GDPR
Scottish Charitable Incorporated Organisation (SCIO)
Welcome
The Shape Connection provides free wellbeing counselling and practical workshops designed to support mental health and resilience.
This agreement explains how we work and how your personal data is handled in line with UK GDPR.
By signing (or ticking consent online), you confirm that you understand and agree to the following:
1. Confidentiality
All counselling sessions are confidential.
Confidentiality may only be broken if:
- There is risk of serious harm to you or others
- There are safeguarding concerns involving a child or vulnerable adult
- We are required to disclose information by law (e.g., court order)
Where possible, we will discuss this with you first.
Workshop discussions are confidential within the group; however, absolute confidentiality in group settings cannot be guaranteed.
2. Data We Collect
For counselling:
- Name and contact details
- GP details (where relevant)
- Emergency contact
- Relevant health and wellbeing information (special category data)
- Session notes
For workshops/courses:
- Name
- Contact details
- Organisation (if applicable)
- Attendance records
- Feedback forms
For online services:
- IP address
- Login details
- Session access records
3. Legal Basis for Processing
We process your data under:
- Article 6(1)(b) – Contract (delivery of counselling/course services)
- Article 6(1)(f) – Legitimate interest (service administration & quality improvement)
- Article 9(2)(h) – Provision of health or social care (for counselling data)
- Explicit consent (where required)
4. Storage & Security
We:
- Store digital records on secure, password-protected systems
- Limit access to authorised personnel only
- Use encrypted platforms for online counselling
- Keep paper records in locked storage
- Do not record online sessions without explicit written consent
5. Retention Periods
Counselling records: retained for 7 years after last session
Workshop attendance records: retained for 3 years
Safeguarding records: retained for 7 years (or longer if legally required)
Financial records: retained for 6 years
After retention periods, data is securely deleted or destroyed.
6. Your Rights
You have the right to:
- Access your data
- Request correction
- Request erasure (where legally possible)
- Restrict processing
- Withdraw consent
- Complain to the ICO (Information Commissioner’s Office)
7. Online Counselling Specifics
For online sessions:
- You are responsible for ensuring a private, confidential space
- We use secure platforms but cannot guarantee absolute internet security
- Sessions will not be recorded without explicit consent
8. Participant Agreement
I confirm that:
I understand my rights under GDPR
I understand confidentiality and its limits
I understand how my data will be processed
I consent to The Shape Connection holding and processing my data
