Last updated · September 2026
Privacy Policy
Atheneia is committed to protecting your privacy and handling your personal data in line with UK GDPR and the Data Protection Act 2018. This policy explains what we collect, why, and your rights over it.
Who we are
Atheneia is operated by Elena Hikmet. For the purposes of UK data protection law, Atheneia is the data controller responsible for your personal data.
If you have any questions about this policy or how your data is handled, please contact Atheneia through the contact page or via Instagram @atheneia.co.
GDPR information
In May 2018 the Data Protection Act was replaced by the General Data Protection Regulations (GDPR). The changes to the Data Protection Act are aimed at ensuring that your personal, confidential and sometimes sensitive data, is held privately and securely. This means that any data you give to Atheneia must be processed in a way you agree with. GDPR exists to protect your rights as a consumer. It applies to your identifiable data; your name, contact details, session records and any communication between the client and therapist.
1. Why information is collected
Your information is collected so as to provide appropriate and personalised hypnotherapy sessions.
There is a legal obligation to retain your records as required by professional bodies and insurers.
2. What information is collected
During our hypnotherapy sessions, I may collect:
- Contact information (name, address, phone number)
- Emergency details
- Relevant background information
- Therapy notes
This information will be collected solely in support of your therapy and will be in line with all ethical guidelines.
3. How information is stored
It is important to note that only Atheneia will have access to your data.
All physical, written records will be secured behind 2 physical locks.
All emails and electronic methods are stored in double-password-protected software. Emails require two-factor authentication to access.
4. How long information is retained for
In accordance with the National Hypnotherapy Council (NCH), information is stored securely for:
- Adult client: 8 years after the final session
- Client aged 17–18: Until they reach the age of 26
- Client aged under 16: Until they reach the age of 25
After this period of time, all records are destroyed securely and confidentially.
5. Destruction of information
All records will be destroyed securely after the above time periods. In accordance with insurance policies displayed by Holistic Insurance Services, the destruction of this data cannot be completed before the minimum holding time. This is due to the sensitive nature of hypnotherapy sessions.
6. Access to your information
In line with GDPR, you may request a copy of any information Atheneia holds, including session notes, within 30 days.
Your identity will need to be confirmed before the sending of any information.
This request must be made in written form.
7. Confidentiality
Keeping your records secure and maintaining the confidentiality of our sessions is of the utmost importance.
Your information will only be shared if it is legally required, if I believe there may be a risk of serious harm to you or others, or if seeking supervision from a supervisor. In this case, anonymity will of course be maintained.
8. Contact outside of sessions
Atheneia is obliged by GDPR to protect your confidentiality at all times. So, for this reason, Atheneia may acknowledge you, but to protect your privacy, will not approach you. If you choose to discuss your therapy with other people, that is your choice and you are welcome to do so.
9. Information sharing
Atheneia will only share your information with other social or healthcare practitioners with your written consent.
Should they write to your GP, to notify them that you have entered into a therapeutic relationship with them, or to notify them that your therapy has been successfully concluded, Atheneia would require your signature, in line with GDPR requirements.
Atheneia has a duty of care towards their clients, so the only exceptions to this would be if they believed that you were about to harm yourself or others. Should this occur, then Atheneia would be required to inform the relevant authorities.
However, Atheneia would always aim to discuss this with you before taking any action.
Legally, Atheneia would also have to provide the police with information as set out in a warrant or court order, should the situation arise.
10. Data controller
Elena Hikmet is the data controller for any and all information collected during these hypnotherapy sessions.
ICO registration: ZC181787
Newsletter consent
You will only receive the Atheneia Journal if you have actively consented by submitting your email. You can unsubscribe at any time using the link in any email, or by contacting Atheneia.
Contact form consent
By submitting the contact form you consent to Atheneia holding the details you provide for the purpose of responding to your enquiry. Your details are not used for anything else without your permission.
Data retention
Contact enquiries are retained only as long as needed to respond and complete any follow-up. Newsletter subscriptions are retained until you unsubscribe. Client records are retained in line with professional best practice and your instructions.
Third-party services
Atheneia uses a small number of third-party services to operate the website – for example hosting, email delivery and, where enabled, analytics. Each processor acts on Atheneia's instructions and is expected to meet appropriate data protection standards.
Analytics & website cookies
Where analytics are enabled, Atheneia uses anonymous, aggregated data to understand how the site is used. You can manage your cookie preferences at any time from the Cookie Preferences link in the footer. See the Cookie Policy for full details.
Changes to this policy
This policy may be updated from time to time. The date above will reflect the most recent revision.
This page is provided as a placeholder structure for launch. Have the final wording reviewed by a qualified legal professional before publishing.