Data Protection & Privacy Policy
Last Updated: 01/08/2026
Version: 1.0
ICO Registration Number: ZB671451
Data Controller: Laura Clark, Shadowed Path Psychology
1. Purpose of This Policy
Shadowed Path Psychology (“we”, “us”, “our”) is committed to protecting your privacy and handling your personal data with transparency, care, and respect. This policy explains how we collect, use, store, and protect personal data in line with:
UK General Data Protection Regulation (UK GDPR)
Data Protection Act 2018
Privacy and Electronic Communications Regulations (PECR)
Data (Use and Access) Act 2025 (DUAA)
ICO guidance
We only collect the minimum data necessary to deliver our services, operate our business, and meet legal obligations.
2. Data We Collect and Why
We collect only the data required for each activity. The table below outlines what we collect, where it comes from, and the legal basis for processing.
We do not collect or store credit card details. All payments are processed securely by third‑party providers.
3. Third‑Party Data Processors
We use trusted third‑party platforms (“Processors”) to deliver services. Each processor has its own security measures and complies with UK GDPR and DUAA requirements.
Our processors include:
MailerLite – email delivery, marketing automation, segmentation
Squarespace – website hosting, sales, analytics
Eventbrite – event registration, ticketing, attendee management
Zoom – webinar delivery
Google Workspace – secure storage of administrative documents (e.g., SAR logs)
Microsoft Forms – anonymous feedback collection
Dropbox – file storage and analytics
Vimeo – video hosting and analytics
Substack – newsletter and blog subscription management
Instagram/ Facebook (Meta) – direct messages, engagement analytics
We audit processors periodically to ensure compliance with UK GDPR and DUAA.
4. International Data Transfers
Some processors store data outside the UK. Where this occurs, we ensure appropriate safeguards are in place.
United States Transfers
Many providers (e.g., Squarespace, Zoom, Dropbox, Vimeo, Substack, Meta) store data in the USA.
Where possible, we rely on:
UK‑US Data Bridge certification, or
Standard Contractual Clauses (SCCs) with the UK Addendum
We have conducted a Transfer Risk Assessment (TRA) and determined that these safeguards provide an essentially equivalent level of protection to UK standards.
5. Anonymous Feedback
Our feedback forms are designed to be fully anonymous. We do not collect IP addresses, device identifiers, or metadata.
You may optionally provide your first name and give explicit consent for us to use your name and/or feedback in future marketing or testimonial materials.
If you choose to provide your name or to opt-in to your feedback being used for marketing, the legal basis for processing is Consent, which you may withdraw at any time.
6. Email Marketing, Consent & Soft Opt‑In
We operate a strict opt‑in policy for marketing unless the soft opt‑in applies.
Explicit Consent
You may subscribe to our mailing list via:
Website forms
Event sign‑ups
Substack
MailerLite forms
Every email includes an unsubscribe link.
Soft Opt‑In (PECR & DUAA 2025)
We may send marketing emails about similar products or services if:
You purchased from us (including free downloads), or
You requested a resource or lead magnet
This is known as the “soft opt‑in”. You can opt out at any time.
Purchase‑Based Personalisation
If you buy a product or service, we store:
Item purchased
Transaction date
Order value
We use this to tailor recommendations (e.g., relevant webinars or resources). This profiling is low‑risk, non‑intrusive, and does not produce legal or significant effects.
7. Automated Decision‑Making & DUAA Transparency
Under the Data (Use and Access) Act 2025, we must explain any automated processes.
We use automated segmentation within MailerLite and Squarespace to:
Tag purchases
Track engagement
Deliver relevant content
These processes:
Do not make decisions with legal or significant effects
Are used only for marketing relevance
Can be opted out of at any time
You may request:
A DUAA Access Report showing when your data was accessed and by whom
Human review of any automated process
To opt out of profiling entirely
8. Accessibility Data & Special category data
For live events, you may choose to share accessibility needs to help us ensure the event is inclusive and accessible. Some accessibility information may reveal health‑related details and therefore qualify as special category data under UK GDPR.
We only collect the minimum information necessary and process this data with your explicit consent, which is requested at the point of collection (e.g., registration). Accessibility data is used solely for event delivery and is deleted after the event unless you request ongoing support or provide consent for future use.
Given the reflective nature of our workshops, we recognise some people may opt to make personal disclosures within discussions or debriefs. Participants are encouraged to be mindful of the setting and only share what they feel is relevant and comfortable. For this reason, live webinars are not recorded, prerecorded webinars are shared following the event. Participants may also use pseudonyms or first names.
8. Community Access
We do not require special category data (e.g., health information) to access ‘community access’ pricing or “Pay It Forward”/ ‘community Hero’ schemes.
If you voluntarily share personal circumstances (e.g., mental health, financial hardship), we treat this with strict confidentiality and use it only to process your request.
9. Pay It Forward & Donor Transparency
“Pay It Forward”/”community Hero” contributions are handled confidentially.
Donors remain anonymous
Recipients remain anonymous
Aggregated statistics may be published (e.g., number of community slots funded)
No identifiable data is shared
10. Data Retention
We retain data only as long as necessary:
Transaction records: 6 years (HMRC requirement)
Marketing data: Until consent is withdrawn
Event data: Deleted 12 months after the event unless you opted into marketing
SARs: Retained as required by law
Anonymous feedback: Retained indefinitely (non‑personal data)
11. Your Rights
Under UK GDPR, DPA 2018, and DUAA 2025, you have the right to:
Access – request a copy of your data
Rectification – correct inaccurate data
Erasure – request deletion
We may retain financial records required for HMRC compliance
Restriction – limit how your data is used
Data Portability – request your data in a transferable format
Object – to marketing, profiling, or legitimate interest processing
Withdraw Consent – at any time
DUA Access Report – showing when your data was accessed
Human Review – of any automated process
To exercise your rights, email: info@shadowedpathpsychology.co.uk
12. Security Measures
We protect your data through:
Strong, unique passwords
Two‑Factor Authentication (2FA) on platforms where available
Industry‑standard antivirus and firewall protection
Limiting access to essential personnel only
No data scraping or purchasing of data
We are in the process of rolling out 2FA across all systems. Our devices use industry‑standard security tools, including antivirus and firewall protection. We are implementing full‑disk encryption across all devices using industry‑standard tools (e.g., BitLocker). Full‑disk encryption ensures that data remains protected even if a device is lost or stolen. Recovery keys are stored securely, and encryption status is reviewed periodically.
13. Complaints
If you have concerns about how your data is handled:
Email us at info@shadowedpathpsychology.co.uk
You may also contact the ICO: https://ico.org.uk/make-a-complaint/(Make a complaint | ICO)
14. Contact Information
Data Protection Lead: Laura Clark, Shadowed Path Psychology
Email:info@shadowedpathpsychology.co.uk
Address:
Shadowed Path Psychology
Clyde Offices
2nd Floor
48 West George Street
Glasgow
G2 1BP
15. Updates to This Notice
We may update this notice periodically. The latest version will always be available on our website.