Privacy Policy

Last updated: 12/03/26

Who We Are

Gilia Practice is the trading name of Gillian McCarthy, a sole trader based in Scotland, United Kingdom.

Gillian McCarthy, trading as Gilia Practice, is the data controller responsible for your personal data.

If you have any questions about this Privacy Policy or how your personal data is handled, you can contact:

Email: hello@giliapractice.com
Website:
www.giliapractice.com

What Personal Data We Collect

We may collect and process the following types of personal data.

Information you provide directly

When you contact us, book a consultation, or enquire about services, we may collect information such as:

  • Name

  • Email address

  • Telephone number

  • Any information you include in your enquiry or message

If you become a client, we may collect additional information that is relevant to providing hypnotherapy or coaching services.

Special Category Data (Health Information)

As a hypnotherapy and coaching practice, we may collect health-related information or other sensitive personal data that you choose to share as part of the therapeutic process.

Under UK GDPR this is known as “special category data.”

This information is only collected where necessary to:

  • understand your situation

  • provide appropriate therapeutic support

  • ensure sessions are conducted safely and effectively

Such information is treated with a high level of confidentiality and stored securely.

The lawful basis for processing this type of data is typically:

  • Explicit consent, and

  • Provision of health or therapeutic services

You are not required to disclose any information you do not wish to share, although certain information may be necessary in order to provide appropriate support.

Website Usage Information

When you visit the website, certain information may be collected automatically, including:

  • IP address

  • Browser type

  • Device information

  • Pages visited and time spent on the site

  • Referral source (for example search engines)

This information helps us understand how visitors use the website and allows us to improve its performance.

This data is typically collected using website analytics tools.

Cookies

Our website may use cookies or similar technologies to improve your browsing experience and help us understand how the site is used.

Cookies are small text files stored on your device.

You can manage or disable cookies through your browser settings.

How We Use Your Personal Data

Your personal data may be used for the following purposes:

  • Responding to enquiries or messages

  • Arranging consultations or appointments

  • Delivering hypnotherapy or coaching services

  • Maintaining appropriate client records

  • Improving website performance and services

  • Meeting legal, regulatory, or professional obligations

We only collect and use personal data that is necessary and proportionate for these purposes.

Lawful Basis for Processing

Under UK GDPR, we rely on the following lawful bases for processing personal data:

Legitimate Interest

To respond to enquiries, manage communications, and operate the business effectively.

Contract

Where processing is necessary to provide services you have requested.

Legal Obligation

Where we are required to retain certain records for tax, legal, or regulatory purposes.

Consent

Where you have provided consent, for example by submitting an enquiry form or agreeing to share personal information.

Explicit Consent (Special Category Data)

Where sensitive personal information such as health-related information is shared for the purpose of therapeutic services.

Confidentiality

Confidentiality is a fundamental part of therapeutic work.

Information shared during consultations or sessions will be treated as confidential.

However, there are limited circumstances where confidentiality may need to be breached, including where:

  • there is a serious risk of harm to you or others

  • disclosure is required by law

  • information is required by a court order

Where possible, this would be discussed with you before any disclosure is made.

How We Store and Protect Your Data

We take appropriate technical and organisational measures to protect your personal data.

This includes reasonable safeguards designed to protect personal information from:

  • unauthorised access

  • loss or theft

  • misuse or disclosure

Data may be stored securely in electronic systems and, where necessary, physical records.

Only authorised individuals have access to personal data where it is required for legitimate purposes.

While we take care to protect your information, no internet transmission can be guaranteed to be completely secure.

Data Retention

Personal data is kept only for as long as necessary for the purposes for which it was collected, including to meet legal, professional, and regulatory obligations.

For example:

  • Enquiry information may be retained for administrative purposes.

  • Client records may be retained for a reasonable period in accordance with professional practice and legal requirements.

When personal data is no longer required, it will be securely deleted or anonymised.

Sharing Your Information

Your personal data will not be sold or rented to third parties.

In some cases, information may be shared with trusted service providers who help operate the business, such as:

  • website hosting providers

  • secure email services

  • appointment or booking systems

These providers are required to process personal data securely and only for the purposes specified.

Information may also be disclosed where required by law.

International Data Transfers

Some website services or software providers may store data outside the United Kingdom.

Where this occurs, we ensure that appropriate safeguards are in place to protect personal data in accordance with UK GDPR requirements.

Your Data Protection Rights

Under UK GDPR, you have the following rights:

  • The right to be informed about how your data is used

  • The right to access your personal data

  • The right to request correction of inaccurate data

  • The right to request deletion of your data in certain circumstances

  • The right to restrict processing of your data

  • The right to data portability

  • The right to object to certain types of processing

If you would like to exercise any of these rights, please contact:

hello@giliapractice.com

Complaints

If you have concerns about how your personal data is handled, please contact us in the first instance so we can try to resolve the matter.

You also have the right to lodge a complaint with the UK data protection regulator:

Information Commissioner’s Office (ICO)
https://ico.org.uk

Links to Other Websites

Our website may contain links to external websites.

We are not responsible for the privacy practices or content of third-party websites. We encourage you to review the privacy policies of any external sites you visit.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in legal requirements or business practices.

The latest version will always be available on this page.

Contact

If you have any questions about this Privacy Policy or how your personal data is handled, please contact:

Gillian McCarthy
Trading as Gilia Practice

Email: hello@giliapractice.com
Website:
www.giliapractice.com