The One Session Guarantee
I will solve your problem in one session or I will continue working with you for free until you do.
Before your session, we agree in writing the one problem you want gone and how you'll know it has. After the session, you rate it. If it's 3 out of 10 or lower and it no longer limits you, it's solved. If it isn't, I keep working with you at no extra charge until it is, with no time limit, as long as you come to the sessions, do the seven-day aftercare practice and tell me honestly how you're getting on.
It doesn't cover results that depend on other people, such as a promotion, a pay rise or a specific income. It doesn't cover problems we haven't agreed in writing. It doesn't cover medical or clinical conditions, which I'll refer to your GP or a licensed professional.
I only take clients on after a strategy call where I'm confident I can help. If I'm not, I'll tell you, point you somewhere better, and you won't pay.
None of this affects your legal rights as a consumer.
Privacy Policy
Last updated: October 2026
1. Who I Am
The data controller is Rachel Ghinn, a sole-practitioner therapist based in England, registered with the Information Commissioner's Office (registration number ZC103484). If you have any questions about this policy or how your personal data is handled, please contact me:
Rachel Ghinn | rachelghinn.com | rachel@rachelghinn.com | 07463 877298
2. What Personal Information I Collect
I only collect the personal information I need to provide you with The Reset. This may include:
• Your name and contact details (telephone number and/or email address)
• Relevant health information and medical history that you share with me
• Session notes, which I type during sessions
• Recordings of our Zoom sessions (see section 8)
• Your communication with me, such as emails or messages
• If you use my website or contact me through it, basic information such as your name, email address and message (see section 13)
I do not collect your home address, as it is not needed for the work we do together.
3. How I Collect Your Information
I collect personal information directly from you, through our strategy call, my intake questions, and our sessions on Zoom. You book your strategy call and sessions through Cal.com, which collects your name, email address and booking details. You pay by card through Stripe or by bank transfer (BACS). Stripe handles your card details and I never see or store them. If you pay by bank transfer, I see only the payment details your bank shows me, and I don't store your bank details.
4. My Lawful Basis for Processing Your Data
I process your personal data under the UK GDPR. The lawful bases I rely on are:
Legitimate interests (Article 6(1)(f)). For most general practice data, such as session notes, contact details and managing our working relationship. I have assessed that the purpose is genuine (to provide an effective, safe service and meet my professional responsibilities), that processing is necessary, and that the impact on your privacy is minimal because I collect no more than I need and apply appropriate security.
Recognised legitimate interests (Data (Use and Access) Act 2025). In limited circumstances such as preventing or detecting crime, safeguarding or public safety, no balancing test is required. For example, if I'm asked to share information with the police or another statutory body for public safety reasons, the requesting organisation takes responsibility for the necessity of that disclosure.
Legal obligation (Article 6(1)(c)). Where I must process your data to comply with the law, for example in response to a court order.
Vital interests (Article 6(1)(d)). If there is a risk to life, yours or someone else's, I may need to share information to protect it.
5. Special Category Data
Health information is 'special category data' under the UK GDPR and gets extra protection. I process the health information you share with me under Article 9(2)(h), for the provision of health care, and in line with my professional obligations as a therapist. I record our sessions with your explicit permission (Article 9(2)(a)), which you give in your Client Agreement and which you can withdraw at any time.
6. How I Use Your Information
I use your personal information to:
• Provide The Reset, online on Zoom
• Keep notes and recordings to support your work with me, and for my own review and training
• Contact you about appointments and follow-up
• Meet my professional and legal obligations
7. Who I Share Your Information With
I treat your information as strictly confidential. I do not share your personal data with anyone except:
• Where I am legally required to, for example by court order
• Where there is a serious risk to your safety or the safety of others (recognised legitimate interests may apply, see section 4)
• With my clinical supervisor, on a confidential and anonymised basis wherever possible, as my professional code of practice requires
• With the services I use to run my practice, which process your data on my behalf: Cal.com (bookings), Stripe (card payments), Zoom (sessions) and Wix (my website)
I do not sell, rent or share your personal data for marketing purposes.
8. Online Sessions and Recordings (Zoom)
Sessions take place on Zoom, a third-party platform with its own privacy policy that you can read at zoom.us/privacy. By using Zoom, your connection data is processed by Zoom under its own terms. Please use a private and secure internet connection.
I record every session, with your permission, for internal review and training. You can ask for a copy of your recording at any time. I never share recordings outside my practice. Recordings are stored securely and deleted after 12 months, or sooner if you ask. If you do not want to be recorded, please tell me before you book.
9. How Long I Keep Your Information
I keep your personal information only as long as necessary. In line with professional guidance:
• Client records are kept for 7 years after your final session, or until a minor reaches the age of 25
• Session recordings are kept for 12 months
• After these periods, records are securely destroyed
You can ask for early deletion in certain circumstances (see section 10).
10. Your Rights
Under the UK GDPR you have the right to:
• Access: ask for a copy of the personal information I hold about you (a Subject Access Request, or SAR)
• Rectification: ask me to correct inaccurate information
• Erasure: in certain circumstances, ask me to delete your data
• Restriction: ask me to limit how I use your data
• Object: object to processing based on legitimate interests
• Portability: in some cases, ask for your data in a portable format
To use any of these rights, contact me using the details in section 1. I will respond within one calendar month.
Subject Access Requests. If you make a SAR, I will carry out reasonable and proportionate searches of the records I hold. Under the Data (Use and Access) Act 2025, I'm not required to search every document or communication if it is unlikely to contain relevant data or would be disproportionately difficult. I may ask you for clarification, in which case the deadline is paused until you reply.
11. Data Protection Complaints
If you have a concern about how I've used your personal information, please contact me first so I can try to put it right. You can use the electronic complaints form at https://forms.gle/XogWq2w3h4TKoPgL8 or email rachel@rachelghinn.com.
I will acknowledge your complaint within 30 days, keep you informed of progress, and tell you the outcome without undue delay.
If you're not satisfied with my response, you can complain to the Information Commissioner's Office (ICO): ico.org.uk, helpline 0303 123 1113.
This procedure is about how your personal data is handled. For complaints about the nature of therapy or my professional practice, you can contact my professional register directly and anonymously.
12. Data Security
I take the security of your information seriously. This includes:
• Written notes are stored securely and are not accessible to anyone else
• Electronic records, including emails and recordings, are stored on password-protected devices
• I avoid sending sensitive personal information by unencrypted email where I can
• I review my security practices regularly
13. My Website
rachelghinn.com is built on Wix, which processes visitor data on my behalf and uses cookies to make the site work. If you contact me through the website, I use your details only to reply to you. You can read Wix's privacy policy at wix.com/about/privacy.
14. Changes to This Policy
I may update this policy from time to time. The latest version is always on my website. If changes are significant, I'll tell existing clients directly.
Rachel Ghinn | rachelghinn.com | rachel@rachelghinn.com | Registered in England | ICO Registration No. ZC103484