Privacy Policy
Last updated: 12/03/26
Who We Are
Gilia Practice is the trading name of Gillian McCarthy, a sole trader based in Scotland, United Kingdom.
Gillian McCarthy, trading as Gilia Practice, is the data controller responsible for your personal data.
If you have any questions about this Privacy Policy or how your personal data is handled, you can contact:
Email: hello@giliapractice.com
Website: www.giliapractice.com
What Personal Data We Collect
We may collect and process the following types of personal data.
Information you provide directly
When you contact us, book a consultation, or enquire about services, we may collect information such as:
Name
Email address
Telephone number
Any information you include in your enquiry or message
If you become a client, we may collect additional information that is relevant to providing hypnotherapy or coaching services.
Special Category Data (Health Information)
As a hypnotherapy and coaching practice, we may collect health-related information or other sensitive personal data that you choose to share as part of the therapeutic process.
Under UK GDPR this is known as “special category data.”
This information is only collected where necessary to:
understand your situation
provide appropriate therapeutic support
ensure sessions are conducted safely and effectively
Such information is treated with a high level of confidentiality and stored securely.
The lawful basis for processing this type of data is typically:
Explicit consent, and
Provision of health or therapeutic services
You are not required to disclose any information you do not wish to share, although certain information may be necessary in order to provide appropriate support.
Website Usage Information
When you visit the website, certain information may be collected automatically, including:
IP address
Browser type
Device information
Pages visited and time spent on the site
Referral source (for example search engines)
This information helps us understand how visitors use the website and allows us to improve its performance.
This data is typically collected using website analytics tools.
Cookies
Our website may use cookies or similar technologies to improve your browsing experience and help us understand how the site is used.
Cookies are small text files stored on your device.
You can manage or disable cookies through your browser settings.
How We Use Your Personal Data
Your personal data may be used for the following purposes:
Responding to enquiries or messages
Arranging consultations or appointments
Delivering hypnotherapy or coaching services
Maintaining appropriate client records
Improving website performance and services
Meeting legal, regulatory, or professional obligations
We only collect and use personal data that is necessary and proportionate for these purposes.
Lawful Basis for Processing
Under UK GDPR, we rely on the following lawful bases for processing personal data:
Legitimate Interest
To respond to enquiries, manage communications, and operate the business effectively.
Contract
Where processing is necessary to provide services you have requested.
Legal Obligation
Where we are required to retain certain records for tax, legal, or regulatory purposes.
Consent
Where you have provided consent, for example by submitting an enquiry form or agreeing to share personal information.
Explicit Consent (Special Category Data)
Where sensitive personal information such as health-related information is shared for the purpose of therapeutic services.
Confidentiality
Confidentiality is a fundamental part of therapeutic work.
Information shared during consultations or sessions will be treated as confidential.
However, there are limited circumstances where confidentiality may need to be breached, including where:
there is a serious risk of harm to you or others
disclosure is required by law
information is required by a court order
Where possible, this would be discussed with you before any disclosure is made.
How We Store and Protect Your Data
We take appropriate technical and organisational measures to protect your personal data.
This includes reasonable safeguards designed to protect personal information from:
unauthorised access
loss or theft
misuse or disclosure
Data may be stored securely in electronic systems and, where necessary, physical records.
Only authorised individuals have access to personal data where it is required for legitimate purposes.
While we take care to protect your information, no internet transmission can be guaranteed to be completely secure.
Data Retention
Personal data is kept only for as long as necessary for the purposes for which it was collected, including to meet legal, professional, and regulatory obligations.
For example:
Enquiry information may be retained for administrative purposes.
Client records may be retained for a reasonable period in accordance with professional practice and legal requirements.
When personal data is no longer required, it will be securely deleted or anonymised.
Sharing Your Information
Your personal data will not be sold or rented to third parties.
In some cases, information may be shared with trusted service providers who help operate the business, such as:
website hosting providers
secure email services
appointment or booking systems
These providers are required to process personal data securely and only for the purposes specified.
Information may also be disclosed where required by law.
International Data Transfers
Some website services or software providers may store data outside the United Kingdom.
Where this occurs, we ensure that appropriate safeguards are in place to protect personal data in accordance with UK GDPR requirements.
Your Data Protection Rights
Under UK GDPR, you have the following rights:
The right to be informed about how your data is used
The right to access your personal data
The right to request correction of inaccurate data
The right to request deletion of your data in certain circumstances
The right to restrict processing of your data
The right to data portability
The right to object to certain types of processing
If you would like to exercise any of these rights, please contact:
Complaints
If you have concerns about how your personal data is handled, please contact us in the first instance so we can try to resolve the matter.
You also have the right to lodge a complaint with the UK data protection regulator:
Information Commissioner’s Office (ICO)
https://ico.org.uk
Links to Other Websites
Our website may contain links to external websites.
We are not responsible for the privacy practices or content of third-party websites. We encourage you to review the privacy policies of any external sites you visit.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements or business practices.
The latest version will always be available on this page.
Contact
If you have any questions about this Privacy Policy or how your personal data is handled, please contact:
Gillian McCarthy
Trading as Gilia Practice
Email: hello@giliapractice.com
Website: www.giliapractice.com
