only during your web session and automatically deleted when you close your browser. They store an anonymous session ID allowing you to browse a website without having to log in to each page but they do not collect any personal data from your computer.
Persistent cookies: stored as a file on your computer and remain there when you close your web browser. We use persistent cookies for Google Analytics.
Strictly necessary cookies: essential to enable you to use the website effectively and cannot be turned off.
Performance cookies: enable us to monitor and improve the performance of our website, for example by counting visits and identifying traffic sources.
Functionality cookies: allow our website to remember choices you make and provide enhanced features. Information collected by these cookies is usually anonymised.
CHANGES TO THIS PRIVACY POLICY
We will notify you of any changes we make to this privacy policy. This policy was last updated in July 2026 to reflect the requirements of the Data (Use and Access) Act 2025.
CONSENT
Your use and undertaking of the services of Maria Christie Hypnotherapy constitutes your approval and acceptance of this agreement, and consent to our use and storage of your personal information as detailed above. You have the right to withdraw your consent at any time by contacting us at hello@mariachristie.co
Maria Christie Hypnotherapy | mariachristiehypnotherapy.com | © Maria Christie 2026
Note: This privacy policy is provided for informational guidance. We recommend having it reviewed by a qualified solicitor to ensure it meets your specific legal obligations as a healthcare-adjacent practice.