Privacy Policy
THE DRAGON MINDSET
Last Updated: August 2026
This Privacy Policy sets out how Einir Trimble (trading as The Dragon Mindset / www.thedragonwebsite.com) collects, uses, stores, and protects any personal information you provide when using our website or participating in 1-to-1 mindset, hypnotherapy, or coaching sessions.
We are committed to ensuring your privacy is protected in full accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Data (Use and Access) Act 2025.
1. Data Controller Information
Einir Trimble is the Data Controller responsible for your personal data.
-
Trading Name: The Dragon Mindset
-
Website: www.thedragonwebsite.com
-
Contact Email: info@thedragonmindset.com
-
ICO Registration Number: ZB536550
-
2. Information We Collect
We collect different types of information depending on how you interact with us:
-
Standard Personal & Contact Data: Name, email address, phone number, billing address, and transaction details processed via secure payment gateways (we do not store full payment card details).
-
Special Category Data (Health & Wellbeing Data): During 1-to-1 consultation calls and sessions, you may disclose sensitive health information, medical history, psychological goals, emotional stress factors, lifestyle habits, and personal history.
-
Technical & Analytics Data: IP address, browser type, device details, and site usage data collected via cookies.
3. Lawful Basis for Processing Data
Under UK data protection law, we rely on the following legal bases to process your information:
-
Explicit Consent (Article 9(2)(a) UK GDPR): Required for processing Special Category Data (health and emotional wellbeing information) shared during 1-to-1 sessions. You may withdraw consent at any time, though doing so will prevent us from continuing 1-to-1 work.
-
Contractual Necessity (Article 6(1)(b) UK GDPR): To deliver 1-to-1 sessions, manage bookings, and handle payments.
-
Legitimate Interests (Article 6(1)(f) UK GDPR): To run our business effectively, maintain site security, and respond to general inquiries.
-
Legal Obligation (Article 6(1)(c) UK GDPR): To comply with UK tax, legal, and accounting requirements.
4. How We Store and Protect Your Data
We maintain strict technical, physical, and organizational security measures to protect your information:
-
Physical Records: Any physical forms or handwritten session notes are stored strictly secure in locked storage within a secured premises.
-
Digital Records: Electronic forms, emails, and client records are stored on password-protected, encrypted devices using UK GDPR-compliant cloud systems.
-
Payment Security: All financial transactions are processed through encrypted, PCI-DSS-compliant payment providers (e.g., Stripe, PayPal).
5. Data Retention
-
1-to-1 Session Records: In compliance with professional practice standards, legal claims periods, and insurance requirements, client records and session notes are retained for 7 years following your final session. After 7 years, physical notes are securely destroyed and digital files permanently deleted.
-
General Website Inquiries: Retained for up to 2 years if no ongoing client relationship is established.
-
Financial & Tax Records: Retained for 6 years post-transaction to comply with UK HMRC accounting requirements.
6. Confidentiality & Third-Party Sharing
We do not sell, rent, or trade your personal information. Information disclosed in 1-to-1 sessions remains strictly confidential.
Exceptions to Confidentiality: Confidentiality during 1-to-1 work may only be broken under the following circumstances:
-
There is a legal obligation or court order requiring disclosure.
-
There is a serious, immediate risk of severe harm to yourself or others.
-
You explicitly request or permit us to share information with your GP or healthcare team.
Third-Party Service Providers: We share standard transactional data only with vetted third-party service providers necessary to operate our website and business (such as web hosting providers, booking systems, payment processors, and analytics platforms). All service providers are contractually bound to keep your data secure.
7. Cookies & Web Analytics
Our website uses small text files called cookies to analyze web traffic and improve site functionality. You can set your browser to reject cookies or manage your preferences via our on-site cookie banner. Rejecting non-essential cookies will not prevent you from using our site.
8. Your Legal Rights
Under the UK GDPR, you have the following rights regarding your personal data:
-
Right to be informed: Transparency regarding how we process your personal data.
-
Right of access: The right to request a copy of the personal data we hold about you.
-
Right to rectification: The right to request correction of inaccurate or incomplete data.
-
Right to erasure ("Right to be forgotten"): Request deletion of your data where retention is no longer required by law or insurance.
-
Right to restrict or object to processing: Limit how we use your data or object to marketing.
-
Right to data portability: Obtain a copy of your digital data in a structured, machine-readable format.
To exercise any of these rights, please contact us in writing at info@ethypnotherapy.com. We will acknowledge and respond to your request within 30 days.
9. Complaints & The ICO
If you have concerns about how your data is handled, please contact us directly first so we can resolve the issue. You also have the right to lodge a complaint with the UK data protection regulator:
Information Commissioner’s Office (ICO)
-
Website: www.ico.org.uk
-
Helpline: 0303 123 1113


