Beyond Grief
How I look after the information you share with me.
Last updated 23 August 2026
I know a privacy policy is not the reason you came here. But if you are going to tell me something as personal as who you have lost, you deserve to know exactly what happens to that information.
This policy explains what personal information I collect, why I collect it, who else can see it, how long I keep it and what rights you have. It applies to my website, my mailing list, enquiries, discovery calls and the coaching itself.
If anything here is unclear, please just ask.
Beyond Grief is a grief coaching practice run by Lisa Galbraith, operating as a sole trader.
I am the data controller for the information described in this policy, which means I decide what is collected and what happens to it.
There is no legal requirement for me to appoint a Data Protection Officer, so questions about your information come straight to me.
When you enquire or book a call. Your name, email address, phone number if you give it, and whatever you choose to tell me in an enquiry form, an email, a direct message or a booking form. That usually includes something about your loss and what you are looking for help with.
When we work together. Notes from our sessions covering what you are going through, what we discussed, what we agreed to work on and how things are progressing. This will include information about your health, including your emotional and mental wellbeing, and it may include information about your beliefs, your family and your circumstances. It will almost always include information about the person or pet you have lost.
Recordings. Where you agree to it, a recording or transcript of a session so that you or I can look back at it. You can say no to this and it makes no difference to the support you get. You can change your mind at any point.
Payments. Your name, billing details, what you paid, when and for what. Card details are handled by Stripe, my payment provider, not by me. I never see or store your full card number.
If you join my mailing list. Your name and email address, when you signed up, and whether you open or click the emails I send.
When you use my website. Technical information such as your IP address, browser type, the pages you look at and how you arrived. Some of this comes from cookies, which are covered in section 10.
Testimonials. If you offer to share your experience, your words and whatever name you are happy to be shown by. Only ever with your permission, taken separately and in writing. Please know that anything published on my website or social media can be seen worldwide and cannot be completely recalled once it is out there, although I will always remove it from my own channels if you ask.
What you have to give me. Your name, your contact details and enough about what you are dealing with are needed for our coaching agreement, because without them I cannot safely take you on as a client. Everything else, including session recordings and joining my mailing list, is entirely your choice.
Grief coaching means you will often talk about people other than yourself. Your partner, your parent, your child, your friend, the person you are caring for. Those details become part of your record.
That information reaches me from you rather than from them. I do not contact anyone you mention, and in almost every case telling them directly would be impossible, would take disproportionate effort, or would break your confidence, so I rely on the exemption in Article 14(5)(b) of the UK GDPR. I record only what is relevant to supporting you, and I keep it under the same terms as your own information.
Information about someone who has died is not “personal data” under UK data protection law. I treat it with the same care anyway, both because of what it means to you and because it can identify living relatives.
Under UK data protection law I need a lawful basis for using your information. Mine are set out below.
| What I use it for | Lawful basis |
|---|---|
| Responding to your enquiry and holding a discovery call | Taking steps at your request before entering a contract, and my legitimate interest in replying to people who contact me and keeping my practice running safely |
| Delivering your coaching sessions and keeping session notes | Performance of our contract |
| Health and other sensitive details within those notes | Your explicit consent (see below) |
| Recording sessions | Your consent |
| Taking payment and keeping business accounts | Performance of our contract, and my legal obligations under tax law |
| Sending marketing emails and newsletters | Your consent |
| Publishing a testimonial | Your consent, and your explicit consent for anything sensitive within it |
| Website cookies that are not strictly necessary | Your consent, except where the law says otherwise (see section 10) |
| Keeping records to defend a complaint, a claim or an insurance matter | My legitimate interests, and the establishment or defence of legal claims |
| Passing on information where someone is at serious risk | See section 6 |
You can ask me for the assessment behind any of the legitimate interests above and I will send it to you.
Information about your health, including your mental and emotional health, is treated as “special category” data and gets extra protection. So does information about your beliefs, your ethnicity, your sex life or your sexual orientation, if any of that comes up in our work.
I rely on your explicit consent to record and use that information. I ask for that consent separately from my terms and conditions, in a form you sign or confirm in writing, and it is never a condition of working with me. You can withdraw it at any time by emailing me and I will stop. Withdrawing it does not undo anything I did before you withdrew it, and I may still need to keep a limited record for insurance and legal reasons, which is explained in section 9.
What you tell me stays between us. There are three narrow exceptions.
Where I have to do this, I rely on Article 9(2)(c) of the UK GDPR, protecting someone’s vital interests, where you are not able to give consent, or on the safeguarding condition in paragraph 18 of Schedule 1 to the Data Protection Act 2018. I keep an Appropriate Policy Document explaining how I meet that condition and you can ask me for a copy.
Wherever it is safe and appropriate to do so, I will tell you first.
If you are in crisis right now, please do not wait for our next session. Samaritans are there day and night on 116 123, and your GP or NHS 111 can help too.
I do not sell your information. I do not share it for anyone else’s advertising. It is shared only with the services I use to run the practice, and only so far as they need it.
HeyClients, Zoom, Microsoft, Google and Stripe act as my processors, which means they act on my instructions and under a contract with me. My insurer and my professional advisers act in their own right and have their own duties of confidentiality and data protection.
If I ever start taking your work to a coaching supervisor, which is normal practice and done using first names or no names at all, I will update this policy and tell you first.
Some of the providers above store information outside the UK, including in the United States. Where that happens, the transfer is protected either by UK adequacy regulations, including the UK Extension to the EU to US Data Privacy Framework, or by the standard contractual protections that UK law requires, such as the International Data Transfer Agreement or the UK Addendum.
If you would like the detail on a specific provider, email me and I will tell you what is in place.
| Type of record | How long |
|---|---|
| Enquiries that do not become clients | 12 months from your last contact |
| Client records and session notes | 7 years from the end of our work together. This reflects the six year period in which a claim can normally be brought under the Limitation Act 1980, plus a margin |
| Session recordings and transcripts | 12 months after the session, then deleted |
| Payment and accounting records | At least 5 years after the 31 January submission deadline for the relevant tax year, which is what HMRC requires of self employed records |
| Mailing list details | Until you unsubscribe, after which I keep only enough to make sure you are not emailed again |
| Website analytics | 14 months, then deleted |
When a retention period ends, records are deleted or securely destroyed.
My website uses cookies. Some are strictly necessary to make the site work, such as remembering your booking form or keeping the site secure, and these do not need your consent.
Some cookies only count how the site is being used so that I can improve it, or remember how you like the site to display. Under the rules that came into force on 5 February 2026 these do not need your consent, but you can turn them off at any time, free of charge, in the cookie settings on the site.
Anything used for marketing, and anything that shares your information with another company for its own purposes, is only set if you agree. You can change your mind at any time through the cookie settings or by clearing cookies in your browser.
Accounts are protected with strong, unique passwords and two-factor authentication where the provider offers it. Devices are password protected and encrypted. Session notes are kept in HeyClients rather than in loose documents or notebooks, and paper notes, if I make any, are destroyed once typed up.
No system is perfect. If something did go wrong I would record it, and where the breach is likely to put your rights at risk I would report it to the Information Commissioner’s Office without undue delay and within 72 hours of becoming aware of it. If it were likely to put you at high risk, I would tell you directly and without undue delay, and explain what you can do.
You have the right to:
There is no charge in almost every case. I will respond within one month, and that month runs from when I have confirmed who you are or received any clarification I have had to ask for. If a request is complicated, or you have made several, I can take up to two further months and will tell you why within the first month. I would only charge a fee, or refuse, if a request were manifestly unfounded or excessive.
No decision about you is made by automated means. The only analysis I do is seeing which of my emails get opened or clicked, so that I can tell what is useful. It has no effect on the support you get and you can ask me to stop.
To use any of these rights, email [email protected].
If you are unhappy with how I have handled your information, please tell me. You have the right to complain directly to me and I would much rather hear it and put it right.
You can complain using the complaints form on my website, by email to [email protected] with “Data protection complaint” in the subject line, or by post to the address in section 2. I will acknowledge your complaint within 30 days, look into it properly, keep you updated on progress and tell you the outcome without undue delay.
You can also complain to the Information Commissioner’s Office, at any time. Coming to me first does not take away that right.
If your complaint is about me as a practitioner rather than about your information, I am a member of the Association for NLP (ANLP), and they have their own complaints process for complaints about members. You can find it at www.anlp.org.
Beyond Grief is for adults. I do not knowingly collect information about anyone under 18 through my website or mailing list.
I will update this policy when the way I work changes. The date at the top tells you which version you are reading. If a change materially affects you, I will let current clients know by email.
If anything in here is unclear, or you want to know what I hold about you, email [email protected] and I will answer you properly.