Privacy Policy

Privacy Notice & Data Protection Policy

The Inner Ordinate Project Ltd. (“we”, “our”, “us”) is committed to protecting your privacy and your personal boundaries. This privacy notice explains how we collect, use, and securely store your personal data across all of our services, websites, and trading names, which include Inner Ordinate Alchemy, Inner Ordinate Mind, and The Inner Ordinate Project. We operate in compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Data (Use and Access) Act 2025.

1. The Personal Data We Collect

We only collect information that is strictly necessary to provide you with our various services and training programs safely and effectively.

  • From Website Visitors & Enquirers: Name, email address, and any details you provide via our contact forms. We also collect IP addresses and basic usage data through strictly necessary cookies to keep our websites secure.
  • Automatically Collected Device Data: When you visit our websites, we automatically collect basic technical information (such as your IP address, browser type, and time zone) necessary to maintain website security, prevent fraud, and monitor general site performance.
  • From Individual Clients via Intake Forms (Therapy, Hypnotherapy, NLP & Spiritual Healing): Name, date of birth, contact details, and emergency contact information.
  • Health & Safeguarding Data (Special Category Data): For 1-to-1 clients, we collect relevant medical, lifestyle, and psychological history strictly to ensure your safety and maintain our professional duty of care. This includes GP, family doctor, or medical practitioner details where applicable to the specific clinical or therapeutic service booked.
  • Consultation & Session Notes: Information regarding your therapeutic goals, intentions, energetic history, and ongoing session notes.
  • From Seminar, Workshop & Corporate Training Attendees: Work email addresses, job titles, organisation or institutional names, and corporate billing or invoicing details.
  • Transaction Data: Details of payments for sessions and services. (We do not store or hold your sensitive credit card information; all payments are processed securely by our third-party payment processor, Stripe).
  • For detailed information on the cookies and tracking technologies we use, please review our standalone Cookie Policy linked in the website footer.

2. Who Has Access To Your Data & Third-Party Processors

We rely on trusted third-party providers to manage some services. These platforms act as “Data Processors” and handle your data according to their strict privacy policies:

  • Hostinger: Used for our website hosting, infrastructure, and secure server maintenance.
  • Google Workspace (Forms, Sheets, Calendar & Drive): Used for capturing mandatory intake data securely, scheduling sessions, securely logging client responses, and safely storing encrypted session notes.
  • Stripe: Used for secure payment processing.
  • WordPress Plugins (WPForms, WP Mail SMTP, Security/Caching): Used to securely capture inquiries and protect the website from spam.
  • Social Media & Messaging Platforms (Meta, Instagram, WhatsApp): If you choose to contact us via direct messaging or social media, your name and messages will be temporarily stored on their respective servers. We rely on their privacy policies for the security of these platforms, and we strictly advise against sending sensitive medical or health information via these channels.
  • Testimonials: Managed via our website’s testimonial plugin and displayed only with your explicit consent.

3. International Data Transfers

Some of our third-party processors (such as Google Workspace and Stripe) operate on secure servers outside of the UK. Whenever your data is transferred internationally, we ensure it is protected by strict legal safeguards, such as the UK International Data Transfer Agreement (IDTA) or the UK-US Data Bridge, ensuring your privacy rights remain fully protected under UK law.

4. Lawful Basis (How and Why We Use Your Data)

We only use your information for specific reasons, relying on the following lawful bases under UK GDPR:

  • Explicit Consent: Where we process special category data, such as information about your physical or mental health, we do so with your explicit consent obtained via our intake forms. You may withdraw your consent for ongoing therapy at any time.
  • Contractual Necessity: We process your personal information to arrange sessions, manage your bookings, and provide you with the therapies you have requested.
  • Legitimate Interest: If you contact us, it is in our legitimate interest to use your contact details to reply and provide customer service.

5. Safeguarding and Exceptions to Confidentiality

Your privacy is a priority, and our sessions are strictly confidential. However, under our professional Duty of Care, we may choose to reveal information about you to the appropriate authority if:

  • There is a legal requirement to share information (e.g., a court order).
  • There is good cause to believe that not disclosing information will expose you or others to a serious risk of harm (e.g., if you are at active risk of suicide or severe harm).

6. Data Retention (How Long We Keep It)

We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for.

  • Client Intake Forms & Session Notes: In accordance with the strict requirements of our professional liability insurance, we are legally obligated to retain all client records for a minimum period of 7 years following the last occasion on which treatment was given. For minors, records will be kept for 7 years after their 18th birthday (until age 25). After this period, data is securely destroyed.
  • Financial Records: Retained for 7 years to comply with HMRC requirements.

7. Your Legal Rights & Responsibilities

Under UK data protection law, you have the right to request access to, correction of, or erasure of your personal data.

  • Duty to Keep Data Accurate: It is your responsibility to keep us informed if your personal information (such as your address, emergency contact, or medical status) changes during your relationship with us.
  • The Right to Erasure (Exemption): Please note that the right to erasure is not absolute. Under UK GDPR Article 17(3)(e), we are legally required to refuse requests to delete your therapeutic records before the mandatory 7-year retention period expires. This data retention is strictly necessary for the “establishment, exercise or defence of legal claims” as mandated by our professional insurers.

8. Data Protection Complaints (DUAA Compliant)

If you have any concerns regarding how your personal data has been handled, you have the right to make a formal complaint.

  • How to complain: Email data@theinnerordinateproject.com with the subject “Data Protection Complaint”.
  • Our Response: We will formally acknowledge receipt within 30 days and provide a full response without undue delay.
  • Escalation: If dissatisfied, you retain the right to escalate the matter to the Information Commissioner’s Office (ICO) at ico.org.uk.

Document History

  • August 2026: Initial publication of Privacy Policy.