Last reviewed: 2026
1. Who I am
Dr. Neil Drew is a Chartered Clinical Psychologist registered with the Health and Care Professions Council (HCPC), providing adult autism and ADHD assessments, psychological therapy, medico-legal work, and professional supervision. My practice is based at The Poundbury Practice, The Pediment, 17 Buttermarket, Poundbury, Dorset.
In this policy, "I" and "me" refer to Dr. Neil Drew. I am the data controller responsible for any personal information you provide in connection with my services.
2. Data protection and your rights
I comply with UK GDPR and the Data Protection Act 2018. This means your personal information must be processed lawfully, fairly, and transparently, kept only for as long as necessary, and stored securely.
You have the right to access the information I hold about you, to request corrections, to ask for your data to be deleted or restricted, and to object to processing. If you are unhappy with how I handle your data, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
3. How I obtain your consent
Before collecting personal information, I explain what I am asking for and why. I use your information only for the purposes for which it was provided. I will not use it for marketing or share it for commercial purposes without your explicit consent.
You may withdraw your consent or ask me to stop processing your data at any time by contacting me at drneildrew@protonmail.com. Withdrawing consent may affect my ability to continue providing care, and we will discuss this together.
4. Why I need your personal data
As a registered health professional, I am required to keep accurate records of my clinical work. The information I collect is necessary to assess your needs, provide a safe and effective service, communicate with you, and meet my professional and legal obligations.
5. What information I collect
When you first make contact, I may collect your name, contact details, date of birth, GP information, and details of the support you are looking for. During assessment or therapy, I record relevant clinical information in note form, identified by initials where possible, to support your care and any reports or letters we agree together.
I collect only the information I need and avoid gathering unnecessary personal or sensitive data. I may ask you to complete questionnaires or screening measures as part of your assessment.
6. How I use your data
I use your data to arrange appointments, maintain clinical records, prepare reports or letters we have agreed, and ensure continuity of care. I may also use anonymised information for service evaluation, audit, or professional development, but this will never identify you personally.
7. How I store and protect your information
I take reasonable, industry-standard steps to protect your information from loss, misuse, unauthorised access, or disclosure. Electronic records are stored on password-protected devices and encrypted where possible. Any paper notes are kept in a locked location accessible only to me.
Video appointments are conducted using secure, encrypted platforms. I recommend you join from a private location where you cannot be overheard. Email is used for appointment arrangements and general information only, and I avoid sending sensitive clinical information by email unless we have agreed a secure method in advance.
8. Who else can see your information
I treat everything you share as confidential. I will only disclose information without your consent if the law requires it, if it is necessary to protect you or someone else from serious harm, or to protect public safety. Wherever possible, I will discuss this with you first.
As part of my professional practice, I may discuss anonymised or first-name-only cases in clinical supervision with another qualified practitioner. This is a standard professional requirement to ensure safe, high-quality practice. My supervisor does not have access to your records and is bound by the same confidentiality obligations.
9. How long I keep your information
I follow professional guidance from the HCPC and BPS, which requires clinical records to be kept clear, accurate, and complete. Health records are typically retained for seven years after the end of treatment, or longer where there is a legal or professional reason to do so. After this period, records are securely destroyed.
10. Accessing and correcting your data
You can ask to see the information I hold about you, or request corrections, at any time. I will respond within one month of receiving a written request and will provide a copy in a commonly used format free of charge. I routinely share draft reports with you before finalising them so you can request corrections at that stage.
11. Data breaches
In the unlikely event of a data breach affecting your personal information, I will take immediate steps to contain it, notify the ICO where required, and inform you of what happened and what action has been taken. The most common risk is email sent to the wrong address, so I take care to check addresses and, where possible, reply within an existing email thread.
12. Changes to this policy
I may update this privacy policy from time to time. If I make material changes, I will notify you by email or at our next appointment. The current version will always be available on this website.
13. Contact
If you have any questions about this privacy policy, or would like to access, correct, or delete your personal information, please contact me at drneildrew@protonmail.com.