Cookie Consent Policy
Last Updated: December 1st 2025
Guided Healing Limited (trading as martinpavion.com) is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, store, and protect your data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Data Controller Information
Legal Entity: Guided Healing Limited
Trading Name: martinpavion.com
Company Registration Number: 11474773
Registered Address: 5 Brayford Square, London, E1 0SG
Contact Email: moc.noivapnitramobfsctd-8b7d2c@lagel
Contact Phone: +44 7537 131248
Website: martinpavion.com
Guided Healing Limited is the “data controller” for the purposes of UK data protection law. This means we are responsible for deciding how we hold and use personal information about you.
2. What Information We Collect
We collect and process the following categories of personal information:
2.1 Identity and Contact Information
- Full name
- Email address
- Phone number
- Postal address
- Date of birth
2.2 Health and Wellbeing Information (Special Category Data)
- Health questionnaire responses
- Mental health and emotional wellbeing information
- Information about current or past medical conditions
- Medications you are taking
- Information about therapy or psychiatric treatment
- Session notes and progress records
- Audio/video recordings of sessions (with your explicit consent)
2.3 Financial Information
- Payment card details (processed securely by our payment providers)
- Billing address
- Payment history and invoices
2.4 Technical Information
- IP address
- Browser type and version
- Device information
- Cookie data
- Website usage analytics
2.5 Communications
- Email correspondence
- Messages sent through our website
- Records of phone conversations (when relevant to service delivery)
- Feedback and survey responses
3. How We Collect Your Information
We collect your personal information through the following methods:
- Website forms: Contact forms, booking forms, and waiver forms created using Crove
- Booking system: Amelia Bookings integrated with our website
- Email communications: Correspondence via Gmail, Amazon SES, and MXroute
- Session recordings: Google Meet and Zoom (with your explicit consent)
- Payment processing: Stripe, PayPal, and direct bank transfer
- Website analytics: Google Analytics tracking
- Marketing platform: Mautic (self-hosted email marketing system)
- Direct interactions: During telephone calls, video sessions, and email exchanges
4. Legal Basis for Processing
Under UK GDPR, we must have a legal basis for processing your personal information. We rely on the following legal bases:
4.1 Consent
- Processing health information (special category data) for coaching and hypnotherapy services
- Recording sessions for transcription and evaluation purposes
- Sending marketing communications and newsletters
- Using cookies and analytics on our website
4.2 Contract Performance
- Delivering coaching, hypnotherapy, NLP, and spiritual hypnosis services
- Processing payments
- Managing bookings and appointments
- Providing client support
4.3 Legal Obligation
- Maintaining financial records for tax purposes (6 years as required by HMRC)
- Complying with professional body requirements (ICF and IHA codes of ethics)
- Retaining records for insurance and liability purposes
- Reporting safeguarding concerns where legally required
4.4 Legitimate Interest
- Improving our services and website functionality
- Preventing fraud and ensuring payment security
- Maintaining business records for potential legal claims
- Website security and IT infrastructure protection
5. How We Use Your Information
We use your personal information for the following purposes:
5.1 Service Delivery
- Providing hypnotherapy, coaching, NLP, and spiritual hypnosis sessions
- Creating and maintaining your client records
- Scheduling and managing appointments
- Communicating about your sessions and progress
- Providing session recordings and transcripts (where applicable)
- Sharing resources and materials relevant to your sessions
5.2 Administrative Purposes
- Processing payments and maintaining financial records
- Sending booking confirmations and reminders
- Managing cancellations and rescheduling
- Responding to your enquiries
- Maintaining professional indemnity insurance records
5.3 Legal and Regulatory Compliance
- Complying with ICF (International Coaching Federation) Code of Ethics
- Complying with IHA (International Hypnosis Association) Code of Ethics
- Meeting professional indemnity insurance requirements
- Fulfilling tax and accounting obligations
- Responding to legal requests or court orders
5.4 Marketing and Communications (with your consent)
- Sending newsletters and educational content
- Informing you about new services or offerings
- Sharing relevant articles, resources, or blog posts
- Inviting you to participate in surveys or feedback requests
5.5 Website Improvement
- Analysing website traffic and user behaviour
- Improving user experience and website functionality
- Testing new features and services
6. Third-Party Service Providers
We work with trusted third-party service providers who process your data on our behalf. These processors are contractually obligated to handle your data securely and only for the purposes we specify.
6.1 Booking and Scheduling
- Amelia Bookings: Appointment scheduling and calendar management
6.2 Payment Processing
- Stripe: Secure payment card processing (PCI-DSS compliant)
- PayPal: Alternative payment processing
6.3 Communication Services
- Gmail (Google Workspace): Email hosting and communication
- Amazon SES: Transactional email delivery
- MXroute: Email routing and management
- Google Meet: Video conferencing for remote sessions
- Zoom: Alternative video conferencing platform
6.4 Recording and Transcription
- Google Drive: Secure storage of session recordings
- Noota: Session recording and transcription services
6.5 File Hosting and Storage
- Amazon S3: Secure file storage and delivery
- Self-hosted server: martinpavion.com web server for file hosting
6.6 Customer Relationship Management
- SuiteCRM: Self-hosted CRM system for client records management
- WordPress Database: Website and membership data storage
6.7 Marketing and Analytics
- Mautic: Self-hosted email marketing platform
- Google Analytics: Website traffic analysis and user behaviour tracking
- Social media platforms: Facebook, Instagram, LinkedIn advertising pixels
6.8 Form Management
- Crove: Online forms including waiver forms and health questionnaires
7. International Data Transfers
Some of our third-party service providers are based outside the United Kingdom. When we transfer your data internationally, we ensure appropriate safeguards are in place:
- United States (Google, Amazon, Stripe, PayPal): These providers participate in the UK-US Data Bridge Framework or have implemented Standard Contractual Clauses (SCCs) approved by the ICO
- European Economic Area: Covered by UK GDPR adequacy regulations
- Self-hosted systems: Mautic and SuiteCRM are hosted on UK-based servers under our direct control
We regularly review our international data transfer arrangements to ensure ongoing compliance with UK data protection law.
8. Data Security
We take the security of your personal information seriously and have implemented appropriate technical and organisational measures:
8.1 Technical Security Measures
- SSL/TLS encryption for all website communications
- Secure password-protected access to all systems
- Regular security updates and patches
- Encrypted storage of sensitive data
- Secure backup systems with encryption
- Firewall protection on all servers
- Two-factor authentication on critical systems
8.2 Organisational Security Measures
- Access to personal data limited to authorised personnel only
- Confidentiality agreements with any staff or contractors
- Regular review of data protection practices
- Data protection impact assessments for high-risk processing
- Incident response and breach notification procedures
8.3 Session Recording Security
- All session recordings are stored with access controls
- Client-identifying information is redacted where appropriate
- Recordings are used solely for transcription and evaluation purposes
- Recordings can be deleted upon client request
- Explicit consent obtained before any recording begins
9. Data Retention
We retain your personal information for as long as necessary to fulfil the purposes for which it was collected:
9.1 Client Records
- Session notes and health information: 7 years from your last session
- Rationale: Professional standards, insurance requirements, and potential legal claims
9.2 Financial Records
- Invoices, payment records, and receipts: 6 years from the end of the financial year
- Rationale: HMRC legal requirement
9.3 Session Recordings
- Audio/video recordings: Up to 7 years or until you request deletion
- Transcripts: 7 years as part of session records
9.4 Marketing Communications
- Email marketing lists: Until you unsubscribe or withdraw consent
- Deleted within 30 days of unsubscribing
9.5 Website Analytics
- Google Analytics data: 26 months (Google’s default setting)
- Cookie data: As specified in our Cookie Policy (typically 12 months)
9.6 Exceptions to Retention Periods
We may retain data beyond these periods where:
- Required by law or regulatory obligations
- Necessary for legal proceedings or potential claims
- Required by our professional indemnity insurance
- You have specifically consented to longer retention
10. Your Rights Under UK GDPR
Under UK data protection law, you have the following rights regarding your personal information:
10.1 Right to Access (Subject Access Request)
You have the right to obtain confirmation that we are processing your data and to receive a copy of your personal information. We will respond within one month of your request.
10.2 Right to Rectification
You have the right to have inaccurate or incomplete personal information corrected. Please contact us if you believe any information we hold is incorrect.
10.3 Right to Erasure (“Right to be Forgotten”)
You can request deletion of your personal information in certain circumstances, such as:
- The data is no longer necessary for the purposes it was collected
- You withdraw consent (where consent was the legal basis)
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
Important limitations: We may not be able to delete your data if we need to retain it for:
- Legal or regulatory compliance (e.g., financial records for HMRC)
- Establishing, exercising, or defending legal claims
- Professional indemnity insurance requirements
- ICF and IHA ethical code compliance
10.4 Right to Restrict Processing
You can ask us to restrict processing of your data in certain situations, such as when you contest the accuracy of the data or when processing is unlawful.
10.5 Right to Data Portability
Where technically feasible, you have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another data controller.
10.6 Right to Object
You have the right to object to:
- Processing based on legitimate interests
- Direct marketing (including profiling)
- Processing for research or statistical purposes
10.7 Right to Withdraw Consent
Where we rely on your consent as the legal basis for processing, you can withdraw that consent at any time. This will not affect the lawfulness of processing before withdrawal.
10.8 Rights Related to Automated Decision-Making
We do not use automated decision-making or profiling that produces legal or similarly significant effects.
How to Exercise Your Rights
To exercise any of these rights, please contact us:
- Email: moc.noivapnitramobfsctd-1a5c1f@lagel
- Phone: +44 7537 131248
- Post: Guided Healing Limited, 5 Brayford Square, London, E1 0SG
We will respond to your request within one month. In complex cases, we may extend this by a further two months and will inform you of any delay.
11. Confidentiality and Professional Ethics
As a registered practitioner with the International Coaching Federation (ICF) and the International Hypnosis Association (IHA), we adhere to strict professional codes of ethics regarding confidentiality.
11.1 Confidentiality Commitment
All information you share during sessions is treated with the strictest confidence and will not be disclosed to third parties except as outlined below.
11.2 Exceptions to Confidentiality
We may be required or permitted to disclose your information without your consent in the following circumstances:
- Risk of harm: If we believe there is an imminent or likely risk of danger to yourself or others
- Safeguarding concerns: Suspected abuse, neglect, or violence toward a child or vulnerable adult
- Legal obligations: When required by law, valid court order, or subpoena
- Illegal activity: If required to report illegal activities to appropriate authorities
- Professional supervision: Anonymous case discussion with clinical supervisors (no identifying details shared)
- Insurance purposes: Where necessary to support a professional indemnity claim
Where possible, we will inform you before making such disclosures unless doing so would compromise safety or legal requirements.
11.3 Collaboration with Healthcare Providers
With your written consent, we may communicate with your GP, therapist, or other healthcare providers to ensure coordinated and safe care. We will never contact your healthcare providers without your explicit permission except in emergency situations.
12. Cookies and Website Tracking
12.1 What Are Cookies?
Cookies are small text files placed on your device when you visit our website. They help us provide you with a better experience and allow certain website features to function.
12.2 Types of Cookies We Use
Essential Cookies (No Consent Required)
- Session management and security
- Booking system functionality
- Form submission and validation
Analytics Cookies (Consent Required)
- Google Analytics: Tracks website traffic, user behaviour, and page performance
- Helps us understand how visitors use our site and identify areas for improvement
- Data is anonymised where possible
Marketing Cookies (Consent Required)
- Facebook Pixel: Tracks conversions and enables targeted advertising
- LinkedIn Insight Tag: Measures campaign performance
- Instagram Pixel: Tracks engagement with social media content
12.3 Managing Cookie Preferences
You can control cookie settings through:
- Our cookie consent banner when you first visit the website
- Your browser settings (most browsers allow you to block or delete cookies)
- Opt-out tools provided by Google Analytics and social media platforms
Note: Disabling certain cookies may affect website functionality.
12.4 Google Analytics Opt-Out
You can opt out of Google Analytics tracking by installing the Google Analytics Opt-out Browser Add-on.
13. Special Category Data (Health Information)
The nature of our services means we process “special category data” as defined by UK GDPR, particularly health and wellbeing information.
13.1 Explicit Consent
We obtain your explicit consent before processing any health-related information. This consent is requested through:
- Our health questionnaire and waiver form (via Crove)
- Session recording consent forms
- Verbal confirmation at the beginning of our professional relationship
13.2 Purpose Limitation
Health information is used solely for:
- Determining your suitability for our services
- Delivering safe and effective hypnotherapy, coaching, and spiritual hypnosis sessions
- Identifying any contraindications or need for medical referral
- Maintaining appropriate session notes for continuity of care
- Complying with professional ethics and insurance requirements
13.3 Enhanced Security
Health information receives additional security protections:
- Encrypted storage in password-protected systems
- Access restricted to Martin Pavion only
- Separate storage from general marketing or website data
- Regular security audits and reviews
14. Children’s Privacy
Our services are designed for adults aged 18 and over. We do not knowingly collect personal information from children under 18 without parental or guardian consent.
If we work with a minor (under 18):
- We require written consent from a parent or legal guardian before collecting any information
- All communications and session arrangements are made with the parent/guardian
- Enhanced safeguarding protocols apply
- The parent/guardian has full access to the child’s records
If you believe we have inadvertently collected information from a child without proper consent, please contact us immediately at moc.noivapnitramobfsctd-4f62d4@lagel.
15. Marketing Communications
15.1 How We Market to You
With your consent, we may send you marketing communications including:
- Newsletters with educational content and wellbeing tips
- Information about new services or programmes
- Invitations to workshops, webinars, or events
- Blog posts and articles relevant to your interests
- Special offers or promotions
15.2 Consent and Opt-In
We will only send marketing communications if you have:
- Explicitly opted in via our website forms or during booking
- Signed up for our newsletter or membership
- Provided consent through a checkbox or similar mechanism
We never add people to marketing lists without consent or purchase email lists from third parties.
15.3 Unsubscribing
You can opt out of marketing communications at any time by:
- Clicking the “unsubscribe” link at the bottom of any marketing email
- Emailing moc.noivapnitramobfsctd-91748a@lagel with “Unsubscribe” in the subject line
- Updating your preferences in your WordPress member account
We will process your unsubscribe request within 2 working days. You will continue to receive essential service-related communications (booking confirmations, session reminders, etc.) even after unsubscribing from marketing.
15.4 Marketing Platform
Our marketing emails are sent via Mautic, a self-hosted platform on our secure UK servers. This means your marketing data is not shared with external email service providers.
16. Data Breach Notification
In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will:
- Notify the Information Commissioner’s Office (ICO) within 72 hours of becoming aware of the breach
- Inform you directly without undue delay if the breach is likely to result in a high risk to your rights
- Provide details about the nature of the breach, potential consequences, and measures taken
- Offer advice on steps you can take to protect yourself
We maintain comprehensive incident response procedures and regularly test our breach notification processes.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in:
- Our data processing practices
- Legal or regulatory requirements
- Technology and service providers
- Business operations
When we make significant changes, we will:
- Update the “Last Updated” date at the top of this policy
- Notify existing clients via email where appropriate
- Display a prominent notice on our website
- Request new consent if required by law
We encourage you to review this Privacy Policy periodically. Your continued use of our services after changes are posted constitutes acceptance of the updated policy.
18. Contact and Complaints
18.1 Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Data Protection Contact:
Email: moc.noivapnitramobfsctd-7a5afa@lagel
Phone: +44 7537 131248
Post: Guided Healing Limited, 5 Brayford Square, London, E1 0SG
We aim to respond to all enquiries within 5 working days.
18.2 Making a Complaint
If you are unhappy with how we have handled your personal information, you have the right to lodge a complaint with the supervisory authority:
Information Commissioner’s Office (ICO)
Website: https://ico.org.uk
Telephone: 0303 123 1113
Address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We would appreciate the opportunity to address your concerns before you contact the ICO, so please contact us first at moc.noivapnitramobfsctd-fc203@lagel.
19. Professional Standards and Oversight
Our data protection practices are informed by and comply with the ethical standards of:
- International Coaching Federation (ICF): ICF Code of Ethics 2025
- International Hypnosis Association (IHA): IHA Code of Ethics
These professional codes require us to maintain the highest standards of confidentiality and data protection, often exceeding legal minimum requirements.
If you have concerns about professional ethics or standards of practice, you may also contact:
Acknowledgment: By using our services, booking sessions, or providing your personal information, you acknowledge that you have read, understood, and agree to this Privacy Policy and our data processing practices as described herein.
This Privacy Policy was drafted to comply with UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR), and relevant professional ethical codes.