Privacy Notice
Adaptive Path Community CIC
Last updated: 20 July 2026
Adaptive Path Community CIC (“Adaptive Path”, “we”, “us”, “our”) is committed to protecting your privacy and handling your personal information with the care you would expect from a mental health service. This notice explains what information we collect, why we collect it, how we use and protect it, and the rights you have over it. It applies to everyone who contacts us, uses our counselling and EMDR services, is referred to us, or partners with us as an organisation.
We are a “data controller” under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Who we are
Adaptive Path Community CIC is a Community Interest Company registered in England and Wales (company number 17011650), with its registered office at Labyrinth Business Centre, 43–47 Middle Hillgate, Stockport, SK1 3DG.
Our registration with the Information Commissioner’s Office (ICO) is being finalised; our registration number will be added here once confirmed.
If you have any questions about this notice or about how we handle your information, you can contact us at patrick@adaptivepath.co.uk.
The information we collect
Depending on how you engage with us, we may collect:
Identity and contact details — your name, email address, telephone number, and postal address.
Health and wellbeing information — this is “special category” data under UK GDPR and is treated with particular care. It may include the reasons you are seeking support, relevant history you choose to share, notes made during sessions, risk information, and any information provided by a person or organisation who refers you.
Referral information — where you are referred by a GP, another professional, an employer, or a funded scheme, we may receive relevant details from them.
Appointment and correspondence records — records of your enquiries, bookings, cancellations, and communication with us.
Payment information — where sessions are paid for, we keep a record of payments. Card details are handled by our payment provider and are not stored by us.
Website information — when you use our website we may collect limited technical data (such as pages visited) through our website platform and its analytics.
Why we use your information, and our lawful basis
Under UK GDPR we must have a lawful basis for using your personal data. Ours are:
To provide counselling, EMDR, and related services to you — the performance of a contract with you, and our legitimate interests in delivering a safe, effective service. For health information specifically, we rely on the UK GDPR Article 9 condition for the provision of health and social care (Article 9(2)(h)), and, where appropriate, your explicit consent.
To keep you safe and meet our safeguarding and legal duties — where there is a serious risk to your safety or the safety of others, we may need to share information (see “Confidentiality and its limits” below). Here we rely on our legal obligations and the protection of vital interests.
To manage appointments and communicate with you — performance of our contract with you and our legitimate interests in running the service.
To administer payments and keep proper financial records — performance of our contract and compliance with our legal obligations.
To improve our service and meet regulatory and professional standards — our legitimate interests, using anonymised information wherever possible.
Where we rely on consent, you can withdraw it at any time, though this will not affect anything done before you withdrew it, and some information may need to be retained to meet our legal and professional obligations.
Confidentiality and its limits
The counselling relationship is confidential, and we treat what you share with the seriousness it deserves. There are limited circumstances in which we may need to share information without your consent: where there is a serious and immediate risk to your life or safety, or to someone else’s, including a child or vulnerable adult; where we are required to do so by law, including a court order; or where safeguarding duties require us to act. Wherever it is safe and appropriate to do so, we will discuss this with you first.
Clinical supervision
As part of safe, ethical practice, our therapists discuss their work in clinical supervision. Wherever possible this is done in a way that does not identify you. Our supervisors are themselves bound by strict confidentiality.
Who we share your information with
We do not sell your information, and we do not share it for marketing. We may share it with:
clinical supervisors, as described above, on a confidential and normally anonymised basis;
your GP or another healthcare professional, only with your consent, or where there is a serious risk to safety;
people or organisations who refer or fund your sessions — where your support is arranged through an employer, scheme, or third party, we will share only what is necessary and appropriate, and we will be clear with you about what that involves;
service providers who help us operate — for example our website platform, secure email and file storage, and payment provider. These providers act on our instructions under contract;
regulatory, safeguarding, or legal authorities, where we are required or permitted to do so by law.
Some of our service providers may process data outside the UK. Where that happens, we take steps to ensure your information is protected by appropriate safeguards recognised under UK data protection law.
How long we keep your information
We keep your information only for as long as necessary. For clinical records, we follow the retention guidance of our professional body and indemnity provider. Our standard retention period is seven years from the end of your therapy for adults; for anyone seen as a child, we keep records until their 25th birthday (or their 26th if they were 17 when last seen). Financial records are kept for the period required by law. After the retention period, records are securely destroyed.
How we protect your information
We use appropriate technical and organisational measures to keep your information secure, including access controls, secure storage, and encryption where appropriate. We keep the amount of information we hold to what is necessary, and we review our practices to keep them safe.
Your rights
Under UK data protection law you have the right to be informed about how we use your data (this notice); to access the personal data we hold about you; to rectify information that is inaccurate or incomplete; to erase your data in certain circumstances (this is limited for health records we are obliged to retain); to restrict or object to our processing in certain circumstances; to data portability in certain circumstances; and to withdraw consent where we rely on it.
To exercise any of these rights, contact us at patrick@adaptivepath.co.uk. We will respond within one month. There is normally no charge.
Complaints
If you are unhappy with how we have handled your information, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Helpline: 0303 123 1113. ico.org.uk
Changes to this notice
We may update this notice from time to time. The date at the top shows when it was last revised. Where changes are significant, we will make that clear.