Privacy Policy
Last updated: 16/07/2026
1. Data Controller
This website is operated by:
Name: Barbara Zironi
Website:
www.barbarazironi.com Email: hello@barbarazironi.com
Location: United Kingdom
For the purposes of UK data protection law (UK GDPR) and the Data Protection Act 2018, the Data Controller is Barbara Zironi.
2. Overview
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected when you use this website or engage our services. It also explains your rights under UK GDPR.
When you provide your personal details, they are processed and stored for these reasons:
Therapy Delivery: We collect personal information, background history, psychological health, and lifestyle details to provide you with the best possible therapy treatment. Requesting sessions and our agreement to provide them constitutes a contract.
Legitimate Interest (Safety & Effectiveness): We have a "legitimate interest" in collecting this information, as we cannot deliver therapy safely or effectively without it. You can refuse to provide this information; however, doing so means we will be unable to provide therapy treatment.
Legitimate Interest (Communication): It is necessary to contact you to confirm appointments, share therapeutic materials, or discuss any matter connected to your therapy.
We collect data when you complete contact forms, send emails, call us, or fill out electronic/paper intake forms during your consultation (including your name, address, age, gender, contact details, and relevant medical/background history).
3. Personal Data We Collect
We may collect and process the following categories of personal data:
3.1 Information you provide
Name
Email address
Postal address (where relevant)
Telephone number
Age and gender (where relevant)
Booking and appointment details
Messages sent via website forms or email
Intake or consultation information
3.2 Sensitive (Special Category) Data
Where necessary for hypnotherapy or coaching services, you may provide sensitive information such as:
Physical or mental health information
Fertility or reproductive information
Medical history relevant to services
Lifestyle or personal circumstances
This data is processed only when necessary to provide services and with your explicit consent.
3.3 Technical & Interaction Data
IP address
Browser, device, and operating system information
Website usage, interaction, and performance data
Cookie consent records (managed via Complianz Cookie Consent)
4. How We Use Your Data
Personal data is used to:
Respond to enquiries and manage bookings
Deliver professional hypnotherapy and coaching services
Maintain accurate client records
Communicate about scheduled sessions
Improve website performance and secure its operation
Meet legal, regulatory, or professional obligations
5. Lawful Bases for Processing
We process personal data under the following lawful bases:
Contract: To take steps at your request prior to entering into a contract, or to perform the contract (providing therapy/coaching).
Legitimate Interests: For administrative communication, service management, and website security.
Consent / Explicit Consent: For processing sensitive (special category) health data, or where cookies/marketing consent is required.
Legal Obligation: To comply with professional standards, insurance requirements, or law enforcement.
6. Data Storage and Security
We take security seriously and implement robust technical measures to protect your data.
6.1 Electronic records
Website Security & Encryption: Our website uses an SSL/HTTPS certificate to encrypt data transmitted through our online forms. Website security, login protection, and system hardening are actively managed and monitored via Really Simple Security.
Cloud Storage: Electronic files and client records are stored securely with our third-party provider, Google Workspace. Access is strictly limited to the Data Controller via password-protected, regularly updated accounts using multi-factor authentication.
Email & Delivery Security: Website form submissions and transactional emails are routed securely using WP Mail SMTP to prevent data interception and ensure reliable delivery.
6.2 Paper records
Handwritten client therapy notes are securely stored in a locked, fireproof filing cabinet. Only the Data Controller has access to this information. They are destroyed by professional shredding once the legal minimum retention period has elapsed.
7. Data Retention
Client records are retained for a period of 8 years after your final session (unless professional insurance, legal, or regulatory obligations require a longer retention period). After this time, electronic data is permanently deleted, and paper records are shredded.
8. Third-Party Service Providers & International Transfers
We use trusted third-party service providers (Data Processors) to operate our website and services:
Spacemail: Professional email hosting.
WP Mail SMTP: Secure routing and delivery of emails sent via website contact forms.
Google Workspace & Google Calendar: Secure cloud storage of client documentation and appointment scheduling.
Complianz: Management of cookie consents, legal policies, and user privacy preferences.
PayPal: Safe transaction and payment processing.
Hosting Provider: Host of our website database and files (optimized via LiteSpeed Cache for performance).
These providers process data strictly on our instructions. Where data is transferred outside the United Kingdom (e.g., to US-based cloud systems like Google), we ensure appropriate safeguards (such as Standard Contractual Clauses or adequacy decisions) are in place to guarantee an equivalent level of protection under the UK GDPR.
9. Payments
Payments may be processed via PayPal, which complies with UK GDPR and PCI-DSS security standards. We do not store or see your payment card or financial details on our website. You can review PayPal's full privacy practices here:
10. Data Sharing
Personal data is never sold, leased, or shared for marketing purposes. Data is only shared:
With your explicit consent.
To coordinate requested services.
To comply with legal, professional, or regulatory obligations.
To protect vital interests (e.g., in a medical or safeguarding emergency).
11. Your Rights
Under the UK GDPR, you have the following rights:
Access: Request a copy of the personal data we hold about you.
Rectification: Request correction of inaccurate or incomplete data.
Erasure: Request deletion of your data (subject to our 8-year legal and professional record-keeping retention requirements).
Restriction: Request that we restrict the processing of your data.
Objection: Object to processing based on legitimate interests.
Withdraw Consent: Withdraw your consent at any time for sensitive data processing (which may result in us being unable to continue your therapy).
To exercise any of these rights, please contact us at: hello@barbarazironi.com
You also have the right to lodge a complaint with the UK supervisory authority: Information Commissioner’s Office (ICO) Website:
12. Cookies
We use cookies to ensure essential site functions, analyze traffic, and improve user experience.
Consent Management: We use Complianz | GDPR/CCPA Cookie Consent to display a conditional cookie banner, allowing you to accept or decline non-essential cookies. No non-essential tracking cookies will load until you have actively provided consent.
You can change your cookie preferences or withdraw consent at any time directly through the cookie settings panel on our website.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, website plugins, or legal obligations. The "Last Updated" date at the top of this page will reflect when changes were last made.
14. Contact
For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact:
Barbara Zironi
Email: hello@barbarazironi.com