Who am I?
Dr Simone Grey, Chartered Counselling Psychologist, HCPC number: PYL044592
Social Media & Digital Communication Policy
I maintain both professional and personal social media accounts. My professional pages (for example, Instagram, Facebook, or LinkedIn) are designed to share general information, psychoeducation, wellbeing content, and updates about my work. You are welcome to follow or engage with my professional accounts if you wish. However, doing so does not indicate or establish a therapeutic relationship, and I will not acknowledge or interact with current or former clients publicly to protect your privacy and confidentiality.
I do not accept friend or contact requests from current or former clients on my personal accounts. This helps maintain clear and ethical boundaries, protect your confidentiality, and preserve the professional nature of our work together.
Please do not use social media platforms or direct messaging features (such as Instagram DMs, Facebook Messenger, or WhatsApp) to discuss therapy or personal matters. These platforms are not secure or monitored for clinical communication.
If you need to contact me between sessions, please use the Practice Better client portal or email (as appropriate for your service) for confidential, secure communication.
Any interactions on social media are considered public and may become part of your clinical record if clinically relevant. To maintain your privacy, I will not respond to comments, tags, or messages related to our work together.
This policy is designed to ensure that your confidentiality is protected and that our professional relationship remains focused on your therapeutic care.
Cookies
This website uses cookies to help it function effectively and to improve your browsing experience. Cookies are small text files stored on your device that collect information about how you use the site.
Types of cookies used
Essential cookies – These are necessary for the site to work properly (for example, remembering privacy preferences or enabling secure login areas).
Performance cookies – These help me understand how visitors use the website, such as which pages are most frequently viewed, so I can improve the site. These are usually anonymised and collected through services like Google Analytics.
Functionality cookies – These allow the website to remember choices you make (for example, language settings or region).
Managing cookies
When you first visit this site, you’ll be asked to accept or decline non-essential cookies. You can change your preferences or delete cookies at any time through your browser settings. Most browsers allow you to block or delete cookies if you prefer not to accept them.
Third-party services
Some cookies may come from third-party services integrated into the site, such as embedded videos, appointment booking widgets (e.g., Practice Better), or analytics tools. These third-party providers have their own privacy and cookie policies.
By continuing to use this site, you consent to the use of essential cookies as described above.
If you have any questions about how cookies are used, please contact me via the details on the Contact page.
If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.
When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.
If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.
Embedded content from other websites
Pages on this site may include embedded content such as videos, images, or booking forms (for example, from Practice Better, YouTube, or Instagram). Embedded content from other websites behaves in the exact same way as if you had visited the other website directly.
These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content — including tracking your interaction if you have an account and are logged in to that website.
I only embed content from reputable, secure sources relevant to my professional work (for example, therapy booking systems or educational media). However, I do not control how these third-party websites collect or use your data. You can find out more about their data practices by checking their own privacy or cookie policies.
Who I share your data with
As a practitioner regulated by the Health and Care Professions Council (HCPC), I am committed to maintaining your confidentiality and protecting your personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Your information is collected and used only for the purposes of providing psychological and nutritional services, managing your care, and meeting professional, legal, and regulatory obligations.
I will not share your personal information with any third party without your explicit consent, except in the following limited circumstances:
Risk of harm: If I believe that you or someone else is at risk of serious harm, I have a professional and legal duty to share relevant information with appropriate services (for example, your GP, emergency services, or safeguarding authorities).
Legal requirement: If I am required to disclose information by a court order or other legal directive.
Supervision and professional oversight: I may discuss aspects of my work anonymously with a clinical supervisor in accordance with HCPC standards. Supervisors are bound by the same professional confidentiality requirements.
Collaborative care: With your consent, I may share relevant information with other professionals involved in your care (for example, your GP, psychiatrist, or dietitian) to support continuity of treatment.
When data is shared, it is done securely, on a need-to-know basis, and only the minimum necessary information is disclosed. I keep a clear record of what was shared, with whom, and why.
Your information is never sold, used for marketing, or passed to third parties for non-clinical purposes. All records are stored in line with HCPC confidentiality standards and ICO (Information Commissioner’s Office) guidance.
If you have questions about how your information is stored or shared, you have the right to request clarification or to access your records at any time.
How long we retain your data
In accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the HCPC Standards of Conduct, Performance and Ethics, I retain client information only for as long as necessary to meet legal, professional, and clinical obligations.
Clinical records (including session notes, contact details, and relevant correspondence) are typically retained for seven years from the date of your last contact with the service. This is the standard retention period recommended for HCPC-registered psychologists and aligns with guidance from professional insurers.
For clients who were under 18 at the time of therapy, records are kept until the client reaches the age of 25 (or for seven years after the end of therapy, whichever is longer).
After the retention period has expired, all electronic and paper records are securely deleted or destroyed. Any financial or administrative data that must be retained for tax or audit purposes is held only for the legally required duration (normally six years) and then permanently deleted.
If you request that your data be deleted before this period, I will consider the request in line with professional, legal, and insurance obligations. In some cases, I may be required to retain certain records for regulatory or risk-management reasons even if consent is withdrawn.
What rights you have over your data
Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, you have a number of legal rights in relation to the personal information I hold about you. These rights exist to give you transparency, control, and assurance over how your data is used.
You have the right to:
Access your information – You can request a copy of the personal data I hold about you (commonly known as a Subject Access Request). I will provide this within one month of receiving a written request, unless legal or professional obligations require otherwise.
Request correction – If you believe any of the information I hold is inaccurate or incomplete, you can ask for it to be corrected.
Request deletion (“right to be forgotten”) – You may ask for your data to be deleted. In some cases, I may need to retain certain records to comply with legal, professional, or insurance obligations (for example, clinical record-keeping requirements).
Restrict processing – You may request that I limit how your data is used, for instance while a correction or complaint is being considered.
Data portability – You can ask for an electronic copy of your information to be transferred to another practitioner or service where appropriate and feasible.
Object to processing – You have the right to object to certain types of data use (for example, for marketing purposes — though this practice does not engage in direct marketing).
Lodge a complaint – If you are concerned about how your data has been handled, you can raise this with me directly, or contact the Information Commissioner’s Office (ICO), which regulates data protection in the UK:
Website: www.ico.org.uk
Telephone: 0303 123 1113
I take all data-protection rights seriously and will respond to any requests promptly and transparently, in line with my duties as an HCPC-registered practitioner and UK GDPR obligations.
Where your data is sent
Your personal information is stored and processed securely within the United Kingdom (UK) and, where relevant, through carefully selected third-party platforms that comply with UK GDPR and Data Protection Act 2018 requirements.
I use reputable, encrypted systems to manage bookings, notes, payments, and communication — for example, Practice Better, email providers, and accounting platforms. These services may process or store data on secure servers outside the UK (for instance, in Canada or the European Economic Area), but only where there are adequate data-protection safeguards in place, such as:
The country has been granted an adequacy decision by the UK Government, meaning it offers an equivalent level of protection to UK law; or
The provider uses approved data-transfer mechanisms, such as the UK Addendum to the EU Standard Contractual Clauses, to ensure your information remains protected.
No data is sold, shared for marketing purposes, or transferred to countries without lawful protection standards.
Electronic communications (for example, email) are protected through password-secured accounts and encryption wherever possible. Sensitive clinical data is shared only via secure channels (such as the Practice Better portal) and never through social media or unencrypted messaging services.
If international transfer of your information is necessary (for instance, when using a secure cloud service), it will always be done in accordance with UK GDPR provisions and the HCPC confidentiality standards to keep your information safe.
