Privacy Policy

How we look after
your information.

Last updated: 5 May 2026

1. Who We Are

Our website address is: https://londonfeedingtherapy.com

London Feeding Therapy Ltd is a specialist paediatric feeding therapy practice providing services in person and via telehealth to clients in the UK and internationally. We are committed to protecting your privacy and handling your personal data in accordance with UK data protection laws.

Data Controller: London Feeding Therapy Ltd
Data Protection Contact: Katie Philcox, Director
Contact Email: [email protected]
Registered Address: 167–169 Great Portland Street, London, W1W 5PF
Company Registration Number: 16962681
ICO Registration Number: [ICO registration number to follow]

2. Legal Basis for Processing

We process personal data under the following lawful bases as defined by UK GDPR:

  • Contract Performance: To provide feeding therapy services you have requested
  • Consent: Where you have given explicit consent for processing health data
  • Legitimate Interests: For administrative purposes, improving our services, and business operations
  • Legal Obligation: To comply with professional, legal, and regulatory requirements

3. What Personal Data We Collect and Why

3.1 Contact Form and Initial Enquiries

When you submit an enquiry through our online contact form, we collect:

  • Your name
  • Email address
  • Telephone number
  • Any information you provide in your message

Purpose: To respond to your enquiry and assess whether our services are appropriate for your needs.

3.2 Client Information

If you become a client, we collect and process:

  • Full name, date of birth, address
  • Contact details (phone, email)
  • Emergency contact information
  • Any healthcare professional details you choose to share with us for the purpose of approved collaboration
  • Details about parents/carers/guardians
  • Medical history relevant to feeding therapy
  • Dietary information and feeding concerns
  • Assessment results and therapy progress notes
  • Video/audio recordings of therapy sessions (only with explicit consent)
  • Payment and billing information

Purpose: To provide appropriate, safe, and effective feeding therapy services, maintain accurate clinical records, communicate with you and other professionals involved in care (with consent), and fulfill our professional obligations.

3.3 Special Category Data (Health Data)

Feeding therapy involves processing special category personal data including health information. We process this data based on:

  • Your explicit consent
  • The provision of health or social care treatment
  • Compliance with legal obligations under UK law

3.4 Website Usage Data

Contact Form When you use the contact form on our website, we collect the information you provide (such as your name and email address) in order to respond to your enquiry. This data is not used for marketing purposes without your separate consent.

Cookies Our website uses essential cookies to ensure basic functionality. These cookies do not collect personal data and are discarded when you close your browser.

Embedded Content from Other Websites Pages on this site may include embedded content (e.g., videos or images). Embedded content from other websites behaves in the same way as if you had visited those websites directly. These websites may collect data about you, use cookies, and monitor your interaction with that content.

Analytics We use website analytics tools to understand how visitors use our website. This helps us improve our services and user experience. Analytics data is anonymised where possible.

4. How We Collect Information

We collect information through:

  • Online contact forms on our website
  • Email, telephone, and video consultations
  • Information you provide verbally during therapy sessions
  • Information from other professionals (with your consent) such as GPs, other therapists, teachers, or medical consultants
  • Observation and assessment during therapy sessions

5. Who We Share Your Data With

We respect your privacy and will only share your information when necessary and appropriate:

With Your Consent:

  • Other healthcare professionals involved in your/your child’s care (GPs, paediatricians, speech therapists, occupational therapists, dietitians)
  • Educational settings (schools, nurseries) where relevant to therapy goals
  • Family members or carers as appropriate for therapy delivery

Without Consent (Legal Obligations):

  • If we have serious concerns about the safety or wellbeing of a child or vulnerable adult (safeguarding)
  • When required by law or court order
  • To our professional regulatory body (Health and Care Professions Council – HCPC) if required
  • Our professional indemnity insurers in case of a complaint or legal claim

Service Providers (Data Processors): We use trusted third-party service providers who process data on our behalf:

  • Telehealth Platform: Google Meet
  • Email Services: Google Workspace
  • Website Hosting: Boost Metrica EURL, 16 rue Cuvier, 69006 Lyon, France (SIREN 979 407 277)
  • Cloud Storage: Google Drive

All service providers are carefully selected, GDPR-compliant, and bound by Data Processing Agreements to protect your information.

Important Note on Telehealth Security:
We use secure, encrypted platforms for telehealth sessions. However, no online platform can guarantee 100% security. You will be informed of any risks before beginning telehealth services, and we will obtain your informed consent regarding the use of online therapy and associated risks.

6. International Data Transfers

If you are located outside the UK, or if we use service providers located outside the UK/EEA, your data may be transferred internationally. We ensure adequate safeguards are in place, including:

  • Standard Contractual Clauses approved by the UK Information Commissioner’s Office
  • Adequacy decisions recognising equivalent data protection standards
  • Your explicit consent where required

For International Clients:
If you are receiving services while located outside the UK, please be aware:

  • Your data will be processed in accordance with UK GDPR
  • Different data protection laws may apply in your country of residence
  • You should ensure you have appropriate local support arrangements in case of emergency
  • Our professional indemnity insurance covers international telehealth provision

7. How Long We Retain Your Data

Enquiry data: Retained for up to 12 months if you do not proceed to therapy, then securely deleted.

Client records: Retained for 7 years from the date of last contact, in line with health sector norms, ICO guidance, and BACB Ethics Code 2.05, then securely destroyed.

Financial records: Retained for 7 years as required by HMRC.

Data is retained to meet regulatory obligations, respond to potential complaints or legal claims, and support continuity of care. After the retention period, all personal data is securely destroyed.

8. Your Rights Under UK GDPR

You have the following rights regarding your personal data:

Right of Access: Request a copy of the personal data we hold about you (Subject Access Request)

Right to Rectification: Request correction of inaccurate or incomplete data

Right to Erasure: Request deletion of your data (exceptions apply for legal and clinical obligations)

Right to Restrict Processing: Request that we limit how we use your data

Right to Data Portability: Receive your data in a structured, commonly used format

Right to Object: Object to processing based on legitimate interests

Right to Withdraw Consent: Withdraw consent for processing at any time (does not affect processing already completed)

Rights Related to Automated Decision-Making: We do not use automated decision-making or profiling in our services

How to Exercise Your Rights:
To exercise any of these rights, please contact us at [email protected]. We will respond within one month. We may need to verify your identity before processing your request.

Please note that some rights may be limited by legal or professional obligations. For example, we cannot delete clinical records during the required retention period.

9. How We Protect Your Data

We implement appropriate technical and organizational security measures:

  • Encrypted storage of electronic records
  • Password-protected systems with role-based access controls
  • Secure, GDPR-compliant telehealth platforms with end-to-end encryption
  • Secure cloud storage with UK-based servers where possible
  • Regular security reviews and updates
  • Confidentiality obligations and data protection training
  • Physical security measures for any paper records
  • Secure disposal of data (shredding, secure digital deletion)
  • Regular backups stored securely
  • Anti-virus and anti-malware protection
  • Strong password policies

10. Data Breach Procedures

In the unlikely event of a data breach:

  1. We will investigate and contain the breach immediately
  2. We will notify the Information Commissioner’s Office (ICO) within 72 hours if required by law
  3. We will notify affected individuals without undue delay if there is a high risk to their rights and freedoms
  4. We will document the breach, our response, and any lessons learned
  5. We will take steps to prevent future breaches

If you believe there has been a breach involving your data, please contact us immediately at [email protected]

11. Recording of Therapy Sessions

We do not routinely record therapy sessions. If recording is deemed beneficial for clinical, supervision, or training purposes:

  • We will obtain explicit written consent before any recording
  • You will be informed of the purpose and how the recording will be used
  • You will be informed of who will have access to the recording
  • Recordings are stored securely, encrypted, and password-protected
  • Recordings are retained only for as long as necessary for their stated purpose
  • You have the right to refuse recording without affecting your therapy
  • You may request to view or receive a copy of recordings (subject to clinical considerations)
  • You may request deletion of recordings (subject to clinical record-keeping requirements)

Client-Initiated Recording:
We do not permit clients to record therapy sessions without prior discussion and written consent from the therapist. Unauthorised recording may result in termination of services.

12. Children’s Privacy

Where we provide services to children, we:

  • Obtain consent from a parent or legal guardian for children under 13
  • For children aged 13-15, we seek both parental consent and the child’s assent where appropriate
  • For young people aged 16-17, we assess competence (Gillick competence) to determine if they can consent independently
  • Only collect information necessary for providing therapy services
  • Share information with parents/guardians as appropriate for the child’s age, maturity, and circumstances
  • Follow safeguarding procedures to protect children’s welfare
  • May need to share information without consent if there are safeguarding concerns

13. Confidentiality and When It May Be Overridden

We maintain strict confidentiality in accordance with professional standards. However, confidentiality may need to be overridden in the following circumstances:

  • Safeguarding concerns: If we believe a child or vulnerable adult is at risk of significant harm
  • Risk to self or others: If there is serious risk of harm to you or another person
  • Legal requirements: Court orders, police investigations with appropriate authority
  • Professional regulatory requirements: If required by the BCBA/IABO or other regulatory bodies

Where possible, we will discuss concerns with you before sharing information, unless doing so would increase risk.

14. Third-Party Websites

Our website may contain links to external websites. We are not responsible for the privacy practices or content of these third-party sites. Please review their privacy policies before providing any personal information.

15. Professional and Regulatory Requirements

As a certified behaviour analyst and feeding therapy specialist, we are bound by:

  • Behavior Analyst Certification Board (BACB) Ethics Code for Behavior Analysts (2022)
  • International Behavior Analysis Organization (IBAO) Ethical Guidelines (2021)
  • Professional duty of confidentiality
  • UK data protection legislation (UK GDPR and Data Protection Act 2018)
  • Safeguarding regulations for children and vulnerable adults
  • Professional indemnity insurance requirements

16. Complaints and Concerns

About Our Services:
If you have concerns about our feeding therapy services, please contact us at [email protected].

About Data Protection:
If you have concerns about how we handle your personal data:

  1. Contact us first: [email protected] – We will investigate and try to resolve the issue within 30 days
  2. Contact the ICO: If unsatisfied with our response, you can lodge a complaint with the Information Commissioner’s Office:

17. Changes to This Privacy Policy

We may update this privacy policy periodically to reflect changes in our practices, legal requirements, or services. We will post any changes on this page with an updated “Last Updated” date.

For significant changes that affect how we use your data, we will:

  • Notify active clients directly by email
  • Seek renewed consent where required
  • Provide reasonable notice before changes take effect

We encourage you to review this policy periodically.

18. Consent

By using our services, you acknowledge that you have read and understood this privacy policy. For therapy services, we will ask you to provide explicit written consent for the processing of your health data through our consent forms.

You can withdraw your consent at any time by contacting us, though this may affect our ability to continue providing services.

19. Contact Us

For questions about this privacy policy, to exercise your data protection rights, or for any data protection concerns:

Email: [email protected]
Website: https://londonfeedingtherapy.com

We aim to respond to all queries within 5 working days.


This privacy policy was last updated on 5 May 2026 and complies with UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003.