SIMPLY CALM
Data Protection Policy
Version 1.0 · May 2026 · Alison Thompson & Carmen Kellock
This policy sets out Simply Calm Ltd’s internal approach to data protection and compliance with UK GDPR and the Data Protection Act 2018.
1. Introduction
Simply Calm Ltd is committed to ensuring that all personal data is collected, stored, used, and disposed of in compliance with UK GDPR and the Data Protection Act 2018. This policy sets out our internal procedures and responsibilities.
2. Data Protection Principles
Simply Calm Ltd will ensure that all personal data is:
Processed lawfully, fairly, and transparently
Collected for specified, explicit, and legitimate purposes
Adequate, relevant, and limited to what is necessary
Accurate and, where necessary, kept up to date
Retained only for as long as necessary
Processed in a manner that ensures appropriate security
3. Roles and responsibilities
Data Controller: Simply Calm Ltd (SC883535)
Responsibility for data protection compliance rests jointly with both directors:
Alison Thompson — Lead responsibility for client data and referral information
Carmen Kellock — Lead responsibility for marketing data and mailing lists
4. Data we hold and where we hold it
Simply Calm Ltd holds personal data in the following systems:
Google Drive (atckconsulting@gmail.com) — client referral forms, business records
Gmail — client and business communications
Squarespace — website form submissions, newsletter signups
Stripe — payment records (we do not hold card data)
Mailchimp or equivalent — newsletter subscribers
Xero — financial records
All systems used by Simply Calm Ltd are selected on the basis of their security credentials and GDPR compliance. Access is restricted to the two directors only.
5. Data retention schedule
Data type
Retention period
Client referral forms
2 years
Legitimate interests
Session records
7 years
Professional obligation (NMC)
Financial records
7 years
Legal obligation (HMRC)
Newsletter subscribers
Until unsubscribe
Consent
Website enquiries
2 years
Legitimate interests
Safeguarding records
10 years
Legal obligation
6. Data security
Simply Calm Ltd takes the following measures to protect personal data:
All Google accounts are protected by strong passwords and two-factor authentication
Sensitive documents in Google Drive are set to restricted access (not shared publicly)
Devices used to access personal data are password protected
Personal data is not shared via unsecured channels such as SMS
Referral forms returned by email are moved to a secure Drive folder immediately on receipt
Financial data is processed only through Stripe and Xero — no card data is stored
7. Data breaches
In the event of a data breach, Simply Calm Ltd will:
Assess the risk to individuals affected
Where the breach poses a risk to individuals’ rights and freedoms, notify the ICO within 72 hours
Where the breach poses a high risk, notify affected individuals without undue delay
Document the breach, its effects, and the remedial action taken
To report a data breach or security concern: ATCKconsulting@gmail.com
8. Third party processors
Simply Calm Ltd uses the following third party processors, all of whom are GDPR compliant:
Google LLC — Google Workspace (Drive, Gmail)
Stripe Inc — payment processing
Squarespace Inc — website hosting
Mailchimp (Intuit Inc) — email marketing
Xero Ltd — accounting
9. Subject access requests
Any individual wishing to exercise their data rights should contact us at ATCKconsulting@gmail.com. We will respond within 30 days. There is no charge for a subject access request unless it is manifestly unfounded or excessive.
10. Review
This policy will be reviewed annually by both directors and following any significant change to our data processing activities or relevant legislation.