Data Protection & Privacy Policy

‍ ‍

Last Updated: 01/08/2026 ‍ ‍

Version: 1.0 ‍ ‍

ICO Registration Number: ZB671451 ‍ ‍

Data Controller: Laura Clark, Shadowed Path Psychology‍ ‍

1. Purpose of This Policy‍ ‍

Shadowed Path Psychology (“we”, “us”, “our”) is committed to protecting your privacy and handling your personal data with transparency, care, and respect. This policy explains how we collect, use, store, and protect personal data in line with:‍ ‍

  • UK General Data Protection Regulation (UK GDPR)

  • Data Protection Act 2018

  • Privacy and Electronic Communications Regulations (PECR)

  • Data (Use and Access) Act 2025 (DUAA)

  • ICO guidance

‍We only collect the minimum data necessary to deliver our services, operate our business, and meet legal obligations.‍ ‍

2. Data We Collect and Why‍ ‍

We collect only the data required for each activity. The table below outlines what we collect, where it comes from, and the legal basis for processing.‍ ‍

We do not collect or store credit card details. All payments are processed securely by third‑party providers.‍ ‍

3. Third‑Party Data Processors‍ ‍

We use trusted third‑party platforms (“Processors”) to deliver services. Each processor has its own security measures and complies with UK GDPR and DUAA requirements. ‍ ‍

Our processors include: ‍ ‍

We audit processors periodically to ensure compliance with UK GDPR and DUAA.‍ ‍

4. International Data Transfers‍ ‍

Some processors store data outside the UK. Where this occurs, we ensure appropriate safeguards are in place.‍ ‍

United States Transfers‍ ‍

Many providers (e.g., Squarespace, Zoom, Dropbox, Vimeo, Substack, Meta) store data in the USA.‍ ‍

Where possible, we rely on:‍ ‍

  • UK‑US Data Bridge certification, or

  • Standard Contractual Clauses (SCCs) with the UK Addendum‍ ‍

We have conducted a Transfer Risk Assessment (TRA) and determined that these safeguards provide an essentially equivalent level of protection to UK standards.‍ ‍

5. Anonymous Feedback‍ ‍

Our feedback forms are designed to be fully anonymous. We do not collect IP addresses, device identifiers, or metadata.‍ ‍

You may optionally provide your first name and give explicit consent for us to use your name and/or feedback in future marketing or testimonial materials.‍ ‍

If you choose to provide your name or to opt-in to your feedback being used for marketing, the legal basis for processing is Consent, which you may withdraw at any time.‍ ‍

6. Email Marketing, Consent & Soft Opt‑In‍ ‍

We operate a strict opt‑in policy for marketing unless the soft opt‑in applies.‍ ‍

Explicit Consent‍ ‍

You may subscribe to our mailing list via:‍ ‍

  • Website forms

  • Event sign‑ups

  • Substack

  • MailerLite forms‍ ‍

Every email includes an unsubscribe link.‍ ‍

Soft Opt‑In (PECR & DUAA 2025) ‍ ‍

We may send marketing emails about similar products or services if:‍ ‍

  • You purchased from us (including free downloads), or

  • You requested a resource or lead magnet

‍This is known as the “soft opt‑in”. You can opt out at any time.‍ ‍

Purchase‑Based Personalisation‍ ‍

If you buy a product or service, we store:‍ ‍

  • Item purchased

  • Transaction date

  • Order value

‍We use this to tailor recommendations (e.g., relevant webinars or resources). This profiling is low‑risk, non‑intrusive, and does not produce legal or significant effects.‍ ‍

7. Automated Decision‑Making & DUAA Transparency‍ ‍

Under the Data (Use and Access) Act 2025, we must explain any automated processes.‍ ‍

We use automated segmentation within MailerLite and Squarespace to:‍ ‍

  • Tag purchases

  • Track engagement

  • Deliver relevant content

‍These processes:‍ ‍

  • Do not make decisions with legal or significant effects

  • Are used only for marketing relevance

  • Can be opted out of at any time

‍You may request:‍ ‍

  • A DUAA Access Report showing when your data was accessed and by whom

  • Human review of any automated process

  • To opt out of profiling entirely

8. Accessibility Data & Special category data‍ ‍

For live events, you may choose to share accessibility needs to help us ensure the event is inclusive and accessible. Some accessibility information may reveal health‑related details and therefore qualify as special category data under UK GDPR.‍ ‍

We only collect the minimum information necessary and process this data with your explicit consent, which is requested at the point of collection (e.g., registration). Accessibility data is used solely for event delivery and is deleted after the event unless you request ongoing support or provide consent for future use.‍ ‍

Given the reflective nature of our workshops, we recognise some people may opt to make personal disclosures within discussions or debriefs. Participants are encouraged to be mindful of the setting and only share what they feel is relevant and comfortable. For this reason, live webinars are not recorded, prerecorded webinars are shared following the event. Participants may also use pseudonyms or first names.‍ ‍

8. Community Access ‍ ‍

We do not require special category data (e.g., health information) to access ‘community access’ pricing or “Pay It Forward”/ ‘community Hero’ schemes.‍ ‍

If you voluntarily share personal circumstances (e.g., mental health, financial hardship), we treat this with strict confidentiality and use it only to process your request.‍ ‍

9. Pay It Forward & Donor Transparency‍ ‍

“Pay It Forward”/”community Hero” contributions are handled confidentially.‍ ‍

  • Donors remain anonymous

  • Recipients remain anonymous

  • Aggregated statistics may be published (e.g., number of community slots funded)

  • No identifiable data is shared‍ ‍

10. Data Retention‍ ‍

We retain data only as long as necessary:‍ ‍

  • Transaction records: 6 years (HMRC requirement)

  • Marketing data: Until consent is withdrawn

  • Event data: Deleted 12 months after the event unless you opted into marketing

  • SARs: Retained as required by law

  • Anonymous feedback: Retained indefinitely (non‑personal data)

11. Your Rights‍ ‍

Under UK GDPR, DPA 2018, and DUAA 2025, you have the right to:‍ ‍

  • Access – request a copy of your data

  • Rectification – correct inaccurate data

  • Erasure – request deletion

    • We may retain financial records required for HMRC compliance

  • Restriction – limit how your data is used

  • Data Portability – request your data in a transferable format

  • Object – to marketing, profiling, or legitimate interest processing

  • Withdraw Consent – at any time

  • DUA Access Report – showing when your data was accessed

  • Human Review – of any automated process‍ ‍

To exercise your rights, email: info@shadowedpathpsychology.co.uk‍ ‍

12. Security Measures‍ ‍

We protect your data through:‍ ‍

  • Strong, unique passwords

  • Two‑Factor Authentication (2FA) on platforms where available

  • Industry‑standard antivirus and firewall protection

  • Limiting access to essential personnel only

  • No data scraping or purchasing of data‍ ‍

We are in the process of rolling out 2FA across all systems. Our devices use industry‑standard security tools, including antivirus and firewall protection. We are implementing full‑disk encryption across all devices using industry‑standard tools (e.g., BitLocker). Full‑disk encryption ensures that data remains protected even if a device is lost or stolen. Recovery keys are stored securely, and encryption status is reviewed periodically. ‍ ‍

13. Complaints‍ ‍

If you have concerns about how your data is handled:‍ ‍

  • Email us at info@shadowedpathpsychology.co.uk

  • You may also contact the ICO: https://ico.org.uk/make-a-complaint/(Make a complaint | ICO)‍ ‍

14. Contact Information‍ ‍

Data Protection Lead: Laura Clark, Shadowed Path Psychology ‍ ‍

Email:info@shadowedpathpsychology.co.uk

Address:‍ ‍

Shadowed Path Psychology‍ ‍

Clyde Offices
2nd Floor
48 West George Street
Glasgow
G2 1BP‍ ‍

15. Updates to This Notice‍ ‍

We may update this notice periodically. The latest version will always be available on our website.

‍ ‍