Privacy Policy
This page explains how information may be collected, used, stored, and shared when someone visits the website, contacts the practice, or books a session.
1. Who we are
This website is operated by [Practice / Therapist Name].
Practice email: [EMAIL]
Business / practice address, if applicable: [ADDRESS OR ONLINE-ONLY NOTE]
2. Information we may collect
Depending on how someone uses the website, the practice may collect:
• name and contact details
• information submitted through contact forms
• booking details such as appointment type, date, and time
• payment-related transaction information handled by the payment provider
• technical information such as browser, device, IP address, and basic analytics data
• cookie or consent preferences, where applicable
A general website form should not be used to request or encourage unnecessary sensitive clinical details.
3. How information may be used
Information may be used to:
• respond to enquiries
• schedule and manage appointments
• send booking confirmations and reminders
• process payments through connected providers
• prevent double-booking through calendar integrations
• operate, secure, and improve the website
• meet legal, accounting, or professional obligations where applicable
4. Booking and calendar services
The website may use third-party booking and calendar tools such as [FLUENTBOOKING], [GOOGLE CALENDAR / OUTLOOK, IF USED], or similar services.
When a booking is made, the information required to create and manage that appointment may be processed by those providers according to their own privacy practices and the configuration chosen by the practice.
5. Payments
If online payments are enabled, payment information may be processed by [PAYMENT PROVIDER].
The website should avoid storing full card or payment credentials directly unless the chosen payment infrastructure is specifically designed and configured to do so securely. Add the actual provider name and payment-flow details here before launch.
6. Contact forms and email
Information submitted through the contact form may be sent to the practice by email and/or stored by the form provider or WordPress database depending on configuration.
Add the actual form plugin, email provider, retention behavior, and access controls here once the final setup is confirmed.
7. Cookies and analytics
The website may use essential cookies and, if enabled, analytics or similar technologies to understand website usage and maintain functionality.
List the actual services used here, for example [GOOGLE ANALYTICS / PLAUSIBLE / NONE], and explain how visitors can manage consent or cookie preferences where required.
8. How information may be shared
Personal information should only be shared where reasonably necessary to operate the service or meet a legal obligation. Depending on the final setup, this may include:
• booking providers
• payment processors
• hosting providers
• email providers
• calendar providers
• website security or analytics providers
• professional or legal advisers where appropriate
The practice should not state that data is never shared if third-party service providers are used.
9. Data retention
Personal information should be kept only for as long as reasonably necessary for the purpose for which it was collected, subject to any legal, professional, accounting, insurance, or record-keeping obligations.
Replace this paragraph with the actual retention periods or retention criteria used by the practice.
10. Data security
Reasonable technical and organisational measures should be used to protect information handled through the website. These may include HTTPS, restricted administrator access, secure hosting, backups, updates, strong passwords, and limiting access to information.
No website or internet transmission can be guaranteed to be completely secure, so the final policy should not make absolute security promises.
11. International data processing
Some website providers may process or store information in countries different from where the visitor or therapist is located.
If this applies, identify the relevant providers and explain any safeguards or legal basis required by the laws that apply to the practice.
12. Your privacy rights
Depending on the laws that apply to the visitor and the practice, a person may have rights relating to access, correction, deletion, objection, restriction, consent withdrawal, or obtaining a copy of certain personal information.
Requests can be sent to [PRIVACY CONTACT EMAIL]. The final wording should be adapted to the jurisdictions that actually apply.
13. Children and minors
Clarify whether the practice works with minors and whether the website is intended to collect information from them.
If the practice is for adults only, state that clearly. If minors are served, this section should be reviewed carefully for consent, guardian, and professional requirements.
14. Changes to this policy
This policy may be updated when the website, service providers, booking systems, or legal requirements change.
Last updated: [DATE]
15. Contact
Questions about this privacy policy can be sent to:
[Practice / Therapist Name]
[EMAIL]
[ADDRESS OR ONLINE-ONLY BUSINESS DETAILS, IF REQUIRED]