Privacy policy

Last updated: 23 September 2026

This legal document applies to: https://therapy-in-english.dk

This website is owned and operated by:

Mark Colclough ApS
Smørmosetoften 8
5700 Svendborg
Denmark
CVR: 38285424
Email: [email protected]

1. Introduction

Your privacy matters. This Privacy Policy explains how Mark Colclough collects, uses, stores and protects your personal information when you visit Therapy in English, contact us or use our services. This website is intended for English-speaking individuals and couples in Copenhagen seeking psychotherapy and relationship support.

We are committed to processing your personal data in accordance with the General Data Protection Regulation (GDPR) and applicable Danish data protection legislation.

2. Data controller

The data controller responsible for processing your personal data is:

Mark Colclough ApS
Smørmosetoften 8
5700 Svendborg
Denmark

Email: [email protected]

CVR: 38285424

3. Personal data we collect

Depending on how you interact with us, we may collect and process:

  • your name, email address, telephone number, postal or billing address and preferred contact method;
  • details about a partner, family member or other participant that you provide for a joint service;
  • enquiries, correspondence and callback requests;
  • appointment requests, confirmations, service type, location, attendance, changes, cancellations and booking history;
  • account and authentication information used for the booking system;
  • billing information, invoices, payment status, transaction identifiers, refunds and disputes;
  • professional notes and information you voluntarily provide about your health, relationships, circumstances or therapeutic goals;
  • website, consent, security, device, browser, IP-address and usage information;
  • email-delivery, bounce, open and link-click information where SMTP2GO tracking is enabled; and
  • online-meeting and communications metadata generated through Zoom or WhatsApp.

We minimise what we collect. Please do not send detailed or highly sensitive clinical information through ordinary website forms, email or WhatsApp.

4. Special category data and health information

Psychotherapy enquiries and sessions may involve health information and other special-category personal data. We process such information only where it is necessary for the requested service and an applicable condition under Article 9 GDPR has been established. Where we rely on your explicit consent under Article 9(2)(a), the consent request is separate and specific. You may withdraw that consent at any time, without affecting processing already carried out lawfully.

We do not use therapy, enquiry or booking information for advertising targeting. We avoid unnecessary clinical detail in invoices, payment records, email subject lines and tracked links.

5. Why we process your data

We process personal data to respond to enquiries; arrange and provide psychotherapy or couples therapy; administer bookings, online sessions and client communications; issue invoices and receive payments; meet bookkeeping and other legal obligations; prevent spam, fraud and security incidents; verify email delivery and investigate faults; manage complaints; and, where consent has been given, measure website performance or provide marketing.

6. Legal basis for processing

The lawful basis depends on the purpose:

  • Enquiries and pre-contract steps: Article 6(1)(b) where you ask us to take steps before entering a contract, or Article 6(1)(f) legitimate interests in responding to genuine enquiries.
  • Booking, masterclass purchase, therapy administration and service delivery: Article 6(1)(b), performance of a contract or pre-contract steps.
  • Health and other special-category information: the applicable Article 9 condition, including explicit consent under Article 9(2)(a) where that is the condition relied upon.
  • Invoicing, bookkeeping and mandatory records: Article 6(1)(b) and Article 6(1)(c).
  • Website, message-delivery, fraud and security logs: Article 6(1)(f), our legitimate interests in reliable and secure operations, balanced against your rights.
  • Non-essential analytics or marketing: Article 6(1)(a) consent and the applicable electronic-communications rules.

Where we rely on legitimate interests, you may object. We will stop unless we demonstrate compelling legitimate grounds or the processing is needed for legal claims.

7. Cookies and consent

This website uses cookies to improve functionality, analyse website traffic and support relevant marketing activities.

Non-essential cookies and similar technologies that require consent are not intended to be activated until the relevant consent has been provided. Essential technologies necessary for the website to function may operate without consent where permitted by law.

You may withdraw or change your consent at any time through the cookie settings available on this website.

For further information, please refer to our Cookie Policy.

8. Service providers and data sharing

We share personal data only where necessary to operate the practice, provide the requested service, meet legal obligations or protect legitimate interests. Depending on the service and configuration, recipients may include:

  • NordicWay, WordPress and Elementor Pro — website hosting, publishing and form processing;
  • Amelia Booking — accounts, appointments and booking administration;
  • Post SMTP, SMTP2GO and our mailbox provider — email transmission, receipt, delivery and bounce logging and, while enabled, open and link-click tracking;
  • Stripe — card-payment processing, fraud prevention, transaction records, refunds and disputes where card payment is offered;
  • WhatsApp/Meta — optional practical client communications;
  • Zoom Video Communications — online sessions and associated meeting, device, network and usage data;
  • Cloudflare and Google reCAPTCHA — website delivery, security and abuse prevention;
  • Complianz — consent management; and
  • professional advisers, public authorities or other recipients where disclosure is required by law or necessary for legal claims.

Post SMTP is a locally installed component, but its logs may contain identifiable delivery information. Service-provider roles vary: some act as processors and others may act as independent controllers for defined purposes. We review the applicable terms, data-processing agreements, locations and transfer safeguards.

Information entered into enquiry and callback forms is not sold, used for advertising or transmitted to advertising platforms. It may be processed by the limited providers required to operate the website, prevent abuse and deliver the message.

Some providers may process data outside Denmark or the EEA. Where GDPR transfer restrictions apply, we use an adequacy decision, approved standard contractual clauses or another lawful transfer mechanism. You may contact us for information about the relevant safeguard.

9. AI-assisted administration

AI-assisted tools may be used for limited administrative purposes such as drafting, organising or quality-checking non-clinical communications. Personal information is minimised before use. AI tools do not replace professional judgement and are not used to make automated decisions about access to therapy or how therapy is provided. Sensitive therapy content is not used to train public AI models. Where a provider processes personal data for us, an appropriate contractual and data-protection framework is required.

Zoom recording, transcription and AI meeting features are disabled by default. They will not be used for a session unless every participant has received specific information and given prior informed agreement, and the purpose, lawful basis, access and deletion arrangements have been documented.

10. Retention of personal data

We keep personal data only for as long as necessary for the relevant purpose, legal obligation, complaint or legal claim. Our operational schedule distinguishes among:

  • callback enquiries and related correspondence: retained only as long as reasonably necessary to respond, arrange a consultation and manage any resulting relationship;
  • website submissions and active mailboxes: deleted under the documented practice schedule when no longer required;
  • delivery, bounce, open and click logs: retained only for the period required for delivery verification, fault investigation and security, then deleted or anonymised;
  • booking, masterclass purchase, client and professional records: retained for the period justified by service administration, professional obligations and potential legal claims;
  • payment and accounting records: normally retained for five years from the end of the relevant financial year where Danish bookkeeping law requires it; and
  • backups: removed through the applicable backup-rotation cycle.

Exact technical retention periods are reviewed against the settings of Elementor, Post SMTP, SMTP2GO, the mailbox, Amelia, Stripe, WhatsApp, Zoom and backup systems.

11. Confidentiality

Information submitted through this website is treated confidentially.

However, ordinary email and website contact forms should not be regarded as suitable for communicating highly sensitive personal information. Where appropriate, we may recommend a more secure method of communication.

12. Your rights

Subject to the GDPR and any applicable limitation, you may request access, correction, deletion, restriction, data portability or object to processing. You may withdraw consent at any time. You also have the right not to be subject to a solely automated decision producing legal or similarly significant effects; we do not use such decision-making for therapy services.

To exercise a right, email [email protected]. We may need to verify your identity. We normally respond within one month, although GDPR permits an extension for complex or numerous requests. You may complain to the Danish Data Protection Authority, Datatilsynet, at datatilsynet.dk.

13. Security

Appropriate technical and organisational measures are implemented to protect your personal information against unauthorised access, loss, misuse or disclosure.

Communication with this website is encrypted using HTTPS.

14. Changes to this privacy policy

We may update this Privacy Policy to reflect changes in law, technology or our services. The current version applies from the publication date shown above. Material changes will be communicated where required. An update does not retrospectively change the lawful basis or contractual terms governing completed processing.

15. Related legal documents

This document forms part of the legal framework governing the use of this website and the professional services provided by Mark Colclough ApS.

For a complete understanding of your rights, responsibilities and how your personal information is handled, we encourage you to read all of the following legal documents:

Together, these documents establish the legal framework governing the use of this website, the protection of your personal information, the use of cookies and similar technologies, and the professional relationship between you and Mark Colclough ApS.


If you have any questions regarding these legal documents or how they apply to you, please contact us at [email protected].