Privacy Policy


How We Handle Your Data

At The Neuro-Affirming Partnership Ltd, we respect your brain, your privacy, and your data. This policy explains what information we collect, why we need it, your rights regarding that information, and how we keep it strictly secure in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018).

1. Who We Are & Key Roles

Because we are a small business, our Directors oversee data protection directly to ensure your information is handled with the utmost care.

  - Data Controller: The Neuro-Affirming Partnership Ltd (This means we decide how and why your data is processed).

  - Data Protection Officer (DPO): Mark Rait. The DPO is responsible for ensuring our compliance with data laws.

  - ICO Registration Number: ZC251762

  - Contact Email: mark@neuroaffirmingpartnership.com]

All practitioners, contractors, and staff working for us are contractually bound to comply with this policy.

2. Our Data Protection Principles

We process your data in accordance with the 7 core principles of the UK GDPR:

1.  Lawfulness, Fairness, and Transparency: We will always have a legal reason to use your data and will be open about how we use it.

2.  Purpose Limitation: We only collect data for specific, explicit coaching, mentoring, and educational purposes.

3.  Data Minimisation: We only ask for what we actually need to support you safely and effectively.

4.  Accuracy: We take reasonable steps to ensure your data is accurate and kept up to date.

5.  Storage Limitation: We do not keep your identifiable data for longer than is necessary.

6.  Integrity and Confidentiality (Security): We use highly secure, cloud-based systems to protect your data against unauthorised access, loss, or damage.

7.  Accountability: We take responsibility for our data processing and maintain records to prove our compliance.

3. The Data We Collect & Our Lawful Basis

Under UK GDPR, we must establish a "Lawful Basis" for collecting your data. We collect two types of data:

A. Standard Personal Data

  - What it is: Name, email address, phone number, billing address, and emergency contact details.

  - Lawful Basis: Contract (we need this to fulfil our coaching/mentoring agreement with you) and Legitimate Interest (to manage waitlists or send you business updates).

B. Special Category Data

  - What it is: Because we specialise in neurodiversity, we collect sensitive information regarding your health, neurodivergent traits (e.g., Autism, ADHD profiles), sensory needs, and processing styles.

  - Lawful Basis: Explicit Consent (Article 9 UK GDPR). We will explicitly ask for your permission to process this data via our intake forms. You have the right to withdraw this consent at any time, though it may limit our ability to tailor our support to you.

4. How We Store and Process Data (Our Tech Stack)

We operate a modern, paperless, cloud-based system. We act as the Data Controller, and we use carefully vetted third-party software (Data Processors) to help us deliver our services securely:

  - Google Workspace (Cloud Storage & Communications): All client notes, files, and emails are stored securely in the cloud using Google Workspace. Google Workspace complies with strict global privacy standards and UK GDPR. Access to our Google Drive is restricted by strong passwords and Multi-Factor Authentication (MFA). We do not store client data on unencrypted local hard drives.

  - Google Meet: Used for hosting our remote 1:1, Couples, and Group sessions. We do not record sessions without the explicit, prior written consent of all attendees.

  - Acuity Scheduling: Used for booking appointments and completing secure digital intake forms.

  - MailerLite: Used for maintaining our waitlists and newsletters. You can unsubscribe at any time.

  - Stripe & Clearpay: Used for processing financial transactions. We do not see or store your full credit/debit card numbers on our systems.

5. Data Security & Breach Protocol

We take the security of your data very seriously.

  - Security Measures: All devices used by our staff are password-protected and encrypted. We use role-based access, meaning staff can only access the data necessary for the clients they are working with.

  - Data Breaches: A data breach is an accidental or unlawful loss, alteration, or unauthorised disclosure of personal data. If a breach occurs that poses a risk to your rights and freedoms, our DPO will notify the Information Commissioner’s Office (ICO) within 72 hours. We will also notify you directly without undue delay, advising you on steps to protect yourself.

6. Your Rights (Data Subject Rights)

Under data protection law, you have the following rights:

  - The Right to be Informed: To know how your data is used (which this policy explains).

  - The Right of Access: To request a copy of the data we hold about you (see Section 7 below).

  - The Right to Rectification: To ask us to correct data you think is inaccurate or incomplete.

  - The Right to Erasure (Right to be Forgotten): To ask us to delete your data. (Note: We may have to retain some data for legal, tax, or safeguarding reasons).

  - The Right to Restrict Processing: To ask us to limit how we use your data.

  - The Right to Data Portability: To ask that we transfer the data you gave us to another organisation.

  - The Right to Object: To object to your data being used for direct marketing.

7. Subject Access Request (SAR) Procedure

You have the right to request a copy of the personal information we hold about you. This is called a Subject Access Request (SAR).

  - How to Apply: Please email your request to [Insert DPO Email]. You do not need to use the exact words "Subject Access Request."

  - Timeframe: We will respond to your request free of charge within one calendar month (up to 30 days). If your request is highly complex, we may extend this by a further two months, but we will notify you within the first month if this is the case.

  - Identity Checks: Before releasing any data, we will take reasonable steps to verify your identity to ensure we are not handing your data to the wrong person.

  - Exemptions (Couples & Groups): If your records contain the personal data of a third party (e.g., your partner in Couples Coaching, or another member of a Group Programme), we will heavily redact their information or seek their explicit consent before releasing the records to you, to protect their right to privacy.

8. Third-Party Sharing and B2B Clients

  - No Selling: We will never sell your personal data to third parties.

  - B2B / Organisational Clients: If your employer has paid for your group programme or coaching, we may share basic attendance records with them. However, the contents of your sessions, your specific neurodivergent traits, and your personal insights remain strictly confidential between you and us, unless there is a safeguarding risk (see our Safeguarding Policy).

  - Statutory Sharing: We will only share your data with external agencies (like Social Services or the Police) if we are legally obligated to do so, or to protect you or others from serious harm.

9. Data Retention

We keep your personal data only as long as is necessary to provide our services and meet our legal and accounting obligations.

  - Client Records: We retain your coaching and mentoring notes for 7 years after your last session, after which they are securely and permanently deleted from our cloud servers.

  - Financial Records: HMRC requires us to retain financial transaction data for 6 years.

If you have any questions or concerns about how we process your data, please contact our DPO at mark@neuroaffirmingpartnership.com. If you remain unhappy with our response, you have the right to complain to the Information Commissioner’s Office (ICO) at www.ico.org.uk.

Last Updated: 17 September 2026