How we collect, use, store, and protect your personal data.
This document is the property of Kensington Square Therapy Ltd. It must not be reproduced in whole or in part without written permission. Uncontrolled when printed.
Confidentiality, Privacy and Safeguarding
At Kensington Square Therapy (KST), privacy and trust are central to the work we do. Therapy involves sharing personal experiences and feelings, and we are committed to protecting the information entrusted to us.
Everything shared in sessions is treated with care, dignity, and respect. In most circumstances, what is discussed remains confidential between the client and their therapist.
However, there may be times when we are legally or ethically required to share limited information to protect someone from serious harm, for example if a child or vulnerable person is at risk of abuse or significant danger. We take these responsibilities seriously and share information only when necessary, in line with safeguarding law and professional ethical standards.
This Privacy Policy (Privacy Notice) explains how Kensington Square Therapy Ltd (“KST”) collects, uses, stores, shares, and protects personal data in the course of delivering therapy, counselling, and wellbeing services to children, young people, families, and schools.
This notice fulfils KST’s transparency obligations under Articles 13 and 14 of the UK General Data Protection Regulation (UK GDPR) and informs data subjects of their rights under UK data protection law.
This policy applies to all personal data processed by KST, across all settings:
It applies to data relating to children and young people, parents and carers, school staff, referrers, subcontracted therapists and facilitators, website visitors, and enquirers.
This notice should be read alongside the KST Data Protection Policy, Cookie Policy, Safeguarding Policy, and Consent Form.
This policy operates within the following legal and statutory framework:
KST is the independent data controller for all personal data processed in connection with its services. Where KST provides services within a school, KST and the school may operate as independent controllers in respect of their own records. KST does not act as a data processor for schools.
The personal data KST collects depends on the data subject’s relationship with KST. KST collects only information that is necessary and relevant.
Kensington Square Therapy uses Cloudflare Web Analytics, a privacy-first, cookieless analytics service, to understand aggregate visitor numbers and how the site is being used. Cloudflare does not store IP addresses, does not set cookies, and does not enable any individual visitor tracking. We do not use Google Analytics, advertising trackers, or any service that profiles you.
Where you take out an individual subscription to The Parent Book at theparentbook.com/parents, KST collects:
What KST does not collect about subscribers. KST does not collect or process special category data about subscribers in connection with the subscription. KST does not intentionally collect any personal data about a subscriber’s child or other family member through the subscription, beyond the optional family personalisation details described above (a child’s age or year group and school, never a name and nothing clinical), which you provide and can remove at any time.
KST processes personal data under the following lawful bases as defined by Article 6(1) UK GDPR:
| Processing Activity | Lawful Basis (Art. 6) | Explanation |
|---|---|---|
| Delivering therapy and counselling | Contract (Art. 6(1)(b)) | Necessary for performance of the therapy service agreement with the client or their parent/carer. |
| Safeguarding and child protection | Legal obligation (Art. 6(1)(c)); Vital interests (Art. 6(1)(d)) | Required by Children Act 1989/2004, Working Together 2023, and KCSIE 2024. |
| Clinical record keeping | Legal obligation (Art. 6(1)(c)); Legitimate interests (Art. 6(1)(f)) | Professional and regulatory requirement; legitimate interest in defensible clinical practice. |
| School reporting and communication | Legitimate interests (Art. 6(1)(f)) | Necessary for effective school-based provision; balanced against data subject rights. |
| Parent communication and updates | Contract (Art. 6(1)(b)); Consent (Art. 6(1)(a)) | Contractual where part of service agreement; consent-based for discretionary sharing. |
| Financial administration | Legal obligation (Art. 6(1)(c)) | HMRC accounting and tax obligations. |
| Supervision (clinical) | Legitimate interests (Art. 6(1)(f)) | Professional requirement; names typically anonymised. |
| Website contact form enquiries | Legitimate interests (Art. 6(1)(f)) | Responding to enquiries from prospective clients. |
| Website analytics (aggregate, cookieless) | Consent (Art. 6(1)(a)) | Cloudflare Web Analytics sets no cookies and stores no IP addresses. Event beacons on pages carrying the consent banner fire only when the Analytics option is enabled (see Cookie Policy). |
| Delivering The Parent Book individual subscription (access, magic-link sign-in, renewal reminders) | Contract (Art. 6(1)(b)) | Necessary for performance of the subscription contract. |
| Taking subscription payments and reconciling them | Contract (Art. 6(1)(b)); Legal obligation (Art. 6(1)(c)) | Necessary for the contract and for HMRC and Companies Act 2006 record-keeping. |
| Subscriber product analytics (reading activity, in-house only) | Legitimate interests (Art. 6(1)(f)) | Understanding which editions serve subscribers; balanced by in-house-only processing, no third-party analytics, no advertising profiling, and 12-month anonymisation. Subscribers may object. |
| Storing optional family personalisation details (a child’s age or year group and school) to tailor the library and time the school-year letters | Consent (Art. 6(1)(a)) | Given by ticking the personalisation consent box on the account page; editable or deletable there at any time; withdrawal is effective immediately and does not affect the subscription. |
| Service emails and account security (renewal reminders, magic-link emails, sign-in metadata) | Contract (Art. 6(1)(b)); Legitimate interests (Art. 6(1)(f)) | Necessary to deliver and secure the subscription. Not marketing communications. |
| Marketing emails about new editions and resources | Consent (Art. 6(1)(a)); PECR 2003 reg 22 | Separate, unticked-by-default opt-in at signup, toggleable on the account page. One-click unsubscribe; withdrawal is immediate and does not affect the subscription. |
Therapy notes, clinical assessments, and safeguarding records contain health-related special category data. KST processes this data under the following conditions:
KST processes the personal data of children and young people in accordance with the ICO’s Children’s Code (Age Appropriate Design Code) principles. Where a child is assessed as Gillick competent, KST will seek the child’s own views regarding data sharing, particularly in relation to progress updates to parents and schools.
KST does not profile children, make automated decisions about children, or use children’s data for marketing purposes.
The Parent Book individual subscriber tier is a service for adult parents and carers. Where a subscriber chooses to personalise their library, KST stores a child’s age or year group and their school on the parent’s account, with the parent’s consent, to shape which chapters lead and to time the school-year letters. KST does not collect the child’s name, does not link reading activity to any individual child, holds no clinical or special category data about a child through the subscription, and does not profile any child. The ICO’s Children’s Code is engaged for KST’s clinical services to children (Sections 6.1 and 7.2) but is not engaged for the subscriber tier, which has no child user and holds no identifying child data.
KST respects confidentiality and shares personal data only when necessary, lawful, and proportionate. KST will aim to discuss any necessary sharing with the data subject (or their parent/carer) in advance, unless doing so would increase risk to a child or vulnerable person.
KST may share limited personal data with the following recipients:
KST does not sell, rent, or trade personal data. KST does not share personal data for marketing purposes.
KST uses the following sub-processors to operate the individual subscriber tier. Each acts as a processor under UK GDPR, processes personal data only on KST’s documented instructions, and is bound by a written agreement consistent with Article 28 UK GDPR.
| Sub-processor | Purpose and data | Location and transfer |
|---|---|---|
| GoCardless Ltd (UK, FCA FRN 597190) | Direct debit mandate setup and recurring payment collection. Subscriber name (optional), email, bank account details, GoCardless IDs. | UK. No international transfer engaged. |
| Cloudflare, Inc. | Site hosting, edge delivery and KV storage for subscriber records. Subscriber email, account state, reading activity, transient IP in edge logs. | UK/EU region for KV storage. UK IDTA and EU SCCs for any onward transfer. |
| Resend Inc. | Transactional email delivery (magic-link, renewal, welcome and account emails). Subscriber email and email content. | Resend EU region (eu-west-1, Ireland). No onward international transfer engaged. |
| Google LLC | Google Workspace for administrative and financial records, including subscriber correspondence. Subscriber email, correspondence, invoice records. | US, with UK/EU residency where supported. UK IDTA; Workspace UK Addendum. |
| Xero | Accounting records for subscription income. Subscriber email, invoice metadata, payment amounts. | UK, EU and Australia. UK IDTA and EU SCCs per Xero DPA. |
KST does not use third-party advertising networks, third-party analytics platforms, customer data platforms, or marketing-automation platforms for the subscriber tier, other than the optional marketing-email opt-in, which uses Resend only. KST does not sell, rent or trade subscriber personal data, and does not share it for marketing purposes.
KST uses secure, encrypted systems to store and manage personal data:
Security measures include:
Subscriber records for The Parent Book (email, name where given, GoCardless identifiers, reading activity, optional family personalisation details, account state) are stored in Cloudflare KV in the UK/EU region, encrypted at rest and in transit. Access is restricted to the Director and to deployment automation. Subscriber correspondence and accounting records sit in Google Workspace and Xero as set out above.
The Parent Book /parents pages use one first-party, strictly necessary cookie, tpb_sess, which keeps you signed in after you click a magic link (HttpOnly; Secure; SameSite=Lax; expires 90 days from last sign-in). Its lawful basis is the PECR 2003 reg 6(4)(b) strictly-necessary exemption. No analytics, advertising or third-party cookies are set on the subscriber tier, and it embeds no third-party scripts, pixels or trackers.
Google Workspace data may be processed on servers located outside the United Kingdom. Google LLC operates under UK International Data Transfer Agreement (IDTA) safeguards and has certified compliance with applicable data protection standards.
Kiku stores clinical data on UK-based servers. No clinical data is transferred outside the United Kingdom.
KST reviews the transfer mechanisms of its data processors annually and will update this notice if the legal basis for international transfers changes.
For The Parent Book subscriber tier, the principal international-transfer considerations are Google Workspace (US) and Xero (UK, EU and Australia), both under the UK IDTA supplemented by each provider’s data processing agreement. Resend is EU-hosted (eu-west-1) and does not engage an onward international transfer. GoCardless and Cloudflare KV storage are UK/EU.
KST retains personal data only for as long as necessary. The following retention periods apply:
| Record Type | Retention Period | Legal Basis |
|---|---|---|
| Therapy notes (child clients) | Seven years after end of therapy, or until the child reaches age 25, whichever is longer | Limitation Act 1980; professional guidance |
| Therapy notes (adult clients) | Seven years after end of therapy | Limitation Act 1980 |
| Safeguarding records | Retained in line with local authority guidance; may exceed standard retention | Children Act 1989; Working Together 2023 |
| Consent forms | Duration of therapy plus seven years | Contractual and legal obligation |
| Invoices and financial records | Six years from end of financial year | HMRC requirements; Finance Act |
| Subcontractor records (DBS, insurance) | Duration of engagement plus six years | Legal obligation; insurance requirements |
| Website contact form submissions | Twelve months, or until enquiry resolved | Legitimate interests |
| Complaints records | Six years from date of closure | Limitation Act 1980 |
| DSAR records | Three years from date of response | ICO accountability requirements |
| Subscriber account records (email, name, GoCardless IDs, subscription status) | While active, and six years after final payment | Companies Act 2006; HMRC; Limitation Act 1980 |
| Subscriber reading activity (identifiable) | Twelve months, then anonymised | Legitimate interests (product analytics) |
| Optional family personalisation details (child’s age or year group, school) | While stored on the account; deleted on removal or when the subscription ends | Consent (Art. 6(1)(a)); minimum-necessary |
| Subscriber IP address logs | 30 days, then rotated | Legitimate interests (security) |
| Subscriber consent records (waiver, marketing opt-in) | While relied upon, and six years after withdrawal or end of subscription | Article 7(1) UK GDPR; Limitation Act 1980 |
After the applicable retention period, records are securely deleted (electronic) or destroyed by cross-cut shredding (paper). Deletion is logged.
Under UK GDPR, data subjects have the following rights:
To exercise any of these rights, contact the Data Protection Lead at contact [at] kst.ltd. KST will respond within one calendar month. Identity verification may be required before information is released. Complex or numerous requests may be extended by a further two months, with notification provided within the first month.
Where a request is made by a parent on behalf of a child who is assessed as Gillick competent, KST will consider the child’s own views before responding.
If you hold a Parent Book subscription, you can exercise any of the rights above by emailing hello [at] theparentbook.com from your subscriber email address. In particular, you may withdraw the optional family personalisation at any time by editing or deleting it on your account page, or by asking us; you may object to reading-activity analytics, after which KST stops linking reading activity to your account and anonymises the historical record; and you may withdraw marketing consent at any time with no effect on your subscription. Where KST must retain a limited financial record for six years under the Companies Act 2006 and HMRC rules, it will explain what has been kept and why.
Confidentiality is central to effective therapy but cannot be absolute. KST may share limited personal data without the data subject’s consent where:
Any such sharing is proportionate, recorded, and reported to the Director (as DSL). For full details, see the KST Safeguarding Policy.
When therapy concludes, records are securely stored for the applicable retention period set out in Section 11.
If a child changes school or moves to another therapist, KST can provide a brief handover summary to the new provider with written consent from the parent (and the young person’s consent, where the child is Gillick competent). Records are never transferred automatically.
At the end of the retention period, records are securely deleted or destroyed. KST encourages discussion about record management at the conclusion of therapy.
In the event of a personal data breach, KST will follow the KST Data Breach Response Plan (v1.0-2026). Where a breach poses a risk to the rights and freedoms of individuals, KST will notify the Information Commissioner’s Office within 72 hours and, where the risk is high, will notify affected individuals without undue delay.
| Risk | Mitigation | Likelihood | Impact |
|---|---|---|---|
| Unauthorised access to clinical records | Kiku access controls; MFA; device encryption; annual access review | Low | High |
| Data shared without lawful basis | Lawful basis documented per processing activity; consent forms; staff training | Low | High |
| Retention periods not enforced | Retention schedule maintained; annual deletion review; deletion logged | Medium | Medium |
| DSAR not responded to within statutory timeframe | DSAR procedure documented; response template maintained; Director tracks deadlines | Low | Medium |
| International transfer safeguards change | Annual review of processor transfer mechanisms; IDTA monitoring | Low | Medium |
| Child’s Gillick competence not assessed before sharing | Gillick assessment documented; therapist training; consent form addresses this | Low | High |
| Data breach not detected or reported | Breach response plan; incident reporting training; Kiku audit logs; Google Workspace audit | Low | High |
All records are stored securely within Google Workspace with access restricted to the Director.
Training completion is recorded in the KST Training Log.
If you have any questions or concerns about how KST handles your personal data, please contact:
If you are dissatisfied with how your data has been handled, you have the right to lodge a complaint with the Information Commissioner’s Office:
KST recommends raising any concern with the Data Protection Lead in the first instance, as many issues can be resolved directly and promptly.
Complaints about the individual subscriber tier follow The Parent Book complaints procedure: email hello [at] theparentbook.com with the heading “Complaint”. KST acknowledges within five working days and responds substantively within 20 working days. You may complain to the Information Commissioner’s Office at any time using the details above.
This policy will be reviewed annually or sooner if:
| Version | Author | Approved By | Date Issued | Review Date | Summary of Changes |
|---|---|---|---|---|---|
| 1.0 | Sam McManus | Sam McManus | October 2025 | October 2026 | Initial release |
| 2.0 | Sam McManus | Sam McManus | February 2026 | February 2027 | Major revision: restructured to 24-section governance format; lawful basis table added; retention schedule table added; international transfers section added; children’s data and Gillick competence addressed; risk register added; DPIA position stated; governance maturity assessment added |
| 3.0 | Sam McManus | Sam McManus | August 2026 | August 2027 | Added The Parent Book individual subscriber tier: new data subject category 6.6 (Individual Subscribers) including optional family personalisation (a child’s age or year group and school, held with consent, minimised, never the child’s name and nothing clinical, deletable at any time, never shared); children’s-data note extended for the subscriber tier; lawful bases for subscription processing including personalisation on Art. 6(1)(a) consent and marketing email under PECR 2003 reg 22; sub-processor table (GoCardless, Cloudflare, Resend, Google, Xero); subscriber storage, international transfers and retention; subscriber-tier cookie (tpb_sess); subscriber rights and complaints routes. Aligned with The Parent Book Privacy Notice. Company number 16707111 and registered and trading addresses confirmed. |