Privacy Policy

Paul Shin Therapy, Ireland
Effective date: 27 July 2026

Your privacy matters. This Privacy Policy explains how Paul Shin Therapy ("we", "us", "our") collects and uses personal data when you visit our website, contact us about therapy services, and use our secure client portal, My Sessions.

This policy is intended to meet the requirements of the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.

1. Who we are

Data Controller: Paul Shin Therapy
Contact email: info@paulshintherapy.ie

2. What data we collect

Depending on how you use the website and the My Sessions client portal, we may collect:

  • Contact details such as your name, email address, phone number, address, date of birth, and the content of messages you send
  • Account details for the My Sessions portal, including your email address and a password (stored in securely hashed form โ€” we never see your password)
  • Emergency contact details you provide, such as a contact person's name, phone number, and their relationship to you
  • Appointment details such as session dates, times, session type, and appointment status
  • Payment records such as the amount due, the payment method you selected (e.g. Revolut or bank transfer), payment references, and payment status. Payments themselves are processed by third-party providers (e.g. Revolut) or your own bank; we do not collect or store card numbers or bank login details
  • Forms you complete in the portal, such as the intake form, questionnaires, and therapy agreements, including your electronic signature (typed name and drawn signature) and the date and time of signing
  • Clinical records, meaning brief session notes kept by the therapist to support quality of care
  • Website usage data such as IP address, device type, browser type, pages visited, and approximate location based on IP

3. Special category data

Information about your health and wellbeing โ€” including intake forms, questionnaires, and clinical session notes โ€” is special category data under GDPR. We collect and use this information only to assess suitability for therapy, provide therapy services, and keep essential clinical records, with appropriate safeguards in place.

Clinical session notes are accessible only to your therapist. They are never shared with other clients, are not included in emails, and in the case of couples therapy are not visible to your partner.

4. How we collect data

  • When you fill in a contact form, or email, call, or message us
  • When you are invited to, sign up for, or use the My Sessions client portal
  • When you complete forms in the portal (intake form, questionnaires, therapy agreements)
  • When you book, confirm, or pay for appointments
  • When the therapist records brief clinical notes about sessions
  • Automatically through cookies and similar technologies (see section 9)

5. Why we use your data and our legal bases

We use personal data for the purposes below, under these GDPR legal bases:

  • To respond to enquiries and communicate with you about services
    Legal basis: legitimate interests, and steps prior to entering a contract
  • To provide therapy services, manage your portal account, schedule and confirm appointments, and keep essential clinical records
    Legal basis: performance of a contract; for health-related data, Article 9(2)(h) GDPR (provision of health or social care) together with your explicit consent where collected
  • To administer forms and agreements, including recording your electronic signature and emailing you a copy of signed agreements
    Legal basis: performance of a contract, legal obligation
  • To send you service emails about your appointments โ€” for example booking confirmations, payment reminders, and copies of signed agreements. These are service communications, not marketing
    Legal basis: performance of a contract
  • To handle payments and issue invoices/receipts
    Legal basis: performance of a contract, legal obligation
  • To maintain website and portal security, prevent abuse, and troubleshoot
    Legal basis: legitimate interests
  • To improve our website using analytics (where enabled)
    Legal basis: consent (for non-essential cookies), legitimate interests (for essential operational logs)

6. Couples therapy accounts

If you attend couples therapy, your portal account may be linked with your partner's. In that case, appointments for shared couples sessions are visible to both partners, and either partner may arrange payment for a shared session.

Your individual information remains your own: forms and questionnaires you complete, any individual sessions arranged for you, and all clinical notes are not visible to your partner.

7. Who we share data with

We do not sell your personal data. We share data only when necessary with these categories of providers:

  • Website hosting โ€” Squarespace (our website platform)
  • Secure database and portal infrastructure โ€” Supabase, which hosts the My Sessions portal data on servers located in the European Union
  • Email delivery โ€” Resend, which delivers portal service emails such as appointment confirmations (email content is limited to appointment and account information)
  • Payment processors โ€” Revolut, if you pay via a Revolut payment link, or your own bank if you pay by bank transfer
  • Professional advisers (for example accountant or legal advisers) where required
  • Clinical supervision โ€” client work may be discussed in professional supervision using anonymised information only; supervisors are bound by confidentiality

These providers act as processors and are required to protect your information. Some providers may process limited data outside the EEA (for example email delivery infrastructure). Where this happens, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (where applicable).

Confidentiality may also be limited in the exceptional circumstances set out in your therapy agreement โ€” for example where there is a serious risk of harm, a child protection concern under the Children First Act 2015, or where disclosure is required by Irish law.

8. How long we keep your data

We keep personal data only as long as needed for the purpose it was collected, including legal, tax, insurance, and professional requirements.

  • Clinical records (session notes, intake forms, signed agreements) are retained for 7 years after the last date of service (records relating to under-18s until the client's 25th birthday), in line with professional guidance applicable to psychotherapy practice in Ireland, and are then securely deleted
  • Account and appointment data is kept while you remain a client and for as long as required afterwards for the obligations above
  • Enquiry correspondence that does not lead to therapy is kept only as long as reasonably necessary

You will receive additional privacy information as part of your therapy agreement, including more specific retention and record-keeping details.

9. Your rights under GDPR

You have rights in relation to your personal data, including:

  • The right to access your personal data, including your clinical records (subject to professional judgment as described in your therapy agreement)
  • The right to rectify inaccurate or incomplete data
  • The right to erase data in certain circumstances โ€” note that we may be required to retain clinical records for professional and legal reasons even after a valid erasure request covering other data
  • The right to restrict processing in certain circumstances
  • The right to data portability (where applicable)
  • The right to object to processing based on legitimate interests
  • The right to withdraw consent at any time (where processing is based on consent)

To exercise your rights, contact us at info@paulshintherapy.ie. We may need to verify your identity before responding.

You also have the right to lodge a complaint with the Irish regulator: the Data Protection Commission (DPC).

10. Cookies and analytics

Our website may use cookies and similar technologies to ensure it works properly and to understand how it is used. Cookies are small text files placed on your device.

  • Essential cookies and local storage help the site function โ€” including keeping you securely logged in to the My Sessions portal โ€” and cannot usually be switched off
  • Optional cookies (for example analytics) are used only if enabled and, where required, with your consent

You can control cookies through your browser settings and, where available, through any cookie banner on the site. Disabling cookies may affect some site features, including the ability to stay logged in to the portal.

11. Security

We take technical and organisational measures to protect personal data, including:

  • Encryption of data in transit and at rest
  • Portal data hosted on servers located in the European Union
  • Database-level access controls, so clients can only ever access their own information
  • Passwords stored in securely hashed form
  • Clinical notes restricted to the therapist only

No method of transmission or storage is 100% secure, but we work to reduce risk and limit access to those who need it.

12. Children

This website and the My Sessions portal are intended for adults. We do not knowingly collect personal data from children. If you believe a child has provided personal data through this website, please contact us so we can delete it where appropriate.

13. Changes to this policy

We may update this policy from time to time. The latest version will be published on this page with an updated effective date.

14. Contact

If you have questions about this Privacy Policy or how we handle your data, contact:
Paul Shin Therapy
Email: info@paulshintherapy.ie