Privacy Policy Generator for coaches
Written for session notes, intake forms, professional confidentiality and the advice-versus-information line.
A practitioner privacy notice has to do something most templates never attempt: explain confidentiality and its limits in the same document that explains data protection. Clients read it as a statement about whether their sessions are private, so vagueness there is worse than useless.
Coaching, counselling and therapy practices hold some of the most sensitive records a small business will ever handle, usually in tools designed for something else - a booking app, a notes app and an email inbox. Session notes about mental health are special category data under GDPR and UK GDPR, needing an Article 9 condition rather than just a lawful basis.
Professional confidentiality runs alongside data protection rather than inside it. Membership bodies impose their own duties on record-keeping, supervision and disclosure, and those obligations survive independently of any privacy notice.
The second exposure is the content side. Practitioners publish extensively - blogs, newsletters, free guides, social posts - and the line between general information and personalised advice is exactly where a disclaimer does real work.
What a privacy policy for a coaching or therapy practice has to cover
The Article 9 condition relied on for health data, and in the UK the Schedule 1 condition
Session notes: what is recorded, who can access it, and the retention period your professional body sets
Confidentiality and its limits - safeguarding, legal obligation, risk to life - stated before the first session
Supervision, and that cases may be discussed with identifying details removed
Booking, payment and video platforms as recipients, with what each can see
How a coaching or therapy practice actually moves personal data
Intake and assessment forms
Health history, presenting issues, medication and emergency contacts, collected before any therapeutic relationship exists.
Session notes
The most sensitive record in the practice, often held in a general-purpose notes app with no access control.
Booking and reminder systems
Appointment data reveals that a person is receiving a particular kind of care, which is itself health data.
Supervision records
Case discussion with a supervisor, usually pseudonymised but still traceable within a small practice.
Payment and insurance claims
Where a session is claimed through insurance, the claim links identity to a category of treatment.
Newsletter and content lists
Marketing to people who have disclosed a health concern requires particular care about segmentation.
Third parties the draft will ask you about
a booking platform such as Acuity or Cliniko · Stripe · Google Workspace or Microsoft 365 · a notes or practice-management app · Mailchimp · Zoom or a secure video platform
The rules that apply
Special category data
Health, including mental health, requires an Article 9 condition. Explicit consent or the health and social care condition are the usual routes, each with its own requirements.
Professional body requirements
Membership bodies set their own standards on record-keeping, retention, supervision and the circumstances in which confidentiality may be broken.
Confidentiality and its limits
Safeguarding disclosures and legal obligations override confidentiality, and clients should be told this before the first session rather than at the point of disclosure.
Supervision
Discussing cases in supervision is processing, and clients should know it happens even when identifying details are removed.
Advertising and testimonial rules
Several professional bodies restrict testimonials, and consumer protection rules apply to outcome claims regardless.
What the generated privacy policy contains
Identity and contact details of the controller
Your legal entity, trading name, registered address and a working contact route - plus a representative or DPO where one is required.
Categories of personal data and their sources
What you collect directly, what you observe automatically, and what you receive from third parties such as payment providers or ad platforms.
Purposes and lawful basis, purpose by purpose
A table that pairs each processing purpose with its lawful basis rather than listing all six bases and hoping one fits.
Recipients and sub-processors
The categories of recipient, and for the ones that matter to users - payment, hosting, analytics, support - the named provider.
International transfers and their safeguards
Where data leaves its home jurisdiction, and the mechanism relied on: adequacy, standard contractual clauses, the UK addendum or IDTA.
Retention periods per data category
Concrete periods or the criteria used to set them, which is what regulators ask for first when a complaint lands.
Rights and how to exercise them
Access, rectification, erasure, portability, objection and restriction, with the actual route to make a request and the deadline you work to.
Complaints and supervisory authority
The regulator a user can escalate to, named, with a link - not a generic "your local authority".
The practitioner document set
Identify and record the Article 9 condition
Before the first client, and revisit it if you start taking insurance work.
Move session notes into a system with access control
And set a retention period that matches your professional body’s guidance.
Put confidentiality limits in the contracting conversation
Safeguarding, legal obligation, and supervision - explained before the first session.
Check the video platform settings
Recording, transcription and cloud retention, all off unless deliberately used with consent.
Separate the marketing list from the client record
Different purpose, different basis, different system if possible.
Publish a disclaimer on published content
Distinguishing general information from a therapeutic relationship.
Where this usually goes wrong
Session notes in a general notes app
No access control, no retention rule, and usually synced to a personal account.
No Article 9 condition identified
A lawful basis alone does not permit processing health data.
Confidentiality limits explained only after a disclosure
The limits belong in the contracting conversation and in the privacy notice, before the first session.
Marketing segmented by presenting issue
Using a health disclosure to target content is processing special category data for a new purpose.
Video sessions on a consumer platform
Recording defaults, transcript features and account settings can retain far more than the practitioner realises.
No retention schedule for closed cases
Professional bodies usually set one; the practice usually does not follow it.
Frequently asked questions
Are therapy notes special category data?
Yes. Notes about mental or physical health are health data under GDPR and UK GDPR, requiring an Article 9 condition in addition to a lawful basis, and in the UK usually a Schedule 1 condition with an appropriate policy document.
Can I use a normal booking app for a therapy practice?
You can, if it offers access control, a retention setting and a processor agreement - and if you keep clinical notes out of free-text fields that everyone in the account can read.
Do I have to tell clients about supervision?
You should. Supervision is processing, and clients are entitled to know that their case may be discussed even where identifying details are removed.
How long should I keep client records?
Your professional body usually specifies a period, and it is often long - several years after the last session, and longer where the client was a minor. That guidance is the starting point, not general minimisation instincts.
Is a privacy policy legally required?
If you process personal data, in almost every market yes. GDPR and UK GDPR require the disclosure at the point of collection, CCPA/CPRA requires a notice at collection plus an annually reviewed policy, and app stores and payment processors require a public policy URL before they will list or onboard you.
Can I copy another company’s privacy policy?
It is both a copyright problem and a compliance problem. A copied policy describes someone else’s data flows, processors and retention periods, so it is inaccurate the moment you publish it - and an inaccurate transparency notice is itself a breach of GDPR Article 13.
How often does a privacy policy need updating?
Whenever your processing changes - a new analytics tool, a new payment provider, a new market - and as a backstop, review it annually. CPRA makes the twelve-month review explicit.
Does PolicifyAI give legal advice?
No. PolicifyAI is a technology provider, not a law firm. The output is a structured, jurisdiction-aware draft that a qualified adviser should review before you rely on it.
Privacy Policy Generator for coaches
Answer a short questionnaire and get a draft written for a coaching or therapy practice. Free to start, no card required.
Generate your privacy policyOther documents a coaching or therapy practice needs
Each one is written for the same context, not a generic template.
The same document, by business type
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.