Legal

Privacy Policy

Last updated: 26 July 2026  ·  Effective date: 26 July 2026

This Privacy Policy explains how your personal information is collected, used, stored, and shared when you receive occupational therapy coaching or attend experiential group workshops (online or in person) from BodyMindOT, and when you use this website. It sets out your rights under UK data protection law and is written in accordance with the UK GDPR and the Data Protection Act 2018. It should be read alongside the BodyMindOT Practice Policy and Cookie Policy.

1. Who We Are & Practice Details

BodyMindOT is an independent occupational therapy practice, the trading name of Phoebe Hsieh (Wei-Yun Hsieh), an HCPC-registered Occupational Therapist. Services are provided in accordance with Health and Care Professions Council (HCPC) standards, the Royal College of Occupational Therapists (RCOT) Code of Ethics, and UK data protection law.

For the purposes of data protection law, BodyMindOT is the Data Controller of your personal information — responsible for deciding how and why your data is processed, stored, and protected.

Practice name: BodyMindOT
Lead Therapist & Data Controller: Phoebe Hsieh (Wei-Yun Hsieh) — HCPC Registration OT80369
ICO Registration: ZC198892
Email: phoebehsieh@bodymindot.com

Target client group: Our services are provided strictly to adults aged 18 or over. We do not knowingly process the personal data of anyone under the age of 18.

Services offered: (1) one-to-one online occupational therapy coaching supporting everyday mental wellbeing and daily functioning; and (2) experiential group workshops (online or in person) exploring creativity, movement, and wellbeing in everyday life.


2. Information We Collect

To provide safe, effective, and professional care, and to run this website, we collect and process the following categories of personal data:

We do not ask you to submit health information through the website — any such information is provided entirely at your discretion.


3. How We Collect Your Data


4. Lawful Basis for Processing

Under UK data protection law, we rely on the following lawful bases:

For special category (health) data, we rely on Article 9(2)(h) of the UK GDPR (provision of health and social care, managed by a registered healthcare professional bound by professional secrecy), and on explicit consent (Article 9(2)(a)) where applicable.


5. How We Use Your Data

We will never sell your personal data, or share it with third parties for their own marketing purposes.


6. Storage, Security & Systems

All client records and communications are stored securely using Google Workspace Business. Access is strictly controlled, password-protected, and secured with two-step verification (2FA) and encryption in transit and at rest. Google acts as our data processor under Google's Cloud Data Processing Addendum.

For clients temporarily joining sessions from outside the UK, the service remains governed by the laws and exclusive jurisdiction of the courts of England and Wales. During temporary travel overseas, we continue to apply the same security standards — sessions conducted from private, confidential spaces, on secured devices, over trusted networks — and data remains stored strictly in secure, UK-managed electronic systems.


7. Virtual Sessions & Workshop Security

Online consultations are delivered using Google Meet over secure, encrypted video calling. To ensure the safe delivery of virtual healthcare, we confirm your full identity, your physical location, and your emergency contact information at or before your first session. We do not record video sessions under any circumstances, and clients must not record sessions by any means, to protect the confidentiality and privacy of both parties. Written summaries of agreed actions may be provided on request.

Workshops are group settings. We ask all participants to treat what others share as confidential and not to repeat it outside the group. However, in a group setting we cannot guarantee that every participant will do so, and so you should share only personal health information that you would be comfortable others in the group hearing.


8. Sharing Your Information

Your clinical and personal information is treated with strict confidentiality. It will only be shared under the following conditions:

We also use trusted processors to run the practice and website — our email, records and enquiry form provider (Google Workspace, including Google Forms), our website hosting provider, and Google Meet for consultations — all of whom are required to handle your data securely and in accordance with UK data protection law.

Continuity access: in the event of the practitioner’s incapacity or death, a nominated person (the practitioner’s next of kin) may access records solely to manage continuity — notifying clients, arranging refunds, and securing or transferring records — acting under the same duties of confidentiality and data protection.


9. Photography, Recordings & Testimonials (workshops)

At experiential workshops, BodyMindOT may take photographs, video, or audio, and may use participant testimonials, to record its work and promote future workshops. This is always optional and is never a condition of taking part.

You choose, on the Workshop Registration & Consent Form, exactly what you agree to — for example, being photographed or recorded, use of your image on the website, social media, or in marketing, and written or video testimonials — and how you are identified. We rely on your consent (UK GDPR Article 6(1)(a)); where an image or testimonial reveals health or wellbeing information, we rely on your explicit consent (Article 9(2)(a)).

You may withdraw your consent at any time by emailing phoebehsieh@bodymindot.com. We will stop using the material as soon as practicable, although items already printed or already shared publicly may not always be fully recoverable. Images, recordings, and testimonials are kept only while your consent stands, and no longer than the period stated on the Workshop Registration & Consent Form, after which they are securely deleted.


10. International Data Transfers

Where your data is transferred outside the UK (for example, by a third-party service provider), we ensure that appropriate safeguards are in place — such as UK adequacy regulations or Standard Contractual Clauses — to protect your data to an equivalent standard.


11. Data Retention

We implement a careful, legally compliant retention schedule:

Secure destruction: once the retention period has elapsed, all electronic files on primary systems, emails, and secure backups are permanently and securely deleted. Any temporary paper notes are transferred to electronic records and immediately destroyed.


12. Cookies

This website uses essential, functional browser storage only (to remember your language preference and that you have seen our cookie notice). We do not use advertising or cross-site tracking. Full details are in our separate Cookie Policy.


13. Your Rights Under UK GDPR

You hold the following rights regarding your personal data:


14. How to Complain

If you have any concerns about how your data is handled, please contact us in the first instance so we can resolve the matter. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection:

Website: ico.org.uk  ·  Helpline: 0303 123 1113


15. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page will reflect any changes.


16. Contact

For any questions about this Privacy Policy, your personal data, or to submit a Subject Access Request, please contact:

Phoebe Hsieh (Wei-Yun Hsieh)
Lead Therapist & Data Controller, BodyMindOT
phoebehsieh@bodymindot.com