Beyond Grief

Privacy Policy

How I look after the information you share with me.

Last updated 23 August 2026

1. About this policy

I know a privacy policy is not the reason you came here. But if you are going to tell me something as personal as who you have lost, you deserve to know exactly what happens to that information.

This policy explains what personal information I collect, why I collect it, who else can see it, how long I keep it and what rights you have. It applies to my website, my mailing list, enquiries, discovery calls and the coaching itself.

If anything here is unclear, please just ask.

2. Who I am

Beyond Grief is a grief coaching practice run by Lisa Galbraith, operating as a sole trader.

I am the data controller for the information described in this policy, which means I decide what is collected and what happens to it.

  • Email: [email protected]
  • Website: www.beyondgrief.co.uk
  • Postal address: available on request, just email me and I will send it to you

There is no legal requirement for me to appoint a Data Protection Officer, so questions about your information come straight to me.

3. The information I collect

When you enquire or book a call. Your name, email address, phone number if you give it, and whatever you choose to tell me in an enquiry form, an email, a direct message or a booking form. That usually includes something about your loss and what you are looking for help with.

When we work together. Notes from our sessions covering what you are going through, what we discussed, what we agreed to work on and how things are progressing. This will include information about your health, including your emotional and mental wellbeing, and it may include information about your beliefs, your family and your circumstances. It will almost always include information about the person or pet you have lost.

Recordings. Where you agree to it, a recording or transcript of a session so that you or I can look back at it. You can say no to this and it makes no difference to the support you get. You can change your mind at any point.

Payments. Your name, billing details, what you paid, when and for what. Card details are handled by Stripe, my payment provider, not by me. I never see or store your full card number.

If you join my mailing list. Your name and email address, when you signed up, and whether you open or click the emails I send.

When you use my website. Technical information such as your IP address, browser type, the pages you look at and how you arrived. Some of this comes from cookies, which are covered in section 10.

Testimonials. If you offer to share your experience, your words and whatever name you are happy to be shown by. Only ever with your permission, taken separately and in writing. Please know that anything published on my website or social media can be seen worldwide and cannot be completely recalled once it is out there, although I will always remove it from my own channels if you ask.

What you have to give me. Your name, your contact details and enough about what you are dealing with are needed for our coaching agreement, because without them I cannot safely take you on as a client. Everything else, including session recordings and joining my mailing list, is entirely your choice.

4. Information about other people

Grief coaching means you will often talk about people other than yourself. Your partner, your parent, your child, your friend, the person you are caring for. Those details become part of your record.

That information reaches me from you rather than from them. I do not contact anyone you mention, and in almost every case telling them directly would be impossible, would take disproportionate effort, or would break your confidence, so I rely on the exemption in Article 14(5)(b) of the UK GDPR. I record only what is relevant to supporting you, and I keep it under the same terms as your own information.

Information about someone who has died is not “personal data” under UK data protection law. I treat it with the same care anyway, both because of what it means to you and because it can identify living relatives.

5. Why I use your information, and my lawful basis

Under UK data protection law I need a lawful basis for using your information. Mine are set out below.

What I use it for Lawful basis
Responding to your enquiry and holding a discovery call Taking steps at your request before entering a contract, and my legitimate interest in replying to people who contact me and keeping my practice running safely
Delivering your coaching sessions and keeping session notes Performance of our contract
Health and other sensitive details within those notes Your explicit consent (see below)
Recording sessions Your consent
Taking payment and keeping business accounts Performance of our contract, and my legal obligations under tax law
Sending marketing emails and newsletters Your consent
Publishing a testimonial Your consent, and your explicit consent for anything sensitive within it
Website cookies that are not strictly necessary Your consent, except where the law says otherwise (see section 10)
Keeping records to defend a complaint, a claim or an insurance matter My legitimate interests, and the establishment or defence of legal claims
Passing on information where someone is at serious risk See section 6

You can ask me for the assessment behind any of the legitimate interests above and I will send it to you.

Sensitive information, explained plainly

Information about your health, including your mental and emotional health, is treated as “special category” data and gets extra protection. So does information about your beliefs, your ethnicity, your sex life or your sexual orientation, if any of that comes up in our work.

I rely on your explicit consent to record and use that information. I ask for that consent separately from my terms and conditions, in a form you sign or confirm in writing, and it is never a condition of working with me. You can withdraw it at any time by emailing me and I will stop. Withdrawing it does not undo anything I did before you withdrew it, and I may still need to keep a limited record for insurance and legal reasons, which is explained in section 9.

6. Confidentiality, and the limits of it

What you tell me stays between us. There are three narrow exceptions.

  1. If I believe you or someone else is at serious risk of harm, I may need to pass information to your GP, to emergency services or to another appropriate body.
  2. If I am required to by law, for example a court order.
  3. If it involves the safeguarding of a child or an adult at risk.

Where I have to do this, I rely on Article 9(2)(c) of the UK GDPR, protecting someone’s vital interests, where you are not able to give consent, or on the safeguarding condition in paragraph 18 of Schedule 1 to the Data Protection Act 2018. I keep an Appropriate Policy Document explaining how I meet that condition and you can ask me for a copy.

Wherever it is safe and appropriate to do so, I will tell you first.

If you are in crisis right now, please do not wait for our next session. Samaritans are there day and night on 116 123, and your GP or NHS 111 can help too.

7. Who else sees your information

I do not sell your information. I do not share it for anyone else’s advertising. It is shared only with the services I use to run the practice, and only so far as they need it.

  • HeyClients, my client management system, website, booking and email platform. Your contact details, your notes and your booking history sit here.
  • Zoom, for sessions and any recordings you have agreed to.
  • Microsoft 365 and Google, for email, calendar and file storage.
  • Stripe, for taking payment.
  • My insurer and professional advisers, only if there is a claim or a complaint.

HeyClients, Zoom, Microsoft, Google and Stripe act as my processors, which means they act on my instructions and under a contract with me. My insurer and my professional advisers act in their own right and have their own duties of confidentiality and data protection.

If I ever start taking your work to a coaching supervisor, which is normal practice and done using first names or no names at all, I will update this policy and tell you first.

8. Where your information is stored

Some of the providers above store information outside the UK, including in the United States. Where that happens, the transfer is protected either by UK adequacy regulations, including the UK Extension to the EU to US Data Privacy Framework, or by the standard contractual protections that UK law requires, such as the International Data Transfer Agreement or the UK Addendum.

If you would like the detail on a specific provider, email me and I will tell you what is in place.

9. How long I keep it

Type of record How long
Enquiries that do not become clients 12 months from your last contact
Client records and session notes 7 years from the end of our work together. This reflects the six year period in which a claim can normally be brought under the Limitation Act 1980, plus a margin
Session recordings and transcripts 12 months after the session, then deleted
Payment and accounting records At least 5 years after the 31 January submission deadline for the relevant tax year, which is what HMRC requires of self employed records
Mailing list details Until you unsubscribe, after which I keep only enough to make sure you are not emailed again
Website analytics 14 months, then deleted

When a retention period ends, records are deleted or securely destroyed.

10. Cookies

My website uses cookies. Some are strictly necessary to make the site work, such as remembering your booking form or keeping the site secure, and these do not need your consent.

Some cookies only count how the site is being used so that I can improve it, or remember how you like the site to display. Under the rules that came into force on 5 February 2026 these do not need your consent, but you can turn them off at any time, free of charge, in the cookie settings on the site.

Anything used for marketing, and anything that shares your information with another company for its own purposes, is only set if you agree. You can change your mind at any time through the cookie settings or by clearing cookies in your browser.

11. Keeping your information safe

Accounts are protected with strong, unique passwords and two-factor authentication where the provider offers it. Devices are password protected and encrypted. Session notes are kept in HeyClients rather than in loose documents or notebooks, and paper notes, if I make any, are destroyed once typed up.

No system is perfect. If something did go wrong I would record it, and where the breach is likely to put your rights at risk I would report it to the Information Commissioner’s Office without undue delay and within 72 hours of becoming aware of it. If it were likely to put you at high risk, I would tell you directly and without undue delay, and explain what you can do.

12. Your rights

You have the right to:

  • be told how your information is used, which is what this policy is for
  • ask for a copy of the information I hold about you
  • have it corrected if it is wrong or incomplete
  • ask me to delete it, though I may need to keep some of it for the reasons in section 9
  • ask me to pause using it while a query is sorted out
  • object to me using it where I rely on legitimate interests, and to stop direct marketing at any time, which is an absolute right
  • ask for it in a portable format so you can take it elsewhere
  • withdraw consent at any time, where consent is what I am relying on
  • unsubscribe from my emails, using the link in every one
  • complain, to me if you would like to, and to the Information Commissioner’s Office at any time, as set out in section 13

There is no charge in almost every case. I will respond within one month, and that month runs from when I have confirmed who you are or received any clarification I have had to ask for. If a request is complicated, or you have made several, I can take up to two further months and will tell you why within the first month. I would only charge a fee, or refuse, if a request were manifestly unfounded or excessive.

No decision about you is made by automated means. The only analysis I do is seeing which of my emails get opened or clicked, so that I can tell what is useful. It has no effect on the support you get and you can ask me to stop.

To use any of these rights, email [email protected].

13. Complaints

If you are unhappy with how I have handled your information, please tell me. You have the right to complain directly to me and I would much rather hear it and put it right.

You can complain using the complaints form on my website, by email to [email protected] with “Data protection complaint” in the subject line, or by post to the address in section 2. I will acknowledge your complaint within 30 days, look into it properly, keep you updated on progress and tell you the outcome without undue delay.

You can also complain to the Information Commissioner’s Office, at any time. Coming to me first does not take away that right.

  • Website: www.ico.org.uk/make-a-complaint
  • Helpline: 0303 123 1113
  • Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

If your complaint is about me as a practitioner rather than about your information, I am a member of the Association for NLP (ANLP), and they have their own complaints process for complaints about members. You can find it at www.anlp.org.

14. Children

Beyond Grief is for adults. I do not knowingly collect information about anyone under 18 through my website or mailing list.

15. Changes to this policy

I will update this policy when the way I work changes. The date at the top tells you which version you are reading. If a change materially affects you, I will let current clients know by email.

If anything in here is unclear, or you want to know what I hold about you, email [email protected] and I will answer you properly.

Displaying PASTETHISprivacypolicy.txt.