SIMPLY CALM

Data Protection Policy

Version 1.0  ·  May 2026  ·  Alison Thompson & Carmen Kellock


This policy sets out Simply Calm Ltd’s internal approach to data protection and compliance with UK GDPR and the Data Protection Act 2018.


1. Introduction

Simply Calm Ltd is committed to ensuring that all personal data is collected, stored, used, and disposed of in compliance with UK GDPR and the Data Protection Act 2018. This policy sets out our internal procedures and responsibilities.


2. Data Protection Principles

Simply Calm Ltd will ensure that all personal data is:

  • Processed lawfully, fairly, and transparently

  • Collected for specified, explicit, and legitimate purposes

  • Adequate, relevant, and limited to what is necessary

  • Accurate and, where necessary, kept up to date

  • Retained only for as long as necessary

  • Processed in a manner that ensures appropriate security


3. Roles and responsibilities

Data Controller: Simply Calm Ltd (SC883535)

Responsibility for data protection compliance rests jointly with both directors:

  • Alison Thompson — Lead responsibility for client data and referral information

  • Carmen Kellock — Lead responsibility for marketing data and mailing lists


4. Data we hold and where we hold it

Simply Calm Ltd holds personal data in the following systems:

  • Google Drive (atckconsulting@gmail.com) — client referral forms, business records

  • Gmail — client and business communications

  • Squarespace — website form submissions, newsletter signups

  • Stripe — payment records (we do not hold card data)

  • Mailchimp or equivalent — newsletter subscribers

  • Xero — financial records


All systems used by Simply Calm Ltd are selected on the basis of their security credentials and GDPR compliance. Access is restricted to the two directors only.


5. Data retention schedule

Data type

Retention period

Client referral forms

2 years

Legitimate interests

Session records

7 years

Professional obligation (NMC)

Financial records

7 years

Legal obligation (HMRC)

Newsletter subscribers

Until unsubscribe

Consent

Website enquiries

2 years

Legitimate interests

Safeguarding records

10 years

Legal obligation


6. Data security

Simply Calm Ltd takes the following measures to protect personal data:

  • All Google accounts are protected by strong passwords and two-factor authentication

  • Sensitive documents in Google Drive are set to restricted access (not shared publicly)

  • Devices used to access personal data are password protected

  • Personal data is not shared via unsecured channels such as SMS

  • Referral forms returned by email are moved to a secure Drive folder immediately on receipt

  • Financial data is processed only through Stripe and Xero — no card data is stored


7. Data breaches

In the event of a data breach, Simply Calm Ltd will:

  1. Assess the risk to individuals affected

  2. Where the breach poses a risk to individuals’ rights and freedoms, notify the ICO within 72 hours

  3. Where the breach poses a high risk, notify affected individuals without undue delay

  4. Document the breach, its effects, and the remedial action taken


To report a data breach or security concern: ATCKconsulting@gmail.com


8. Third party processors

Simply Calm Ltd uses the following third party processors, all of whom are GDPR compliant:

  • Google LLC — Google Workspace (Drive, Gmail)

  • Stripe Inc — payment processing

  • Squarespace Inc — website hosting

  • Mailchimp (Intuit Inc) — email marketing

  • Xero Ltd — accounting


9. Subject access requests

Any individual wishing to exercise their data rights should contact us at ATCKconsulting@gmail.com. We will respond within 30 days. There is no charge for a subject access request unless it is manifestly unfounded or excessive.


10. Review

This policy will be reviewed annually by both directors and following any significant change to our data processing activities or relevant legislation.