Protect confidentiality and privacy
Counselling records can contain highly sensitive personal information. BACP guidance expects practitioners to protect information from unauthorised access or disclosure, understand applicable data-protection responsibilities and keep records that are adequate, relevant and limited to what is necessary.
PracticeKit reduces one common source of exposure by not synchronising working client records to a PracticeKit cloud service.
It also avoids session recording and AI transcription. Client conversations are not captured or sent to an external note-generation service.
Device-only storage
Working records stay on the iPad used for the practice rather than passing through a PracticeKit account or server.
Protected access
Face ID, Touch ID or the device passcode protects access, with automatic locking after inactivity.
Encrypted exports
Optional backup files use AES-256-GCM encryption with a password chosen by the practitioner.
Privacy-aware attachments
EXIF metadata, including embedded location information, is stripped from photographs before storage.
Your responsibilities as data controller
For client records entered into PracticeKit, the practitioner or their organisation ordinarily determines the purpose and means of processing. PracticeKit cannot choose the lawful basis, special-category condition, retention period or disclosure policy for a particular practice.
Your privacy notice should clearly explain how personal data is collected, used, stored and protected; applicable rights; who may receive the information; retention; and foreseeable limitations to confidentiality.
“Device-only” does not by itself make processing UK GDPR compliant. Appropriate governance also includes a lawful basis, transparency, data minimisation, device security, backup handling, retention, disposal and procedures for individual rights.
Retention and secure deletion
There is no single retention period suitable for every counselling practice. Set and document a period based on legal requirements, insurance, contractual obligations, client group, setting and professional judgement. PracticeKit can prompt reviews of completed client records and permanently removes associated data when a client record is deleted.
Transparent error reporting
PracticeKit uses privacy-restricted Sentry error reporting to identify technical failures. Personal data transmission is disabled, and client names, notes and safeguarding information are not intentionally included. Full details are set out in the Privacy & Data Practices page.
Professional sources
- BACP: Confidentiality and record keeping
- BACP privacy notice guide
- ICO UK GDPR guidance and resources
This page describes product features, not legal advice or certification of compliance. Practitioners should consult current ICO guidance and obtain specialist advice where needed.
Keep control of where client records live
Use a practice-management tool designed to minimise unnecessary data movement.
Get early access