I'm on Summer break from 15th August to 6th September. I'll respond to enquiries on my return.
I'm on Summer break from 15th August to 6th September. I'll respond to enquiries on my return.
Legal
Last updated: 10th August 2026
August 2026 changes
Updated ahead of the BACP's 2026 Ethical Framework, which takes effect on 1st November 2026.
+Named the providers that run parts of the booking system
+Added how I use AI, and where it cannot reach
+Added legal bases, who's responsible, and the ICO complaints route
+Retention periods now match what the systems actually do
−Removed ClinicalWill.app; executor details are now held in my own encrypted document
−Removed the "no third-party services" claim, which was no longer accurate
May 2026 changes
−Removed iCloud as practice email storage
+Added Google Workspace for practice email from March 2026
January 2026 changes
−Removed Acuity Scheduling (third-party)
+Added own booking system (booking.talktoluke.com)
Here's what happens to your data, explained clearly rather than hidden in legal language.
The short version: I keep your details secure, I don't sell them to anyone, and the small number of situations where anything leaves the room are all listed below.
The long version: here's everything you need to know.
I am. Luke Row, sole practitioner, and the data controller for everything described here. For questions, requests or complaints about your data, email hello@talktoluke.com.
It depends how far we get:
Please share only what's needed at each stage. The message boxes aren't for urgent help.
UK data protection law requires a legal basis for everything above. Mine, in plain words:
Consent is not the basis for your clinical records. Your therapy doesn't rest on something you might feel pressured to give. Where I do rely on consent, you can withdraw it at any time.
The house rules first: every account involved in running this practice has two-factor authentication or passkeys enabled, with physical Titan security keys on the accounts that matter most, and I use end-to-end encryption wherever it's available. The details:
Email: Google Workspace, which has handled my practice email since March 2026. My account is protected with hardware passkeys and Google's Advanced Protection Program.
Text messages: iMessage or WhatsApp, both encrypted.
My computer: password-protected, encrypted Mac. Session notes are stored separately from your personal details, with identifying information kept to a minimum. If notes could still be linked to you they count as personal data, and I treat them that way.
Scheduling: I built and run the booking system myself (booking.talktoluke.com), and I decide what happens to the data in it. Specialist providers run parts of it, and each one touches something different:
Some of these companies are based outside the UK. Where that's the case, the transfer is covered either by the UK-US data bridge (Stripe, Vercel and Google are certified) or by UK-approved contract terms that bind the provider to the same standards (Neon, Resend and Upstash).
Payments: the first session is paid through my booking system via Stripe. After that, UK clients pay by bank transfer; international clients continue using Stripe. I don't store your card details. Stripe handles that with bank-level encryption.
Online sessions: sessions run on Zoom, using my personal meeting room rather than a scheduled event, so Zoom never receives appointment details from my booking system. That room is set up for end-to-end encryption. Some clients prefer FaceTime, which is end-to-end encrypted by default. Either way, sessions are never recorded.
This is worth being precise about, so here it is in full.
In therapy, not at all. Sessions are never recorded or transcribed. I don't use AI to take notes, to summarise what we discuss, or to help me think about your case. Nothing you tell me is typed into a chatbot.
In the booking system, as a coding tool. I built the booking system myself, and I use an AI coding assistant to help write and maintain the software behind it. To keep that well away from your information, the assistant reaches the database through a separate restricted account that cannot read names, emails, phone numbers, dates of birth, addresses or GP details. Those columns are blocked by the database itself, so it doesn't depend on me remembering to be careful. When I need to investigate a problem with a particular booking, I work from a reference number and masked values such as p***@t***.com.
Nothing about you is decided by a machine. No automated system makes decisions about your care, your suitability for therapy, or your appointments. Those are all mine, and I'm accountable for them.
Supervision: I'm in clinical supervision every week to discuss my work; it's an ethical requirement of practising. I keep identifying details to a minimum, first names at most, and no supervisor has access to your records or contact details.
Safety: if I'm seriously worried about your safety or someone else's, I'll talk to you first wherever that's safe and possible, and we'd usually agree together what support to involve, such as your GP or crisis services. I can only break confidentiality without your consent where the law requires it, or where the risk is serious enough that disclosure is legally and ethically justified. If that ever happens, I share the minimum necessary. My Safeguarding page sets out how this works and who you can contact.
If I die or become incapacitated: my therapeutic executor will contact current clients to let them know. The contact details needed for this are held in an encrypted, password-protected document.
You can:
The bottom line: I treat your information the way I'd want mine treated - securely, respectfully, and with the minimum fuss necessary.
This privacy notice forms part of our contract when we begin working together. When you book, you also receive a copy of our working agreement in your confirmation email, so you have a record of what you agreed to and when.
Questions? Just ask. I'd rather explain something clearly than hide behind legal jargon.